Compliance

GDPR, call recording & AI voice agents: the compliance guide

29 August 2026 · 10 min read

Reviewing documents and compliance paperwork at a desk

The short answer

It can be, and compliance is your responsibility as data controller rather than the vendor’s. You need a lawful basis for processing calls, clear disclosure to the caller, a defined retention period, a data processing agreement with every provider in the chain, and extra care where health or legal data is involved.

This is practical guidance from deploying voice agents for UK service businesses, not legal advice. If you are in a regulated sector, have your DPO or solicitor review your specific setup. Said once — the rest of this page will not hedge every sentence.

Why this stops deals, and why it should not

Compliance is the objection that kills automation projects in clinics, dental practices and law firms — the three sectors that would benefit most, because their reception desks are the most overloaded.

It usually kills them for the wrong reason. Not because a practice looked at the requirements and found them unworkable, but because nobody could get a straight answer, so the safest thing was to do nothing. Doing nothing has its own compliance profile, incidentally: patient details on sticky notes and voicemails sitting in a shared inbox for three years is not a stronger position than a documented agent with a defined retention period.

Here is the straight version.

You are the data controller. The vendor is a processor.

This is the point most vendor pages skip, and everything else follows from it.

When a caller speaks to an agent on your line, you decide why that data is collected and what happens to it. That makes you the controller and your vendor a processor acting on your instructions. Which means:

  • The lawful basis is yours to establish.
  • The disclosure obligation is yours.
  • The retention decision is yours.
  • If a caller exercises their rights, the request lands with you.
  • If the processor leaks it, you are still accountable to the regulator and the caller.

No vendor certificate transfers that. Any provider who tells you they “handle GDPR for you” is describing their own processor obligations and quietly leaving yours with you.

Lawful basis: consent or legitimate interests?

Two realistic options for handling calls.

Legitimate interests is the usual basis for answering, qualifying and booking. Answering your phone is plainly within your interests and the caller’s, and they initiated the call. Document a legitimate interests assessment: what the interest is, why the processing is necessary, and why it does not override the caller’s rights. It is a short document and it is the thing you produce if asked.

Consent becomes the right basis for anything the caller would not expect. Recording the call for training. Using transcripts to improve a model. Marketing follow-up to someone who rang about a booking. Consent must be freely given, specific and withdrawable — and “continuing the call” is a weak vehicle for it, since the alternative is not being served.

Practical rule: legitimate interests for handling the call, consent for anything beyond handling it.

Recording, transcription, and the difference that matters

Recording audio and transcribing it are separate processing activities and people conflate them constantly.

A voice agent needs to process speech in the moment to function. Whether you retain the audio afterwards is a separate decision — and for many deployments the right answer is that you do not. A structured transcript, or even just the extracted outcome (name, number, job type, appointment booked), is often all the business actually needs.

This is the single easiest compliance win available: retain the least you can still run the business on. No stored audio means no stored biometric-adjacent voice data, a smaller breach surface, cheaper storage, and a much simpler answer when someone asks what you keep.

If you do retain recordings, you need a stated purpose, a stated period, and the ability to find and delete a specific caller’s data on request. “It’s all in the platform somewhere” is not a retention policy.

What the caller must be told, and when

At the start of the call, briefly:

  • That they are speaking to an automated assistant. Do not obscure this. Beyond the compliance argument, being coy is the fastest way to lose a customer’s trust — and disclosure requirements in this area are tightening, not loosening.
  • What happens to the information. One clause is enough: “your details are used to handle your enquiry.”
  • That the call is recorded, if it is — and why.
  • Where the full detail lives. A pointer to your privacy notice.

Twelve seconds of audio. Then get on with helping them.

Your privacy notice needs the longer version: what is collected, lawful basis, retention period, who the processors are, international transfers, and how to exercise rights. If your notice does not currently mention automated call handling, it needs updating before you go live — not after.

The processor chain, and the DPA you actually need

A voice agent is not one company. It is typically four or five:

  • The telephony provider carrying the call.
  • The speech-to-text service.
  • The language model provider.
  • The orchestration platform.
  • Whoever built and hosts it.

