ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
View Original →
FAQ #1069 Published

Does PCI DSS apply to paper with cardholder data (for example, receipts, reports, etc.)?

Yes, PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted by any media, including paper records. PCI DSS Requirements 9.5 through 9.8 specifically addresses the safeguarding of physical media, including paper records, containing cardholder data.

(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.