September 18, 2015

In addition to the myriad rules and regulations governing call centers today, there are few issues more vexing than “compliance.’ What is it, and how does one achieve it? It’s certainly a murky area.
That may be one reason why longtime industry insider and compliance expert Mike McAlpen recently wrote a blog post on this very issue.
“The good news is that many of these compliance pitfalls can be addressed fairly easily, without a lot of additional resources,” McAlpen wrote. “I always tell people that before they assume they’re in the clear, they should invest in at least a brief consultation with a local attorney who specializes in security and compliance.”
That’s sound advice for any company that has even the slightest concern about whether it is in full compliance with local and federal regulations. But McAlpen goes a step further and lists some important questions all call center managers should ask themselves. Namely:
Do you record your calls, and collect credit information? If you do, be careful. “You need to be aware that it violates PCI (News – Alert)-DSS standards—the Holy Grail of credit-card processing security—to store the secret CVV2 number (the three- or four-digit number often listed on the back of the card)—at any time, in any way, no matter what level of encryption or encapsulation is used,” McAlpen notes. If your company regularly records the entire call, you’re probably storing this information in your recordings. That will put you out of compliance and could lead to problems down the road.
Do you store Credit information for repeat customers? Once again, leading PCI-DSS consultants often say that “nothing should stick” within your systems—meaning that credit card information and other sensitive data should not be stored.
Do you record your ’agents'" calls? Most companies announce (or should announce) that incoming calls are recorded. Outgoing calls? Not so much, even though most states require that the recipients of those calls also be notified. If you’re not doing so, McAlpen suggests, you might well be in violation of compliance regulations. Look into it, and make the necessary adjustments.
Call monitoring might be an issue: “Some contact center software allows supervisors to listen in on conversations. The ‘whisper’ option lets managers speak to the agent—so the caller can’t hear the supervisor—to provide guidance on how to handle the call. ‘Barge’ allows supervisors to listen and join the call if they feel it’s necessary,” McAlpen says. But again, in some jurisdictions, these options are subject to regulation. Be sure you’re not inadvertently violating the law when a supervisor logs in.
McAlpen concludes that these are “fairly easy, low-cost, or no-cost suggestions that any contact center manager can easily implement. ”They put you in a much better position to comply with regulations and can help your company avoid problems.” But failing to do so is what can get you into trouble. Isn’t it worth taking a few minutes to brush up on the law and see how and where it applies? Better to do it now on your own than later with lawyers involved.
