Account Data Compromise
An Account Data Compromise (ADC) is an incident in which an unauthorised person gains access to card payment data within a business's environment, typically with the intent to misuse it. Card networks treat such incidents as ADC events, which can trigger investigation, notification, and response obligations. Because an ADC involves compromised payment data, it may carry costs beyond those of a general data breach.
An Account Data Compromise (ADC) is an event in which account data held or processed in a merchant, issuer, or acquirer environment is accessed by an unauthorised party, generally with intent to exploit that data. Card networks such as Mastercard define and manage ADC events through published rules and alert processes, with obligations that vary by the date the first ADC Alert is published and by the parties involved. An ADC event follows a lifecycle spanning pre-breach, during-breach, and post-breach activities, and issuers and acquirers are expected to understand this lifecycle and maintain incident response capabilities. Note that the specific ADC rules, alert procedures, and financial responsibilities are governed by individual card brand and network programs and differ by region and version; readers should confirm current requirements against the applicable network's published ADC documentation.
Why it matters
An Account Data Compromise is treated by card networks as a distinct category of incident, not simply a general data breach. Because an ADC involves card payment data specifically, it can carry costs and obligations beyond those of an ordinary data breach, including network-driven investigation, notification, and response requirements. General breach cost figures circulate widely, but these represent broad data-breach studies rather than ADC-specific measurements; exact ADC costs depend on the incident, the parties involved, the card brand programs that apply, and the region, and should not be assumed from general breach statistics.
For merchants, issuers, and acquirers, the practical significance of an ADC is that it can trigger formal obligations under a card network's published ADC rules and alert processes. These obligations vary by the date the first ADC Alert is published and by the parties involved, which means the timing and content of an ADC Alert can directly shape what a business must do and what financial responsibility it may bear. Confirming current requirements against the applicable network's published ADC documentation is essential, because the specific rules, alert procedures, and financial responsibilities differ by card brand, region, and version.
Because an ADC event follows a lifecycle spanning pre-breach, during-breach, and post-breach activities, the value of preparation is high. Organisations that understand this lifecycle and maintain incident response capabilities are better positioned to meet notification timelines and network obligations if an ADC occurs. Treating an ADC as a payment-security incident with its own governance, rather than folding it into generic breach handling, helps ensure the correct network processes are followed.
Who it's relevant to
Inside ADC
Common questions
Answers to the questions practitioners most commonly ask about ADC.