Patricia S. Brackin
  • Apopka, FL
  • United States
Share on Facebook Share Twitter

Patricia S. Brackin's Friends

  • ARMA'12

Patricia S. Brackin's Groups

Patricia S. Brackin's Discussions

PCI DSS COMPLIANCE
2 Replies

17 CFR 257.2 9(b) requires 3 year retention of credit card authorizations.  Under the new PCI Data Security Standards, we are under pressure to destroy these records as soon as they are no longer…Continue

Started this discussion. Last reply by Patricia S. Brackin Aug 18, 2010.

 

Patricia S. Brackin's Page

Gifts Received

Gift

Patricia S. Brackin has not received any gifts yet

Give Patricia S. Brackin a Gift

Latest Activity

Julie J. Colgan, CRM replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"Ha! Jeff! You are always so kind! A great point you make about keeping the "inked" copy of ELs (and Waivers, for that matter). For contractual documents such as that, particularly when they cover fiduciary issues, the imaged copy is more…"
Nov 1, 2010
Jeff Lewis replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"Julie -- You always answer before I can and in a better way than I could. The only caveat I would add to scanning engagment letters is you may want to keep the originals as sometimes a judge will require the original signature. I have heard this in…"
Nov 1, 2010
Patricia S. Brackin replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"Yes, Julie. I agree that, when feasible, anything to be retained permanently should be scanned to the firm's document management system. Like you, I'm uncomfortable with the long-term viability of removable media."
Nov 1, 2010
Julie J. Colgan, CRM replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"No problem Patricia. Your response made me giggle a little ... so what do you do with the Certificate of Destruction for the Certificates of Destruction that your colleagues were proposing be destroyed ...? :) And to Christie's comment about…"
Nov 1, 2010
Christie Narver, CRM replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"I agree with Julie, life of the 'firm'. Scanning them onto a CD is an alternative to keeping the paper copies. We seem to be doing more and more scanning of our 'permanent' documents. Christie Narver, CRM Rutan & Tucker, LLP"
Nov 1, 2010
Patricia S. Brackin replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"Thanks, Julie; that is what I thought as well. The question had come up in our department, and there were some who felt they could be disposed of 3 to 7 years after the records were destroyed."
Nov 1, 2010
Julie J. Colgan, CRM replied to Patricia S. Brackin's discussion RETENTION OF CERTIFICATES OF DESTRUCTION in the group Legal
"Hi Patricia, in my experience, CoDs are kept as "permanent" records. In the event you are ever asked to produce a record that has been destroyed (by a client, in response to a subpoena, etc.), you need proper documentation proving it was…"
Nov 1, 2010
Patricia S. Brackin added a discussion to the group Legal
Thumbnail

RETENTION OF CERTIFICATES OF DESTRUCTION

How long should Certificates of Destruction be retained after the related records are destroyed?See More
Nov 1, 2010
Patricia S. Brackin replied to Patricia S. Brackin's discussion PCI DSS COMPLIANCE
"Thanks, Jennifer; that is essentially what we have decided to do. What company do you work for?"
Aug 18, 2010
Jennifer Walker-Ostertag, CRM replied to Patricia S. Brackin's discussion PCI DSS COMPLIANCE
"I consider retaining records for the time recommended by the CFRs that a company is regulated by a valid "business purpose", and I will recommend that my company retains these for three years (after which they are "no longer needed…"
Aug 18, 2010
Patricia S. Brackin joined ARMA'12's group
Jun 2, 2010
Patricia S. Brackin posted a discussion

PCI DSS COMPLIANCE

17 CFR 257.2 9(b) requires 3 year retention of credit card authorizations.  Under the new PCI Data Security Standards, we are under pressure to destroy these records as soon as they are no longer needed for business purposes.  I'm curious to see what retention policy is being used by other large enterprises.
Jun 2, 2010
Patricia S. Brackin is now a member of ARMA iConference
Jun 2, 2010

Comment Wall

You need to be a member of ARMA iConference to add comments!

Join ARMA iConference

  • No comments yet!
 
 
 

© 2012   Created by ARMA'12.

Badges  |  Report an Issue  |  Terms of Service