How to take payments over the phone

Taking card payments over the phone is legal and manageable in the UK, provided card data is kept away from staff and systems that don't need it—using keypad entry, secure links, or outsourced compliant providers significantly reduces compliance scope.

Author
Sophie Weston
Published on
Aug 5, 2026
Read time
7 mins
One hand holds a smartphone while another hand inserts a blue bank card into the smartphone, symbolising mobile card payments.

You take a payment over the phone by collecting a customer's card details, either spoken aloud or entered by keypad, and processing them through a virtual terminal, secure payment link, or card machine connected to your merchant account. The safest methods keep the card number away from staff and call recordings entirely, using keypad entry or a secure link instead of a spoken card number.

Key takeaways

  • Taking payments over the phone is legal in the UK and remains common practice
  • PCI DSS applies to any business that stores, processes or transmits card data, phone channels included
  • Keypad entry and secure payment links are currently the lowest-risk methods, since they keep card data away from staff and recordings
  • The CVV must never be stored after a transaction is authorised, regardless of method
  • Outsourcing payment handling to a compliant provider can reduce a business's own compliance scope

What is MOTO, and why does it come up in phone payments?

Definition: MOTO stands for Mail Order and Telephone Order. It's the card scheme classification for any payment taken without the physical card present, including phone payments. MOTO transactions carry a higher fraud risk than in-person, chip-and-PIN payments, because a fraudster only needs the card number rather than the card itself. This is why phone payments come with more specific security requirements than tapping a card in person.  

Is it legal to take card payments over the phone in the UK?

Yes. Taking payments over the phone is legal and common practice across UK businesses, from tradespeople and clinics to retailers and professional services. It isn't restricted by law in the way some assume. What is required is compliance with PCI DSS, the payment card industry's security standard, and with UK GDPR and the Data Protection Act 2018 wherever personal or card data is involved.

Definition: PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements created by the major card schemes (Visa, Mastercard, Amex and others). It isn't government legislation, but it's a contractual condition of your merchant agreement, enforced by your acquiring bank. Any business that stores, processes or transmits card data must meet it, regardless of size.  

What are the main ways to take a payment over the phone securely?

There are four common approaches, and they carry very different levels of risk and compliance burden. Keypad entry or a secure payment link is the lowest-risk option for most businesses, since card data never has to be seen or heard by a person, and doesn't end up sitting in a call recording.

MethodHow it worksSecurity consideration
Spoken card detailsCustomer reads their card number aloud to a member of staffHighest risk. The number passes through the agent, the call, and often the call recording
Pause-and-resume recordingCall recording is manually paused while the customer reads their details, then resumedReduces recording risk only. The agent still hears the full card number
Keypad or secure link entryCustomer enters details via phone keypad (tones are masked) or a secure payment link sent by text or emailCard data bypasses staff and recordings entirely, which significantly reduces compliance scope
Virtual terminalStaff enter card details into a secure payment page on behalf of the customerRequires the same protections as any system handling live card data, so access controls and encryption matter

What should never be recorded or stored during a phone payment?

Certain details must never be stored once a payment has been authorised, regardless of the method used.

  • The CVV or CVC security code (the 3 or 4 digit number on the card)
  • A full, unmasked card number, if it isn't required for a legitimate ongoing purpose
  • Any spoken card details captured in a call recording without adequate controls

If your call recording could realistically have captured a customer reading out their card number, that recording falls inside your cardholder data environment and needs to be treated accordingly. This is one of the most common gaps businesses discover once they look closely at their process.

How can a business reduce its PCI compliance burden for phone payments?

The core principle is scope reduction: the fewer systems and people that touch live card data, the smaller your compliance obligation. Businesses that keep card data away from staff and internal systems, for example by using keypad entry, secure payment links, or an outsourced provider with its own compliance certification, typically qualify for a shorter self-assessment questionnaire (SAQ A) rather than the much longer version required when card data flows through in-house systems (SAQ D).

Can an answering service or receptionist take payments on your behalf?

Moneypenny's receptionists can securely take payments over the phone on a client's behalf, following data protection and PCI compliant processes, using a client's own virtual terminal to process the transaction. This means a business can offer phone payments without needing in-house staff to handle card data directly.

This is a useful option for businesses that take occasional or seasonal phone payments, or that don't want to build and maintain their own compliant in-house process. The payment still runs through the business's own merchant account and systems, with the receptionist simply guiding the customer through it.

What happens if a business isn't compliant?

Non-compliance is managed through your merchant agreement rather than through a government body. Acquiring banks and card schemes can apply fines, increase transaction costs, or in serious cases withdraw a business's ability to accept card payments. If a data breach occurs, a business may also face separate obligations and penalties under UK GDPR, since card data is personal data.

Taking payments over the phone is legal, common, and manageable, provided the process is built around keeping card data away from people and systems that don't need to see it. Keypad entry, secure payment links, and outsourced, compliant payment handling are the lowest-risk routes for most businesses.

Sources

Frequently asked questions

  • Is it still common for UK businesses to take payments over the phone?

Yes. Despite the growth of online payments, a significant number of UK customers still prefer to pay by phone, particularly for larger purchases, service bookings, or when dealing with a query directly with a business.

  • What's the safest way to take card payments over the phone?

Methods that keep the card number away from staff and call recordings, such as keypad entry with masked tones or a secure payment link, are currently considered the safest approach, because they significantly reduce what falls inside your compliance scope.

  • Do I have to record calls when taking a phone payment?

There's no requirement to record calls. If you do record calls for other reasons (training, quality, dispute resolution), you need a process that prevents card details, and particularly the CVV, from being captured and stored in that recording.

  • Can I ask a customer for their CVV number over the phone?

You can ask for it to authorise the transaction, but it must never be stored afterwards. This applies whether the number is spoken, typed, or captured any other way.

  • What's the difference between SAQ A and SAQ D?

Both are Self-Assessment Questionnaires used to evidence PCI compliance. SAQ A applies to businesses that keep card data out of their own systems entirely (for example, by using a compliant third-party provider), and involves far fewer controls to evidence. SAQ D applies where card data passes through in-house systems, and is a considerably longer and more detailed assessment.

Smiling young woman with long dark hair wearing a white top against a plain light background.
Sophie Weston
Content Marketing Executive at Moneypenny

Sophie creates content that helps businesses communicate with clarity and confidence. As part of the team at Moneypenny, she focuses on customer experience, business communications and the role of AI in shaping better conversations. Her writing is practical, people-first and designed to turn complex ideas into something genuinely useful.

Topics
Business Tips
Phone answering service

Latest articles

A man in a black suit climbing on large 3D letters spelling the word 'SKILLS' with a colorful gradient background of red, orange, blue, and pink hues.
Blog
August 25, 2026

What soft skills and qualities make a great receptionist?

A man in a suit placing a large white dice with green check marks on a pyramid of dice, some showing green check marks and others red X marks, against a colorful gradient background.
Blog
August 20, 2026

What are the dos and don'ts of customer service?

A man in a suit carrying a briefcase walking up a wide staircase with handrails on both sides under a vibrant sky blending pink, orange, blue, and turquoise colours.
Blog
August 18, 2026

How to scale your business using AI

Get your quote from the UK’s #1 provider today

Provide us with a few details and we’ll contact you to explain how Telephone Answering will work for your business. Alternatively, call 0333 202 1005 to find out more.

What to expect:
  • Thousands of businesses on board
  • Unmatched sector expertise
  • Award-winning culture
No. of Employees:
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.