Payments & Security

PCI DSS: What It Means for Contact Centres Taking Card Payments

PCI DSS — the Payment Card Industry Data Security Standard — is the global set of security rules for any organisation that stores, processes or transmits payment card data.

If your contact centre takes card payments over the phone, PCI DSS applies to you.

It's maintained by the PCI Security Standards Council (PCI SSC), the body founded by the major card brands. The current standard is the 4.x generation, with v4.0.1 the active version following the retirement of earlier versions.

This guide explains, in plain English, what PCI DSS is, the 12 high-level requirements, and the specific techniques contact centres use to take phone payments securely.

This is general information, not security or compliance advice — for your obligations, work from the official standard and a qualified assessor.

What it is

A security standard, maintained by the PCI Security Standards Council, that sets out how organisations must protect payment card data they store, process or transmit.

Why it matters

Contact centres handling card numbers by phone are squarely in scope. Done badly, you risk breaches, fines and lost trust; done well, you can dramatically shrink what's in scope.

What this guide covers

What PCI DSS is, the 12 requirements at a high level, the current version, and the practical contact-centre techniques: DTMF masking, pause-and-resume, descoping and SAQs.

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a set of technical and operational requirements designed to protect payment card data.

It applies to any organisation that stores, processes or transmits cardholder data — from global banks to a small business taking the occasional card payment by phone.

It's maintained by the PCI Security Standards Council, founded by the major card brands (Visa, Mastercard, American Express, Discover and JCB).

Importantly, PCI DSS is a contractual and industry standard rather than a law.

But that doesn't make it optional: your bank and the card schemes require compliance as a condition of accepting card payments, and non-compliance can carry real financial and commercial consequences.

What it is

A card-industry security standard that protects cardholder data, validated through self-assessment questionnaires or formal assessments depending on your volume and risk.

What it is not

It is not a government law, not a one-off certificate you earn and forget, and not something you can fully delegate by simply "using a compliant provider". You still have obligations.

Why It Matters for Contact Centres

A contact centre that takes card payments by phone is one of the highest-risk environments for cardholder data: numbers are read aloud, typed into systems, and potentially captured in call recordings.

That's exactly why PCI DSS matters here.

🔒 You're handling the riskiest data

Card numbers spoken over the phone can be overheard by agents, captured in recordings, and exposed across screens and systems — a large attack surface unless deliberately controlled.

💸 The cost of getting it wrong

A breach can mean card-scheme fines, forensic investigation costs, remediation, and — often most damaging — a serious loss of customer trust that's hard to win back.

📉 You can shrink the problem

The smart move isn't just to secure card data — it's to stop card data from entering your environment at all. "Descoping" can hugely reduce both your risk and your compliance burden.

The 12 Requirements (a High-Level View)

PCI DSS is structured around 12 core requirements, grouped under six control objectives. The list below is a plain-English summary — the full, authoritative wording lives in the standard itself, published by the PCI SSC.

  1. Install and maintain network security controls (firewalls and equivalent) to control traffic in and out of the cardholder data environment.
  2. Apply secure configurations to all system components — no vendor default passwords or settings.
  3. Protect stored account data — minimise what you store and render it unreadable (e.g. encryption, truncation).
  4. Protect cardholder data with strong cryptography during transmission over open, public networks.
  5. Protect all systems and networks from malicious software.
  6. Develop and maintain secure systems and software, including timely patching.
  7. Restrict access to cardholder data by business need-to-know.
  8. Identify users and authenticate access — unique IDs and strong authentication, including multi-factor where required.
  9. Restrict physical access to cardholder data and the systems that handle it.
  10. Log and monitor all access to network resources and cardholder data.
  11. Test the security of systems and networks regularly.
  12. Maintain an information security policy and supporting programs for all personnel.
Australia

How it fits the Australian picture

PCI DSS is a global standard and applies to Australian businesses the same way it does elsewhere — through your acquiring bank and the card schemes.

