Registration for Britannic's Annual Summit is now open!

Register Now!

*Updated 14 September 2026* 

For organisations taking card payments by phone, PCI DSS compliance becomes significantly easier when sensitive payment data never enters the wider communications environment in the first place.

That means moving beyond an annual compliance exercise and asking a more practical question. Where can cardholder data currently travel across agents, desktops, telephony, contact centres, CRM platforms and call recordings, and how much of that exposure can be removed?

This is particularly important in 2026. PCI DSS v4.0.1 is now the active version of the Payment Card Industry Data Security Standard and requirements that were previously future-dated became effective from 31 March 2025.

At the same time, payment fraud continues to grow. UK Finance's Annual Fraud Report, published on 15 June 2026, found that criminals stole £1.28 billion through payment fraud during 2025. Remote purchase fraud losses reached £423.5 million, while cases increased by 13% to 3.2 million.

For contact centre, IT, security and compliance leaders, the objective should therefore be clear.

Reduce the number of people, systems and recordings exposed to payment data, then apply appropriate controls to what remains.

What Is PCI DSS Compliance in 2026?

The short answer

PCI DSS is the global payment security standard designed to protect cardholder data and sensitive authentication data. It applies to organisations that store, process or transmit cardholder data, as well as some organisations that can affect the security of the cardholder data environment.

PCI DSS v4.0.1 is now the current supported version of the standard.

The framework covers technical and operational controls across areas including access management, authentication, vulnerability management, network security, monitoring, testing and information security governance.

One important distinction is that PCI DSS should not simply be considered a once-a-year certification exercise.

Organisations need to understand where payment data exists, what systems can access it, how that environment changes and whether controls continue to operate as intended.

PCI SSC also makes clear that compliance validation requirements are managed by payment brands, acquirers and other organisations responsible for individual compliance programmes. This means businesses should confirm exactly which assessment and validation requirements apply to their environment rather than relying on a generic merchant level alone.

Why Does PCI DSS Scope Matter So Much?

The larger the cardholder data environment becomes, the more systems, processes and people an organisation may need to secure and assess.

For a contact centre taking payments manually, that could potentially involve more than the payment gateway.

Depending on the architecture, payment data may interact with:

  • Agents
  • Agent desktops
  • Telephony platforms
  • Contact centre technology
  • Call recordings
  • CRM platforms
  • Networks
  • Remote working environments
  • Payment applications
  • Third-party services

PCI SSC states that VoIP traffic containing payment card data can fall within PCI DSS scope once that traffic reaches infrastructure controlled by the organisation.

This is why Britannic recommends approaching PCI DSS from the perspective of data minimisation and scope reduction first.

Rather than asking how every existing system can be secured around card data, organisations should first establish whether card data needs to enter those systems at all.

Why Can Call Recording Create A PCI DSS Risk?

Call recording creates a particular challenge when customers read card information aloud.

A recording can unintentionally become another location where sensitive data is stored.

PCI SSC clarified this again in June 2025. PCI DSS Requirement 3.3.1 prohibits the storage of sensitive authentication data, including card verification codes, after authorisation. This applies to digital audio recordings as well as other forms of storage.

PCI SSC recommends preventing sensitive authentication data from being recorded wherever technology allows.

This distinction is important.

Recording the customer's conversation is not necessarily the problem. Recording payment credentials within that conversation is.

The architecture should therefore allow organisations to retain the business value of call recording for areas such as quality management, dispute resolution, training and analytics while preventing sensitive payment data from entering the recording.

Is Pausing A Call Recording Enough?

Pausing and resuming recording can help prevent sensitive information being captured, but it is not the only approach available.

Organisations should consider the complete payment journey rather than focusing solely on the recorder.

Payment Approach Agent Exposure Recording Exposure Operational Consideration
Customer reads card details aloud High Potentially high Card data can pass through multiple systems and processes
Manual pause and resume Card details may still be heard by the agent Reduced if operated correctly Relies on processes being followed consistently
Automated recording suppression Depends on design Payment section excluded Reduces reliance on manual agent actions
DTMF masking Agent does not need to see or hear card details Card details can be removed from the voice stream Can substantially reduce exposure across the contact centre
External secure payment journey Reduced Reduced
Customer may leave the original conversation depending on design

The correct approach depends on the organisation, payment journey, technology and applicable PCI DSS validation requirements.

The important point is that removing payment data from an environment is fundamentally different from simply protecting it after it has entered that environment.

How Does DTMF Masking Protect Telephone Payments?

DTMF stands for Dual-Tone Multi-Frequency and describes the signals created when numbers are entered using a telephone keypad.

With a secure DTMF payment solution, a customer can enter their card information through their telephone keypad while remaining connected to the agent.

The payment information is masked or suppressed so the agent does not need to see or hear the card details. The sensitive payment information can also be prevented from entering the voice recording.

This helps organisations separate the customer conversation from the payment-data journey.

Britannic's secure payment proposition uses this approach to help organisations take telephone payments while reducing the amount of sensitive card data exposed to agents and communications systems.

This can make PCI DSS management considerably more straightforward, although deploying a secure payment solution does not automatically make an organisation fully compliant. Scope, controls and validation responsibilities still need to be understood across the complete environment.

What Is Britannic's PCI Scope Reduction Framework?

Britannic recommends assessing telephone payment environments through five stages.

Stage Question Action
1. Map Where does payment data currently travel? Map every system, person, recording and third party involved in the payment journey
2. Minimise Where can card data be removed completely? Stop unnecessary collection, visibility and storage
3. Isolate What genuinely needs to remain within the payment environment? Separate payment processing from wider communications and business systems where appropriate
4. Protect How are the remaining systems secured? Apply access, authentication, monitoring, vulnerability and security controls
5. Prove Can the organisation demonstrate that controls work? Test, document, monitor and review the environment continuously

The order matters.

