What is payment card data retention?
Payment card data retention covers how long an organization keeps cardholder data and what it may never keep. PCI DSS prohibits storing sensitive authentication data, such as the CVV or full magnetic stripe data, after authorization. Other cardholder data must be kept only as long as there is a business need.
What the buyer is really asking
PCI DSS forbids storing sensitive authentication data such as CVV after authorization and requires a retention limit for anything else. If your processor tokenizes cards, say you keep only tokens and the last four digits. Otherwise give the retention period and how data is purged.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you limit retention of payment card data?”
- “Do you store CVV or full track data?”
- “How long do you keep cardholder data?”
Evidence to have ready
- The card data section of your retention policy
- Processor documentation showing tokenization
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.