In this article
Call recording under GDPR is legal, but compliance is not automatic. Whether your organisation records calls through Microsoft Teams, Zoom, Webex, a contact centre platform, or any other system, the same GDPR obligations apply: a lawful basis for recording, transparency with participants, controlled retention, and appropriate security and access controls.
This guide explains what GDPR requires for call recording, what compliance recording means in practice, and how those obligations translate across common communications platforms.
For the full foundational picture, including the EU-wide rules, lawful bases, and individual rights in detail, see our companion article, Telephone Call Recording and GDPR: Understanding the Rules Across the EU. This piece builds on that with what has changed for 2026.
Key takeaway: GDPR does not prohibit call recording. It requires that recording is done lawfully, transparently, and with appropriate governance. The obligation is platform-agnostic and applies regardless of which system captures the call.
Quick check: are you meeting your GDPR obligations?
Run through these six questions for every tool that records, transcribes, or summarises your calls and meetings, including any AI note-taker or personal transcription app your staff have added themselves.
- Do you know every tool capturing audio, transcripts, or summaries across your organisation, including ones individuals installed without IT approval?
- Do you have a lawful basis for the recording and processing each one carries out, and can you evidence it?
- Are participants given clear information that recording or AI processing is taking place, in a way they would reasonably encounter rather than buried out of sight?
- Are recordings, transcripts, and summaries kept only as long as needed, with a reliable way to delete them once that point is reached?
- Could you find and produce the relevant material if someone made a subject access request?
- Is access limited to those who need it, with security measures proportionate to how sensitive the recordings are?
If you can’t answer yes to all six, the gap is usually governance rather than the recording itself. Consumer-grade AI note-takers and ad-hoc transcription tools capture the audio but rarely handle the lawful basis, notification, retention limits, and accountability that GDPR expects.
Is call recording allowed under GDPR?
Yes. GDPR does not prohibit recording calls. It requires that organisations have a legitimate reason to record, tell participants the recording is happening, keep recordings only for as long as necessary, and protect the data appropriately.
A recorded call almost always captures personal data. A voice, name, phone number, or email is enough to bring it within scope, so GDPR applies to virtually every business call recording programme regardless of size, sector, or platform.
This applies to:
- Internal meetings involving named employees
- B2B calls with suppliers or partners
- Customer service and support calls
- Sales calls with prospects
- Client advisory meetings
- AI-generated transcripts or summaries of any of the above
The fact that a call is between two organisations does not remove GDPR obligations. The individuals taking part are natural persons, and their data is being processed.
What GDPR requires for call recording
Several key obligations of GDPR 1 sit at the core of any call recording programme, on any platform.
- A lawful basis for recording. Every recording programme needs a documented legal ground. The most common options are:
- Legal obligation. Where a sector regulation requires recording (financial services is the most common example), that obligation is the lawful basis and consent is not required.
- Legitimate interests. Appropriate for quality assurance, training, and dispute resolution. It requires a balancing test weighing the organisation’s interests against the individual’s rights, which is best documented so it can be evidenced.
- Consent. A valid basis, but often difficult to rely on for systematic recording. It has to be freely given and can be withdrawn at any time, which is a problem where recording is routine or where there is an imbalance of power between the organisation and the individual.
- Transparency. Participants must be told the call is being recorded before or at the start of recording, and why. The legal test is that the information actually reaches them in a form they would reasonably encounter, so a line in a privacy policy they are unlikely to see does not meet it on its own. The notification belongs in the call flow itself: an audible announcement, an IVR message, or an in-app disclosure.
- Retention limits. GDPR requires deletion once the recording’s purpose has been served. There is no universal retention period. Organisations should set purpose-specific schedules and should enforce them automatically rather than rely on manual deletion or a single default setting across every recording type. Some jurisdictions impose specific retention limits for certain types of recordings or recording purposes. Consult your governance, legal, or compliance team to ensure retention periods align with applicable requirements.
- Security and access controls. GDPR requires appropriate technical and organisational measures to keep recordings secure, proportionate to their sensitivity and the risk involved. It does not mandate any specific control. Measures such as encryption, limiting access to those who need it, and keeping a record of access are common and sensible ways to meet this, but the test is what is appropriate to the risk, not a fixed checklist.
Key note: Different recording purposes within the same organisation may need different lawful bases. A financial services firm recording regulated client calls and running a separate system for internal quality assurance may have to document both. Beyond the obligations above, other GDPR principles also apply, including data minimisation, accuracy, and the data subject rights such as access and erasure.
What is compliance recording?
The term “compliance recording” appears across the industry and in platform documentation, but its meaning is not always spelled out.
- Convenience recording is usually user-initiated. A participant clicks a button to start recording a call or meeting. It is optional, it can be stopped or missed, and it is generally stored in the user’s personal file storage. It is useful for notes and reference, but it cannot guarantee that every in-scope communication is captured.
