Account Data
Account data is the payment card information involved in a transaction, made up of cardholder data and/or sensitive authentication data. Because it is a prime target for attackers, storing or handling it creates significant risk and must be protected under defined security controls.
In PCI DSS terminology, account data is the umbrella term for cardholder data and/or sensitive authentication data. Cardholder data includes the primary account number (PAN) and, when present, cardholder name, expiration date, and service code; some of this data may be stored under defined controls (for example, the PAN must be rendered unreadable per applicable requirements). Sensitive authentication data includes full track data, card verification codes/values (such as CAV2/CVC2/CVV2/CID), and PINs/PIN blocks, and must not be stored after authorization even if encrypted. Note that requirement numbering and wording differ across PCI DSS versions, so confirm specifics against the current published standard.
Why it matters
Account data is the core asset that most payment security controls are designed to protect. Because it consists of cardholder data and/or sensitive authentication data, it is a prime target for attackers, and any system that stores, processes, or transmits it creates a significant, business-critical exposure. Understanding what falls under account data is the starting point for defining PCI DSS scope: environments that touch this data are subject to the standard's controls, while accurately identifying and reducing where account data lives can shrink both scope and risk.
The distinction within account data matters enormously in practice. Cardholder data (the PAN and, when present, cardholder name, expiration date, and service code) may be stored under defined controls, such as rendering the PAN unreadable. Sensitive authentication data (full track data, card verification codes such as CAV2/CVC2/CVV2/CID, and PINs/PIN blocks) must not be stored after authorization, even when encrypted. Confusing these two categories is a common source of compliance failures, since a control that is acceptable for one may be prohibited for the other.
Because the term "account data" is used differently in other domains (for example, ERP account master data or user account information in consumer platforms), teams should be careful to use it in the specific PCI DSS sense when discussing payment security. Misapplying the term can lead to mis-scoping and to controls being applied to the wrong data. Note also that requirement numbering and wording differ across PCI DSS versions, so specifics should be confirmed against the current published standard rather than assumed.
Who it's relevant to
Inside Account Data
Common questions
Answers to the questions practitioners most commonly ask about Account Data.