Call Centre PCI Compliance & Security

We are a leading UK call centre with the highest level of call centre PCI compliance, PCI DSS level 1. Everyone at Impact is committed to safeguarding client data and we have several world-class cyber security programmes in place to protect the security of client data. Our cyber security is independently audited by qualified industry-leading security assessors on an annual basis. Clients can rest assured that we have security taken care of.

Call Centre PCI DSS Compliance

Impact is proud to have gained the highest level of call centre PCI DSS compliance. It is testament to our commitment to the very highest levels of cyber security throughout every area of our business. We recognise that we have a responsibility to diligently protect all client data. To honour this responsibility, we go above and beyond to secure our call centre environment with a range of physical and digital security methods. Our combination of security methods ensures that client data remains secure and protected at all times. Data security does not end at our call centre, we also have cyber security programmes in place to protect call centre agents that work from home. The flexibility to work from home enhances the reliance of our operations and is just as secure as working from our call centre due to the robust measures that are in place.

PCI1

PCI Compliance Call Center: PCI DSS Level 1

Being a PCI compliance call center is a significant achievement as only a selection of call centres achieve the standards required. We are particularly unique in that we are one of only a handful of UK outsourced call centres to attain Level 1 compliance which is the highest level available. PCI DSS is the global information security standard governed by the Payment Card Industry Security Standards Council (PCI SCC), the council consists of all the major card brands including Visa, Mastercard and American Express. Importantly, PCI DSS level 1 is the only level of compliance with a mandatory annual audit by a PCI SCC appointed assessor. This is the only level Visa and Mastercard will accept for an outsourced call centre that processes over 300,000 card transactions annually. Level 1 compliance measures include conducting a quarterly security scan of the network and an annual penetration test which identifies potential security vulnerabilities. Together, these measures provide on-going assurance that the call centre remains secure and compliant with PCI DSS standards. We strongly recommend that you do not risk your card merchant account with anything less than the highest level of compliance.

By working with a call centre that has PCI DSS level 1 compliance, you can rest assured that your client card payment details are safeguarded with the best available cyber security systems. Many UK call centres are PCI DSS compliant but at a lower level, which has practical implications for businesses that require their chosen call centre outsourcing partner to handle secure phone payments. In many cases, call centres without level 1 compliance are required to use an automated payment line to process card payments for their customers. In this case, a potential customer will be able to speak to a call centre agent up until the point at which a card payment is required. They will then be redirected to the automated payment line to complete the payment process themselves. This can result in a lower sales conversion rate as the customer will need to continue the process unaided and may decide to exit the process before completing the all-important final step. By choosing to partner with a PCI DSS level 1 compliant call centre such as Impact, phone payments can be processed on the same phone line by a call centre agent due to the higher levels of security that are in place. This removes the requirement for an automated payment line and often increases the success rate of each phone interaction as the end-customer can be guided through the payment process by a helpful call centre agent.

cyber 1

Cyber Essentials Plus
Certified

We are passionate about maintaining high security standards throughout our call centre and retain a Cyber Essentials Plus certification. The Cyber Essentials scheme has been developed to help businesses protect themselves against Cyber-attacks and demonstrate a clear commitment to cyber security. The Cyber Essentials Plus certification requires organisations to implement robust protective measures and verifies that these are in place with an in-depth technical verification. The more rigorous nature of the Plus certification provides additional assurance to all our clients that we take cyber security seriously and have appropriate security programmes in place to maintain the security of our systems. After an extensive annual audit, our listing with the National Cyber Security Centre, which is part of GCHQ, is confirmed. The Cyber Essentials Plus certification also meets the prerequisite qualification for participating in government contracts. This allows our call centre to provide call centre services to government organisations and departments.

Our professional approach to cyber security ensures that we not only meet but also exceed many of the requirements and standards that form part of the Cyber Essentials scheme. We are always striving to improve security and our in-house IT function go above and beyond to establish and maintain the secure systems that play an integral role in all aspects of the call centres operations. If you are looking to partner with a world-class call centre that takes security seriously, we could be the perfect partner for your business. Few UK call centres adopt the security measures that we have in place to protect their clients. The combination of our PCI DSS Level 1 certification and Cyber Essentials Plus accreditation places us at the vanguard of the call centre sector and gives our clients the confidence to trust us with their most sensitive data. Whether your business handles sensitive data, financial information, health information or card payment details, we can help you to keep it safe while also delivering quality customer service or sales services to your clients at scale. If you have specific security requirements that you would need us to meet, why not get in touch with our specialists? Many of our existing clients have stringent security requirements that we not only meet but also exceed. We are always looking for ways to improve security standards and should be able to accommodate the security standards that you require.

By being customer centric, your company can grow using effective relationships and improving the customer experience.
Services
DGPR Compliant

GDPR COMPLIANT

The General Data Protection Regulation (GDPR) is a well-established data protection law that has been in operation since May 2018. As a call centre that handles significant amounts of personal data on behalf of clients, we take compliance with data protection law seriously across our business. We comply with all seven GDPR principles introduced by the ICO of purpose limitation, data minimisation, accuracy, storage limitation, integrity & confidentiality (security), accountability and lawfulness, fairness & transparency. Any data that we collect on individuals that reside within the EU is held, stored, and destroyed in-line with the GDPR. We invest in extensive and on-going training for our employees and intelligent technology including software and systems to ensure that we remain compliant with all aspects of data protection law.

Check

TPS & MPS COMPLIANT

We are compliant with the Telephone Preference Service (TPS) and Mail Preference Service (MPS) for all the call centre services that we deliver on behalf of clients. Customers/consumers can choose to opt out of receiving calls, mail or both. The regulation of the TPS and MPS schemes is handled by the Information Commissioner’s Office (ICO). Any companies that are found to be in breach of the TPS or MPS can be reported to the ICO. We proactively work with all our clients to ensure that any data being used as part of the services that we provide is checked for communication preferences. This helps to ensure that we communicate with consumers that want to receive communications. If a customer opts to stop receiving communications from our clients, their information will be removed from our system in compliance with GDPR.

InformationCommissioner 20161206011125661

ICO REGISTERED

Impact is registered as a data controller for our own call centre data and a data processor on behalf of our clients. This ensures that we are in a position to deliver call centre services that comply with the data security laws in the UK. The Information Commissioner’s Office (ICO) is the independent UK authority with responsibility for upholding information rights in the public interest.

Payment Processors

In order to process payments safely and securely for our clients, we have partnered with leading payment processors including Worldpay, Braintree, Stripe, Opayo, Chase Paymentech and Paysafe to name but a few. By choosing Impact as your outsourced call centre, you will benefit from the strong relationships that we have built with world leading payment processors. As a call centre we invest in quality technology and systems to ensure that we can process payments at scale across our portfolio of services.

Choose Impact As Your Secure PCI Compliant Call Centre

We are committed to building long-term partnerships based on trust, performance, and security. As a secure PCI compliant call centre, we deliver world-class call centre services backed by industry leading technology and stringent cybersecurity standards. If you would like to find out more about how we can help your business while safeguarding its sensitive data, call us on 01794 230 230 or complete the contact form below.

We Are Trusted By National Brands

If you choose to partner with Impact, you will be in great company with some of the UK’s leading brands. Impact is trusted by national businesses across a diverse range of sectors many of which have used our expertise in customer service, sales and pick & pack fulfilment. Discover more about how we have helped with their business requirements in our case studies section.

Contact Us
Do you have questions?
Don’t wait, let's talk
Impact House, Unit 7,
Romsey Industrial Estate,
Greatbridge Road,
Romsey, Hampshire SO51 0HR