- Compliance recording is automatic and policy-driven. It is usually configured to capture every call involving assigned users, whether or not participants choose to start it. Recordings are captured into a centralised, governed archive rather than personal storage, and access, retention, and deletion are controlled at an organisational level.
Both models can be GDPR-compliant. Convenience recording is not inherently non-compliant: if a lawful basis is in place, participants are notified, retention is controlled, and access is restricted, an individual recording meets the same standard as any other. The difficulty is that those rules then depend on individuals applying them consistently, every time. Someone has to remember to start the recording, give the notification, store it in the right place, and delete it on schedule. Across an organisation, that is hard to guarantee and harder to evidence in an audit.
The distinction matters where recording obligations are systematic. If every in-scope call has to be captured, retained to a defined schedule, and shown to an auditor or regulator, relying on individual behaviour introduces gaps. Compliance recording removes that dependency by enforcing capture, retention, and access at the platform level rather than leaving them to the user.
Most enterprise communications platforms support both models, but they are usually separate capabilities with different configurations and, in some cases, different licensing or third-party integrations.
What GDPR requires for retention
There is no universal GDPR retention period for call recordings. Retention has to match the purpose.
| Recording type | Illustrative range |
| Customer service / QA | 3-12 months |
| Sales | 3-12 months |
| Training recordings | 1-6 months |
| Dispute resolution | Until the dispute is resolved |
| Sector-regulation mandated | Varies by regulation |
The day ranges above are indicative only. GDPR does not prescribe specific retention periods. Retention should be defined, documented, and justified according to the purpose of the recording.
Retention periods should be determined by the purpose of the recording. Some organisations retain transcripts and recordings for several years where they support long-term customer relationships, knowledge management, dispute resolution, or regulatory obligations. The key requirement is that the retention period is documented, justified, and reviewed periodically.
A common pitfall is removing a default expiry setting without putting a purpose-specific retention process in its place. Without a replacement, recordings can sit far longer than their purpose justifies, which creates a storage-limitation problem under GDPR.
What GDPR cares about is the outcome: data is deleted once its purpose ends. Automating deletion is one reliable way to make that happen, rather than relying on manual housekeeping that can slip, but the law is concerned with the result rather than the mechanism.
How GDPR applies across recording platforms
GDPR obligations are platform-agnostic. The same requirements apply however a call is captured: through a cloud communications or telephony provider, an on-premises or self-hosted recording system, or a local device or on-device AI tool that records, transcribes, or summarises. The technology does not change the obligations.
What changes is how each setup meets them. Some platforms enforce notification, retention, and access controls natively; others leave those to configuration or to a third-party archive; and locally run or on-device tools often capture audio and AI outputs entirely outside any central governance. In every case the same questions apply: is there a lawful basis, are participants informed, is retention controlled, is access appropriate, and can the data be found and produced on request. Where a platform cannot meet these on its own, the gap has to be closed with policy, configuration, or an additional governance layer.
A note on financial services recording
Financial services is the clearest example of recording driven by legal obligation. Under MiFID II (Article 16(7)) 2, investment firms must record telephone conversations and electronic communications relating to transactions, and retain them for at least five years, which a competent authority can extend to seven. National regulators enforce these rules, including the FCA in the UK and BaFin in Germany, and market abuse surveillance duties under the Market Abuse Regulation (MAR) 3 sit alongside them.
For firms in scope, the recording obligation is itself the lawful basis, retention is set by the regulation rather than by choice, and the audit and search requirements are stricter than for general business recording.
What the EU AI Act changes in 2026
Article 50 of the EU AI Act 4 sets out several transparency obligations that become applicable from 2 August 2026, covering different uses of AI. The one most relevant to calls is the duty to inform people when they are interacting with an AI system, unless that is obvious from the circumstances and context of use. Separate duties cover AI-generated content, deepfakes, and emotion recognition, so if a platform also analyses sentiment or emotion from a call, check whether those apply.
For any platform where AI handles or assists calls (voice agents, AI-assisted IVR, AI call routing, or automated participants joining a meeting), the practical implementation of the interaction duty is a disclosure at or before first interaction. Article 50 does not prescribe a specific form, but a disclosure buried in a privacy policy is unlikely to satisfy it where participants could not reasonably be expected to know they were dealing with AI.
This obligation sits alongside GDPR, not inside it. Both apply. The specifics differ depending on whether the organisation is acting as a provider or a deployer of the AI system, and procuring a compliant product does not transfer all deployer obligations to the vendor.
Three further AI considerations apply across all platforms:
- AI-generated outputs are usually personal data. Transcripts, meeting summaries, action items, and AI-generated notes will often constitute personal data, because they relate to identified or identifiable individuals. Where they do, they need the same retention, access, and deletion treatment as the recordings themselves, and they fall within the scope of a subject access request.
