Insight
PII and PCI: how personal data and card data differ
PII and PCI are often mixed up, because both protect information about people. However, they come from different rules, so a merchant must satisfy each on its own terms.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
What PII and PCI each mean
PII means personally identifiable information, such as names, emails and addresses. Privacy laws govern it. In contrast, PCI DSS is an industry standard for payment account data, enforced through card brand contracts.
| Topic | PII | PCI DSS |
|---|---|---|
| Source of the rules | Privacy laws | Card brand contracts |
| Data covered | Information identifying a person | Account data, such as the card number |
| Who enforces | Regulators | Acquirers and card brands |
Where PII and PCI overlap
A card number with a name is both personal data and account data. Therefore one database can fall under privacy law and PCI DSS at the same time.
Also, breach response may involve both regimes. So plans should cover notification duties under each.
PII and PCI data check
Tick what you have done.
Your result appears here as you tick, so you can see what is still open.
Where PII and PCI differ in practice
PCI DSS is prescriptive. For example, it sets specific requirements for scanning, logging and passwords. Privacy laws are usually principle-based, so they focus on purpose, consent and minimisation.
- PCI DSS: detailed technical requirements
- Privacy laws: lawful basis, rights and minimisation
- Both: protect data and limit what you keep
A practical approach
Classify data once, then map each type to its rules. Also reduce what you store, because less data lowers risk under both. As a result, one discovery exercise serves two programmes.
In addition, avoid treating PCI DSS compliance as privacy compliance. They answer different questions.
Where Winslow helps
We focus on the PCI DSS side and note where privacy questions arise. We are not a QSA and not a law firm. Gap analysis generally runs $8,000 to $40,000. The standard is in the PCI SSC document library.
Also involve legal advisers for the privacy side. So technical controls and legal duties stay aligned.
PII and PCI questions
Is a card number PII and PCI data at once?
Often yes, especially when stored with a name.
Does PCI DSS compliance cover privacy law?
No. Privacy duties are separate.
Can one programme manage PII and PCI together?
Yes, with shared discovery and clear mapping to each set of rules.
Which is stricter?
PCI DSS is more prescriptive, while privacy laws can carry heavier penalties.
Related guides
Untangle PII and PCI in your data
Describe the data you hold. We reply in writing, usually within one business day.
Ask us anything