ANZ provides a complimentary PCI DSS Compliance Program to our merchants, including
PCI-approved Network Vulnerability Scanning – please email pcicompliance@anz.com or contact
ANZ on 1800 039 025 to request access to our PCI DSS program.
7.2 Securing transaction Records
In general, no Cardholder data should be stored unless it is strictly for use within the business
and absolutely necessary.
However, if you have authority from ANZ to process mail order / telephone order,
eCommerce, recurring or manual payments you may be required to store cardholder data
and transaction records. Please ensure all paper and electronic records containing cardholder
data are secured (e.g. locked filing cabinet), these may include: MOTO order forms, merchant
copies of Manual transactions, cardholder records for recurring or pre-authorisation
transactions.
Where storage of cardholder data is required, you must ensure both the type of
cardholder data retained, and the method used to store it is compliant with PCI DSS and ANZ
requirements.
Here are a few simple guidelines:
• Never email credit card numbers or request your customers provide their credit card
number by email
• Ensure that you process eCommerce transactions with security codes (CVV2/CVC2), but do
not store these codes after they have been authorised
• Keep cardholder data storage to a minimum, only what is necessary for business or legal
needs
• Once a transaction is processed, obscure all digits except the first 6 and last 4 digits of the
credit card Number (e.g. 1234 56
XX XXXX
7890) on all paper and electronic records
• Store cardholder data in a secure environment with strict controls and restricted access
• Use strong passwords which are changed at least every 90 days for all administrator roles
and users with access to your customer’s card details
• Avoid storing cardholder data on PC’s, laptops or mobile phones
• Do not store your customer’s card details online or unencrypted on your computer
• Securely dispose of cardholder data as soon as its use has expired. PCI DSS recommends
shredding, pulping, incinerating or other methods which make it impossible to reconstruct
the cardholder data. ANZ requires you keep transaction records for 30 months minimum.
Under no circumstances should sensitive information be stored; this information includes
security codes (CVV2, CVC2), PIN or magnetic stripe data.
The following sources provide guidance on card data storage:
The General Conditions – see Section 14 ‘Information collection, storage and disclosure’.
For more information, visit the PCI Security Standards Council website at
https://www.pcisecuritystandards.org/index.shtml