By Sagar Shankaran, Founder of CallSphere
Achieve GDPR-compliant call recording with this guide to lawful bases, DPIAs, data subject rights, and retention for European business communications.
Key takeaways
The General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — is the most comprehensive data protection framework in the world. It applies to any organization that processes personal data of individuals in the European Economic Area (EEA), regardless of where the organization is based. Call recordings are unambiguously personal data under GDPR, as they contain voice data that can directly identify individuals.
Since GDPR enforcement began in May 2018, European Data Protection Authorities (DPAs) have issued over EUR 4.8 billion in total fines. Call recording violations represent a growing category: in 2025, DPAs across the EU issued 213 enforcement actions specifically related to call recording practices, with penalties totaling EUR 147 million.
This guide provides a complete framework for GDPR-compliant call recording, covering lawful bases, Data Protection Impact Assessments, data subject rights, cross-border transfers, and practical implementation.
GDPR Article 6 requires that all processing of personal data be based on one of six lawful bases. For call recording, three are primarily relevant:
flowchart LR
REQ(["Inbound request"])
PII["PII detection<br/>regex plus NER"]
POL{"Policy engine<br/>OPA or rules"}
REDACT["Redact or mask"]
LLM["LLM call"]
OUT["Response"]
AUDIT[("Append only<br/>audit log")]
BLOCK(["Block plus<br/>notify DPO"])
REQ --> PII --> POL
POL -->|Allow| REDACT --> LLM --> OUT --> AUDIT
POL -->|Deny| BLOCK
style POL fill:#4f46e5,stroke:#4338ca,color:#fff
style AUDIT fill:#ede9fe,stroke:#7c3aed,color:#1e1b4b
style BLOCK fill:#dc2626,stroke:#b91c1c,color:#fff
style OUT fill:#059669,stroke:#047857,color:#fff
Definition: The data subject has given clear, affirmative consent to the processing of their personal data for one or more specific purposes.
GDPR consent requirements for call recording:
Practical challenges with consent for call recording:
When consent works best: Outbound marketing calls, customer satisfaction surveys, optional quality feedback calls — situations where the individual has a genuine choice to participate.
Definition: Processing is necessary for the legitimate interests of the controller or a third party, except where overridden by the interests, rights, or freedoms of the data subject.
Using legitimate interest for call recording requires a three-part test (Legitimate Interest Assessment — LIA):
Purpose test: Is there a legitimate interest? Common legitimate interests for call recording include:
Necessity test: Is recording necessary to achieve the interest, or could a less intrusive method achieve the same result? Consider whether notes, summaries, or post-call surveys could serve the purpose without full recording.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
Balancing test: Do the data subjects' interests, rights, and freedoms override the legitimate interest? Consider:
Documentation requirement: The LIA must be documented in writing and made available to the supervisory authority upon request.
When legitimate interest works best: Internal quality monitoring, employee training, dispute resolution — situations where recording serves a genuine business need and individuals are notified but not asked for explicit consent.
Definition: Processing is necessary for compliance with a legal obligation to which the controller is subject.
Application to call recording: Financial services firms subject to MiFID II, FCA regulations, FINRA rules, or equivalent mandates can rely on legal obligation as their lawful basis for recording investment-related communications.
Requirements:
When legal obligation works best: MiFID II-mandated recording of investment communications, regulatory requirements in financial services, legally required complaint recording.
GDPR Article 35 requires a DPIA for processing that is "likely to result in a high risk" to individuals' rights and freedoms. Systematic call recording meets this threshold because it involves:
Most DPAs have explicitly included call recording in their lists of processing operations requiring a DPIA.
A compliant DPIA must include:
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Unauthorized access to recordings | Medium | High | RBAC, MFA, encryption at rest, audit logging |
| Data breach exposing recordings | Low | Critical | AES-256 encryption, network segmentation, incident response plan |
| Recordings retained beyond necessity | High | Medium | Automated retention enforcement, periodic review |
| Recordings used for undisclosed purposes | Medium | High | Purpose limitation controls, access justification requirements |
| AI analysis creating discriminatory profiles | Medium | High | Bias testing, human oversight, fairness audits |
GDPR grants data subjects several rights that apply directly to call recordings:
Data subjects can request:
Response deadline: One month from receipt of request, extendable by two months for complex requests.
Practical considerations:
If a call recording contains inaccurate information (e.g., an agent recorded incorrect account details during the call), the data subject can request rectification.
