Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

PII and PCI: how personal data and card data differ

PII and PCI are often mixed up, because both protect information about people. However, they come from different rules, so a merchant must satisfy each on its own terms.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Pii and pci: classify the data, map the rules and protect both

What PII and PCI each mean

PII means personally identifiable information, such as names, emails and addresses. Privacy laws govern it. In contrast, PCI DSS is an industry standard for payment account data, enforced through card brand contracts.

TopicPIIPCI DSS
Source of the rulesPrivacy lawsCard brand contracts
Data coveredInformation identifying a personAccount data, such as the card number
Who enforcesRegulatorsAcquirers and card brands

Where PII and PCI overlap

A card number with a name is both personal data and account data. Therefore one database can fall under privacy law and PCI DSS at the same time.

Also, breach response may involve both regimes. So plans should cover notification duties under each.

PII and PCI data check

Tick what you have done.

Your result appears here as you tick, so you can see what is still open.

Where PII and PCI differ in practice

PCI DSS is prescriptive. For example, it sets specific requirements for scanning, logging and passwords. Privacy laws are usually principle-based, so they focus on purpose, consent and minimisation.

  • PCI DSS: detailed technical requirements
  • Privacy laws: lawful basis, rights and minimisation
  • Both: protect data and limit what you keep

A practical approach

Classify data once, then map each type to its rules. Also reduce what you store, because less data lowers risk under both. As a result, one discovery exercise serves two programmes.

In addition, avoid treating PCI DSS compliance as privacy compliance. They answer different questions.

Where Winslow helps

We focus on the PCI DSS side and note where privacy questions arise. We are not a QSA and not a law firm. Gap analysis generally runs $8,000 to $40,000. The standard is in the PCI SSC document library.

Also involve legal advisers for the privacy side. So technical controls and legal duties stay aligned.

PII and PCI questions

Is a card number PII and PCI data at once?

Often yes, especially when stored with a name.

Does PCI DSS compliance cover privacy law?

No. Privacy duties are separate.

Can one programme manage PII and PCI together?

Yes, with shared discovery and clear mapping to each set of rules.

Which is stricter?

PCI DSS is more prescriptive, while privacy laws can carry heavier penalties.

Related guides

Untangle PII and PCI in your data

Describe the data you hold. We reply in writing, usually within one business day.

Ask us anything