It sits alongside, not instead of, Australian privacy obligations: if you handle personal and financial data, the Privacy Act 1988 and the Australian Privacy Principles still apply, overseen by the Office of the Australian Information Commissioner (OAIC).

Treat PCI DSS and your privacy obligations as complementary, not interchangeable.

Phone Payments in a Contact Centre

Taking card payments over the phone creates specific PCI DSS challenges, because the card number passes through your agents, your telephony — including any CTI (computer-telephony integration) that links calls to your systems — and potentially your call recordings. Here are the key techniques and terms.

DTMF masking

The customer types their card number on their phone keypad instead of reading it aloud.

The DTMF tones are suppressed or masked so the agent can't hear them and they're never written to the call recording — keeping the card data out of your environment entirely.

Pause-and-resume recording

The call recording is paused while card details are taken and resumed afterward, so the number isn't captured in the recording.

It's better than recording everything — but it's a weaker control than DTMF masking, because the agent still hears the number.

Descoping & SAQs

Descoping means designing your processes so cardholder data never enters your systems — for example, routing the customer to an automated payment line, or using DTMF masking with a payment provider.

The less card data touches your environment, the smaller your "cardholder data environment" (CDE) and the lighter your compliance burden.

How you validate compliance depends on your transaction volume and how you process payments. Most smaller merchants use a Self-Assessment Questionnaire (SAQ) — and there are different SAQ types for different setups.

Effective descoping can move you to a simpler SAQ with far fewer applicable controls. Larger merchants may require a formal assessment by a Qualified Security Assessor.

💡 Challenge the lazy default: "just pause the recording"

Pause-and-resume is widely treated as the go-to fix, but it's a comparatively weak control: it depends on the pause working reliably every time, and the agent still hears and handles the card number.

Our editorial position is that contact centres should aim higher — use DTMF masking or descope the card data out of your environment altogether, rather than settling for the cheapest tick-box option.

Common Pitfalls

PCI DSS trips up contact centres in predictable ways. Here are the most common.

Treating it as a one-off project

Compliance isn't a certificate you earn once. PCI DSS expects controls to be operating continuously — "compliant on assessment day" but lax the rest of the year is exactly the gap that leads to breaches.

Assuming your provider covers you

Using a PCI-compliant payment provider helps, but it rarely removes all your obligations. Responsibilities are shared, and you still need to understand and manage your part of the scope.

⚠️ Card data in places you forgot

The most dangerous card data is the data you didn't realise you were keeping — numbers jotted on notepads, sitting in old call recordings, pasted into CRM notes, or sent over chat.

Hunt these down. The safest card data is the data you never captured in the first place.

Frequently Asked Questions About PCI DSS

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for any organisation that stores, processes or transmits payment card data. It's maintained by the PCI Security Standards Council, founded by the major card brands, and applies to businesses of all sizes — including contact centres that take card payments by phone.

Is PCI DSS a law?

No. PCI DSS is an industry and contractual standard, not legislation. However, your acquiring bank and the card schemes require compliance as a condition of accepting card payments, so it isn't optional in practice. In Australia it also sits alongside legal privacy obligations under the Privacy Act 1988.

What is the current version of PCI DSS?

The current generation is PCI DSS version 4.x, with v4.0.1 the active version after earlier versions were retired. v4.0.1 is described by the PCI SSC as a limited revision that introduced no new or removed requirements compared with v4.0. Because versions and deadlines change over time, always confirm the current version and any applicable dates directly with the PCI Security Standards Council.

Why does PCI DSS matter for contact centres?

Contact centres that take card payments by phone handle some of the riskiest cardholder data: numbers read aloud, typed into systems and potentially captured in call recordings. PCI DSS sets the standard for protecting that data — and good practice can also shrink the amount of card data in your environment, reducing both risk and compliance effort.

What is DTMF masking?

