PCI DSS and Call Recording: Keeping Card Data Safely Out of Recordings
How contact centers comply with PCI DSS v4.0.1 during call recording: no card data in recordings, pause/resume vs. DTMF masking, no CVV after authorization.
Why PCI DSS Affects Call Recording
As soon as a contact center accepts card payments over the phone and records calls, a conflict arises: recordings serve quality and compliance — but they must not contain payment card data. This is precisely where the PCI DSS (Payment Card Industry Data Security Standard) comes in. The current version 4.0.1 has been mandatory since March 31, 2025.
For operators of customer service and contact center environments, this means: recording and card payment must be technically and cleanly separated — otherwise, there is a risk of audit findings, penalties from card organizations, and an increased data privacy risk.
What PCI DSS Requires for Recordings
The core requirement is clear: call recordings must not contain cardholder data. Recordings that capture the full card number (PAN), the card verification value (CVV/CVC), or the PIN in the audio violate Requirement 3 of the standard.
The rule is particularly strict for sensitive authentication data: CVV/CVC, full magnetic stripe data, and PIN must under no circumstances be stored after authorization — not even encrypted, not even "just briefly."
The Core Conflict: Recording Meets Card Data
In practice, the problem arises at the moment of payment: the customer speaks or types their card details while the call is ongoing and being recorded. Without a protective mechanism, the PAN and CVV end up in the audio file — and thus within the scope of the PCI DSS. The scope then includes the recording system, storage, and all connected systems, which drastically increases effort and risk.
The goal is therefore to keep the card data moment completely out of the recording — and ideally out of the entire agent workstation.
Pause/Resume: Common, but Risky
The classic approach is pause/resume: the recording is paused during card data entry and continued afterward. This works, but it is prone to error and is increasingly viewed critically in audits. Typical weaknesses: employees forget to pause, the timing is not exact, or the "pause" function of the recording solution only mutes the file while the audio continues in the background. Manual pause/resume often fails to meet the expectation of automatic, reliable exclusion of sensitive data.
If pause/resume is used, it should be triggered automatically, for example by the payment system, logged seamlessly, and demonstrably pause the audio — not just the visible file.
DTMF Masking: The Resilient Approach
The more robust path is DTMF masking (also known as DTMF suppression): if the customer enters the card number using the telephone keypad, the key tones are intercepted and routed directly to the payment service provider — as neutral tones, without card data reaching the agent, their screen, or the recording. The agent remains on the call but does not hear any recognizable digits, and the recording contains no card data.
Through this channel separation, the card data moment leaves the area of responsibility of the contact center. This significantly reduces the PCI scope and is the approach that reliably holds up in audits. An alternative with a similar effect is outsourcing the payment to a secure IVR self-service.
Implementation in Practice
For clean operations, a clear workflow is recommended: first, check at which points in the call card data is collected. Next, technically separate the payment from the agent and recording path — preferably via DTMF masking or secure IVR. If pause/resume is used, trigger it automatically and log it seamlessly. Additionally, ensure that CVV/CVC and other sensitive authentication data are never stored, retention periods are enforced automatically, and regular random samples prove that no card data enters recordings.
How onsoft Supports You
onsoft provides legally compliant call and screen recording for contact centers with encrypted, audit-proof storage, automated retention periods, and targeted recovery. For PCI-relevant processes, recording and the payment moment can be cleanly separated — including automatically triggered pausing and seamless logging. In combination with AI speech analysis and quality management, compliance evidence and service quality remain in one system.
Frequently Asked Questions
Are card data allowed to be stored in call recordings?
No. According to PCI DSS, recordings must not contain cardholder data. Having the card number, verification value, or PIN in the audio violates Requirement 3.
Is pause/resume sufficient for PCI DSS?
Manual pause/resume is considered error-prone and increasingly critical in audits. It should be triggered automatically and logged seamlessly; DTMF masking or a secure IVR is more resilient.
What is DTMF masking?
The card data entered via the telephone keypad is routed directly to the payment service provider as tones, so that it reaches neither the agent, the screen, nor the recording.
May the CVV/CVC be stored?
No. Sensitive authentication data such as CVV/CVC, magnetic stripe data, and PIN must under no circumstances be stored after authorization.
Since when has PCI DSS v4.0.1 been in effect?
Version 4.0.1 has been mandatory since March 31, 2025.


