Breaking down the 2022 Nacha Data Protection Requirements
Blog post from Basis Theory
Nacha’s ACH data-security rule, effective June 30, 2022, requires ACH originators, third-party service providers, and third-party senders processing at least 2 million annual ACH transactions to render stored account numbers unreadable, including both consumer and business accounts. The requirement applies to systems that retain account data for recurring payments, accounts payable and receivable, claims management, and related uses, while also requiring organizations to track where information is stored and who can access it. Nacha does not mandate a specific technical method, but identifies encryption and tokenization as approaches that can protect data at rest while preserving operational usability. Tokenization replaces sensitive account information with usable tokens, potentially simplifying recurring transactions, data searches, access controls, and encryption-key management. The discussion also notes that expanding privacy regulations, fraud risks, and consumer expectations may increase demand for protection of other sensitive data types, while Basis Theory presents its tokenization platform as a Nacha-approved option for helping organizations meet these requirements.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.