PCI DSS Compliance in Call Centers: What Your Business Needs to Know
If your call center agents take payment card information over the phone, PCI DSS applies to your operation — and to every vendor handling those calls on your behalf. Here is what compliance actually requires.
PCI DSS Compliance in Call Centers: What Your Business Needs to Know
If your call center agents take credit or debit card information over the phone — for orders, payments, deposits, or any other transaction — the Payment Card Industry Data Security Standard (PCI DSS) applies to your operation. It also applies to every call center vendor you use to handle those calls on your behalf.
This is an area where a lot of businesses have significant exposure without realizing it. The assumption that "our payment processor handles PCI compliance" is only partially correct — and the part it misses can result in substantial fines, card brand penalties, and loss of the ability to accept card payments entirely.
Here is what PCI DSS actually requires in a call center context, and what you need to ask any call center partner before they touch a payment transaction.
What PCI DSS Is and Why It Applies to Call Centers
PCI DSS is a set of security standards developed by the major card brands (Visa, Mastercard, American Express, Discover) to protect cardholder data. Any organization that stores, processes, or transmits cardholder data must comply — and "transmits" is the key word for call centers.
When a customer reads their card number to an agent over the phone, that card number is being transmitted through your call center's infrastructure: the phone system, the agent's workstation, the CRM or order management system where it may be entered, and the call recording system that may have captured it. Every point in that chain is in scope for PCI DSS.
The standard applies whether you handle payments in-house or through an outsourced call center. If you outsource, your vendor's environment is in scope — and you are responsible for ensuring they are compliant.
The Biggest PCI Risk in Call Centers: Call Recordings
The single most common PCI compliance failure in call center environments is call recording.
Most call centers record 100% of calls. If an agent takes a card number over the phone and that call is recorded, the recording contains cardholder data — specifically the Primary Account Number (PAN), and potentially the CVV and expiration date. Under PCI DSS:
- CVV2/CVC2 data (the 3-4 digit security code) must never be stored — not in any form, including call recordings. This is an absolute prohibition with no exceptions.
- PANs stored in recordings must be protected with encryption, access controls, and retention limits.
The practical implication: if your call center records calls and agents verbally collect card numbers, you either need to pause recordings during the card capture portion of the call, use a DTMF (touch-tone) card capture system that masks the digits from the recording, or implement a technology solution that automatically removes card data from recordings.
Many call centers — including many that claim PCI compliance — do not have this properly implemented.
PCI DSS Requirements Most Relevant to Call Centers
PCI DSS v4.0 (the current version) has 12 requirement categories. The ones most directly relevant to call center operations:
Requirement 3 — Protect stored account data No CVV storage, ever. PANs must be rendered unreadable in storage (encryption, tokenization, or truncation). This applies to CRM records, order management systems, and call recordings.
Requirement 4 — Protect cardholder data in transit Card data transmitted over networks must be encrypted. This includes VoIP phone systems — if your call center uses VoIP and card numbers are spoken on calls, the VoIP infrastructure must be encrypted.
Requirement 7 — Restrict access to system components and cardholder data Only agents who need access to cardholder data should have it. Access should be role-based and logged.
Requirement 9 — Restrict physical access to cardholder data In a call center context, this means workstations where agents enter card data must be in physically secured areas. Agents should not be able to photograph screens or write down card numbers.
Requirement 10 — Log and monitor all access to system components All access to systems that touch cardholder data must be logged and monitored. This includes CRM access, payment system access, and call recording system access.
Requirement 12 — Support information security with organizational policies Written security policies, agent training on cardholder data handling, and vendor management requirements (including requiring PCI compliance from your call center partners).
Scope Reduction: The Smart Approach
The most effective PCI compliance strategy for call centers is scope reduction — minimizing the number of systems and people that touch cardholder data in the first place.
The most common scope reduction approach is DTMF tone masking: when a customer needs to provide card information, the agent instructs them to enter the card number using their phone keypad rather than reading it aloud. The DTMF tones are captured by a secure payment system and masked from the agent's screen and the call recording. The agent never sees or hears the card number.
This approach:
- Removes the agent from PCI scope (they never handle card data)
- Removes the call recording from PCI scope (no card data is captured)
- Significantly reduces the compliance burden on the call center environment
- Improves security by eliminating the human element from card capture
If you are outsourcing calls that involve payment collection, ask your vendor whether they support DTMF tone masking. If they do not, every agent and every system in their environment that touches those calls is in PCI scope — and you need to verify their compliance.
What to Ask Your Call Center Vendor
Before allowing any call center vendor to handle calls that involve payment card data, ask:
- Are you PCI DSS certified? Ask for their current Attestation of Compliance (AOC) or Report on Compliance (ROC). A verbal claim of compliance is not sufficient.
- How do you handle call recordings that contain card data? Specifically: do you pause recordings during card capture, use DTMF masking, or have another approach?
- Do you store CVV data in any form? The correct answer is no, never.
- Who has access to cardholder data in your environment? Access should be role-based and logged.
- What is your process when a PCI violation or data breach occurs? They should have a documented incident response plan.
If a vendor cannot answer these questions specifically and in writing, do not allow them to handle payment transactions on your behalf.
Summit Call Solutions and PCI Compliance
Summit Call Solutions operates PCI-compliant environments for clients whose programs involve payment collection. Our approach includes DTMF tone masking for card capture, call recording controls that prevent storage of cardholder data, role-based access controls on all systems that touch payment data, and documented security policies that meet PCI DSS v4.0 requirements.
If you are evaluating call center partners for a program that involves payment collection, contact us to discuss how we structure compliant payment handling.
Explore Topics
Written by
Summit Call Solutions
Content creator and writer sharing insights and stories.
