When your business takes payments over the phone, it's important to consider how securely those card details are handled. PCI DSS (Payment Card Industry Data Security Standard) is a set of requirements designed to protect cardholder data and reduce fraud. If you use a supplier to manage your phone payments—such as a VoIP or phone system provider—it's sensible to check whether they comply with PCI DSS standards. This helps ensure that sensitive payment information is processed and stored securely, reducing your risk of data breaches and financial penalties.
Why PCI DSS compliance matters for UK SMEs
Non-compliance with PCI DSS can lead to serious consequences beyond fines. A data breach involving payment information can damage your customers' trust and harm your business reputation. It can also cause downtime if systems need to be taken offline to investigate or fix vulnerabilities, impacting staff productivity and sales. For many UK small businesses, meeting PCI DSS requirements is part of broader data protection efforts that align with UK GDPR and the Data Protection Act 2018, especially when handling payment data.
A common scenario: phone payments in a growing SME
Imagine a UK business with around 50 employees that regularly takes card payments by phone. Initially, they used a basic phone system without much security oversight. After a minor data incident, they engaged a managed IT provider who recommended switching to a VoIP system with built-in PCI DSS compliance features, such as encrypted call recording and secure payment processing. The provider also helped implement multi-factor authentication (MFA) for staff accessing payment systems and regular security audits. This approach reduced the risk of card data exposure, improved compliance readiness, and gave the business peace of mind.
Practical checklist: what to do when choosing or reviewing suppliers
- Ask your supplier: Are you PCI DSS compliant? Can you provide evidence such as an Attestation of Compliance (AoC)?
- Review how card data is handled: Does the supplier use secure, encrypted channels for phone payments? Are call recordings of payment details stored securely or avoided altogether?
- Check access controls: Who has access to payment data? Is access restricted and logged?
- Confirm security measures: Do they enforce multi-factor authentication for systems handling payments? What are their patching and vulnerability management practices?
- Understand incident response: What is their process if a data breach occurs involving payment information?
- Evaluate contract terms: Are PCI DSS compliance and data protection responsibilities clearly defined in the service level agreement (SLA)?
- Internal checks: Ensure your own staff follow secure payment handling policies, such as not writing down card details and using approved payment terminals.
While PCI DSS compliance is primarily the responsibility of the payment processor or phone system supplier, your business also shares responsibility for ensuring that any third-party providers meet these standards. This is especially important if you are subject to audits or need to demonstrate compliance to your bank or the ICO.
Discussing your phone payment processes with a trusted managed IT provider or IT advisor can help clarify your obligations and identify any gaps. They can assist you in selecting suppliers who meet PCI DSS requirements and help implement complementary security controls within your business. Taking these steps supports smoother audits, reduces cyber risks, and protects your customers' payment information.