DTMF masking lets the customer enter their card number on their phone keypad rather than reading it aloud. The keypad tones are suppressed or masked so the agent can't hear them and they aren't written into the call recording. This keeps the card data out of your environment and is generally a stronger control than pausing call recordings.

Is pausing the call recording enough?

It's better than recording everything, but in our editorial view it's a comparatively weak control. Pause-and-resume depends on the pause working reliably every time, and the agent still hears and handles the card number. Contact centres should aim higher — using DTMF masking or descoping card data out of their environment entirely.

What is descoping, and what is an SAQ?

Descoping means designing your processes so cardholder data never enters your systems — for example via DTMF masking or routing payments to an automated line. The less card data touches your environment, the smaller your cardholder data environment and your compliance burden. An SAQ (Self-Assessment Questionnaire) is how many smaller merchants validate compliance; there are different SAQ types for different setups, and effective descoping can move you to a simpler one.

Does using a compliant payment provider make me compliant?

Not entirely. Using a PCI-compliant provider helps and can reduce your scope, but PCI DSS responsibilities are shared. You still need to understand which controls remain yours, document your scope, and keep them operating. Don't assume the provider covers everything.

Where to Next

To apply PCI DSS well in a contact centre, start with the practical guidance — then go to the PCI Security Standards Council for the authoritative standard.

📞

Call Centre Hub

Practical guidance for running a secure, high-performing contact centre that takes payments.

🏛️

Official Source (PCI SSC)

The PCI Security Standards Council publishes the standard, the SAQs and supporting guidance — the authoritative source.

🤝

Become a Member

Access ACXPA's full library of standards, resources and training for contact centre and CX teams.

, start with the practical guidance for applying PCI DSS in your operation — then go to the PCI SSC for the authoritative standard.

📞

Call Centre Hub

Practical guidance for running a secure, high-performing contact centre that takes payments.

🏛️

Official Source (PCI SSC)

The PCI Security Standards Council publishes the standard, the SAQs and supporting guidance — the authoritative source.

🤝

Upgrade your Membership

, upgrade to unlock the full member resources, benchmarking and training for contact centres.

, here's the practitioner side from ACXPA — plus accredited suppliers and the authoritative standard.

📞

Members Call Centre Hub

Your full library of practitioner-led resources for running a secure, high-performing contact centre.

🗂️

ACXPA Supplier Directory

Find contact centre technology providers with PCI DSS compliance, tagged in the ACXPA Supplier Directory.

🏛️

Official Source (PCI SSC)

The PCI Security Standards Council — the authoritative source for the standard, the SAQs and supporting guidance.

Summary: PCI DSS for Contact Centres

PCI DSS is the card industry's security standard for protecting payment card data, and any contact centre that takes card payments by phone is squarely in scope.

It's built around 12 high-level requirements, maintained by the PCI Security Standards Council, with v4.0.1 the current active version of the 4.x generation — though versions and deadlines change, so confirm the current detail with the PCI SSC.

Our editorial position is simple: don't just secure card data — stop it entering your environment.

DTMF masking and descoping beat the lazy default of pause-and-resume, and effective descoping can shrink both your risk and your compliance burden. The safest card number is the one you never captured.

This page is general information, not security or compliance advice.

For your obligations, work from the official PCI Security Standards Council standard and a qualified assessor, and remember your Australian privacy obligations under the OAIC apply too.

For applying it well operationally, start with ACXPA's Call Centre resources.

0 Comments

Leave a reply

ACXPA PLATINUM SPONSORS

ACXPA Platinum SPONSORS
ACXPA SILVER SPONSORS
ACXPA Platinum SPONSORS
ACXPA BRONZE SPONSORS
ACXPA Platinum SPONSORS
ACXPA Platinum SPONSORS
Copyright © 2026 | Australian Customer Experience Professionals Association | Website Terms of Use | Privacy Policy

Log in with your email address

or Become an ACXPA Member

Forgot your details?

Create Account