FieldRegister
Every field · Financial

Payment card or bank account details

Card numbers are in scope for PCI DSS and bank details are sensitive PI under CPRA. A CRM is not a card data environment.

personal data
personal data?
confidential
sensitivity
never
AI use
contract
lawful basis usually relied on

Keep it how long

Not in the CRM at all: tokenise in the payment processor.

The gap we see most

Card or account numbers typed into a notes or custom field to take payment over the phone.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Payment details in a CRM field GDPR Art.32 · CCPA/CPRA §1798.150 · ISO/IEC 27701:2019 6.7.1
GDPR Art.32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rig...

Evidence an auditor accepts: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome
CCPA/CPRA §1798.150 Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring...

Evidence an auditor accepts: Reasonable security program documentation (encryption, access control, monitoring); Incident response plan including 30-day cure handling; Breach notification procedure
ISO/IEC 27701:2019 6.7.1 Cryptographic controls

The policy on the use of cryptographic controls must take account of jurisdictions that require cryptography for particular categories of personal data such as health data or national identifiers, the organization must tell the customer in what circumstances it applies cryptography to the personal d...

Evidence an auditor accepts: Cryptographic policy referencing jurisdiction specific mandates for categories of personal data; Documentation issued to customers describing where cryptography is applied and to what; Description of customer facing cryptographic capabilities such as customer managed keys

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Government identifier (passport, national ID, SSN, tax number) · Password, PIN or security answer