PCI Compliance for Taking Payments Over the Phone: Complete UK Guide (2026)

Introduction – PCI compliance over the phone payments

Taking card payments over the phone remains one of the most common payment methods used by UK businesses. From customer service teams and contact centres to professional services firms and healthcare providers, thousands of organisations accept payments during live telephone conversations every day.

However, many businesses are unaware that accepting card details verbally can significantly increase their PCI DSS compliance obligations.

If employees can hear, record, write down, store or access cardholder data, your organisation may fall within a much larger scope of PCI DSS requirements.

This guide explains how PCI DSS applies to telephone payments, the risks businesses face, and the most effective ways to reduce compliance scope while maintaining an excellent customer experience.

What Is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard designed to protect cardholder data.

Any organisation that stores, processes or transmits payment card information must comply with PCI DSS requirements.

The current standard is PCI DSS v4.0.1, which became fully effective in March 2025 and introduced a number of additional security requirements for organisations handling payment data.

For businesses taking card payments over the phone, compliance is not simply about securing payment systems. It also includes:

  • Staff handling payments
  • Call recordings
  • Telephone platforms
  • Contact centre systems
  • CRM platforms
  • Network infrastructure
  • Access controls
  • Security monitoring

The more places cardholder data can appear, the greater the compliance burden.

Why Telephone Payments Create PCI Compliance Challenges

Online payments are relatively straightforward.

A customer enters their card details into a secure payment page and the information is transmitted directly to the payment processor.

Telephone payments are different.

When a customer reads card details aloud to an employee, those details can potentially be:

  • Heard by staff
  • Written down
  • Stored in emails or notes
  • Captured in call recordings
  • Visible within CRM systems
  • Exposed through screen recordings
  • Accessed by unauthorised personnel

As a result, many businesses unknowingly bring large parts of their organisation into PCI scope.

Common PCI Compliance Risks When Taking Payments Over the Phone

1. Call Recording Systems

One of the most common compliance issues occurs when payment card details are captured within call recordings.

Many businesses record calls for quality assurance, training or dispute resolution purposes.

If card numbers, expiry dates or CVV codes are included within those recordings, the recordings themselves become sensitive payment data.

This dramatically increases compliance requirements.

2. Employees Hearing Card Details

If an employee can hear cardholder information, there is always a risk of accidental disclosure, human error or malicious activity.

Even well-trained employees represent a potential point of exposure.

3. Written Notes

Some organisations still record payment details on paper before processing transactions.

This creates significant security and compliance concerns.

4. Contact Centre Systems

Modern contact centres often integrate telephony, CRM, analytics and call recording systems.

If cardholder data enters any part of this environment, those systems may fall within PCI scope.

How PCI DSS Applies to Telephone Payments

The key question is simple:

Does cardholder data enter your environment?

If card details pass through systems you own, manage or control, those systems may be subject to PCI DSS requirements.

This can include:

  • Telephone systems
  • Contact centre platforms
  • Call recording solutions
  • Desktop applications
  • Internal networks
  • Databases
  • Storage systems

Reducing compliance scope therefore becomes a matter of preventing cardholder data from entering your environment in the first place.

Methods Used to Take PCI Compliant Phone Payments

1.Traditional Verbal Card Payments

The customer reads their card details to the employee.

Advantages:

  • Familiar process
  • No additional technology required

Disadvantages:

  • High compliance burden
  • Increased security risk
  • Greater audit requirements
  • Higher exposure to human error

For most organisations, this is the highest-risk approach.

2. Pause and Resume Recording

Historically, many businesses paused call recordings while payment details were collected.

Advantages:

  • Relatively simple

Disadvantages:

  • Relies heavily on staff actions
  • Risk of recordings not being paused correctly
  • Does not remove cardholder data from the agent environment

While still used in some organisations, many businesses are moving towards more secure alternatives.

3. Secure IVR Payments

Customers are transferred to a secure payment environment where they enter card details using their telephone keypad.

