Credit Card or Payment Card Industry (PCI) Information

Data Type Description 

Information related to credit, debit, or other payment cards. This data type is governed by the Payment Card Industry (PCI) Data Security Standards and overseen by the University of Michigan Treasurer's Office. Credit or debit card numbers cannot be stored in any electronic format without the expressed, written consent of the U-M Treasurer's Office. That office is responsible for the only PCI-compliant environment at the university.

If your unit wants to start accepting credit card payments, contact the University of Michigan Treasurer's Office to arrange for this. You cannot handle the transactions using departmental computers.

Restrictions listed here do not apply to your own personal credit card information. However, it is recommended that you follow the same precautions with regard to your own personal information as you would with university data.

Data Steward: University Treasurer: treasury@umich.edu

Examples 

  • Cardholder name
  • Credit/debit card account number
  • Credit/debit card expiration date
  • Credit/debit card verification number
  • Credit/debit card security code
Andrew File System (AFS): 
Not Permitted
BlueJeans Video Conferencing: 
Not Permitted
Canvas: 
Not Permitted
Cloud Storage Included with Software: 
Not Permitted
CTools: 
Not Permitted
Data Warehouse: 
Not Permitted
Desktop Backup (Powered by CrashPlan): 
Not Permitted
MiDesktop: 
Not Permitted
Digital Signage: 
Not Permitted
Echo360 - Lecture Capture and LectureTools: 
Not Permitted
eResearch: 
Not Permitted
Flux: 
Not Permitted
Globus: 
Not Permitted
ITS Exchange Email and Calendar: 
Not Permitted
Amazon Web Services GovCloud at U-M: 
Not Permitted
Amazon Web Services (AWS) at U-M: 
Not Permitted
Box Additional Apps (Non-Core): 
Not Permitted
Box at U-M Core Apps: 
Not Permitted
Google Non-Core Services: 
Not Permitted
Google Drive at U-M: 
Not Permitted
Google Mail and Calendar at U-M and Inbox by GMail: 
Not Permitted
Google at U-M Core Services: 
Not Permitted
MiDatabase: 
Not Permitted
MiServer: 
Not Permitted
MiShare: 
Not Permitted
MiStorage (CIFS): 
Not Permitted
MiStorage (NFS): 
Not Permitted
MiVideo: 
Not Permitted
MiWorkspace: 
Not Permitted
Personal Accounts (Dropbox, Slack, etc.): 
Not Permitted
Personally Owned Devices (phone, tablet, laptop, etc.): 
Not Permitted
Qualtrics: 
Not Permitted
ServiceNow: 
Not Permitted
Statistics and Computation Service: 
Not Permitted
MiBackup: 
Not Permitted
Turbo Research Storage (NFS): 
Not Permitted
Turbo Research Storage (NFSv4+Kerberos or CIFS): 
Not Permitted
Michigan Medicine Exchange/Outlook Email and Calendar: 
Not Permitted
Armis: 
Not Permitted
Document Imaging System: 
Not Permitted
SignNow at U-M (E-Signature): 
Not Permitted
Piazza Q&A: 
Not Permitted
Dedoose: 
Not Permitted
Gradescope: 
Not Permitted
Electronic Research Notebook at U-M: 
Not Permitted
Microsoft Azure at U-M: 
Not Permitted
Google Cloud Platform at U-M: 
Not Permitted
Perusall: 
Not Permitted
Yottabyte Research Cloud: 
Not Permitted