PCI Compliant Call Center Services
If your call center agents take payment card information over the phone, PCI DSS applies to your entire operation — and to every vendor handling those calls on your behalf. Here is what compliance actually requires, and how Summit handles it.
Why PCI DSS applies to your call center
PCI DSS is a set of security standards developed by the major card brands — Visa, Mastercard, American Express, Discover — to protect cardholder data. Any organization that stores, processes, or transmits cardholder data must comply. "Transmits" is the key word for call centers.
When a customer reads their card number to an agent over the phone, that card number is being transmitted through your call center's infrastructure: the phone system, the agent's workstation, the CRM or order management system where it may be entered, and the call recording system that may have captured it. Every point in that chain is in scope for PCI DSS.
The standard applies whether you handle payments in-house or through an outsourced call center. If you outsource, your vendor's environment is in scope — and you are responsible for ensuring they are compliant.
The biggest PCI risk in call centers: call recordings
Most call centers record 100% of calls. If an agent takes a card number over the phone and that call is recorded, the recording contains cardholder data — including the PAN and potentially the CVV. PCI DSS absolutely prohibits storing CVV2/CVC2 data in any form, including call recordings. This is one of the most common PCI compliance failures in call center environments — including at vendors that claim to be PCI compliant.
PCI DSS v4.0 requirements for call centers
PCI DSS has 12 requirement categories. These six are most directly relevant to call center operations.
Requirement 3
Protect stored account data
No CVV storage, ever — not in CRM records, not in call recordings, not anywhere. PANs must be rendered unreadable in storage through encryption, tokenization, or truncation. This is an absolute prohibition with no exceptions.
Requirement 4
Protect cardholder data in transit
Card data transmitted over networks must be encrypted. For VoIP call centers, if card numbers are spoken on calls, the VoIP infrastructure must be encrypted. This is frequently overlooked in VoIP-based call center environments.
Requirement 7
Restrict access to cardholder data
Only agents who need access to cardholder data should have it. Access must be role-based and logged. In a call center context, this means not all agents should have access to payment systems — only those assigned to programs that involve payment collection.
Requirement 9
Restrict physical access
Workstations where agents enter card data must be in physically secured areas. Agents should not be able to photograph screens or write down card numbers. Physical security controls are part of the PCI scope for call center facilities.
Requirement 10
Log and monitor all access
All access to systems that touch cardholder data must be logged and monitored — including CRM access, payment system access, and call recording system access. Logs must be retained and reviewed.
Requirement 12
Organizational security policies
Written security policies, agent training on cardholder data handling, and vendor management requirements — including requiring PCI compliance from your call center partners — are all required under PCI DSS v4.0.
Scope reduction: the smart approach
The most effective PCI compliance strategy for call centers is scope reduction — minimizing the number of systems and people that touch cardholder data in the first place. The most common approach is DTMF tone masking.
When a customer needs to provide card information, the agent instructs them to enter the card number using their phone keypad rather than reading it aloud. The DTMF tones are captured by a secure payment system and masked from the agent's screen and the call recording. The agent never sees or hears the card number.
What DTMF tone masking achieves
- Removes the agent from PCI scope — they never handle card data
- Removes the call recording from PCI scope — no card data is captured
- Significantly reduces the compliance burden on the call center environment
- Improves security by eliminating the human element from card capture
- Reduces the risk of agent-side fraud or data theft
If you are outsourcing calls that involve payment collection, ask your vendor whether they support DTMF tone masking. If they do not, every agent and every system in their environment that touches those calls is in PCI scope — and you need to verify their compliance before allowing them to handle payment transactions.
What to ask your call center vendor before they handle payment transactions
Are you PCI DSS certified? Ask for their current Attestation of Compliance (AOC) or Report on Compliance (ROC). A verbal claim of compliance is not sufficient.
How do you handle call recordings that contain card data? Do you pause recordings during card capture, use DTMF masking, or have another approach?
Do you store CVV data in any form? The correct answer is no, never.
Who has access to cardholder data in your environment? Access should be role-based and logged.
What is your process when a PCI violation or data breach occurs? They should have a documented incident response plan.
Can you provide your most recent Attestation of Compliance or Report on Compliance for review?
If a vendor cannot answer these questions specifically and in writing, do not allow them to handle payment transactions on your behalf.
How Summit Call Solutions handles PCI compliance
Summit Call Solutions operates PCI-compliant environments for clients whose programs involve payment collection. Our approach is built around scope reduction first — minimizing the number of systems and people that touch cardholder data — and documented controls for everything that remains in scope.
DTMF tone masking for card capture — agents never see or hear card numbers
Call recording controls that prevent storage of cardholder data, including CVV
Role-based access controls on all systems that touch payment data
Physical security controls at both our Enfield, CT and near-shore facilities
Documented security policies that meet PCI DSS v4.0 requirements
Agent training on cardholder data handling before assignment to any payment program
For full details on our compliance and security standards, including our approach to data handling, access controls, and business continuity, see our compliance and security page.
Frequently asked questions
Does PCI DSS apply to call centers that do not store card data?
Yes. PCI DSS applies to any organization that stores, processes, OR transmits cardholder data. A call center where agents verbally collect card numbers is transmitting cardholder data — even if the data is never stored. The phone system, agent workstations, and call recordings are all in scope.
What is the difference between PCI DSS and TCPA compliance for call centers?
PCI DSS governs the security of payment card data — how it is collected, transmitted, stored, and protected. TCPA governs how outbound calls can be made — consent requirements, calling hours, DNC compliance, and dialer technology. Both apply to call centers that handle payment transactions on outbound programs. They are separate compliance frameworks with separate requirements.
How do I know if my call center vendor is actually PCI compliant?
Ask for their current Attestation of Compliance (AOC) or Report on Compliance (ROC) — the formal documentation produced by a Qualified Security Assessor (QSA) after a PCI DSS assessment. A verbal claim of compliance is not sufficient. Also ask specifically how they handle call recordings that contain card data — this is where most non-compliant vendors have gaps.
What happens if my call center vendor has a data breach involving card data?
If cardholder data is compromised in your call center vendor's environment, you are responsible for notifying the card brands and potentially affected cardholders. You may face fines from the card brands, forensic investigation costs, and liability for fraudulent charges. This is why verifying your vendor's PCI compliance — not just taking their word for it — is a business-critical requirement.
Handle payment calls without the PCI compliance risk
Summit Call Solutions operates PCI-compliant environments for programs that involve payment collection. If you are evaluating call center partners for a program that involves payment transactions, contact us to discuss how we structure compliant payment handling.
