Skip to content
KnowledgeCity

By KnowledgeCity

Loyalty Program Data Sits Outside PCI DSS: What Hotel Groups Still Have to Train Staff to Protect

14 min read

Loyalty Program Data Sits Outside PCI DSS: What Hotel Groups Still Have to Train Staff to Protect

Key Takeaways

  • PCI DSS v4.0.1 defines cardholder data as the Primary Account Number and a small cluster of payment-specific fields; loyalty account numbers, stay history, member profile data, and tier status are not among the defined elements and fall outside PCI scope.
  • Hotel loyalty program data is governed by state and federal privacy laws, including CCPA/CPRA for California-resident members and PIPEDA for Canadian guests. PCI DSS reaches only cardholder data.
  • In December 2024, the FTC finalized an order against Marriott and Starwood over multiple data breaches exposing loyalty numbers, passport numbers, and personal information belonging to more than 344 million customers worldwide.
  • Cal. Code Regs. tit. 11, § 7100(b) requires a business that buys, receives for commercial purposes, sells, or shares for commercial purposes the personal information of 10 million or more consumers in a calendar year to establish, document, and comply with a training policy covering everyone responsible for handling CCPA consumer requests or the business's CCPA compliance.
  • Compliance training for employees who manage loyalty accounts must address social engineering recognition, escalation protocols, privacy law obligations, and data minimization practices. The cardholder data environment framework answers a different set of risks.

Your PCI compliance program covers the payment card environment and stops at its edge. Outside that environment sits the loyalty database, holding member names, stay preferences, tier status and redemption history for millions of guests. A different body of law governs those loyalty records, and it brings its own training requirements.

The price of that gap is already documented in an FTC enforcement file. In December 2024 that file put a number on it, finalizing a consent order against Marriott and Starwood that covered more than 344 million customers worldwide. Those breaches exposed loyalty numbers and passport numbers, and PCI DSS v4.0.1 treats neither as cardholder data.

Canada's privacy regulator arrived at the same finding from a different statute. Investigating the identical breach, the Office of the Privacy Commissioner held that the Starwood reservation database contained personal information under PIPEDA, and assessed Marriott's safeguards against that law. The PCI compliance reports Marriott already held answered none of it.

Why Loyalty Program Data Falls Outside PCI DSS and What That Means for Hotel Security Training

The Scope Boundary PCI DSS Draws and Where Loyalty Records Land

PCI DSS v4.0.1 anchors its scope to the Primary Account Number. The cardholder name, expiration date and service code join that number once they are stored alongside it. Every obligation the framework places on you flows from the same number, training included.

Loyalty records never carry that number at all. Account numbers, email addresses, stay histories and redemption records are personal information under privacy law, and the standard publishes no exclusion list because it never needs one. Those records enter PCI scope only when a PAN travels beside them.

That boundary is what decides who gets trained at all. Requirement 12.6 asks for a formal security awareness program covering the personnel who reach the cardholder data environment, and it trains nobody else. Your loyalty desk agents and reservation coordinators may never reach that environment at all.

Build your training map around PCI alone and a large share of the people handling guest data every day sit outside any structured obligation. In a 300-room property the guest-data population is usually larger than the payment-facing one. Check which of these guest-data roles your own properties staff:

  • Loyalty desk and member services: handle account resets, tier adjustments and redemption changes, and reach payment systems rarely or never.
  • Reservation coordinators: collect and amend member profile fields during booking, including contact details and stay preferences.
  • Guest relations agents: receive inbound requests about member records and act as the escalation point for disputed account activity.

CCPA/CPRA, PIPEDA, and State Privacy Law as the Operative Compliance Layer

Each of those roles falls to privacy law instead. California Civil Code section 1798.140(v) is the privacy law that defines what counts as personal information. It covers identifiers such as name and account number, commercial records of what a consumer purchased, and inferences drawn to build a profile. A loyalty record matches all 3 of those categories at once.

