Hi, Carlos
PCI-DSS policy is designed to prevent internal users to send out emails containing credit card information for branded credit cards such as Visa, MasterCard, American Express, Discover, or JCB.
Initially, i'd like to know how did you implement this DLP policy, how are you testing the policy, and how are you avoiding emails with PDFs that contain credit card numbers to be caught.
Also, can you share with me a Message Tracking reflecting this failure?
Regards,
-Juan C Ramon