Call centres have a responsibility to safely store customer data. Yet in a highly regulated industry, call centres face special challenges with secure data storage. In addition to figuring out how to safeguard sensitive information that is stored, some of these challenges include:
- Adhering to an alphabet soup of regulatory guidelines and industry requirements such as the Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS), the European Union’s General Data Protection Regulation (GDPR), the new California Consumer Privacy Act (CCPA) plus many others
- Keeping on top of changes to these compliance regulations (which occur frequently) and understanding/meeting new compliance requirements as they are added
- Ensuring the integrity of other stored data when removing personal data.
- Assessing the call centre’s level of preparedness to handle new customers in relation to evolving requirements
- Determining if the call centre is agile enough to manoeuvre within current compliance frameworks
- Dealing with the possibility of being fined or receiving a penalty for non-compliance
The fact is that research has proven that non-compliance is costly, and problems stemming from audits are more common than you might think. A 2017 Ponemon Institute study on “The True Cost of Compliance with Data Regulations” found that companies with issues for non-compliance pay $14.82 million on average—a figure that increased 45 percent over a six-year period. This is why secure and compliant storage of customer data is so vital.
Sorting Out Storage Needs by Compliance Realities
Going back to the challenge of “alphabet soup” above, each set of regulations and guidelines necessitates a unique and targeted approach to ensuring compliance, which affects how an organization should store its data compliantly. Below is a run-down of key storage considerations to keep in mind for each type of regulation:
HIPAA compliance. Any company that stores/manages healthcare-related data—which includes call centers and telemedicine as well as insurance organizations—must be compliant with HIPAA regulations. The key here is outlined by Health and Human Services (HHS) 45 CFR § 164.304, which defines a security incident as “the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.”
In relation to storage procedures, this means any type of electronic personal health information (ePHI) must remain completely unmodified. Traditional storage area network (SAN) and network-attached storage (NAS) isn’t quite up to this task, despite its common usage. A 2018 report from Verizon revealed that the majority of data breaches—68 percent—remained undiscovered for months or years. This helps explain why any regulated body such as a call center must be able to instantly retrieve their audit logs and complete audit trail to prove who accessed the data at any given point in time. The inability to identify full access history, including the origin of unauthorized modification—or even attempted unapproved access—to ePHI via access logs, can result in non-compliance. While HIPAA doesn’t mandate monitoring frequency to ensure data authenticity, monitoring data in real-time can help provide data protection against ransomware and other types of hacking.
PCI DSS requirements. These guidelines are designed to safeguard cardholder data, particularly in relation to public-network transmission of encrypted information. A thorough examination of these requirements reveals the tall order that enterprises face in ensuring proper data storage to stay fully compliant.
PCI DSS 3.1 to 4.1 are particularly relevant to these storage requirements, and specify that organisations must follow policies for data retention—as well as data disposal—to minimise the amount of cardholder data that remains stored in company systems. These guidelines also focus on operational/security processes and procedures to boost cardholder data protection. Encryption is also covered in 3.1 to 4.1, including encrypting data at rest as well as during transmission, and procedures to manage/protect encryption keys.
GDPR’s accountability principle. “The right to be forgotten,” as GDPR’s new accountability principle is often referred to, requires that companies exhibit high accountability for managing and handling customer data. A significant component of this mandate relates to creating documented policies to give staff clear instructions on these data protection requirements, and being ready to address any concerns that regulators might have.
When preparing your data protection policy, the following areas should be considered to stay GDPR compliant:

