Not having the data in the first place. Which I believe was her point about the "tokenisation" of the credit card numbers - apparently they explicitly did not save six of the digits which make them usable.

Except that they DID have (some of) the data, which means that they could be used in a social engineering attack which is most certainly a 'format' above encryption, not below it.