Starting with security controls before understanding whether systems need access to payment data can result in organisations protecting unnecessary complexity.

A better payment architecture aims to remove unnecessary exposure before additional controls are introduced.

What Should Businesses Review Before Taking Telephone Payments?

A PCI DSS review should follow the complete transaction rather than looking at the payment gateway in isolation.

PCI DSS Telephone Payment Checklist

Organisations should establish

  • Where cardholder data enters the organisation
  • Whether agents can see or hear card information
  • Whether call recordings can capture card information
  • Whether payment information passes through VoIP infrastructure
  • Whether card data enters the CRM or customer record
  • Whether browser sessions or agent desktops can access cardholder data
  • Whether remote workers can access the payment environment
  • Which third-party providers are involved
  • Whether third-party responsibilities are documented
  • Whether access is restricted according to business need
  • Whether multi-factor authentication requirements are being met
  • Whether vulnerability scanning and testing requirements apply
  • How security events are logged and monitored
  • Whether payment flows have changed since the previous assessment
  • Whether recordings and payment data have appropriate retention policies
  • Whether staff understand their payment security responsibilities
  • Whether controls are tested after significant technology changes
  • Who owns PCI DSS compliance internally
  • How compliance evidence is collected and maintained

This should be treated as a cross-functional exercise involving IT, cybersecurity, compliance, contact centre operations and relevant business owners.

Does Outsourcing Payments Remove PCI DSS Responsibilities?

Not completely.

Moving payment processing to a specialist third-party provider can significantly reduce the number of PCI DSS requirements directly applicable to an organisation's environment.

However, PCI SSC states that outsourcing payment processing does not remove the merchant's responsibilities completely.

Organisations may still need to validate compliance, confirm that relevant service providers maintain appropriate PCI DSS status, document responsibilities and monitor providers over time.

This reinforces an important distinction.

Reduced PCI DSS scope does not mean zero PCI DSS responsibility.

The objective is to make those responsibilities smaller, clearer and easier to manage.

How Can Secure Payments Work With A Modern Contact Centre?

Payment compliance should not force organisations to compromise customer experience.

A customer may have spent several minutes explaining an issue before reaching the payment stage. Forcing them into an unfamiliar process, transferring them unnecessarily or ending the conversation can introduce friction at exactly the point they are trying to complete a transaction.

Modern contact centre platforms can integrate secure payment journeys alongside voice and digital customer interactions.

Britannic works across contact centre environments including 8x8 and Five9, integrating communications, payment journeys and wider business systems according to each organisation's requirements.

The goal is to keep the customer journey straightforward while separating sensitive payment information from systems and people that do not need access to it.

How Has Secure Payment Technology Worked In Practice?

The Institution of Engineering and Technology previously used physical PDQ machines to process telephone payments, which created a time-consuming process for agents.

Britannic helped The IET move to SIP telephony and a cloud-based secure payment solution using DTMF masking.

Customers could enter payment information through their telephone keypad without exposing card details to agents or storing them within the voice environment.

The project allowed agents to take payments while working from different locations and helped The IET save 30 hours per month compared with its previous payment process.

The example demonstrates an important principle.

PCI DSS projects do not have to create additional operational friction. Redesigning how payment data moves through the organisation can improve security and efficiency at the same time.

What Other Compliance Requirements Apply To Call Recording?

PCI DSS is only one consideration when organisations record customer conversations.

Call recordings can contain personal information and therefore need to be managed in accordance with applicable data protection requirements.

The Information Commissioner's Office states that recording business calls may be appropriate where necessary for purposes such as providing evidence of transactions, training or quality control.

Organisations should consider proportionality, establish an appropriate lawful basis and make workers and customers aware of relevant monitoring and recording practices.

This means an effective recording strategy should consider both

  • what needs to be recorded
  • what should never enter the recording

Payment data is a particularly clear example of why those questions need to be considered separately.

Why Should PCI DSS Be Treated As Continuous Compliance?

Technology environments rarely remain static for an entire year.

Organisations introduce new contact centre platforms, cloud services, integrations, payment providers, remote working arrangements, AI applications and customer channels.

Every significant change can alter where data travels or which systems can affect the security of the cardholder data environment.

This is one reason PCI DSS v4.0.1 places greater emphasis on ongoing security processes rather than treating compliance as a single point-in-time exercise.

The wider cybersecurity environment reinforces the need for this approach. IBM's 2026 Cost of a Data Breach research found that the average UK data breach cost £3.13 million, while 22% of UK organisations surveyed reported experiencing AI-generated attacks.

A PCI DSS assessment therefore needs to be connected to wider security governance, change management and operational processes.

How Can Businesses Make PCI DSS Compliance More Manageable?

The most effective approach is not to surround an unnecessarily large environment with more security controls.

It is to simplify the payment architecture.

Organisations should understand the complete payment journey, minimise where card information appears, separate payment processing from wider systems wherever possible and then apply appropriate controls to what remains.

For telephone payments, that often means preventing sensitive payment details from reaching agents, recordings and other communications systems in the first place.

The result can be a smaller PCI DSS footprint, clearer operational responsibility and a payment journey that remains convenient for the customer.

Britannic helps organisations assess their communications, contact centre, call recording and payment environments to identify where sensitive payment data is exposed and where the payment journey can be simplified.

Organisations reviewing PCI DSS v4.0.1, telephone payments or call recording can book a complimentary meeting with Britannic to map the existing payment journey and identify opportunities to reduce unnecessary PCI DSS scope.