KuberEva Book a call

Home/Documentation/PCI DSS

PCI DSS in the contact center

The moment a customer reads a card number to an agent, the voice path becomes part of your cardholder data environment — along with the recording, the transcript, and everything downstream of them.

Where things stand

PCI DSS v4.0.1 has been mandatory since 31 March 2025. Version 4.0 sunset on 31 December 2024. So the transition period is over — v4.0.1 is simply the standard now.

On the point that matters most for voice, v4.0.1 is unambiguous: call recordings must not contain cardholder data. Recordings that capture PANs, CVVs, or PINs in audio form violate Requirement 3.

The CVV point is absolute Sensitive authentication data — CVV, PIN — must not be stored after authorization under any circumstances, encrypted or otherwise. There is no compensating control that makes a stored CVV acceptable. A recording containing a spoken CVV is a violation regardless of how well that recording is protected.

Why pause-and-resume no longer holds up

The traditional control is procedural: agents are trained to pause the recording before the customer reads their card details, and resume afterwards.

The problem is arithmetic. Agent compliance with pause/resume typically runs somewhere in the 80–95% range — which means 5 to 20% of recordings still capture card data. At any meaningful call volume that is a large number of non-compliant recordings, and each one drags its storage, its backups, and its downstream consumers into scope.

The position now is that pause-and-resume, which depends on an agent remembering under pressure, is not adequate. Organizations are expected to use technical masking architectures rather than relying on manual agent compliance.

DTMF masking: the accepted technical control

DTMF masking is the preferred control. The customer enters their card number on the telephone keypad rather than speaking it, and the tones are suppressed in real time.

Three things happen simultaneously:

Tokenization and DTMF masking together — where customers input card numbers via their keypad, bypassing agent ears and call recording entirely — are now the accepted standard for inbound calls where payments are taken. Critically, the agent stays on the line throughout, so the customer experience is preserved rather than being pushed to an IVR and back.

Map where cardholder data actually flows

This is the step most often done incompletely. Card data in a contact center goes further than people expect, and every destination inherits scope.

Fig. 1 — spoken digits versus masked digits what falls in scope
Customer speaks the number Caller Agent Call recording Transcript QM & analytics Backups · AI tooling All of it in PCI scope every system, every backup, every assessment Customer keys it in — DTMF masked Caller Agent stays on the line · hears masked tones digits never touch agent, recording or transcript Payment processor — token returned Everything above leaves scope
The compliance case is obvious; the financial case is usually stronger. Once card data never enters the voice path, the recording platform, storage, backups, transcription, QM and analytics all drop out of the assessed environment — every assessment cycle, not once.
DestinationFrequently overlooked because
Call recording storageIt is the obvious one, and usually the only one addressed.
Backups and archivesRetention is often years. A recording deleted from primary storage may persist in backup well beyond that.
Speech-to-text transcriptsA transcript of a spoken card number is cardholder data in text form — arguably worse, because it is searchable.
Quality management samplesQM tooling pulls copies into a separate system with its own access model.
Speech and interaction analyticsAnother copy, another platform, often a third-party cloud service.
AI systems reading transcriptsThe newest and least-governed path. Agent-assist, summarization, and coaching tools consume transcripts wholesale — including any card data in them.
Screen recordingIf an agent types a card number into a CRM field, the screen capture contains it too.
Agent notes and CRM free textAgents write things down. Free-text fields are a persistent source of stray PANs.
Chat and email channelsCustomers send card details over any channel available to them, regardless of instruction.
The AI addition to this problem Agent-assist and summarization tools are being deployed rapidly and often outside the governance that covers recording platforms. If a transcript containing card data reaches an AI service, that service is now in scope — and possibly outside your data residency boundary. Include AI tooling in the data-flow map explicitly. It is frequently the newest and least-documented path.

Scope reduction is the real prize

The compliance argument for a technical control is straightforward. The financial argument is usually stronger.

Every system that touches cardholder data falls within the assessed environment. Once card data never enters the voice path in the first place, a substantial estate — recording platform, storage, backups, transcription, QM, analytics — can move out of scope. For most organizations that reduction is the largest saving in the project, and it recurs every assessment cycle.

Design questions worth asking early

  1. Where does masking happen? In the network at the SBC, in the CCaaS platform, or in a hosted payment service? This determines what is in scope and who carries what responsibility.
  2. What does the agent see and hear? Confirm they get progress feedback without any digits.
  3. What happens on failure? If the masking service is unavailable, does the call fall back to an unmasked path? That fallback is a compliance hole.
  4. How are outbound and callback flows handled? Masking is usually designed for inbound and quietly missing on outbound.
  5. What about the other channels? Chat, email, and web forms need their own controls.
  6. How is evidence produced? Your QSA will want to see that the control operated continuously, not that it exists.
  7. What about historical recordings? Existing archives containing card data remain a liability. Remediation — targeted deletion or redaction — is a separate piece of work that needs a plan.

Where this intersects with migration

A CCaaS migration or a move to SIP is the natural moment to fix this, because the media path is being redesigned anyway. Retrofitting masking into a settled architecture is considerably more expensive than designing it in.

Conversely, a migration that does not address it will faithfully reproduce the existing problem on a new platform — and the new platform frequently adds transcription and AI features that widen the exposure.

Related reading

Scope reduction usually pays for the whole project. We map the data flow first.

Book a call