Sensitive 3DS SDK Data Elements
3DS Data Element Type: Cardholder Data (CHD)
Description: At a minimum, cardholder data consists of the full PAN. Cardholder data may also appear in the form of the full PAN plus any of the following: cardholder name, expiration date, and/or service code.
Protection Requirements: Confidentiality
Retention by 3DS SDK Allowed?: No
3DS Data Element Type: 3DS Authentication Data
Description: Includes consumer device information and encrypted device data.
Protection Requirements: Confidentiality / Integrity
Retention by 3DS SDK Allowed?: No
3DS Data Element Type: 3DS (Ephemeral) Public Key Data
Description: Includes the ACS Ephemeral Public Key (QT) and the 3DS SDK Ephemeral Public Key (QC).
Protection Requirements: Integrity
Retention by 3DS SDK Allowed?: No
3DS Data Element Type: Internal 3DS Key Material
Description: Internal 3DS SDK ephemeral private keys and session keys.
Protection Requirements: Confidentiality / Integrity
Retention by 3DS SDK Allowed?: No
3DS Data Element Type: 3DS Personal Assurance Data
Description: Information captured by the 3DS SDK during 3DS transactions intended to reflect authenticity of ACS service providers during the challenge flow. Includes issuer logos, certificates, etc.
Protection Requirements: Confidentiality / Integrity
Retention by 3DS SDK Allowed?: No
3DS Data Element Type: 3DS Authentication Challenge Data
Description: Includes information such as the ACS Transaction ID, ACS HTML content, cardholder challenge response data, etc.
Protection Requirements: Confidentiality / Integrity
Retention by 3DS SDK Allowed?: No
3DS Data Element Type: 3DS SDK Reference Data
Description: nformation about the 3DS SDK specifically. Includes the 3DS SDK reference number and 3DS SDK Application ID (sdkAppID).
Protection Requirements: Integrity
Retention by 3DS SDK Allowed?: Yes
3DS Data Element Type: 3DS SDK Production Code
Description: Compiled production code for the 3DS SDK
Protection Requirements: Confidentiality / Integrity
Retention by 3DS SDK Allowed?: N/A