PDA

View Full Version : Is it allowed to print a full PAN on a customer receipt?


Georg Thurner
05-23-2007, 07:50 AM
After studying the specification and various forums, it is still not clear to me if it is allowed to print the full (unmasked) PAN number on a customer receipt.

I found this article http://www.eweek.com/article2/0,1895,2124968,00.asp but I need more information if PCI DSS also covers printed PANs.

G2w
05-23-2007, 08:13 AM
It is my understanding (from a QSA training class) that it is allowed to put the full PAN on the merchant copy of the receipt but not the customer copy. Some states do not allow the full PAN on the merchant receipt either (I think CA is an example). Obviously the merchant could be in violation of PCI if they did not store the printed copies of receipts with full PAN on them in a secure manner.

jbhall56
05-24-2007, 06:31 PM
Under Title I, §113 of the Fair and Accurate Credit Transactions Act (FACTA), only the last five digits of the card account number can be printed on electronically printed receipts provided to the customer.

This truncation requirement does not apply to handwritten receipts or receipts imprinted with a copy of the credit card.

Georg Thurner
05-25-2007, 12:04 AM
But to achieve PCI DSS compliancy do I also have to take care about printed PAN number on customer receipts?

We not currently doing business in USA - so FACTA doesn't apply to us.

jbhall56
05-25-2007, 01:26 AM
Item 3.3 states:

Mask the PAN when displayed (the first six and the last four digits are the maximum number of digits to be displayed).

Note: This requirement does not apply to employees and other parties with a specific need to see the full PAN; nor does the requirement supercede stricter requirements in place for displays of cardholder data (for example, for point of sale [POS] receipts).

So, in your case since you are not in the US and do NOT have to comply with FACTA, you would follow the PCI DSS and mask to its recommendations in 3.3. The italicized note was for US merchants that are required to comply with FACTA.

I would recommend only displaying the last four digits and masking the rest, but that's just my personal preference.