- AI can operate without a traditional recording being initiated. Some AI tools process live audio and generate outputs such as summaries and notes without ever creating a recording file. Organisations should confirm whether AI tools are active for in-scope users and make sure the governance framework covers AI outputs, not just recorded audio.
- Local recording and AI does not remove GDPR obligations. Some organisations run AI transcription or summarisation on their own infrastructure or local machines rather than through a cloud service. A locally generated transcript is still personal data. The same rules apply: lawful basis, retention limits, access controls, and the ability to locate and produce the data on request.
What a GDPR compliant call recording setup looks like
Whatever the platform, a GDPR compliant call recording solution should have:
- Clear notification that calls may be recorded, including appropriate disclosure where AI systems are used to process recordings.
- The ability to withdraw consent where consent is the legal basis for recording.
- Purpose-specific retention schedules, supported by controls to ensure recordings are not retained longer than necessary.
- Appropriate access controls and audit capabilities to ensure that access to recordings is limited to authorised personnel and can be monitored where required.
- Search and retrieval capabilities that help organisations locate relevant recordings and associated data for subject access requests, investigations, audits, and compliance activities.
- Governance of AI-generated outputs, ensuring transcripts, summaries, and AI-generated notes are subject to appropriate retention, access, and security controls consistent with organisational policy and regulatory requirements.
As a result, many organisations in regulated industries use dedicated compliance recording and archiving platforms alongside their communications systems to help meet retention, security, audit, and governance requirements that may extend beyond native platform capabilities.
How Argus Archive helps
Argus Archive is a compliance recording and archiving platform that integrates with Microsoft Teams through the compliance recording API and supports archiving from other enterprise communications environments.
Recordings are captured automatically for all assigned users and stored in a dedicated compliance archive, with immutable storage, purpose-specific retention schedules, automated deletion at period end, and legal hold on demand. A tamper-evident audit log records every access event.
AI-powered search enables compliance and governance teams to locate recordings using keywords, phrases, and semantic meaning rather than exact matches alone. Users can quickly search across the archive by participant name, phone number, date range, call direction, and conversation topics. AI-generated outputs, including transcripts and meeting summaries, are governed under the same retention, access control, and audit framework as recordings.
Explore the Argus Archive platform or contact the team to discuss your compliance recording requirements.
Frequently asked questions
Is call recording legal under GDPR?
Yes. GDPR does not prohibit call recording. It requires a lawful basis, transparency with participants, appropriate retention limits, and adequate security. Provided those conditions are met, recording calls is lawful.
Does GDPR apply to internal calls and meetings?
Yes. GDPR applies whenever personal data is processed, regardless of whether a call or meeting is internal or external. If internal calls or meetings are recorded and contain personal data, organisations must have a lawful basis for processing, provide appropriate transparency, implement suitable security controls, and ensure recordings are not retained longer than necessary.
Does GDPR apply to B2B calls?
Yes. GDPR applies whenever personal data relating to an identifiable individual is processed, whether the call is between businesses or with a consumer. Participants in B2B calls are natural persons whose voice, name, and contact details are personal data.
Do you need consent to record calls under GDPR?
Not always. Consent is one of six lawful bases under GDPR, and it is often difficult to rely on for systematic recording, because it has to be freely given and can be withdrawn at any time. Where a sector regulation makes recording mandatory, that obligation is the lawful basis. Most other organisations rely on legitimate interests, which requires a balancing test, best documented so it can be evidenced.
How long can call recordings be kept under GDPR?
GDPR does not prescribe a fixed retention period for call recordings. Organisations should define, document, and justify retention according to the purpose of the recording. Depending on that purpose, recordings may be retained for months or several years. The important requirement is that recordings are not kept longer than necessary and are deleted when their purpose has been fulfilled.
Does GDPR apply to AI-generated transcripts?
Yes, where they relate to an identifiable individual. AI-generated transcripts, summaries, and meeting notes are personal data because they capture what identifiable individuals said. They need the same lawful basis, retention limits, access controls, and deletion processes as the underlying recordings, and they fall within the scope of a Subject Access Request (SAR). A SAR response is not unconditional, though: it may require redacting other people’s information, and certain exemptions can apply under UK GDPR and member-state law. For more information on Subject Access Requests, read our foundational GDPR Article.
References
- GDPR Regulation (EU) 2016/679 Official consolidated text (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng ↩︎
- Article 76 of the Delegated Regulation (EU) 2017/565 Offical consolidated text (EUR-LEX): https://eur-lex.europa.eu/eli/reg_del/2017/565/oj/eng. ↩︎
- Market Abuse Regulation (MAR) (EU) No 596/2014: https://eur-lex.europa.eu/eli/reg/2014/596/oj/eng ↩︎
- EU AI Act Regulation (EU) 2024/1689 Official text (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng ↩︎
Disclaimer
This article is provided for informational purposes only and does not constitute legal advice.
Organizations should consult their data protection officer or legal counsel for guidance on their specific situation and applicable national requirements.
