When contact-center systems store, process or transmit payment-card data, map the complete card-data path across agent desktops, recordings, CRM, notes, chat, email, payment applications, telephony and processors.
The strongest architecture often keeps full card data out of the agent and recording environment entirely. Evaluate segmentation, recording controls, access restrictions, authentication, logging, vulnerability management and the responsibilities of each service provider.
Request current applicable PCI validation evidence rather than relying on the phrase "PCI compliant."
This guide is educational and is not legal or PCI compliance advice.