GDPR for contact centers and call recording
Verified 2026-10-01 · 57 sources · tier 1–2
Also known as gdpr-call-recording.
GDPR Article 6(1) permits processing of personal data only where at least 1 of 6 lawful bases applies: consent, contract, legal obligation, vital interests, public task, or legitimate interests 36. For contact centers, call recordings and transcripts constitute personal data subject to these principles and the storage limitation mandate of Article 5(1)(e), which requires personal data to be kept in identifiable form no longer than necessary for the purposes of processing 46.
Lawful bases and caller notification
GDPR defines consent as a freely given, specific, informed, and unambiguous indication of wishes given by a statement or clear affirmative action 18. Under GDPR Article 7(3), a data subject may withdraw consent at any time, though withdrawal does not make processing carried out before the withdrawal unlawful 19. Where processing rests instead on legitimate interests or public task, GDPR Article 21(1) lets the data subject object, after which the controller must stop processing unless it shows compelling legitimate grounds or needs the data for legal claims 41.
When personal data is collected directly from the data subject, such as when a caller is recorded, GDPR Article 13(1) requires the controller to give prescribed information at the time the data is obtained 37. This notice must include specific details:
- The controller's identity and contact details, the purposes and legal basis of processing, and the legitimate interests pursued where Article 6(1)(f) is relied on 38.
- The recipients or categories of recipients and, where applicable, the intended transfer to a third country and the safeguards relied on 39.
- The period for which the data will be stored or, if that is not possible, the criteria used to determine that period 40.
Where personal data is not obtained directly from the data subject, GDPR Article 14(3)(a) requires notice within a reasonable period and at the latest within 1 month of obtaining it 4.
At the national supervisory authority level in France, the CNIL's guidance page on listening to and recording workplace calls is dated 5 May 2009 and carries a CNIL banner stating the page is obsolete and being updated 12. The CNIL page states that employers may not set up permanent or systematic call listening or recording except where the law requires it 11. The CNIL page also states that callers must be told orally at the start of the conversation that the system exists, its purpose, and that they can object 10, and that call recordings may be kept for at most 6 months 13.
Data subject rights handling
GDPR Article 15 gives data subjects a right to confirmation of processing, access to their personal data and supplementary information, and a copy of the personal data undergoing processing 1. The EDPB's final guidance on the right of access is Guidelines 01/2022, version 2.1, dated 17 April 2023 on the EDPB site 26. Article 15(4) provides that the right to obtain a copy must not adversely affect the rights and freedoms of others 2.
GDPR Article 17(1) gives the data subject a right to erasure without undue delay on listed grounds, including where the data is no longer necessary, consent is withdrawn, or an objection succeeds 29. The erasure right does not apply to the extent processing is necessary to comply with a Union or Member State legal obligation or for the establishment, exercise, or defence of legal claims 28.
GDPR Article 12 establishes statutory timelines and procedural rules for data subject requests:
- Article 12(3) requires the controller to act on requests under Articles 15 to 22 without undue delay and in any event within 1 month of receipt 24.
- The 1-month period may be extended by 2 further months where necessary, provided the controller tells the data subject of the extension and reasons within the first month 25.
- Responses are free of charge, but for manifestly unfounded or excessive requests, particularly repetitive ones, the controller may charge a reasonable fee or refuse to act 22.
- Where the controller has reasonable doubts about the requester's identity, it may ask for additional information needed to confirm it 23.
Under ICO guidance for the UK GDPR, if the organisation asks the requester for clarification, the 1-month subject access time limit pauses and resumes the day after the clarification is received 35. ICO guidance also states that organisations must make a reasonable and proportionate search to answer a subject access request but need not run searches that are unreasonable or disproportionate 34.
Biometrics and impact assessments
GDPR defines biometric data as personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics that allow or confirm unique identification of a natural person 8. Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a natural person unless an Article 9(2) exception, such as explicit consent, applies 9.
GDPR Article 35(1) requires a data protection impact assessment (DPIA) before processing likely to result in a high risk, and Article 35(4) requires supervisory authorities to publish lists of operations that need one 21.
Infringements of basic principles, lawful-basis and consent rules, data subject rights under Articles 12 to 22, and transfer rules carry administrative fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher 30.
Processors, sub-processors, and international transfers
Under GDPR Article 28(1), controllers must use only processors that provide sufficient guarantees of appropriate technical and organisational measures 43. Article 28(3) requires a binding contract under which the processor acts only on documented instructions, binds staff to confidentiality, secures data, assists with data subject requests, deletes or returns data at the end of services, and allows audits 42. The EDPB adopted Opinion 22/2024 under Article 64 on obligations arising from reliance on processors and sub-processors, dated 9 October 2024 on the EDPB site 27.
