Card data handling

Can employees write down card numbers?

Employees should not routinely write down complete card numbers. A paper note containing a primary account number, or PAN, is cardholder data and remains subject to PCI DSS safeguards. If a temporary written record is genuinely necessary for an approved business process, the organization must control access, retention, transport, storage, and destruction. Card verification codes and other sensitive authentication data must not be stored after authorization, even on paper.

Paper does not remove card data from scope

Writing information on a form, order slip, receipt, or note does not make it harmless. PCI Security Standards Council FAQ 1069 states that PCI DSS applies whenever a PAN is stored, processed, or transmitted on any medium, including paper. Physical records containing cardholder data therefore need safeguards appropriate to their use and environment.

The safest routine is to avoid creating the record. Employees should enter payment details directly into an approved payment channel when the business process permits it. Handwritten notes, sticky notes, notebooks, and unattended order forms are difficult to monitor and easy to copy, misplace, photograph, or discard incorrectly.

Never retain sensitive authentication data after authorization

A card verification code, sometimes called CVV, CVC, CID, or a similar brand-specific term, is sensitive authentication data. PCI SSC guidance says this data cannot be stored after authorization, even when encrypted. The same prohibition applies to full magnetic-stripe or chip-equivalent track data and PIN or PIN-block data.

An employee should not add a security code to a customer profile, spreadsheet, paper order file, notebook, or future-payment instruction. If a documented payment workflow temporarily captures a security code before authorization, the business must follow its provider and payment-brand requirements and ensure the value is not retained after authorization. This page does not establish that a particular workflow is eligible or compliant.

Use a safer decision path

For an immediate payment

Use the approved terminal, hosted checkout, invoice, payment link, or virtual terminal assigned to the transaction. Do not copy card details into a separate note for convenience.

For a future payment

Use a provider-supported card-on-file or tokenized workflow when available and authorized. Do not retain the full card number or security code as a homemade substitute.

For a paper-based exception

Pause and confirm the written procedure, business need, permitted data fields, access controls, retention period, secure storage, and destruction method with the responsible compliance contact.

Control any approved paper records

If an approved process produces paper containing a PAN, restrict access to personnel with a legitimate business need. Keep the record in controlled storage, maintain custody during movement, and prevent unauthorized viewing or copying. Do not leave it at a register, reception desk, delivery area, shared printer, vehicle, or open workspace.

PCI SSC FAQ 1318 explains that PCI DSS does not set one universal maximum retention period for cardholder data. Instead, storage should be limited to what is necessary for legal, regulatory, or business purposes under a documented retention and disposal policy. When the record is no longer required, destroy it so the account data cannot be reconstructed. The appropriate method depends on the medium and the organization's documented process.

Respond carefully to an unexpected note

If an employee discovers a note, form, image, or file containing card details outside the approved workflow, do not circulate it or photograph it for convenience. Limit further exposure, preserve relevant facts, and notify the organization's security, privacy, or compliance contact through the established reporting process. Follow that team's instructions for containment and secure disposal.

Do not paste the card number into chat, email, a support ticket, or a general contact form while asking for help. Record non-sensitive context instead, such as where the item was found, when it was discovered, and who has controlled custody. If the business suspects unauthorized access, use its incident response plan and provider notification process.

Train employees around the actual payment workflow

A short rule such as "never write card numbers" is a strong default, but training should also show employees what to do instead. Identify the approved tools for phone orders, invoices, recurring payments, delayed charges, and other common situations. Explain which data must never be retained, where to report a mistake, and who can approve an exception.

Review the PCI compliance FAQ hub for related scope questions, explore fraud prevention and security guidance, and compare approved remote-payment options through the virtual terminals, invoicing, and payment links hub. The right control depends on how the business accepts payments and which systems handle account data.

Replace informal notes with an approved process

Map the situations that currently lead employees to write down card details, then ask the payment provider or qualified compliance contact for an approved alternative. Update procedures and training before changing the workflow. When requesting general guidance, never submit cardholder data, card verification codes, passwords, bank credentials, complete account numbers, or secret API keys.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US