08 Apr Why A PCI Compliant Call Centre Is Important
Why a PCI Compliant Call Centre is Important
PCI Compliant Call Centres play an important role in processing payments made over the phone for their clients. So what is PCI DSS? The Payment Card Industry Data Security Standard is a set of regulations maintained by Visa, Mastercard, American Express, JCB, Electron & Discover governing the processing of cardholder data.
These regulations apply to both manual and electronic forms of payment processing and currently consist of 335 controls within 12 mandatory standards. Businesses found to be non-compliant face significant financial penalties and risk losing their Merchant Services Accounts should a data breach occur.
In this article, we outline why a PCI compliance call center is important and explain PCI DSS in more detail.

Is PCI Compliance Mandatory?
All merchants must be PCI compliant and attest to that compliance annually. All service providers processing payments on behalf of the merchant must be PCI compliant and attest to that annually. A merchant is not PCI compliant if their outsourced service provider is not compliant.
What Are The Different Levels Of Call Centre PCI Compliance?
For a service provider such as a call centre, there are only 2 levels of compliance. These levels are based on the number of transactions processed per year. For more than 300,000 transactions annually, a service provider must be Level 1 compliant. NB this is very different to the 4 levels that apply to yourself as a merchant.
A commonly-held (and dangerous) misconception is that call centres are not service providers and are treated the same as merchants. However, the PCI Security Council is unambiguous where a business entity is directly involved in the processing, storage, or transmission of cardholder data. We handle card payments on your behalf and thus we are regarded unequivocally as a service provider (Visa refer to us as a Merchant Agent).
What Is The Difference Between Level 1 And Level 2 PCI Compliance?
As far as implementing the appropriate security measures, controls, processes and procedures, there is no difference! Level 2 only requires an organisation to fill in and attest a self-assessment questionnaire annually.
Level 1 however, mandates that a service provider must be audited annually by a Qualified Security Assessor (QSA) registered with the PCI Security Standards Council (PCI SCC). This audit results in the Report On Compliance (ROC) that will be compiled as material proof of PCI compliance and remains valid for 1 year.
What Is The Real Danger Of Non-Compliance?
There’s no need whatsoever to highlight the reality of data breaches – we see high profile companies in the news almost monthly. In reality, many (lesser-known) UK companies are being hacked daily. Insecure systems can be hacked by software robots within minutes. If systems are not secure enough to be deemed PCI compliant, it’s not a case of if but when a data breach is going to occur.
Fines imposed by the brands (Visa, Mastercard, etc.) can be exponentially painful to the merchant as penalties are incurred on each and every instance of card data compromised or stolen.
Visa, Mastercard, etc., protect their brands and their reputations, and as such, data breaches resulting from non-compliance will often result in the withdrawal of the Merchant Services Accounts. Attempts to re-apply for new Merchant Accounts are severely hampered where breaches have occurred in a non-compliant environment.
What Is Impact’s Approach To PCI Compliance?
As a PCI Level 1 compliant outsourced call centre, Impact Call Centre:
- Maintains strict policies, procedures and processes within its Information Security Management System (ISMS) covering all areas of electronic and manual handling of payment card data. Some of these are classified as Internal Confidential but many are Commercial Private and can be provided to you on request
- Is subject to an annual audit by a Qualified Security Assessor ensuring we meet every one of the applicable 335 security controls of PCI DSS
- Undergoes periodic penetration testing (we invite qualified hackers into our building to try and infiltrate our networks) as well continuous automated vulnerability scanning
Impact’s approach to PCI compliance enables us to handle payments personally over the phone allowing your customers to give their card details directly to our agents. Solutions that transfer the customer to an automated payment system make PCI compliance much easier but inevitably increase the possibility of the order process being abandoned and losing the sale.
It also means that, if required, we can use our clients’ own web portals for taking payments on their behalf – an option that would not be available through automated payment methods.
PCI Compliance Call Center That Securely Processes Phone Payments
If you need a secure and trusted PCI compliance call center that has world-class cybersecurity programmes to protect client data, why not not speak to Impact? Our commitment to data security is validated and audited by industry-leading security assessors. We are one of only a few UK call centres to attain Level 1 PCI DSS compliance. As a security conscious business, don’t trust your merchant account with anything but the best.
Impact helps businesses across a diverse range of sectors to securely process card payments made over the phone. Our clients include a major London Airport and a world leading memory foam mattress manufacturer.
Contact our team of call centre specialists by calling 01794 230 230 or completing the enquiry form on our contact page.