A processor such as a CCaaS provider may not engage a sub-processor without the controller's prior specific or general written authorisation 47. Under general written authorisation, the processor must inform the controller of intended additions or replacements, giving the controller an opportunity to object 48. A processor must impose the same data protection obligations on its sub-processors by contract and remains fully liable to the controller for a sub-processor's failure 49.
International data transfers outside the EEA must rely on valid transfer mechanisms:
- A transfer covered by a Commission adequacy decision requires no specific authorisation 3. The Commission renewed the United Kingdom's GDPR adequacy decision by a decision dated 19 December 2025 50. The Commission's adequacy finding for the United States covers only commercial organisations participating in the EU-US Data Privacy Framework, under a decision adopted on 10 July 2023 51.
- Without an adequacy decision, Article 46(2)(c) allows transfers under standard data protection clauses adopted by the Commission, provided enforceable rights and effective remedies are available 45. The Commission's modernised standard contractual clauses were issued on 4 June 2021 by Implementing Decision 2021/914 and cover controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers 44.
- Absent adequacy or appropriate safeguards, Article 49(1)(a) permits a transfer on the data subject's explicit consent after being informed of the risks, though this derogation does not apply to public authorities exercising public powers 20.
AWS states that its Service Terms include the June 2021 Commission SCCs and that its DPA applies them automatically when customer data is transferred outside the EEA 5. AWS also states it may use 3 types of sub-processors: AWS entities providing underlying infrastructure, AWS entities supporting specific services, and contracted third parties for specific services, depending on region and services used 6.
Platform recording architectures and controls
In Webex Contact Center, the default retention period for call recordings and transcripts in new organisations is 1,095 days 55. Existing organisations retain recordings indefinitely until an administrator configures a retention period 54. Webex Contact Center administrators can set 1 retention period, from 7 to 3,600 days, that applies to both call recordings and transcripts 56. Cisco warns that setting a Webex Contact Center retention period of 180 days or less may affect the performance and availability of certain AI-driven features 57.
In Amazon Connect, voice recording is enabled per contact by placing a Set recording and analytics behavior block in the flow, which can record agent and customer, agent only, or customer only 16. Amazon Connect delivers call and screen recordings to the customer's own Amazon S3 bucket, encrypted with the KMS key configured at instance creation, after holding them intermediately during and after the contact 17. When a customer is on hold the agent is still recorded, and the conversation between agents during a transfer is recorded 14. AWS recommends placing the recording block in an inbound or outbound whisper flow, because in a queue flow it may run after the agent joins and the call may not be recorded as intended 15.
Genesys Cloud provides a GDPR API with a subjects endpoint for finding a person by identifiers such as name, phone or email, and a requests endpoint for export (access), update (rectification) and delete (erasure) requests 33. Genesys states it needs no longer than 14 days to remove or anonymise personal data on a GDPR forget-me request, and typically 1-2 days for access requests 32. Genesys states its GDPR API cannot be used for bulk requests, cannot search file attachment contents, and cannot discover data not associated with External Contacts profiles 31.
See also
See also Recording consent and AI processing privacy. See also Webex Contact Center recording and contact data retention. See also CDR privacy redaction and evidence-safe reporting.
Applicability
Applies to: Cisco Webex Contact Center, Amazon Web Services Amazon Connect, Amazon Web Services, and Genesys Cloud. Deployments: on-premises and multi-tenant. Sources checked 2026-10-01. The evidence covers the EU/EEA region under GDPR 36, the UK under UK GDPR 35, and France under CNIL guidance 12.
What remains uncertain
- The Latombe v Commission judgment and appeal outcome are not covered by the sources below.
- Member State call-recording and interception laws are not covered by the sources below.
- The application of GDPR purpose limitation and DPIA requirements to AI transcription and speech analytics on recordings is not covered by the sources below.
- Cisco Webex Contact Center privacy data sheet sub-processors and transfer mechanisms are not covered by the sources below.
- Webex Contact Center per-recording deletion for erasure requests is not covered by the sources below.
- ePrivacy Directive consolidated text on interception and business-practice recording is not covered by the sources below.
- EDPB Guidelines 01/2022 content on audio recordings and redaction of third-party voices is not covered by the sources below.
- Genesys Cloud GDPR export vs delete scope for call recordings is not covered by the sources below.
