Card expiration dates
Detects references to card expiration dates in financial and compliance documents. Commonly found in Australian regulatory filings, transaction records, and audit documentation. Phrase-level concept detection anchored on card-specific expiry vocabulary; it does not parse MM/YY or month-year values.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- identifier/document-structure anchored regex with constrained context replaces phrase-only detection.
- Detection quality
- Topic false positive
- Jurisdictions
- global
- Regulations
- AML/CTF Act (Cth), IPA 2009 (Qld), NDB Scheme (Cth), Privacy Act 1988 (Cth), SOCI Act 2018 (Cth), GDPR, PCI-DSS
- Frameworks
- ISO 27001, ISO 27701, PCI-DSS, SOC 2
- Data categories
- financial
- Scope
- wide
- Risk rating
- 4
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:card\s+expiration\s+date|valid\s+thru|card\s+expires|card\s+validity)\b
Corroborative evidence keywords
card expiration dates, card, expiration, dates, financial, accounts, payments, fiscal, monetary, accounting, treasury, audit, revenue, expenditure, budget, ledger, accounts payable, accounts receivable, balance sheet, profit and loss (+1 more)
Proximity: 300 characters
Should match
card expiration date— Primary topic phrase matchvalid thru— Alternative topic phrase matchcard expires— Additional topic phrase matchcard validity— Card-specific validity phrase match
Should not match
unrelated generic text without domain phrases— No relevant topic phrases presentplaceholder value 12345— Random text should not match topic-specific regexpayroll reimbursement— Generic word pair from old broad template should not matchSoftware licence expiry date.— Generic expiry-date wording demoted out of the primary - non-card expiries must not anchorPCI DSS cardholder data policy— PCI and payment wording demoted out of the primary - corroborative evidence only
Known false positives
- Financial terminology appearing in published reports, accounting textbooks, regulatory guidance, or template documents without actual transaction data. Mitigation: Require corroborative evidence keywords within the proximity window. Cross-reference with structured financial identifiers to confirm actual sensitive data.
- In Australian English, standard business terminology overlapping with financial detection keywords in routine correspondence and documentation. Mitigation: Increase confidence threshold when scanning business correspondence. Layer with transaction-specific patterns for higher precision.
References
- https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf
- https://handbook.apra.gov.au/standard/cps-234