Contact centres are now privy to more customer data than ever before, with so many of our transactions happening online and omni-channel now as the industry default. However, there’s still work to be done when it comes to making contact centres more secure and compliant.
One research survey found that 70% of agents collecting PII confirmed the data by reading it out aloud. 30% of agents have persistent access rights, and 11% have been approached by an internal or external threat. A different study confirms that 73% of companies believe they should be more stringent when it comes to contact centre compliance. These statistics point to one key requirement – tightening the security measures around customer data collection and utilisation, especially in the context of payment information.
That’s what makes PCI DSS compliance so important.
What is PCI DSS?
The Payment Card Industry Data Security Standard defines guidelines and regulations on data security in the payments industry. This covers six areas – network security, efforts to protect cardholder data, vulnerability management, access control, security monitoring and testing, and policy/documentation.
What is the Cost of PCI DSS Non-Compliance for Contact Centres?
PCI typically finds the merchant’s partner bank in case there is a data breach, which can be traced back to a security or compliance misstep. While PCI DSS isn’t legally binding, the fines levied on the bank is usually passed onto the merchant organisation. Repeat offenders can even be blacklisted from working with customers using cards from that bank.
How can Contact Centres Achieve PCI DSS Compliance?
To achieve compliance, contact centres must go through three steps – first, rework their processes and infrastructure to meet the six requirements as stated, second, demonstrate the compliance efforts with proper documentation, and third, undergoing an external audit to prove and certify compliance. Importantly, contact centres must be audited regularly, for continued compliance certification.