See also
Related to
- Contact centre AI data residency retention and training boundaries — Owns the alias 'gdpr'; covers AI processing and residency; while this topic covers recording lawful basis; notice; access; retention and processors
- HIPAA for contact centers and UC — Parallel US health-privacy regime for contact centers
- PCI DSS for contact centers — Parallel compliance regime for recordings containing card data
- Webex Contact Center recording and contact data retention — Vendor retention settings that implement Article 5(1)(e) storage limitation for Webex Contact Center
Referenced by
- HIPAA for contact centers and UC — Sibling privacy-compliance topic (EU) for contact-center data; HIPAA is the US health-data equivalent. No claims in this packet are tagged to it.
- WhatsApp Business in contact centers — WhatsApp opt-in and opt-out obligations sit alongside data-protection consent rules
Sources
- 1GDPR Article 15 gives the data subject a right to confirmation of processing, access to their personal data and supplementary information, and a copy of the personal data undergoing processing.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 15(1) and 15(3) · Checked 2026-10-01
- 2GDPR Article 15(4) provides that the right to obtain a copy must not adversely affect the rights and freedoms of others.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 15(4) · Checked 2026-10-01
- 4Where personal data is not obtained from the data subject, GDPR Article 14(3)(a) requires notice within a reasonable period and at the latest within one month of obtaining it.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 14(1) and 14(3)(a) · Checked 2026-10-01
- 5AWS states that its Service Terms include the June 2021 Commission SCCs and that its DPA applies them automatically when customer data is transferred outside the EEA.General Data Protection Regulation (GDPR) Center · section on the AWS GDPR DPA and SCCs · Checked 2026-10-01
- 6AWS states it may use three types of sub-processors: AWS entities providing the underlying infrastructure, AWS entities supporting specific services, and contracted third parties for specific services, depending on region and services used.General Data Protection Regulation (GDPR) Center · section on sub-processors · Checked 2026-10-01
- 7Because consent is withdrawable at any time and must be demonstrable, while legitimate interests is subject to a right to object, a contact center choosing a lawful basis for call recording is choosing which caller opt-out mechanism it must operate, not whether one exists.inferredRegulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Articles 6(1), 7(1), 7(3) and 21(1) read together · Checked 2026-10-01
- 8GDPR defines biometric data as personal data from specific technical processing of physical, physiological or behavioural characteristics that allow or confirm unique identification of a person.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 4(14) · Checked 2026-10-01
- 9GDPR Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a natural person unless an Article 9(2) exception, such as explicit consent, applies.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 9(1) and 9(2)(a) · Checked 2026-10-01
- 10The CNIL page states that callers must be told orally at the start of the conversation that the system exists, its purpose, and that they can object.L'écoute et l'enregistrement des appels sur le lieu de travail · section 'L'information des personnes' · Checked 2026-10-01
- 11The CNIL page states that employers may not set up permanent or systematic call listening or recording except where the law requires it.L'écoute et l'enregistrement des appels sur le lieu de travail · section 'Quelles limites à ces dispositifs ?' · Checked 2026-10-01
- 12The CNIL's guidance page on listening to and recording workplace calls is dated 5 May 2009 and carries a CNIL banner stating the page is obsolete and being updated.L'écoute et l'enregistrement des appels sur le lieu de travail · page header and status banner · Checked 2026-10-01
- 13The CNIL page states that call recordings may be kept for at most six months.L'écoute et l'enregistrement des appels sur le lieu de travail · section 'Quelles garanties pour la vie privée ?' · Checked 2026-10-01
- 14In Amazon Connect, when a customer is on hold the agent is still recorded, and the conversation between agents during a transfer is recorded.Data handled by Connect Customer · section 'Call recordings and screen recordings', bullet list · Checked 2026-10-01
- 15AWS recommends placing the recording block in an inbound or outbound whisper flow, because in a queue flow it may run after the agent joins and the call may not be recorded as intended.Flow block in Connect Customer: Set recording and analytics behavior · section 'Flow types', Tip · Checked 2026-10-01
- 16In Amazon Connect, voice recording is enabled per contact by placing a Set recording and analytics behavior block in the flow, which can record agent and customer, agent only, or customer only.Enable contact recording · 'To set up recording of conversations', steps 4-5 · Checked 2026-10-01
- 17Amazon Connect delivers call and screen recordings to the customer's own Amazon S3 bucket, encrypted with the KMS key configured at instance creation, after holding them intermediately during and after the contact.Data handled by Connect Customer · section 'Call recording and screen recording storage' · Checked 2026-10-01
- 18GDPR defines consent as a freely given, specific, informed and unambiguous indication of wishes given by a statement or clear affirmative action.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 4(11) · Checked 2026-10-01