Compliance with CCPA and CPRA is therefore a standing obligation for your California-resident members. That obligation holds whether or not the same property also processes payment cards under a separate framework. The two frameworks run in parallel, and satisfying one leaves the other untouched.

Canadian guests bring PIPEDA into the same estate. Canada's Privacy Commissioner recorded 3 contraventions in the 2022 findings on the Marriott breach, covering inadequate safeguards, weak accountability and excessive retention. That investigation reached up to 12.8 million Canadian records. Records held in British Columbia, Alberta and Quebec fall instead to substantially similar provincial statutes.

The practical effect is that one loyalty database can answer to 4 different regimes at once, depending on where the member lives:

Where the member is

Governing law

What it asks of training

California

CCPA and CPRA

Inform everyone who handles consumer privacy inquiries; document the policy above the 10 million consumer threshold

Canada, federally regulated

PIPEDA

Safeguards proportionate to sensitivity, with accountability assigned to a named individual

British Columbia, Alberta, Quebec

Provincial statutes

Substantially similar duties, applied in PIPEDA's place

Payment card fields only

PCI DSS v4.0.1

Requirement 12.6 awareness training for cardholder data environment personnel

Retention is where hotel groups most often exceed what the law allows, because a loyalty profile has no natural end date. Excessive retention was 1 of the 3 PIPEDA contraventions found against Marriott. Review how long your properties keep a dormant loyalty profile on file. Whatever that review turns up becomes a training requirement, and our guide to regulatory compliance training sets out how to make the conversion.

The training duties attached to privacy law look nothing like the PCI model. California Civil Code section 1798.130(a)(6) requires that everyone handling consumer privacy inquiries be informed of what the law demands. The CPRA regulations extend that same duty to your compliance staff, which widens it well past the front desk.

One threshold in those regulations deserves a direct check against your own volumes. Title 11, section 7100(b) adds a documented training policy for any business that buys, sells or shares the personal information of 10 million or more consumers in a calendar year. Work out whether your brand crosses that line, because the documentation duty that follows is audited on its own terms.

344 Million Customers worldwide affected by multiple data breaches under the FTC's December 2024 final order against Marriott International and Starwood Hotels. The breached data included Starwood Preferred Guest loyalty numbers, passport numbers, and personal information, none of which constitute cardholder data as PCI DSS v4.0.1 defines it. Source: Federal Trade Commission, December 2024 Final Order

WHICH HOTEL DATA PCI DSS COVERS Inside PCI DSS Primary Account Number and payment fields Outside PCI DSS Loyalty account numbers and tier status Outside PCI DSS Stay history and member profile data Governed by State and federal privacy law FTC order, December 2024 344 million customers exposed Privacy law covers the rest

What Compliance Training for Employees Must Address When PCI DSS Does Not Apply

Social Engineering Scenarios That Exploit the Loyalty-Data Knowledge Gap

Documentation duties assume your staff can identify the attack when it arrives, and account-takeover fraud reaches hotels by telephone. A caller reports being locked out of a member account, and the agent who takes that call is working from whatever verification script the property gave them. An agent following weak steps resets the credential or redirects the points to an address the caller supplies.

No part of that call touches the payment card environment. The systems and the data the call reaches are outside PCI scope, which leaves anyone trained only inside a PCI program with no preparation for it. Train your loyalty line on the verification failure itself.

Email attacks run the same play against the same staff. Those who manage member correspondence receive messages impersonating brand administrators or booking platforms. A single spoofed confirmation link harvests the employee's own system login and hands an attacker the console behind it. That single credential then opens member records in volume.

The FTC's order treats that harm as its own category. Under the order Marriott must review loyalty rewards accounts when a customer asks, and restore stolen points, a remedy that exists because loyalty credentials are worth stealing on their own. KC Phishing runs simulated campaigns against those patterns and assigns microlearning the moment somebody clicks.

