Requirement 3.2.1

Do not store the full contents of any track from the magnetic stripe (located on the back of a card, contained in a chip, or elsewhere).

This data is alternatively called full track, track, track 1, track 2, and magnetic-stripe data.
Note: In the normal course of business, the following data elements from the magnetic stripe may need to be retained:

  • The cardholder’s name,
  • Primary account number (PAN),
  • Expiration date, and
  • Service code

To minimize risk, store only these data elements as needed for business.

Note: See PCI DSS Glossary of Terms, Abbreviations, and Acronyms for additional information.