PCI DSS and call recordings: how to remove card data before licensing
To remove card data from call recordings, map every system holding audio and transcripts, detect spoken card numbers in text and audio, redact them, test a sample for misses and document the result. PCI DSS expects stored card data to be protected and security codes not to be retained after authorization.
How do you remove card data from call recordings before licensing?
Find every recording and transcript where a caller read out a card number, expiry date or security code, then remove or irreversibly mask that content, and prove it with a sample test, before anything leaves the company. Card data spoken on calls is a common hidden liability in contact centers, billing teams and field-service dispatch. It is also easy to miss, because it sits inside audio that nobody reads.
The reference point is the Payment Card Industry Data Security Standard (PCI DSS), published by the PCI Security Standards Council. It is an industry standard enforced through card brand and acquirer contracts, not a law, and its requirements are updated over time. Confirm the current version and your obligations with your acquirer or a qualified security assessor.
What PCI DSS expects about card data in recordings
In plain terms, and subject to the current text of the standard:
- The primary account number (PAN) must be protected wherever it is stored, and made unreadable if retained.
- Sensitive authentication data, including the card security code, must not be stored after authorization, even if encrypted. This applies to call recordings too, which is why many contact centers pause recording while the caller reads the code.
- Access to any stored cardholder data must be limited to those with a business need.
- Environments that store card data fall within the scope of the assessment, which is why companies work to keep recordings out of scope.
Recordings that capture the security code are a known trouble spot, since the stored audio cannot simply be encrypted to comply. A company that kept such recordings has a remediation task, and it should talk to its assessor. This is a question of company compliance, not something a referral partner investigates.
Prerequisites before you start
- A named owner for the project, such as the head of contact center operations or the compliance lead
- A list of telephony, recording, QA and transcription tools in use, with years of retention for each
- Written notices callers heard, and any pause-and-resume or DTMF masking configuration
- Counsel or a privacy adviser to review the recording-consent position
Step-by-step: detect and remove
- Map the sources. List every system holding audio or transcripts: the call platform, QA tool, transcription vendor, cloud storage and any local exports. Include archived platforms.
- Establish what was configured. Find out when pause-and-resume or keypad masking was introduced. Calls before that date are the highest risk.
- Detect in transcripts. Run pattern matching for digit sequences of card length and for spoken-number phrases ("four one one one"), with a checksum test on candidates to cut false hits.
- Detect in audio. For calls with no reliable transcript, use speech-to-text first and then step 3; flag the time ranges.
- Redact. Remove the segments from audio or replace them with silence or a tone, and mask the digits in transcripts. Keep the surrounding words so the conversation still makes sense.
- Test with a sample. Pull a random sample of redacted calls and listen. Measure misses, not just hits, and set a threshold for acceptable error before moving on.
- Document and delete sources. Record the method and results, then follow retention rules for unredacted originals according to the company's policy and counsel's advice.
The detailed technique for text is in how to redact PII from call transcripts before licensing.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Assuming the pause feature always worked | Agents forget, calls drop, and old platforms lacked it | Test historical calls from each period |
| Searching only for 16-digit strings | Callers pause, repeat and speak numbers in groups | Pattern-match spoken forms and run a checksum test |
| Redacting transcripts but not audio | The audio still holds the numbers | Treat audio and text as separate sources |
| Redacting only card numbers | Names, addresses and account details remain | Run a general PII pass as well |
| Deleting evidence before documenting | No proof of what was removed | Record the method first |
Illustrative example
Illustrative and fictional: a 90-person field-service dispatcher takes payments by phone. The compliance lead finds that keypad masking was added in 2021, and earlier calls contain spoken card numbers. The company flags pre-2021 audio as in need of remediation, transcribes a sample, finds spoken digits in a noticeable share of the sample, and decides to exclude that period until its assessor confirms the cleanup. Calls after the change enter the next review.
Owner checklist before the project starts
- A named project owner and a named compliance contact
- A written list of every system holding audio, transcripts or exports, with retention periods
- The date pause-and-resume or keypad masking started on each platform
- A decision on how many calls to sample per period, with an agreed miss rate
- A rule for originals: who may keep, move or delete them, and when
- A confirmed contact at the acquirer or assessor for questions about the standard
What to say to a contact center owner
How this interacts with other call-data issues
Card data is one of several issues in call audio. Recording-consent rules vary by state, as explained in does "this call may be recorded" cover AI. Voice templates raise their own risk, covered in Illinois BIPA and call recordings. Customer contracts may limit reuse of call content: see confidentiality clause use restrictions. Whether licensing counts as a sale under California privacy law is a separate question, covered in the CCPA sale question. For a related checklist on operational records, see referring companies with incident and on-call data.
Other rules that can apply to the same recordings
PCI DSS is not the only obligation. A company that qualifies as a financial institution, such as a collections agency or a tax preparer, must also meet the FTC's Safeguards Rule, which requires a written information security program and encryption of customer information in transit and at rest. State breach and privacy rules may add duties. This is general information, not legal, tax or financial advice. Confirm with your own counsel, assessor or compliance adviser before acting.
What partners do and do not do
Spotting card data is the company's job, done by its own compliance and IT staff. A partner only asks whether the problem exists and leaves recordings alone. How thorough the cleanup must be is agreed between the company and SourceX before any work begins.
Next step
Ask the owner to run the company fit checker and read how it works. If the company looks like a fit, register as a partner and make the introduction.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is PCI DSS a law?
No. It is an industry standard from the PCI Security Standards Council, applied through contracts with card brands and acquirers. Consequences are set in those contracts, so check them with your acquirer. Separate laws, such as state breach and privacy rules, may also apply to the same data, so companies should check both.
Can encrypted recordings keep the card security code?
The standard says sensitive authentication data, including the security code, must not be stored after authorization, even if encrypted. Recordings that capture the code are therefore a known problem. Check the current requirement with your acquirer or a qualified security assessor, and plan remediation.
Do transcripts count as card data storage?
If a transcript contains a card number it is stored cardholder data, just like the audio. Automatic speech-to-text can turn an audio problem into a text problem. Detect and mask digits in both formats, and treat any transcription vendor as part of the environment.
How much redaction accuracy is enough?
There is no universal figure. Companies set an acceptable miss rate with their compliance team, test a random sample, and document results. Misses matter more than false hits, so tuning usually favors over-masking. Higher-risk periods, such as calls before masking was introduced, deserve larger samples.
Does removing card data make recordings ready to license?
No. It handles one risk. Rights to the content, recording consent, biometric concerns, customer contract limits, and other personal data still need review. SourceX and the company agree redaction requirements before work begins, and nothing is delivered without a signed agreement and the company's authorization.
Related pages
- How to redact PII from call transcripts and audio before licensing them
- Does 'this call may be recorded for training purposes' cover AI training?
- Illinois BIPA and call recordings: when voice data becomes biometric
- How confidentiality clause use restrictions decide what a company can license
- Is licensing company records a 'sale' under the CCPA?
- Checklist: Referring Companies with Incident & On-Call Data
Free resources
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment