What is Credit Card Data?
Credit card data is considered sensitive, private data and specific credit card data, as defined by the Payment Card Industry Data Security Standards (PCI DSS), may or may not be collected or stored.
The following table illustrates commonly used elements of cardholder and sensitive authentication data; whether storage of each data element is permitted or prohibited; and if each data element must be protected. This table is not exhaustive, but is presented to illustrate the different types of requirements that apply to each data element.
PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted. If a PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply.
Definitions of Data Elements:
- Primary Account Number is the sixteen digit card number.
- Cardholder Name is the name of the person on the card.
- Service Code is the three or four digit number on the magnetic-stripe that specifies acceptance requirements and limitation for magnetic-stripe read transactions.
- Expiration Date is the expiration data shown on the card.
- Full Magnetic Stripe is the data stored in the magnetic strip on the card.
- CVC2/CVV2/CID is the three digit code on the back of the card.
- PIN / PIN Block is the personal identification number assigned to the card.
Storing and Handling Credit Card Data
Under the PCI DSS if ANY electronic files contain data elements that require protection they must be encrypted with 128 bit encryption and must have a password associated with the encrypted file. In addition the network used to store the electronic files must be separated from the “primary” network and additional security measures apply in order to meet the PCI DSS compliance requirements.
Due to these strict compliance requirements and the risk associated with not properly securing credit card data, the Girl Scouts of Northern California chooses NOT to store or transmit any Cardholder data or Sensitive Authentication data electronically. The only exception is procesing transaction through our current Point of Sale systems, the Square service and the approved third party vendors listed below.
Furthermore, credit card data may not be emailed under any circumstances. Scanned images, photocopies, word processing or spreadsheet documents may NEVER be used, in any form, to SAVE or transmit Cardholder or Sensitive Authentication data. Faxing forms that contain credit card data should not be done. Fax machines store the fax image electronically.
All credit card data, as previously defined, must be handled in a secure manner. If credit card data is received by fax, hard copy or exists on other hard copy paper format (such as the Girl Scouts membership forms), the paper must be secured under lock while the credit card data is waiting to be processed. Once the credit card data has been used for payment purposes, the credit card data must be destroyed by use of a cross-cut shredder.
As a best practice, paper forms should not be used to accept credit card data for processing. All credit card transactions should be completed by the participant and the GSNorCal Point of Sale systems, the Square provided devices, or through PCI compliant third party online service providers.
Where volunteers are involved in the collection of credit card data on paper forms for processing by the Girl Scouts of Northern California or an Online Service Provider, the volunteers must:
- Never email, save or otherwise store or record the credit card data electronically under any circumstances.
- Ensure that they keep close, personal control of paper forms while information is collected and prior to transferring the forms to the Girl Scouts of Northern California or entering it into the Online Service Provider.
- Strive to ensure that they relay any paper forms with credit card data to the Girl Scouts of Northern California or their Online Service Provider as soon as possible after collecting the information.
- Ensure that any forms that are in their possession that contain credit card data, must be destroyed, preferably by cross cut shredders, and are never kept or stored for any reason after their intended use.
- Ensure that under NO CIRCUMSTANCES, anyone photo copies, scans, emails, faxes or otherwise electronically stores or transmits any credit card data, except through the GSNorCal Point of Sale systems, the Square devices or PCI compliant third party online service providers.