Privacy Law Library

Minnesota Plastic Card Security Act (access device data retention)

MN Plastic Card Security Act

Data security · Financial · Breach notification

Prohibits businesses that accept payment cards from keeping the card security code, PIN verification code, or full magnetic-stripe track data after a transaction is authorized (48 hours for PIN debit). If a business (or its service provider) that violated the rule is breached, it must reimburse the banks and credit unions that issued the affected cards.

Where
Minnesota
Citation
Minn. Stat. 325E.64
Status
In force
In force since
2007-08-01
Enforced by
Civil action by card-issuing financial institutions (325E.64, subd. 3)
People can sue
Limited
Penalties
A merchant that retained prohibited data and then suffers a breach must reimburse card-issuing financial institutions for reasonable costs of card cancellation and reissuance, account closures and reopenings, refunds for unauthorized transactions, and cardholder notification, plus damages the institution paid to cardholders (subd. 3, applicable to breaches on or after August 1, 2008).
Applies to
  • Persons and entities conducting business in Minnesota that accept credit, debit, or stored value cards, and their service providers (325E.64, subds. 1(j), 2)

Security duties

  • Do not retain card security code data, PIN verification code numbers, or full magnetic stripe track contents after authorization (or more than 48 hours after authorization for PIN debit); a service provider's retention counts as the merchant's violation.Minn. Stat. 325E.64, subd. 2

Breach duties

  • After a breach, a violating entity must reimburse issuing financial institutions for reasonable response costs, including card reissuance and cardholder notification.Minn. Stat. 325E.64, subd. 3 · Only if: Applies only to entities that violated subd. 2 and then suffered a breach · From 2008-08-01

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: The short title 'Plastic Card Security Act' is the commonly used name; it does not appear in the statute text.

Research reference, not legal advice.