Compliance & call recording

GDPR-compliant call recording

Record every conversation — encrypted, with consent and an audit trail.

A call-recording system built for GDPR from the start: a consent announcement and opt-out on every call, recordings encrypted under your control, supervisor pause / mask, and a full audit trail — on an appliance you own, on-premises or in your private cloud.

The problem

Recording calls? Then GDPR applies.

If your business records calls — in the call center, in sales, or in support — GDPR applies from the first second. A voice recording is personal data, and the law requires a lawful basis, informing participants, securing the files, and a justified retention period. Most phone systems record, but leave compliance entirely up to you.

Pentacomm flips that: the compliance mechanisms — consent, opt-out, encryption, pause / mask, audit, and retention — are built into the platform, not bolted on later or left to you. You set the policy; the appliance enforces it on every call and keeps the evidence.

How it keeps you compliant

Compliance built in — not bolted on

Every control GDPR expects for call recording is a core platform feature, managed from the same console.

  • Automatic consent announcement — An informing message plays at the start of the call, with a keypad (DTMF) opt-out; the notice and any refusal are recorded on every call.
  • Always-on encryption — Recordings encrypted with AES-256-GCM per segment, with per-tenant keys and a dedicated encryption role. Without the key, a file cannot be played back.
  • Your data stays with you — On-premises or private cloud: recordings and their metadata never leave your perimeter and never pass through a third-party cloud.
  • Supervisor pause & mask — Pause or mask the recording in real time when sensitive data is spoken (payment card, personal data) — without dropping the call. A common PCI-DSS requirement.
  • Optional periodic beep — A discreet, configurable tone that continuously signals a call is being recorded, where regulation requires it.
  • GDPR-grade audit log — Who recorded, who listened, who exported, and when — a complete audit trail for regulator and data-subject requests.
  • Retrieval & export on request — Recordings indexed in searchable CDRs, with CSV, XLSX and PDF export — so you can answer an access or erasure request quickly.
  • Retention under your control — You decide how long each recording is kept; the storage and the retention policy are yours, not a vendor's.

The bottom line

You don't just record the calls — you can prove you do it lawfully. Consent, encryption, audit and retention, built in, on a system you own.

Frequently asked

Call recording and GDPR

Is it legal to record my company's phone calls?

Yes, under certain conditions. GDPR and Romanian law allow call recording if you have a lawful basis (typically legitimate interest or performance of a contract) and you inform participants before recording. Pentacomm automatically plays a consent announcement at the start of the call and can offer a DTMF opt-out, so the notice and the right to refuse are documented on every call.

Do I need the customer's consent to record the call?

You must at least inform the caller that the call is being recorded and for what purpose. Pentacomm delivers the consent announcement before connect and an optional periodic beep during the call, plus a keypad opt-out — and the proof of notice stays in the audit log.

How are the recordings secured?

Every recording is encrypted with AES-256-GCM, per segment, with dedicated per-tenant keys and a separate encryption role. Recordings never leave your perimeter — the appliance runs on-premises or in your private cloud, under your control.

How long can I store the recordings?

As long as your retention policy requires. You own the storage and decide the duration; GDPR requires you not to keep data longer than necessary for the stated purpose. Recordings and their metadata live in a separate database, with a full audit log.

How do I answer a GDPR request for access to a recording?

Recordings are indexed in searchable CDRs, with CSV / XLSX / PDF export, and access is role-controlled and logged. You can quickly retrieve a person's calls and prove who accessed a recording and when.

Can a supervisor pause recording when sensitive data is discussed?

Yes. Supervisors can pause or mask recording in real time (for example while a payment card is read out), without dropping the call — a common requirement for PCI-DSS and for data minimization.

Where is the data stored — with you or with me?

With you. Pentacomm is on-premises or private cloud; we do not host or access your calls or recordings. There is no third-party cloud component on the media path.

See GDPR-compliant recording in action.

Talk to us about a proof-of-concept on your own call center — or about early pilot access. We'll show you consent, encryption, pause / mask, and the audit log on real calls.

Contact us for early access