- 19Under GDPR Article 7(3) a data subject may withdraw consent at any time, and withdrawal does not make processing carried out before the withdrawal unlawful.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 7(3) · Checked 2026-10-01
- 20Absent adequacy or appropriate safeguards, Article 49(1)(a) permits a transfer on the data subject's explicit consent after being told of the risks, but this derogation does not apply to public authorities exercising public powers.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 49(1)(a) and 49(3) · Checked 2026-10-01
- 21GDPR Article 35(1) requires a data protection impact assessment before processing likely to result in a high risk, and Article 35(4) requires supervisory authorities to publish lists of operations that need one.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 35(1) and 35(4) · Checked 2026-10-01
- 22Responses to data subject requests are free of charge, but for manifestly unfounded or excessive requests, particularly repetitive ones, the controller may charge a reasonable fee or refuse to act.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 12(5) · Checked 2026-10-01
- 23Where the controller has reasonable doubts about the requester's identity it may ask for additional information needed to confirm it.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 12(6) · Checked 2026-10-01
- 24GDPR Article 12(3) requires the controller to act on a data subject request under Articles 15 to 22 without undue delay and in any event within one month of receipt.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 12(3), first sentence · Checked 2026-10-01
- 25The one-month period may be extended by two further months where necessary, and the controller must tell the data subject of the extension and reasons within the first month.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 12(3), second and third sentences · Checked 2026-10-01
- 26The EDPB's final guidance on the right of access is Guidelines 01/2022, version 2.1, dated 17 April 2023 on the EDPB site.Guidelines 01/2022 on data subject rights - Right of access · landing page header (document type, date, version) · Checked 2026-10-01
- 27The EDPB adopted Opinion 22/2024 under Article 64 on obligations arising from reliance on processors and sub-processors, dated 9 October 2024 on the EDPB site.Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) · landing page header · Checked 2026-10-01
- 28The erasure right does not apply to the extent processing is necessary to comply with a Union or Member State legal obligation or for the establishment, exercise or defence of legal claims.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 17(3)(b) and (e) · Checked 2026-10-01
- 29GDPR Article 17(1) gives the data subject a right to erasure without undue delay on listed grounds, including that the data is no longer necessary, consent is withdrawn, or an objection succeeds.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 17(1)(a) to (c) · Checked 2026-10-01
- 30Infringements of the basic principles, lawful-basis and consent rules, data subject rights in Articles 12 to 22 and transfer rules carry administrative fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 83(5) · Checked 2026-10-01
- 31Genesys states its GDPR API cannot be used for bulk requests, cannot search file attachment contents, and cannot discover data not associated with External Contacts profiles.Genesys Cloud and GDPR compliance · caveats and configuration guidance sections · Checked 2026-10-01
- 32Genesys states it needs no longer than 14 days to remove or anonymise personal data on a GDPR forget-me request, and typically 1-2 days for access requests.Genesys Cloud and GDPR compliance · question 'How long will it take Genesys Cloud to respond to a GDPR data subject request?' · Checked 2026-10-01
- 33Genesys Cloud provides a GDPR API with a subjects endpoint for finding a person by identifiers such as name, phone or email, and a requests endpoint for export (access), update (rectification) and delete (erasure) requests.Genesys Cloud and GDPR compliance · question headings on the GDPR API · Checked 2026-10-01
- 34ICO guidance states that organisations must make a reasonable and proportionate search to answer a subject access request but need not run searches that are unreasonable or disproportionate.A guide to subject access · section on searching for information · Checked 2026-10-01
- 35Under ICO guidance for the UK GDPR, if the organisation asks the requester for clarification the one-month subject access time limit pauses and resumes the day after the clarification is received.A guide to subject access · section on time limits and clarification · Checked 2026-10-01
- 36GDPR Article 6(1) permits processing of personal data only where at least one of six lawful bases applies: consent, contract, legal obligation, vital interests, public task, or legitimate interests.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 6(1), points (a) to (f) · Checked 2026-10-01
- 37When personal data is collected from the data subject, as when a caller is recorded, GDPR Article 13(1) requires the controller to give the prescribed information at the time the data is obtained.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 13(1), lead-in · Checked 2026-10-01
- 38The Article 13 notice must state the controller's identity and contact details, the purposes and legal basis of processing, and the legitimate interests pursued where Article 6(1)(f) is relied on.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 13(1)(a), (c) and (d) · Checked 2026-10-01
- 39The Article 13 notice must name the recipients or categories of recipients and, where applicable, the intended transfer to a third country and the safeguards relied on.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 13(1)(e) and (f) · Checked 2026-10-01
