If you're a merchant, service provider, or other processor in the PCI
chain and you take CCs via email then your entire email system may be
considered in-scope by your PCI assessor and the full DSS applies.
Which means encryption everywhere, physical access reviews, etc.
Generally, even if you use Office365, G Suite, or some other hosted
solution, this is non-trivial and non-cheap.
As an Amazon Associate we earn from qualifying purchases.
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.