Hacker News new | ask | show | jobs
by CoachRufus87 5517 days ago
is it a PCI violation to store the expiration month/year of a customers CC (for the purpose of knowing when a CC expires and reminding the card holder to update their info)
1 comments

I believe it is a violation to store the expiration date without encrypting it. I could be wrong, here is a link to PCI DSS standards documents.
hey could you send me that link again?

Edit: I looked up the document, TL;DR - you don't need to encrypt the cardholder name, service code, or expiration date unless you are also storing an associated primary account number.