Jump to content

Talk:Payment Card Industry Data Security Standard

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 5 months ago by ~2026-21336-26 in topic Proposed section: Telephone and call centre compliance

Wiki Education assignment: Social Informatics - ITI 547-200 Section 07

[edit]

This article was the subject of a Wiki Education Foundation–supported course assignment, between 4 September 2025 and 10 December 2025. Further details are available on the course page. Student editor(s): Leaves.of.Three (article contribs).

— Assignment last updated by NicholasJohnstoneNMJ83 (talk) 22:47, 22 October 2025 (UTC)Reply

Proposed section: Telephone and call centre compliance

[edit]

Hello,

 I noticed that the French Wikipedia article on PCI DSS ([[:fr:Norme de sécurité de   
 l'industrie des cartes de paiement|fr:Norme de sécurité de l'industrie des cartes de
 paiement]], section 7.2) covers call centre security and DTMF masking as a compliance
  topic, but the English article has no equivalent section.
 Telephone-based card payments are a significant area of PCI DSS compliance — the PCI 
 Security Standards Council has published specific guidance on protecting
 telephone-based payment card data, and DTMF masking technology is widely deployed    
 across contact centre environments.
 I'd like to propose adding a subsection on telephone and call centre compliance,     
 covering:
                                                                                      
 * PCI SSC guidance on call recordings containing cardholder data                     
 * Technical approaches to scope reduction (IVR, DTMF masking, pause-and-resume)
 * How channel separation and DTMF suppression affect self-assessment scope           
                                                                                      
 === Proposed draft text ===                                                          
                                                                                      
 Organisations that accept payment card data over the telephone face specific PCI DSS 
 compliance challenges, as call recordings, agent workstations, and telephony
 infrastructure may all come into contact with cardholder data. The PCI Security      
 Standards Council has issued guidance noting that digital call recordings containing
 sensitive authentication data must not be stored after authorisation, regardless of
 encryption method used.
 Several technical approaches have been developed to reduce PCI DSS scope in telephone
  payment environments:
                                                                                      
 * Interactive voice response (IVR): Calls are transferred to an automated      
 system for card data entry, removing agents from the payment flow entirely. This
 approach eliminates agent exposure to cardholder data but interrupts the             
 customer–agent interaction.
 * DTMF masking: Customers enter card details using their telephone keypad while
  remaining on the call with an agent. The dual-tone multi-frequency (DTMF) signals
 are intercepted and replaced with flat tones in real time, preventing the agent or   
 call recording systems from capturing the card data. The payment data is routed
 directly to a payment processor through a separate channel.
 * Pause and resume: Call recording is manually or automatically paused while   
 the customer provides card details, then resumed. This reduces recording exposure but
  does not prevent agent access to spoken card data.                                  
                 
 The use of DTMF masking and channel separation technologies can allow organisations  
 to reduce their PCI DSS self-assessment scope, as cardholder data does not enter the
 merchant's environment.                                                              
                 
 === References ===
 All statements can be sourced from PCI Security Standards Council publications       
 including the Information Supplement on Protecting Telephone-Based Payment Card Data
 and PCI DSS v4.0 Requirement 3.                                                      
                 
 Disclosure: I work for a company that operates in the telephone payment        
 security space. I am proposing this content for editorial review rather than adding
 it directly, per WP:COI guidelines. Curtlondon (talk) 13:47, 6 April 2026 (UTC)Reply
@Curtlondon: We are highly unlikely to add text that has come directly from an AI chatbot. Sorry. • a frantic turtle 🐢 14:12, 6 April 2026 (UTC)Reply
Oh dear, I did not realise there was a ban on AI content even if it factually correct and helps someone. ~2026-21336-26 (talk) 10:35, 7 April 2026 (UTC)Reply