Onsoft

Solutions

References

Resources

Company

Contact

PCI DSS and Call Recording: Keeping Card Data Safely Out of Recordings

How contact centers comply with PCI DSS v4.0.1 during call recording: no card data in recordings, pause/resume vs. DTMF masking, no CVV after authorization.

Why PCI DSS Affects Call Recording

As soon as a contact center accepts card payments over the phone and records calls, a conflict arises: recordings serve quality and compliance — but they must not contain payment card data. This is exactly where the PCI DSS (Payment Card Industry Data Security Standard) comes in. The current version 4.0.1 has been mandatory since March 31, 2025.

For operators of customer service and contact center environments, this means that recording and card payment must be technically separated in a clean manner — otherwise audit findings, fines from card organizations, and an increased data protection risk are threatened.

What PCI DSS Requires for Recordings

The core is clear: call recordings must not contain cardholder data. Recordings that capture the full card number (PAN), the verification code (CVV/CVC), or the PIN in the audio violate Requirement 3 of the standard.

The rule is particularly strict for sensitive authentication data: CVV/CVC, full magnetic stripe data, and PIN must not be stored under any circumstances after authorization — not even encrypted, and not even "just briefly".

The Core Conflict: Recording Meets Card Data

In practice, the problem arises at the moment of payment: the customer says or types her card details while the call is ongoing and being recorded. Without a protective mechanism, PAN and CVV end up in the audio file — and thus in the scope of the PCI DSS. The scope then includes the recording system, storage, and all connected systems, which drastically increases effort and risk.

The goal is therefore to keep the card data moment completely out of the recording — and ideally out of the entire agent workstation.

Pause/Resume: Common, but Risky

The classic approach is Pause/Resume: the recording is paused during card data entry and then resumed. This works, but is error-prone and is viewed with increasing criticism in audits. Typical weaknesses: employees forget to pause, the timing is not exact, or the "pause" of the recording solution only mutes the file while the audio continues in the background. Manual Pause/Resume often fails to meet the expectation of automatic, reliable exclusion of sensitive data.

If Pause/Resume is used, it should be triggered automatically, for example by the payment system, fully logged, and demonstrably pause the audio — not just the visible file.

DTMF Masking: The Resilient Approach

The more robust path is DTMF masking (also DTMF suppression): if the customer enters the card number via the telephone keypad, the key tones are intercepted and routed directly to the payment service provider — as neutral tones, without card data reaching the agent, their screen, or the recording. The agent remains on the line but hears no recognizable digits, and the recording contains no card data.

Through this channel separation, the card data moment leaves the area of responsibility of the contact center. This significantly reduces the PCI scope and is the approach that reliably holds up in the 2026 audit. An alternative with a similar effect is outsourcing the payment to a secure IVR self-service.

Implementation in Practice

For clean operations, a clear process is recommended: first, check where in the call card data occurs. Next, technically decouple the payment from the agent and recording path — preferably via DTMF masking or secure IVR. If Pause/Resume is used, trigger it automatically and log it seamlessly. Additionally, ensure that CVV/CVC and other sensitive authentication data are never stored, retention periods are enforced automatically, and regular spot checks prove that no card data gets into recordings.

How onsoft Supports This

onsoft provides legally compliant call and screen recording for contact centers with encrypted, audit-proof storage, automated retention periods, and targeted recovery. For PCI-relevant processes, the recording and payment moment can be cleanly separated — including automatically triggered pausing and seamless logging. In combination with AI speech analysis and quality management, compliance proof and service quality remain in one system.

Frequently Asked Questions

Are card details allowed to be stored in call recordings?

No. According to PCI DSS, recordings must not contain cardholder data. Card numbers, verification codes, or PINs in the audio violate Requirement 3.

Is Pause/Resume sufficient for PCI DSS?

Manual Pause/Resume is considered error-prone and increasingly critical in audits. It should be triggered automatically and logged seamlessly; DTMF masking or a secure IVR is more resilient.

What is DTMF masking?

The card details entered via the telephone keypad are routed directly to the payment service provider as tones, so they reach neither the agent, the screen, nor the recording.

Can the CVV/CVC be stored?

No. Sensitive authentication data such as CVV/CVC, magnetic stripe data, and PIN must never be stored after authorization under any circumstances.

Since when has PCI DSS v4.0.1 been in effect?

Version 4.0.1 has been mandatory since March 31, 2025.

→ PCI DSS-compliant call recording with onsoft

Give your call center a fresh boost

Discover the potential of your data! Use our analysis and quality management tools to lead your call center to success.

Give your call center a fresh boost

Discover the potential of your data! Use our analysis and quality management tools to lead your call center to success.