Telappliant
Communications Guide · 20 August 2026

Should my business accept card payments over the phone?

PCI DSS v4 obligations for telephone payments, and the secure ways to take card details by phone in 2026.

By the Telappliant team

Agent taking a card payment securely over the telephone

Taking a card number over the phone is convenient for customers who cannot or do not want to pay online, but it puts your business directly in the scope of PCI DSS. Whether that is worth it depends on your volumes, your channel mix and how you handle the compliance burden.

Why customers still want it

Telephone payments remain common for older customers, high-value transactions people want reassurance on, and businesses like trades, clinics and agencies where the sale naturally happens on a call. Removing the option can lose business, particularly to competitors who still offer it.

What accepting card payments by phone actually commits you to

  • PCI DSS v4.x compliance for any system, person or process that touches cardholder data
  • A documented policy on where card numbers can be written down, said aloud or stored, ideally nowhere
  • Staff training on secure handling and what not to do, such as writing numbers on paper
  • Call recording controls, since a recorded card number is a major compliance and breach risk

The safer alternative most PCI assessors recommend

DTMF masking, sometimes called dual-tone suppression, lets the customer key their card details into the phone keypad while the agent stays on the line, but the tones and the card data never reach the recording, the agent's screen or your network. This removes almost your entire PCI DSS scope compared with an agent typing or reading back numbers.

Deciding whether to offer it

  • Estimate genuine demand: how many customers ask for it versus default to card readers or online links
  • Weigh the PCI compliance overhead against the alternative of losing those transactions
  • Check whether your existing card payment provider or phone system already supports secure telephone payments
  • If volumes are low, a payment link sent by SMS during the call is a lower-risk alternative

If you decide to proceed

Do not build ad hoc telephone payment handling around a member of staff reading numbers back. Use a proper secure telephone payment solution integrated with your phone system, keep card data out of recordings entirely, and get your PCI DSS scope confirmed by your acquiring bank or a qualified assessor before you go live.

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation