The moment an agent hears, writes, or types a customer’s card number, the systems around that agent fall inside PCI DSS scope — the phone platform, the recording store, the desktop, and often the network they sit on.

Most of the work in PCI-compliant phone payments is not securing card data. It is arranging things so you never hold it.

Scope is the whole game

Assessment cost, control burden, and ongoing evidence requirements all scale with scope. A design that keeps card data out of your environment entirely turns a large annual exercise into a small one.

The question to ask any provider:“At what point does card data touch a system you or I control?” The best answer is “it does not.”

The controls that do the work

DTMF masking. The customer keys their card number on the phone keypad. Tones are suppressed or masked so the agent stays on the line but never hears or sees the digits.

Pause-and-resume recording. Recording suspends around payment capture so card data never enters the recording store. Automatic triggering is far safer than relying on an agent to remember.

Agent environment controls. Clean-desk rules, no writing implements, restricted devices, and access limited to what the role requires.

Recordings are where organisations get caught

A recording containing a spoken card number is stored card data, subject to the same requirements as any other. Historic recordings are the common trap — organisations fix the process going forward and leave years of recorded card numbers sitting in storage.

Fixing the process forward is half the job. The archive is the other half.

Agree it before launch

Settle the payment flow, recording behaviour, agent controls, and evidence requirements before the first call rather than during an assessment. Our PCI-compliant call center page covers how that is structured.

This is general information rather than compliance advice. Confirm your obligations with a qualified assessor.