- 40The Article 13 notice must state how long the data will be stored or, if that is not possible, the criteria used to determine that period.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 13(2)(a) · Checked 2026-10-01
- 41Where processing rests on legitimate interests or public task, GDPR Article 21(1) lets the data subject object, after which the controller must stop unless it shows compelling legitimate grounds or needs the data for legal claims.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 21(1) · Checked 2026-10-01
- 42GDPR Article 28(3) requires a binding contract under which the processor acts only on documented instructions, binds staff to confidentiality, secures the data, assists with data subject requests, deletes or returns data at the end, and allows audits.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 28(3)(a), (b), (c), (e), (g) and (h) · Checked 2026-10-01
- 43GDPR Article 28(1) requires a controller to use only processors that provide sufficient guarantees of appropriate technical and organisational measures.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 28(1) · Checked 2026-10-01
- 44The Commission's modernised standard contractual clauses were issued on 4 June 2021 by Implementing Decision 2021/914 and cover controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.Standard contractual clauses (SCC) · section on the modernised SCCs · Checked 2026-10-01
- 45Without an adequacy decision, GDPR Article 46(2)(c) allows transfers under standard data protection clauses adopted by the Commission, provided enforceable rights and effective remedies are available.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 46(1) and 46(2)(c) · Checked 2026-10-01
- 46GDPR Article 5(1)(e) requires personal data, including recordings, to be kept in identifiable form no longer than necessary for the purposes of processing.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 5(1)(e) · Checked 2026-10-01
- 48Under a general written authorisation the processor must inform the controller of intended additions or replacements of sub-processors, giving the controller the opportunity to object.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 28(2), second sentence · Checked 2026-10-01
- 49A processor must impose the same data protection obligations on its sub-processors by contract and remains fully liable to the controller for a sub-processor's failure.Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 28(4) · Checked 2026-10-01
- 50The Commission renewed the United Kingdom's GDPR adequacy decision by a decision dated 19 December 2025.Adequacy decisions · entry 'United Kingdom' · Checked 2026-10-01
- 51The Commission's adequacy finding for the United States covers only commercial organisations participating in the EU-US Data Privacy Framework, under a decision adopted on 10 July 2023.Adequacy decisions · list of adequacy decisions, entry 'United States' · Checked 2026-10-01
- 52Voice-biometric caller authentication such as Amazon Connect Voice ID, which builds a voiceprint to authenticate the caller, is likely to fall within Article 9 as biometric data processed to uniquely identify a person, and so needs an Article 9(2) exception.inferredData handled by Connect Customer · section 'Voiceprints and Voice ID audio recordings', read with GDPR Articles 4(14) and 9(1) · Checked 2026-10-01
- 53The Webex Contact Center retention article describes only age-based automatic purge, so per-caller erasure of an individual recording appears to need a separate mechanism that this packet did not verify.inferredManage Retention and Purge Recordings and Transcripts in Webex Contact Center · whole article (absence of per-request deletion) · Checked 2026-10-01
- 54In Webex Contact Center, existing organisations keep recordings indefinitely until an administrator configures a retention period.Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · section on default retention periods · Checked 2026-10-01
- 55In Webex Contact Center, the default retention period for call recordings and transcripts in new organisations is 1,095 days.Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · section on default retention periods · Checked 2026-10-01
- 56Webex Contact Center administrators can set one retention period, from 7 to 3,600 days, that applies to both call recordings and transcripts.Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · section on administrator configuration · Checked 2026-10-01
- 57Cisco warns that setting a Webex Contact Center retention period of 180 days or less may affect the performance and availability of certain AI-driven features.Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · note on retention and AI features · Checked 2026-10-01
Documents
A guide to subject access
Adequacy decisions
Guidelines 01/2022 on data subject rights - Right of access
L'écoute et l'enregistrement des appels sur le lieu de travail
Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU)
Standard contractual clauses (SCC)
Data handled by Connect Customer
Enable contact recording
Flow block in Connect Customer: Set recording and analytics behavior
General Data Protection Regulation (GDPR) Center
Genesys Cloud and GDPR compliance
Manage Retention and Purge Recordings and Transcripts in Webex Contact Center
Cite this page
APA
WarmTransfer. (2026, October 1). GDPR for contact centers and call recording. WarmTransfer. https://warmtransfer.net/knowledge/gdpr-contact-center
BibTeX
@misc{warmtransfer-gdpr-contact-center,
title = {GDPR for contact centers and call recording},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/gdpr-contact-center},
note = {Verified 2026-10-01}
}