1. SharePoint does not automatically delete credit card or bank account numbers; it has no PCI-specific data removal capabilities.
2. PCI enters SharePoint through invoices, scans, screenshots, bank forms, CSVs, and synced OneDrive folders.
3. PCI DSS requires that sensitive cardholder data be removed from systems that do not require it—SharePoint is one of them.
4. Manual deletion is unreliable because PCI hides inside PDFs, images, spreadsheets, and version histories.
5. Strac automatically detects and deletes PCI in SharePoint libraries, folders, synced OneDrive content, and historical files.
SharePoint provides version control, metadata, and document storage, but it does not scan files for sensitive data or delete them automatically when PCI is found. This creates PCI DSS compliance gaps across multiple requirements (3.2, 3.3, 3.4, 3.5).
Key SharePoint limitations:
No automated deletion of files containing PCI
No detection of PCI inside PDFs, scans, or images
No removal of historical versions containing PCI
No deletion of synced OneDrive content containing sensitive data
No rules for auto-removal based on PCI classification
No workflow to remove PCI from shared or externally accessed libraries
No alert + delete automated processes
Without automated deletion, PCI can remain in SharePoint libraries for years—often undiscovered.
What (PCI) Credit Card Numbers Exposure Looks Like Inside SharePoint Files
PCI frequently enters SharePoint because many business processes rely on document uploads. Files that often contain PCI include:
PDF invoices with full credit card numbers
Scanned authorization forms
Photos or screenshots of customer payment cards
Bank statements and ACH forms
CSV exports from billing systems
Emails saved as files containing card data
ZIP folders with multiple financial documents
Sensitive examples Strac detects and deletes:
4111 1111 1111 1111
4242-4242-4242-4242
5500 0000 0000 0004
Visa, Mastercard, AMEX, Discover numbers
Bank account + routing combinations
IBAN and SWIFT formats
PCI embedded in images, text layers, or PDFs
PCI hidden inside versioned files or archived folders
Deletion must include all versions and duplicates to ensure full PCI removal.
✨What It Means to Delete (PCI) Credit Card Numbers in SharePoint
Deleting PCI in SharePoint is not just about removing the file from a library—it must include:
File deletion from primary library
Deletion of all historical versions
Removal of synced OneDrive copies
Cleanup of folder structures
Removal of external or guest links
Removal of cached previews and document thumbnails
Ensuring PCI does not replicate in workflow automations
Strac helps organizations automatically detect, classify, and delete credit card numbers and bank account information across SharePoint libraries, archived folders, and synced OneDrive content—ensuring PCI never remains stored in non-compliant environments.
Discover & Protect Data on SaaS, Cloud, Generative AI
Strac provides end-to-end data loss prevention for all SaaS and Cloud apps. Integrate in under 10 minutes and experience the benefits of live DLP scanning, live redaction, and a fortified SaaS environment.