3.1.a Examine the data retention and disposal policies, procedures and processes to verify they include at least the following:
• Legal, regulatory, and business requirements for data retention, including
• Specific requirements for retention of cardholder data (for example, cardholder data needs to be held for X period for Y business reasons).
• Secure deletion of cardholder data when no longer needed for legal, regulatory, or business reasons
• Coverage for all storage of cardholder data
• A quarterly process for identifying and securely deleting stored cardholder data that exceeds defined retention requirements.