In short: yes, you can record your company’s phone calls — but not any way you like. Under GDPR, a voice recording is personal data, so recording is only lawful if you meet a few conditions. Here they are, in plain terms.

1. You need a lawful basis

GDPR doesn’t allow processing data “for anything”. You need a lawful basis for recording. The most common in business practice are:

  • Legitimate interest — for example, evidence of transactions, quality improvement or security. It must be documented with a balancing test (your interest vs. the person’s rights).
  • Performance of a contract — where the recording is necessary for the service provided.
  • Consent — valid only if it is freely given, specific, and can be withdrawn as easily as it was given.

Choose the right basis before you start recording, and record it.

2. You must inform participants

Whatever the basis, you have a duty to inform: the caller must know the call is being recorded and for what purpose, before recording. In practice that means an announcement at the start of the call (“This call may be recorded for…”) and, where relevant, a way to opt out.

A periodic tone (beep) during the call is an additional measure accepted in many contexts.

3. Recordings must be secured

Personal data must be protected “by appropriate technical measures”. For recordings, that means first of all encryption and role-limited access — not audio files in a folder anyone can open. Ideally, every access to a recording is logged, so you can prove who listened to it and when.

4. Keep them only as long as necessary

GDPR requires minimization and storage limitation: don’t keep recordings longer than necessary for the stated purpose. Set a clear retention policy (say, X months) and apply it automatically.

5. Answer data-subject requests

A person can ask for access to recordings they appear in, or their rectification or erasure. To answer within the legal deadlines, you need a quick way to retrieve a person’s calls and export what’s relevant.

How a platform built for GDPR makes this easier

You can tick all of the above by hand — or use a system where they’re built in. Pentacomm’s GDPR-compliant recording delivers the consent announcement and opt-out on every call, encrypts recordings under your control, allows pause / mask for sensitive data, and keeps a full audit log — on an appliance you own, on-premises or in a private cloud.

Note: this article is for information only and does not constitute legal advice. For your company’s specific situation, consult a data-protection specialist.