Cardholder Name
The cardholder name is the name printed on a credit or debit card that identifies the person who owns the card and is authorized to use it. It is commonly entered during online checkout and located on the front of the card. It is one of the pieces of information used to identify whom a card belongs to.
The cardholder name is a data element identifying the individual to whom a payment card is issued, typically printed on the front of the card. Under PCI DSS terminology it is classified as cardholder data rather than sensitive authentication data, distinguishing it from full track data, card verification values (CAV2/CVC2/CVV2/CID), and PINs/PIN blocks, which must not be retained after authorization. As cardholder data, the cardholder name may be stored under defined security controls; its precise handling, protection, and effect on assessment scope should be confirmed against the current published PCI DSS standard, as requirement wording and numbering vary by version.
Why it matters
The cardholder name is one of the data elements used to identify whom a payment card belongs to and who is authorized to use it. Because it is classified under PCI DSS terminology as cardholder data rather than sensitive authentication data, it sits in a different category from full track data, card verification values (CAV2/CVC2/CVV2/CID), and PINs or PIN blocks, which must not be retained after authorization. Cardholder data such as the name may be stored under defined security controls, but that permission comes with responsibility: any system that stores, processes, or transmits it may fall within assessment scope and require appropriate protection.
For organizations handling payments, treating the cardholder name correctly matters because misclassifying data elements can lead to gaps in controls or to over-retention of information that should be minimized. While the cardholder name is not sensitive authentication data, it is still personally identifying and is commonly combined with other cardholder data during checkout. How it must be protected, and whether storing it affects scope, depends on the implementation and on the current published PCI DSS standard rather than on the label alone.
Because requirement wording and numbering vary between PCI DSS versions, teams should confirm the specific handling and protection obligations for the cardholder name against the current published standard rather than assuming a fixed requirement. This avoids applying outdated guidance and helps ensure that data classification decisions remain aligned with the applicable version.
Who it's relevant to
Inside Cardholder Name
Common questions
Answers to the questions practitioners most commonly ask about Cardholder Name.