Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

Breaking down the 2022 Nacha Data Protection Requirements

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
1,674
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

Nacha’s ACH data-security rule, effective June 30, 2022, requires ACH originators, third-party service providers, and third-party senders processing at least 2 million annual ACH transactions to render stored account numbers unreadable, including both consumer and business accounts. The requirement applies to systems that retain account data for recurring payments, accounts payable and receivable, claims management, and related uses, while also requiring organizations to track where information is stored and who can access it. Nacha does not mandate a specific technical method, but identifies encryption and tokenization as approaches that can protect data at rest while preserving operational usability. Tokenization replaces sensitive account information with usable tokens, potentially simplifying recurring transactions, data searches, access controls, and encryption-key management. The discussion also notes that expanding privacy regulations, fraud risks, and consumer expectations may increase demand for protection of other sensitive data types, while Basis Theory presents its tokenization platform as a Nacha-approved option for helping organizations meet these requirements.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.