Back to Glossary
⚖️Compliance & Regulations

Cardholder Data

Quick Definition

Payment card information including Primary Account Number (PAN), cardholder name, expiration date, and service code, protected under PCI DSS requirements.

What is Cardholder Data?

Cardholder data (CHD) refers to any information associated with payment cards that must be protected under PCI DSS. At minimum, cardholder data includes the Primary Account Number (PAN)-the 13-19 digit number on the front of the card. Additional cardholder data includes cardholder name, expiration date, and service code. PCI DSS distinguishes between cardholder data and Sensitive Authentication Data (SAD)-magnetic stripe data, CVV2/CVC2, and PINs must never be stored after transaction authorization.

PCI DSS requires organizations that store, process, or transmit cardholder data to implement specific security controls: encrypting CHD in transmission and storage, restricting access through need-to-know principles, maintaining detailed audit logs, regularly testing security systems, and maintaining information security policies. The level of PCI DSS requirements depends on transaction volume, ranging from Level 1 (over 6 million transactions annually) to Level 4 (fewer than 20,000 e-commerce transactions annually).

For testing payment systems, PCI DSS explicitly prohibits using real cardholder data in non-production environments unless those environments meet full PCI DSS requirements-an expensive and complex undertaking. Best practices include using test card numbers provided by payment processors, generating synthetic payment data with valid but non-real card numbers, or masking production cardholder data when copying to test systems. Reducing cardholder data in test environments dramatically reduces PCI DSS compliance scope and costs.

Common Use Cases

  • Payment application testing
  • PCI DSS scope reduction
  • E-commerce development
  • Point-of-sale system testing

🎯How GoMask Helps

GoMask helps reduce PCI DSS scope by generating synthetic cardholder data for testing or masking production payment data before loading into test environments. Our platform generates format-valid but non-real card numbers, ensuring your test environments fall outside PCI DSS audit scope.

Need help with Cardholder Data?

GoMask makes realistic synthetic datasets with the patterns you ask for. Get started in minutes.