How to take payments over the phone
Taking card payments over the phone is legal and manageable in the UK, provided card data is kept away from staff and systems that don't need it—using keypad entry, secure links, or outsourced compliant providers significantly reduces compliance scope.

You take a payment over the phone by collecting a customer's card details, either spoken aloud or entered by keypad, and processing them through a virtual terminal, secure payment link, or card machine connected to your merchant account. The safest methods keep the card number away from staff and call recordings entirely, using keypad entry or a secure link instead of a spoken card number.
Key takeaways
- Taking payments over the phone is legal in the UK and remains common practice
- PCI DSS applies to any business that stores, processes or transmits card data, phone channels included
- Keypad entry and secure payment links are currently the lowest-risk methods, since they keep card data away from staff and recordings
- The CVV must never be stored after a transaction is authorised, regardless of method
- Outsourcing payment handling to a compliant provider can reduce a business's own compliance scope
What is MOTO, and why does it come up in phone payments?
Definition: MOTO stands for Mail Order and Telephone Order. It's the card scheme classification for any payment taken without the physical card present, including phone payments. MOTO transactions carry a higher fraud risk than in-person, chip-and-PIN payments, because a fraudster only needs the card number rather than the card itself. This is why phone payments come with more specific security requirements than tapping a card in person.
Is it legal to take card payments over the phone in the UK?
Yes. Taking payments over the phone is legal and common practice across UK businesses, from tradespeople and clinics to retailers and professional services. It isn't restricted by law in the way some assume. What is required is compliance with PCI DSS, the payment card industry's security standard, and with UK GDPR and the Data Protection Act 2018 wherever personal or card data is involved.
Definition: PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements created by the major card schemes (Visa, Mastercard, Amex and others). It isn't government legislation, but it's a contractual condition of your merchant agreement, enforced by your acquiring bank. Any business that stores, processes or transmits card data must meet it, regardless of size.
What are the main ways to take a payment over the phone securely?
There are four common approaches, and they carry very different levels of risk and compliance burden. Keypad entry or a secure payment link is the lowest-risk option for most businesses, since card data never has to be seen or heard by a person, and doesn't end up sitting in a call recording.
What should never be recorded or stored during a phone payment?
Certain details must never be stored once a payment has been authorised, regardless of the method used.
- The CVV or CVC security code (the 3 or 4 digit number on the card)
- A full, unmasked card number, if it isn't required for a legitimate ongoing purpose
- Any spoken card details captured in a call recording without adequate controls
If your call recording could realistically have captured a customer reading out their card number, that recording falls inside your cardholder data environment and needs to be treated accordingly. This is one of the most common gaps businesses discover once they look closely at their process.
How can a business reduce its PCI compliance burden for phone payments?
The core principle is scope reduction: the fewer systems and people that touch live card data, the smaller your compliance obligation. Businesses that keep card data away from staff and internal systems, for example by using keypad entry, secure payment links, or an outsourced provider with its own compliance certification, typically qualify for a shorter self-assessment questionnaire (SAQ A) rather than the much longer version required when card data flows through in-house systems (SAQ D).
Can an answering service or receptionist take payments on your behalf?
Moneypenny's receptionists can securely take payments over the phone on a client's behalf, following data protection and PCI compliant processes, using a client's own virtual terminal to process the transaction. This means a business can offer phone payments without needing in-house staff to handle card data directly.
This is a useful option for businesses that take occasional or seasonal phone payments, or that don't want to build and maintain their own compliant in-house process. The payment still runs through the business's own merchant account and systems, with the receptionist simply guiding the customer through it.
What happens if a business isn't compliant?
Non-compliance is managed through your merchant agreement rather than through a government body. Acquiring banks and card schemes can apply fines, increase transaction costs, or in serious cases withdraw a business's ability to accept card payments. If a data breach occurs, a business may also face separate obligations and penalties under UK GDPR, since card data is personal data.
Taking payments over the phone is legal, common, and manageable, provided the process is built around keeping card data away from people and systems that don't need to see it. Keypad entry, secure payment links, and outsourced, compliant payment handling are the lowest-risk routes for most businesses.
Sources
- PCI Security Standards Council, official guidance on protecting telephone-based payment card data.
- Information Commissioner's Office, guidance on UK GDPR and payment data security.
Frequently asked questions
- Is it still common for UK businesses to take payments over the phone?
Yes. Despite the growth of online payments, a significant number of UK customers still prefer to pay by phone, particularly for larger purchases, service bookings, or when dealing with a query directly with a business.
- What's the safest way to take card payments over the phone?
Methods that keep the card number away from staff and call recordings, such as keypad entry with masked tones or a secure payment link, are currently considered the safest approach, because they significantly reduce what falls inside your compliance scope.
- Do I have to record calls when taking a phone payment?
There's no requirement to record calls. If you do record calls for other reasons (training, quality, dispute resolution), you need a process that prevents card details, and particularly the CVV, from being captured and stored in that recording.
- Can I ask a customer for their CVV number over the phone?
You can ask for it to authorise the transaction, but it must never be stored afterwards. This applies whether the number is spoken, typed, or captured any other way.
- What's the difference between SAQ A and SAQ D?
Both are Self-Assessment Questionnaires used to evidence PCI compliance. SAQ A applies to businesses that keep card data out of their own systems entirely (for example, by using a compliant third-party provider), and involves far fewer controls to evidence. SAQ D applies where card data passes through in-house systems, and is a considerably longer and more detailed assessment.
Get your quote from the UK’s #1 provider today
Provide us with a few details and we’ll contact you to explain how Telephone Answering will work for your business. Alternatively, call 0333 202 1005 to find out more.
What to expect:
- Thousands of businesses on board
- Unmatched sector expertise
- Award-winning culture