Advantages:

  • Reduces exposure to cardholder data
  • Improves security

Disadvantages:

  • Customer leaves the live conversation
  • Can increase abandonment rates

4. DTMF Masking and Agent-Assisted Payments

DTMF (Dual Tone Multi Frequency) masking allows customers to enter payment details using their telephone keypad while remaining on the call with the employee.

The employee stays available to assist throughout the transaction, but never hears or sees the card details.

Benefits include:

  • Improved customer experience
  • Reduced PCI scope
  • Elimination of card details from recordings
  • Reduced fraud risk
  • Greater customer confidence

This has become one of the most widely adopted approaches for secure telephone payments.

What Is DTMF Masking?

When a customer presses keys on their phone, each button generates a DTMF tone.

DTMF masking technology intercepts these tones before they can be heard by employees or captured by call recording systems.

Instead:

  • The customer enters payment information using their keypad
  • Sensitive tones are removed or masked
  • The payment information is transmitted securely to the payment processor
  • The employee remains on the line throughout the payment process

The result is a seamless payment experience without exposing cardholder data to staff.

Benefits of PCI Compliant Telephone Payments

Reduced Compliance Scope

By preventing cardholder data from entering your environment, businesses can significantly reduce the systems that fall within PCI scope.

Lower Risk

Removing employee access to payment information reduces opportunities for fraud, accidental disclosure and data breaches.

Improved Customer Trust

Customers increasingly expect secure payment experiences.

Knowing their card details are not spoken aloud often improves confidence.

Operational Simplicity

Secure payment technologies can reduce the complexity associated with audits, assessments and compliance management.

Which Businesses Need PCI Compliant Phone Payments?

PCI compliant telephone payment solutions are commonly used by:

  • Contact centres
  • Professional services firms
  • Healthcare providers
  • Local authorities
  • Housing associations
  • Charities
  • Membership organisations
  • Utilities providers
  • Financial services organisations
  • Education providers

Any business accepting card payments by telephone should assess its PCI DSS obligations.

Questions to Ask Your Current Provider

When evaluating a telephone payment solution, consider asking:

  • Do card details ever reach my staff?
  • Can payment information be captured in recordings?
  • Is DTMF masking supported?
  • Does the solution integrate with my existing telephony platform?
  • Can customers remain on the call during payment?
  • What PCI compliance evidence is available?
  • How quickly can the solution be deployed?

PCI Compliant Phone Payments with PortalPCI

PortalPCI helps organisations accept card payments over the phone without exposing cardholder data to employees, call recordings or internal systems.

Customers enter payment details securely using their telephone keypad while remaining on the call with your team.

This approach helps reduce compliance scope, improve customer trust and simplify the process of taking payments over the phone.

Whether you operate a small customer service team or a large contact centre, PortalPCI provides a straightforward way to modernise and secure your payment process.

Frequently Asked Questions

Is it PCI compliant to take card details over the phone?

Yes, but how the payment is taken determines the scope of PCI DSS requirements. Traditional verbal card payments generally create a much larger compliance burden than secure keypad-entry solutions.

What is DTMF masking?

DTMF masking is a technology that prevents card details entered via a telephone keypad from being heard by employees or captured in call recordings.

Can call recordings cause PCI compliance issues?

Yes. If payment card information is recorded, those recordings may become subject to PCI DSS requirements.

What is the safest way to take payments over the phone?

Many organisations use secure keypad-entry solutions with DTMF masking or secure IVR technology to prevent cardholder data from entering their environment.

Does PCI DSS apply to small businesses?

Yes. PCI DSS applies to organisations of all sizes that store, process or transmit payment card information.

Cloud Migrations

Save your business money and maximise your productivity by migrating your business to the cloud with Microsoft Office 365.

Backup & Recovery

Our Endpoint Backup Solution allows your device to be restored from the cloud anywhere, leaving minimal disruption to your business.

Managed IT Support

Our remote help desk gives you and your staff unlimited access to our technicians for any IT issues you might have.

Cyber Security

Portal Technologies can provide you with the consultancy and technician time required to get you Cyber Essentials Certified.

Our Company and IT Support Blog

Portal Technologies
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.