← Airlines and travel
PCI DSS for Airlines, OTAs and Travel Platforms
Travel is the hardest PCI DSS environment to scope: card data arrives through web, app, call centre, agents and GDS integrations, and often persists in booking records and support tooling long after the transaction. Scope, not control maturity, is what drives cost here.
What PCI DSS requires of airlines and travel
- Data-flow mapping across every acceptance channel, including agent and GDS paths.
- Call-centre controls — recording, pause-and-resume, and agent desktop restrictions where card data is spoken.
- Retention review of booking records, PNR data and support tickets that may hold card data.
- Tokenisation of stored card data to take systems out of scope, which is the dominant cost lever.
- Third-party management across GDS, payment gateways and outsourced contact centres.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Channel-by-channel data-flow diagrams reconciled against actual traffic
- Call recording configuration proving card data is not captured
- Retention and deletion evidence for booking and support records
- Tokenisation architecture and the systems it removes from scope
- Vendor attestations across GDS, gateway and contact-centre partners
Where airlines and travel usually come unstuck
- Card data captured in call recordings and quality-monitoring systems.
- PNR and support tickets retaining card data outside the defined CDE.
- Outsourced contact centres treated as out of scope without attestation.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