Every one of those is a processor or sub-processor, and you need a data processing agreement covering the chain. Ask your vendor for a written sub-processor list. It is a completely reasonable request and the answer is diagnostic: a vendor who can produce it in a day has thought about this, and one who goes quiet has not.

Then check three things per link: where the data is processed geographically, what the transfer mechanism is if it leaves the UK or EEA, and whether your call data can be used to train their models. That last one has a correct answer for a business handling customer or patient information, and it is no. Confirm it in writing, not on a marketing page.

Special category data: clinics, dental, and healthcare

The moment a caller mentions a symptom, a condition, a medication, or a treatment, you are handling special category health data. Which means Article 9 as well as Article 6, and a higher standard throughout.

Practical implications:

  • Design the agent to collect less. It does not need the clinical detail to book an appointment. Name, contact, appointment type, urgency. Let the clinician take the clinical history in the room, where it belongs.
  • Shorten retention specifically for these calls. Then hold to it.
  • Route urgency to a human immediately. This is both clinical safety and the right compliance posture. Anything that sounds acute should reach a person, not a queue.
  • Update your record of processing activities. Health data almost certainly warrants a DPIA — treat that as the default answer, not an edge case.
  • Do not let the agent give clinical advice. Ever, on any phrasing. This is a hard boundary configured into the build, not a hoped-for behaviour.

Legal and professional services

Different pressure, similar shape. Enquiry calls to a law firm carry confidentiality and privilege considerations well beyond GDPR, plus professional-conduct obligations.

  • Conflict checks must happen before substance. The agent’s job is to take the enquiry and route it, not to discuss the matter.
  • Confidentiality is not the same as data protection. Your professional duties are stricter and separate. Design to the stricter one.
  • Client identity can itself be sensitive. In family, immigration and criminal work, the fact of the call is confidential information.
  • Retention should follow your existing file policy, not the automation vendor’s default.
  • Keep the disclosure prominent. A caller in distress about a legal problem must not be unsure whether they are confiding in a person.

Pre-deployment checklist

Work through this before the agent takes a live call. If you cannot answer one of them, that is the item to fix.

  • Lawful basis identified and documented (legitimate interests assessment written down)
  • Privacy notice updated to cover automated call handling
  • Opening disclosure scripted: automated assistant, purpose, recording status
  • Retention period set for audio, transcripts, and extracted data — separately
  • Decision made and documented on whether audio is retained at all
  • DPA signed with the vendor; written sub-processor list obtained
  • Processing locations confirmed; transfer mechanism in place if data leaves the UK/EEA
  • Written confirmation that your data is not used for model training
  • Subject access and erasure process tested — can you actually find one caller’s data?
  • Human escalation path defined for urgent, distressed and complaint calls
  • DPIA completed if special category data is in scope
  • Record of processing activities updated
  • Named internal owner for the agent, its logs, and its incident response
  • Breach notification path agreed with the vendor, with a response time in the contract
  • Exit plan: you can export your data and configuration, and the number ports back

How we handle it

We run every deployment as a processor to your controller: a DPA, a written sub-processor list, retention configured to a period you choose rather than a default, and the system running on infrastructure you own and control rather than a platform you rent access to. Your data is not used to train anybody’s model. For clinics and law firms we scope the agent deliberately narrowly — take the enquiry, book or route it, escalate anything urgent to a human — because the least data collected is the least data to protect.

Compliance work is part of the build, not an upsell.

Your next step

Compliance is not the reason to avoid automating your phone. It is a set of decisions with defined answers.

Book a free 30-minute Agent Audit and we will walk your specific setup — sector, data, retention, escalation — and send a written ROI projection within 48 hours. If your compliance position means an agent is the wrong move, we will tell you on the call. No pitch deck.

Frequently asked questions

Your next step

Find your highest-ROI automation.

Book a free 30-minute Agent Audit. We'll map your workflows and send a written ROI projection within 48 hours.

Free 30-minute Agent Audit · Written ROI projection within 48 hours · No pitch deck