MiVoice Office Application Suite - Technical Manual
PCI Compliance
Configuration > Features > Call Recording > Compliance > PCI Compliance

The Payment Card Industry Data Security Standards (PCI-DSS) is designed to safeguard the security of customer's card based payment transactions by ensuring that sensitive card information is not stored and the staff do not have access to them.

How does PCI-DSS effect Call Recording?

If a business is processing MOTO (Mail Order/Telephone Order) payments then it is violation of PCI-DSS to store sensitive card data without proper protection in place, CVV/CV2 cards are never allowed to be stored.

Currently there are two ways supported by the MiVoice Office Call Recorder to avoid storing payment card information:

Process all payments at an unrecorded extension

A single or group of users can be designated as card processing agents. The extensions used by these users can then be added to the Exclusion List so that none of their calls are recorded.

 

Pause recording while payment card details are communicated

The other way to ensure that payment card information is not recorded is to pause the recording while the information is being communicated. This can be done manually by the user or automatically using the window and URL tracking capabilities of the Communicator Desktop client.

 

Removing the payment card information from recordings removes the recorder from PCI-DSS security compliance. However, it is important to ensure that the telephone system itself is secured when transmitting payment card information.