{"id":1209,"date":"2021-03-12T09:31:07","date_gmt":"2021-03-12T09:31:07","guid":{"rendered":"http:\/\/www.pcidssguide.com\/?p=1209"},"modified":"2023-10-09T16:22:14","modified_gmt":"2023-10-09T16:22:14","slug":"what-are-the-pci-dss-data-retention-and-disposal-requirements","status":"publish","type":"post","link":"https:\/\/pcidssguide.com\/what-are-the-pci-dss-data-retention-and-disposal-requirements\/","title":{"rendered":"What are the PCI DSS Data Retention and Disposal Requirements?"},"content":{"rendered":"\n\n\n\n\n

Requirement 3.1 of the Payment Card Industry Data Security Standard (DSS) requires organizations to retain and follow data retention and disposal procedures. The purpose of the data storage and destruction procedure is to ensure that records no longer needed are deleted promptly and adequately.<\/p>\n\n\n\n

The PCI only allows the following credit card information storage if there is a recorded and authorized business need. All data must be secured in accordance with the PCI DSS in all sections. Storage of the following cardholder data protected as required by PCI DSS is permitted under this provision:<\/p>\n\n\n\n