Payment data safety

Can a merchant email credit card information?

A merchant should not use ordinary email as a routine way to request, send, or receive full credit card numbers. PCI DSS does not impose a blanket ban on every email use, but when a primary account number (PAN) travels through an end-user messaging channel, that channel and its supporting systems must meet applicable PCI DSS protections. For most businesses, the practical choice is to keep card data out of email and direct customers to a purpose-built payment method.

The direct answer

Email is only appropriate for a full PAN when the entire transmission process is secured with strong cryptography and handled within the merchant's properly scoped cardholder data environment. Simply placing a confidentiality notice in a message, password-protecting an attachment, masking only part of the message, or assuming a familiar email provider is secure does not by itself establish that the workflow satisfies PCI DSS.

A safer operating rule is straightforward: do not ask customers to type card numbers, security codes, passwords, bank credentials, or secret keys into ordinary email. Use a payment page, hosted invoice, approved virtual terminal, or another channel designated by the merchant's payment provider. Learn more about evaluating payment gateways and payment processing workflows.

Why an emailed card number changes scope

PCI Security Standards Council guidance says that if email or another end-user messaging technology sends or receives a PAN, the channel must be protected under all applicable PCI DSS requirements. Systems related to that channel, such as email servers, mailboxes, archives, backup systems, endpoints, and administrative access, may become part of the cardholder data environment. Encryption does not automatically remove encrypted cardholder data from PCI DSS scope.

This is why an email workflow can create responsibilities far beyond the individual message. Copies may remain in sent folders, synchronized devices, shared mailboxes, security archives, backups, support tools, or quoted replies. A merchant should have its acquirer, payment provider, or qualified security assessor evaluate any proposed card-data workflow before using it.

What to do when card data arrives unexpectedly

Do not reply while leaving the card information in the quoted message. Do not forward it to a coworker, copy it into a ticket, or paste it into an ordinary chat. Instead, follow the organization's documented incident and data-handling procedure. Contact the customer through an approved channel, explain how to complete payment securely, and avoid repeating the account number.

PCI SSC guidance describes two broad paths: secure the channel and include it within the cardholder data environment, or prevent the channel from capturing card data and securely remove the data before it is further stored, processed, or transmitted. Deletion must follow the merchant's approved procedure because removing a message from one mailbox may not remove retained copies elsewhere. Escalate uncertainty to the designated security contact or payment provider.

Build a safer customer process

Give customers one clear payment route

Put the approved payment link or instructions on invoices, order confirmations, and support responses. Tell customers explicitly that general email and contact forms are not payment channels. A consistent route reduces accidental disclosure and makes staff responses easier to standardize.

Train staff for accidental receipt

Provide a short playbook that identifies whom to notify, which approved channel to offer, how to avoid propagating the data, and who is authorized to perform secure removal. Training should cover shared mailboxes, mobile devices, attachments, screenshots, and automated ticket creation.

Limit collection

Collect only the information required for the transaction through the approved system. Never request card verification codes for storage after authorization. Review retention settings and access privileges with the people responsible for security and compliance.

Questions to verify with your provider

  • Which payment channel should staff offer when a customer tries to email card data?
  • Does the proposed workflow send or store a full PAN anywhere outside the approved payment system?
  • Which mailboxes, servers, devices, backups, and integrations would enter PCI DSS scope?
  • What is the documented response when data arrives through an unintended channel?
  • Who confirms secure removal and records the incident?

The exact controls and validation obligations depend on the merchant's environment. PCI SSC guidance is authoritative for the standard, while the merchant's acquirer and payment brands determine validation and program requirements. The Payments Max FAQ offers additional payment-operation guidance.

Choose an appropriate payment workflow

If your team currently receives card details through email, map where those messages travel before changing the process. Then ask your payment provider or security assessor to confirm the approved collection method and incident procedure. For general help evaluating payment options, contact Payments Max. Do not submit cardholder data, passwords, bank credentials, complete account numbers, or secret API keys through the contact form.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US