Per-employee risk scoring is what turns that exercise into a plan you can act on. It shows which loyalty desk and guest relations staff carry the highest exposure, well before a real message reaches a member account. Watch 3 signals in the first campaign:

  • Repeat clickers: anyone who clicks across 2 or more campaigns needs a refresher assignment, because a second simulation only confirms what the first one found.
  • Silent recipients: staff who neither click nor report have not been tested, because a phishing message only trains the person who engages with it.
  • Report rate by desk: a loyalty line that reports at a lower rate than the front desk tells you where the escalation path is unclear. Every completion is written to the audit trail, where CCPA and PIPEDA documentation can draw on it.

KnowledgeCity Compliance Training Software

KnowledgeCity's compliance training software delivers phishing simulation you can target to hotel staff who manage loyalty and guest data.

Explore KC Phishing

What Effective Hotel Compliance Training Programs Must Build

What a Hotel Loyalty Data Compliance Training Curriculum Covers

A curriculum for loyalty staff has to close what the payment model leaves open. Requirement 12.6 training teaches phishing aimed at payment systems and acceptable use of the cardholder environment. Those are real outcomes, and none of them prepares a loyalty agent for a spoofed lockout call.

Closing that gap for a loyalty agent takes 4 capabilities, and each one belongs in the curriculum:

  • Know which rights apply: teach staff the deletion, correction and opt-out rights that attach to member records, and where to route each request.
  • Rehearse the real scenarios: use voice verification spoofing and loyalty redemption phishing drawn from hotel incidents.
  • Set the escalation line: name the requests that must go up, starting with account resets and address changes on confirmed accounts.
  • Limit what gets collected: show which fields check-in requires, and how to decline a request for anything beyond them.

Delivery matters as much as content in a hotel. Your agents rotate across 3 shifts and work at properties with thin training infrastructure, so a desktop compliance portal is unreachable during a peak arrival window. A learning library built for frontline hospitality teams solves the scheduling problem the curriculum cannot.

How Hotel Groups Sustain Compliance Training for Employees Beyond the PCI Audit Cycle

Aligning Training Timing to CCPA/PIPEDA Obligations and Brand-Level Audit Defense

Scheduling is where the two frameworks diverge hardest of all. PCI gives you a calendar, with quarterly scans and an annual recertification that tell security teams when to act. Privacy law hands you nothing comparable to plan against, so the dates have to come from somewhere else.

CCPA and CPRA obligations are continuous, and a consumer request or an incident is what starts the clock. PIPEDA behaves the same way, which leaves no fixed date to plan around in either regime. So your training program for employees who handle loyalty data has to follow operational events and regulatory change, on a schedule the PCI audit year never touches.

Crossing the § 7100(b) threshold turns that schedule into a documented policy. Brand-level policy then has to be matched by property-level evidence, because the distance between the two is what a regulator reads as the finding. The record itself has to answer 3 questions:

  • Who is trained: name the roles themselves, so a loyalty desk agent appears by function and can be found in a headcount total.
  • How often: state the interval and the events that trigger an off-cycle assignment, such as a statutory amendment or a live incident.
  • How completion is verified: point at the individual record the system produces, with a date an auditor can read.

Choose software that can produce that evidence without reconstruction. Exportable completion records tied to named individuals let you answer a regulatory inquiry or a brand audit from what the system already holds. Rebuilding that history by hand takes weeks, while a regulator's deadline is usually measured in days, and that difference is the argument for keeping the completion record continuously current.

That record needs a refresh schedule behind it. Pair an annual update keyed to statutory change with role-specific assignments whenever a new attack pattern appears. Our guide to compliance training that survives a multi-state audit works that schedule through in detail.

How KnowledgeCity Closes the Gap Between Payment Security and Guest Data

Those exportable records are the point where the two obligations become one program. The staff who manage loyalty accounts and process member changes are a population most hotel compliance programs have never formally addressed. PCI reaches the payment environment and stops at its perimeter.

