Source note · PCI DSS for contact centers
Storing card validation codes (CAV2, CVC2, CVV2 or CID) in any form of digital audio recording after authorization violates PCI DSS Requirement 3.3.1.
Checked 2026-09-30
- Vendor
- PCI SSC
- Product
- PCI DSS
- Subsystem
- call recording
- Deployment
- any
- Region
- not restricted
- Release range
- PCI DSS v4.x as of 2026-09-30
- Checked
- 2026-09-30
Sources
- FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? — PCI Security Standards Council · tier 1 standards and regulators · FAQ 1210, answer paragraph 1
Cite this note
APA
WarmTransfer. (2026, September 30). PCI DSS for contact centers: source note pci-dss-contact-center-recording-cvv-prohibited. WarmTransfer. https://warmtransfer.net/knowledge/claims/pci-dss-contact-center-recording-cvv-prohibited
BibTeX
@misc{warmtransfer-claim-pci-dss-contact-center-recording-cvv-prohibited,
title = {PCI DSS for contact centers: source note pci-dss-contact-center-recording-cvv-prohibited},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/pci-dss-contact-center-recording-cvv-prohibited},
note = {Source note pci-dss-contact-center-recording-cvv-prohibited, checked 2026-09-30}
}