Take Payments Over the Phone UK | Security & PCI Compliance Guide
Featured Solution Discover our Link-Pay-Bank solution

How to Take Payments by Telephone


Taking payments over the phone is still a common requirement for many UK businesses, particularly in sectors where customers prefer direct contact or where online checkout isn’t always practical.


However, the way those payments are handled has changed. Traditional methods that rely on customers reading out card details can expose sensitive data, increase compliance requirements, and create unnecessary risk.


Modern approaches allow businesses to accept telephone payments without handling card information directly, improving security while simplifying PCI compliance.


This guide explains how phone payments work, the risks involved, and the safest ways to accept them in the UK today.

PCI DSS Compliant logo



Can You Take Payments Over the Phone in the UK?


Yes, businesses in the UK can accept payments over the phone. However, the method used to take those payments determines whether the process is secure, PCI compliant, and protected against fraud.


Are Telephone Payments Safe?


Telephone payments can be safe when processed using PCI DSS compliant methods.


Traditional approaches, where card details are read aloud and manually entered, introduce risk. Sensitive information can be exposed, misheard, or mishandled during the process.


More secure alternatives remove this risk by allowing customers to enter their payment details directly into a protected environment, without sharing them with staff.


How Do Businesses Take Payments Over the Phone?


There are three common approaches used by UK businesses:


Manual entry via virtual terminal

Staff enter card details provided verbally by the customer during a call.


EPOS or call centre systems

Integrated systems used in larger operations to process payments as part of a wider workflow.


Secure payment links (recommended)

Customers receive a secure link via SMS or email and enter their details themselves.


The method chosen directly impacts security, compliance requirements, and exposure to fraud.

Somebody uses a credit card to make a payment by telephone



How Can You Take PCI-Compliant Phone Payments?


The most effective way to improve compliance is to remove card data from your internal environment.


This is commonly achieved through:



These methods allow customers to complete payments independently, reducing the risk of data exposure.


What Are the Risks of Taking Card Payments Over the Phone?


The risks associated with telephone payments depend largely on how they are processed.


Common risks include:

  • exposure of sensitive card data
  • increased PCI compliance requirements
  • higher likelihood of fraud
  • chargebacks and payment disputes


Reducing these risks relies on using secure, controlled payment methods rather than manual processes.


Do Telephone Payments Have Limits in the UK?


There is no fixed national limit for telephone payments in the UK.


Transaction limits are usually determined by:


  • the business itself
  • the payment provider
  • fraud prevention thresholds
A hand reaches for a security shield



Is It Safe to Give Card Details Over the Phone?


It depends on both the business and the method being used.


Customers should take precautions such as:


  • verifying the legitimacy of the business
  • avoiding sharing details if unsure
  • requesting a secure payment link where possible


What Is the Safest Way to Take Payments Over the Phone?


The safest approach is one where sensitive data is not handled by staff at all.


This typically means:


  • the customer enters their own payment details
  • card data is processed within a secure environment
  • authentication measures such as 3D Secure are applied


This approach reduces risk, simplifies compliance, and improves overall payment security.


Related Questions


Somebody uses a credit card to make a payment by telephone
Take secure phone payments

People Also Asked

Are you allowed to take payments over the phone in the UK?
Yes, UK businesses are allowed to take payments over the phone. However, they must handle card data securely and comply with PCI DSS requirements. The method used to process the payment determines how much responsibility the business has for protecting sensitive information.
Is PCI DSS a legal requirement?
PCI DSS is not law, but it is a contractual obligation between businesses and their payment providers.
How do I accept credit card payments over the phone?
Businesses can accept credit card payments over the phone by using a virtual terminal, a call centre payment system, or by sending a secure payment link to the customer. The most secure approach is to avoid handling card details directly and allow the customer to enter them into a protected payment page.
Can I take payments directly on my phone?
Yes, payments can be taken directly using a mobile device, depending on the setup. This may include using a virtual terminal via a browser or sending secure payment links to customers. The key consideration is ensuring the method used keeps card data secure and compliant.
Do phone payments increase the risk of chargebacks?
They can do, particularly if payments are taken without additional authentication. Card-not-present transactions, including those taken over the phone, generally carry a higher risk of disputes. Using secure methods with authentication helps reduce this risk.
Is it safe to make payments over the phone?
It can be safe, but only when the payment is processed using secure, compliant systems. Sharing card details verbally introduces risk, especially if the business handles or stores that data. Safer methods allow customers to enter their details independently in a secure environment.

Need to ask a question: Request a callback from the team

Need merchant support? Visit Merchant Support