Privacy law reaches the loyalty database and the member profile, and it arrives without PCI's audit calendar to carry it. The space between the two frameworks is where guest data goes unprotected. Closing it starts with treating the loyalty-data training duty as enforceable, because CCPA, CPRA and PIPEDA each make it so.

KnowledgeCity covers both of those populations from a single platform. KC Phishing simulates the voice and email attacks your loyalty staff meet, across email, Slack and Microsoft Teams, then assigns remediation microlearning automatically to whoever engages with the lure. It scores exposure by individual, so you can see which desk puts a member account most at risk. The completion records export in the form an auditor expects.

That turns 2 regulatory obligations into 1 operational program. Your payment staff and your loyalty staff train on the threats each one faces, and the evidence sits in a single record. When the inquiry arrives, you answer it from what the platform already holds.

Frequently Asked Questions

1. Does PCI DSS cover hotel loyalty program data?

PCI DSS v4.0.1 defines cardholder data as the Primary Account Number and a small cluster of fields stored alongside it, including cardholder name, expiration date, and service code. Loyalty account numbers, member email addresses, stay histories, tier status, and redemption records are not among those elements and fall outside PCI DSS scope by definition. Hotel properties that process payment cards are subject to PCI DSS for their cardholder data environment, but the loyalty program database is governed by applicable privacy laws such as CCPA/CPRA for California-resident members and PIPEDA for Canadian guests, not by PCI standards.

2. What privacy laws apply to hotel loyalty member records?

Hotels holding personal information for California-resident members are subject to CCPA/CPRA, which defines personal information broadly under Cal. Civ. Code § 1798.140(v) to include identifiers, commercial information such as stay and redemption history, and consumer profile inferences. Canadian properties and those serving Canadian guests are subject to PIPEDA, which the Office of the Privacy Commissioner of Canada confirmed applies to hotel loyalty program databases in its 2022 investigation of the Marriott and Starwood breach. Additional state privacy statutes may apply depending on the jurisdiction of operation or the residency profile of members in the loyalty database.

3. What should compliance training for employees cover for loyalty data protection?

Compliance training for employees who handle loyalty member data should address privacy law requirements under CCPA/CPRA or PIPEDA, recognition of social engineering attacks including voice-based verification spoofing and phishing emails impersonating brand administrators, escalation procedures for requests exceeding an employee's authorization level, and data minimization practices that limit personal information handling to operationally necessary fields. Generic security awareness training built for cardholder data environments does not adequately cover these scenarios because the attack surface and the legal obligations are different.

4. How do hotel compliance training programs support CCPA and PIPEDA audit defense?

Cal. Code Regs. tit. 11, § 7100(b) requires a business that buys, receives for commercial purposes, sells, or shares for commercial purposes the personal information of 10 million or more consumers in a calendar year to establish, document, and comply with a training policy covering everyone responsible for handling CCPA consumer requests or the business's CCPA compliance. PIPEDA similarly requires organizations to maintain safeguards appropriate to the sensitivity of the information held. Compliance training programs that produce individual completion records, track training by role and location, and export that data for audit review provide the records needed to demonstrate compliance with both frameworks. KC Phishing integrates training records into an audit trail that hotel compliance teams can reference during regulatory inquiries or brand-level security assessments.

References

  1. Federal Trade Commission. (2024, December). FTC Finalizes Order Against Marriott and Starwood Requiring Robust Data Security Program.
  2. Office of the Privacy Commissioner of Canada. (2022). PIPEDA Findings #2022-005: Marriott International Inc. and Starwood Hotels and Resorts Worldwide Inc.
  3. PCI Security Standards Council. (2024). PCI DSS v4.0.1 Document Library.
  4. California Attorney General. (2025). California Consumer Privacy Act (CCPA).
  5. Ravelin. (2026). Global Fraud Trends 2026: Fraud & Payments Survey.
  6. Office of the Privacy Commissioner of Canada. PIPEDA Overview.

Everything your workforce needs, on one platform.

A quick walkthrough tailored to your team — learning, compliance, skills, and performance in one place.