Get fresh insights, pro tips, and thought starters–only the best of posts for you.
Cardholder data (CHD) is the full Primary Account Number (PAN) or the PAN together with related card details such as the cardholder name, expiration date, or service code. According to the Payment Card Industry Data Security Standard (PCI DSS), these data elements must be protected when stored, processed, or transmitted within payment environments.
Organizations that handle payment card information must protect CHD to reduce the risk of fraud, unauthorized access, and compliance violations.
PCI DSS distinguishes between cardholder data and sensitive authentication data (SAD). While both require protection, they are subject to different storage and security requirements.
| Data Type | Examples |
| Cardholder Data (CHD) | PAN, cardholder name, expiration date, service code |
| Sensitive Authentication Data (SAD) | CVV/CVC, PINs, PIN blocks, full magnetic stripe data |
A key distinction is that sensitive authentication data generally cannot be stored after authorization, whereas certain CHD elements may be retained if properly protected according to PCI DSS requirements.
Payment card data is sensitive because it can be misused for fraud and unauthorized transactions if exposed.
Failure to secure CHD can result in:
To mitigate these risks, organizations must implement technical, administrative, and physical security controls across their payment environments.
Protecting cardholder data requires a layered security approach that aligns with PCI DSS requirements.
Common security controls include:
| Security Control | Purpose |
| Encryption | Protects data confidentiality |
| Access controls | Restricts data access to authorized users |
| Network segmentation | Limits exposure of payment systems |
| Multi-factor authentication (MFA) | Strengthens account security |
| Logging and monitoring | Detects suspicious activity |
| Vulnerability management | Identifies and addresses security weaknesses |
Organizations should also minimize data retention and store only the information necessary for business operations.
Organizations handling payment information must ensure that endpoints accessing payment systems remain secure and compliant.
Hexnode UEM helps organizations manage and secure corporate devices through centralized endpoint management, security policies, compliance monitoring, application management, device restrictions, and remote management capabilities. By improving endpoint visibility and helping enforce security controls across managed devices, Hexnode can support PCI DSS-aligned endpoint security and CHD protection initiatives.
Although the terms are often used together, they are not interchangeable.
| Cardholder Data | Sensitive Authentication Data |
| Includes PAN and related card details | Includes CVV, PINs, and magnetic stripe data |
| May be stored under PCI DSS requirements if protected | Generally cannot be stored after authorization |
| Used to identify a payment account | Used to authenticate a payment transaction |
| Subject to PCI DSS protection requirements | Subject to stricter PCI DSS restrictions |
Understanding the difference helps organizations apply the correct security and compliance controls.
CHD refers to payment card information associated with a cardholder, including the Primary Account Number and certain related data elements. Because payment information is highly sensitive, organizations must implement strong security controls, maintain PCI DSS compliance, and secure the endpoints that interact with payment environments.
It depends on whether the token can be associated with or used to retrieve the original PAN within the payment environment.