Source note · PCI DSS for contact centers
If sensitive authentication data cannot be kept out of a call recording, FAQ 1210 requires it to be securely deleted immediately after the transaction is authorized.
Checked 2026-09-30
- Vendor
- PCI SSC
- Product
- PCI DSS
- Subsystem
- call recording
- Deployment
- any
- Region
- not restricted
- Release range
- PCI DSS v4.x as of 2026-09-30
- Checked
- 2026-09-30
Sources
- FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? — PCI Security Standards Council · tier 1 standards and regulators · FAQ 1210, answer paragraph 2
Cite this note
APA
WarmTransfer. (2026, September 30). PCI DSS for contact centers: source note pci-dss-contact-center-recording-sad-delete-after-auth. WarmTransfer. https://warmtransfer.net/knowledge/claims/pci-dss-contact-center-recording-sad-delete-after-auth
BibTeX
@misc{warmtransfer-claim-pci-dss-contact-center-recording-sad-delete-after-auth,
title = {PCI DSS for contact centers: source note pci-dss-contact-center-recording-sad-delete-after-auth},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/pci-dss-contact-center-recording-sad-delete-after-auth},
note = {Source note pci-dss-contact-center-recording-sad-delete-after-auth, checked 2026-09-30}
}