Practical approach: Attach a correction notice to the recording rather than altering the audio file (which would compromise integrity).
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
Data subjects can request deletion of their call recordings when:
Exceptions: Erasure requests can be refused when retention is required for:
Data subjects can request that their recordings be stored but not processed (e.g., not used for training, not analyzed, not shared) while a dispute about accuracy or lawfulness is resolved.
When processing is based on legitimate interest, data subjects can object to the recording. The controller must cease processing unless they demonstrate "compelling legitimate grounds" that override the data subject's interests.
Call recordings containing personal data of EEA individuals may only be transferred outside the EEA using approved mechanisms:
Following the Schrems II ruling (Case C-311/18), organizations relying on SCCs must conduct a TIA evaluating whether the destination country's laws provide essentially equivalent protection:
If call recordings are stored in cloud infrastructure, the storage location matters:
CallSphere offers EEA-based recording storage with optional geographic pinning to specific EU member states, ensuring full GDPR compliance without cross-border transfer complexity.
If customers must accept recording to use your service, consent is likely not freely given. Consider legitimate interest with a robust LIA instead.
Different recording purposes may require different retention periods. Quality monitoring recordings may need only 6 months; compliance recordings may need 5-7 years. Apply the minimum necessary retention for each purpose.
When processing is based on legitimate interest, data subjects have a right to object. Organizations must have a documented process for handling objections and ceasing recording when the objection is valid.
When providing a call recording in response to a Subject Access Request, you must protect the personal data of other individuals on the recording. Redact or mask other participants' voices and personal information.
Systematic call recording requires a DPIA. Operating without one is itself a GDPR violation (Article 35), regardless of whether the recording practices are otherwise compliant.
Not on its own. A notification message is necessary but not sufficient. You must also establish a valid lawful basis (consent, legitimate interest, or legal obligation), complete a DPIA, implement appropriate security measures, and respect data subject rights. The notification message should reference where the caller can find your full privacy notice.
Using call recordings for AI model training is a separate processing purpose that requires its own lawful basis. If the original lawful basis was consent for "quality monitoring," using recordings for AI training exceeds that purpose. You would need either new consent specifically for AI training, or a separate legitimate interest assessment for the training purpose. The EU AI Act may impose additional requirements depending on the AI system's risk classification.
You may refuse the erasure request under Article 17(3)(b) (legal obligation) or 17(3)(e) (legal claims). Document the request, cite the specific legal obligation (MiFID II Article 16(7) and the applicable national transposition), inform the data subject of the refusal and reasoning, and advise them of their right to lodge a complaint with the supervisory authority.
Under Article 33, you must notify your lead supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms. Under Article 34, you must also notify affected individuals without undue delay if the breach poses a "high risk." Document the breach, its effects, and remedial actions in your breach register. Failure to notify can result in fines up to EUR 10 million or 2% of global annual turnover.
Yes. Agents are data subjects whose personal data (voice, statements) is captured in recordings. Employers must inform agents about recording practices, the lawful basis for processing, and agents' rights. Agents generally cannot refuse recording that is a condition of employment or regulatory requirement, but the employer must conduct a balancing exercise and document it in the DPIA.
Written by
Sagar Shankaran· Founder, CallSphere
Sagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
How estate agents and property managers in Luxembourg City and across the Grand Duchy use CallSphere to capture multilingual viewing and enquiry calls 24/7, GDPR compliant.
Clinics in Vilnius, Kaunas, and Klaipėda lose bookings to a busy reception and voicemail. See how CallSphere AI voice and chat agents fill appointments 24/7 in Lithuanian, Russian, and English while staying GDPR-compliant.
Dental and medical clinics across Sweden, Norway, Denmark, Finland and Iceland lose patients to unanswered calls. Here is how a GDPR-aligned CallSphere AI voice and chat agent fixes the front desk.
A pain-to-solution guide for logistics operators and professional-services firms across Poland, Czechia, Hungary and Slovakia to capture cross-border calls 24/7 with a CallSphere AI agent.
A market-data view of Bulgarian small business and outsourcing in 2026, and how CallSphere AI voice and chat agents help firms in Sofia and Plovdiv answer every call in Bulgarian, English, and more.
Dutch logistics, retail and hospitality businesses in Rotterdam, Amsterdam and Eindhoven lose bookings and orders to unanswered phones. See how CallSphere AI voice and chat agents capture every call 24/7 in Dutch and English, GDPR-compliant.
© 2026 CallSphere LLC. All rights reserved.
Made within New York
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI