security identity · published

GDPR for contact centers and call recording

Verified 2026-10-01 · 57 sources · tier 1–2

Also known as gdpr-call-recording.

GDPR Article 6(1) permits processing of personal data only where at least 1 of 6 lawful bases applies: consent, contract, legal obligation, vital interests, public task, or legitimate interests 36. For contact centers, call recordings and transcripts constitute personal data subject to these principles and the storage limitation mandate of Article 5(1)(e), which requires personal data to be kept in identifiable form no longer than necessary for the purposes of processing 46.

Lawful bases and caller notification

GDPR defines consent as a freely given, specific, informed, and unambiguous indication of wishes given by a statement or clear affirmative action 18. Under GDPR Article 7(3), a data subject may withdraw consent at any time, though withdrawal does not make processing carried out before the withdrawal unlawful 19. Where processing rests instead on legitimate interests or public task, GDPR Article 21(1) lets the data subject object, after which the controller must stop processing unless it shows compelling legitimate grounds or needs the data for legal claims 41.

When personal data is collected directly from the data subject, such as when a caller is recorded, GDPR Article 13(1) requires the controller to give prescribed information at the time the data is obtained 37. This notice must include specific details:

  • The controller's identity and contact details, the purposes and legal basis of processing, and the legitimate interests pursued where Article 6(1)(f) is relied on 38.
  • The recipients or categories of recipients and, where applicable, the intended transfer to a third country and the safeguards relied on 39.
  • The period for which the data will be stored or, if that is not possible, the criteria used to determine that period 40.

Where personal data is not obtained directly from the data subject, GDPR Article 14(3)(a) requires notice within a reasonable period and at the latest within 1 month of obtaining it 4.

At the national supervisory authority level in France, the CNIL's guidance page on listening to and recording workplace calls is dated 5 May 2009 and carries a CNIL banner stating the page is obsolete and being updated 12. The CNIL page states that employers may not set up permanent or systematic call listening or recording except where the law requires it 11. The CNIL page also states that callers must be told orally at the start of the conversation that the system exists, its purpose, and that they can object 10, and that call recordings may be kept for at most 6 months 13.

Data subject rights handling

GDPR Article 15 gives data subjects a right to confirmation of processing, access to their personal data and supplementary information, and a copy of the personal data undergoing processing 1. The EDPB's final guidance on the right of access is Guidelines 01/2022, version 2.1, dated 17 April 2023 on the EDPB site 26. Article 15(4) provides that the right to obtain a copy must not adversely affect the rights and freedoms of others 2.

GDPR Article 17(1) gives the data subject a right to erasure without undue delay on listed grounds, including where the data is no longer necessary, consent is withdrawn, or an objection succeeds 29. The erasure right does not apply to the extent processing is necessary to comply with a Union or Member State legal obligation or for the establishment, exercise, or defence of legal claims 28.

GDPR Article 12 establishes statutory timelines and procedural rules for data subject requests:

  • Article 12(3) requires the controller to act on requests under Articles 15 to 22 without undue delay and in any event within 1 month of receipt 24.
  • The 1-month period may be extended by 2 further months where necessary, provided the controller tells the data subject of the extension and reasons within the first month 25.
  • Responses are free of charge, but for manifestly unfounded or excessive requests, particularly repetitive ones, the controller may charge a reasonable fee or refuse to act 22.
  • Where the controller has reasonable doubts about the requester's identity, it may ask for additional information needed to confirm it 23.

Under ICO guidance for the UK GDPR, if the organisation asks the requester for clarification, the 1-month subject access time limit pauses and resumes the day after the clarification is received 35. ICO guidance also states that organisations must make a reasonable and proportionate search to answer a subject access request but need not run searches that are unreasonable or disproportionate 34.

Biometrics and impact assessments

GDPR defines biometric data as personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics that allow or confirm unique identification of a natural person 8. Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a natural person unless an Article 9(2) exception, such as explicit consent, applies 9.

GDPR Article 35(1) requires a data protection impact assessment (DPIA) before processing likely to result in a high risk, and Article 35(4) requires supervisory authorities to publish lists of operations that need one 21.

Infringements of basic principles, lawful-basis and consent rules, data subject rights under Articles 12 to 22, and transfer rules carry administrative fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher 30.

Processors, sub-processors, and international transfers

Under GDPR Article 28(1), controllers must use only processors that provide sufficient guarantees of appropriate technical and organisational measures 43. Article 28(3) requires a binding contract under which the processor acts only on documented instructions, binds staff to confidentiality, secures data, assists with data subject requests, deletes or returns data at the end of services, and allows audits 42. The EDPB adopted Opinion 22/2024 under Article 64 on obligations arising from reliance on processors and sub-processors, dated 9 October 2024 on the EDPB site 27.

A processor such as a CCaaS provider may not engage a sub-processor without the controller's prior specific or general written authorisation 47. Under general written authorisation, the processor must inform the controller of intended additions or replacements, giving the controller an opportunity to object 48. A processor must impose the same data protection obligations on its sub-processors by contract and remains fully liable to the controller for a sub-processor's failure 49.

International data transfers outside the EEA must rely on valid transfer mechanisms:

  • A transfer covered by a Commission adequacy decision requires no specific authorisation 3. The Commission renewed the United Kingdom's GDPR adequacy decision by a decision dated 19 December 2025 50. The Commission's adequacy finding for the United States covers only commercial organisations participating in the EU-US Data Privacy Framework, under a decision adopted on 10 July 2023 51.
  • Without an adequacy decision, Article 46(2)(c) allows transfers under standard data protection clauses adopted by the Commission, provided enforceable rights and effective remedies are available 45. The Commission's modernised standard contractual clauses were issued on 4 June 2021 by Implementing Decision 2021/914 and cover controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers 44.
  • Absent adequacy or appropriate safeguards, Article 49(1)(a) permits a transfer on the data subject's explicit consent after being informed of the risks, though this derogation does not apply to public authorities exercising public powers 20.

AWS states that its Service Terms include the June 2021 Commission SCCs and that its DPA applies them automatically when customer data is transferred outside the EEA 5. AWS also states it may use 3 types of sub-processors: AWS entities providing underlying infrastructure, AWS entities supporting specific services, and contracted third parties for specific services, depending on region and services used 6.

Platform recording architectures and controls

In Webex Contact Center, the default retention period for call recordings and transcripts in new organisations is 1,095 days 55. Existing organisations retain recordings indefinitely until an administrator configures a retention period 54. Webex Contact Center administrators can set 1 retention period, from 7 to 3,600 days, that applies to both call recordings and transcripts 56. Cisco warns that setting a Webex Contact Center retention period of 180 days or less may affect the performance and availability of certain AI-driven features 57.

In Amazon Connect, voice recording is enabled per contact by placing a Set recording and analytics behavior block in the flow, which can record agent and customer, agent only, or customer only 16. Amazon Connect delivers call and screen recordings to the customer's own Amazon S3 bucket, encrypted with the KMS key configured at instance creation, after holding them intermediately during and after the contact 17. When a customer is on hold the agent is still recorded, and the conversation between agents during a transfer is recorded 14. AWS recommends placing the recording block in an inbound or outbound whisper flow, because in a queue flow it may run after the agent joins and the call may not be recorded as intended 15.

Genesys Cloud provides a GDPR API with a subjects endpoint for finding a person by identifiers such as name, phone or email, and a requests endpoint for export (access), update (rectification) and delete (erasure) requests 33. Genesys states it needs no longer than 14 days to remove or anonymise personal data on a GDPR forget-me request, and typically 1-2 days for access requests 32. Genesys states its GDPR API cannot be used for bulk requests, cannot search file attachment contents, and cannot discover data not associated with External Contacts profiles 31.

See also

See also Recording consent and AI processing privacy. See also Webex Contact Center recording and contact data retention. See also CDR privacy redaction and evidence-safe reporting.

Applicability

Applies to: Cisco Webex Contact Center, Amazon Web Services Amazon Connect, Amazon Web Services, and Genesys Cloud. Deployments: on-premises and multi-tenant. Sources checked 2026-10-01. The evidence covers the EU/EEA region under GDPR 36, the UK under UK GDPR 35, and France under CNIL guidance 12.

What remains uncertain

  • The Latombe v Commission judgment and appeal outcome are not covered by the sources below.
  • Member State call-recording and interception laws are not covered by the sources below.
  • The application of GDPR purpose limitation and DPIA requirements to AI transcription and speech analytics on recordings is not covered by the sources below.
  • Cisco Webex Contact Center privacy data sheet sub-processors and transfer mechanisms are not covered by the sources below.
  • Webex Contact Center per-recording deletion for erasure requests is not covered by the sources below.
  • ePrivacy Directive consolidated text on interception and business-practice recording is not covered by the sources below.
  • EDPB Guidelines 01/2022 content on audio recordings and redaction of third-party voices is not covered by the sources below.
  • Genesys Cloud GDPR export vs delete scope for call recordings is not covered by the sources below.

See also

Related to

Referenced by

Sources

  1. 1
    GDPR Article 15 gives the data subject a right to confirmation of processing, access to their personal data and supplementary information, and a copy of the personal data undergoing processing.
  2. 2
    GDPR Article 15(4) provides that the right to obtain a copy must not adversely affect the rights and freedoms of others.
  3. 3
    A transfer to a third country covered by a Commission adequacy decision does not require any specific authorisation.
  4. 4
    Where personal data is not obtained from the data subject, GDPR Article 14(3)(a) requires notice within a reasonable period and at the latest within one month of obtaining it.
  5. 5
    AWS states that its Service Terms include the June 2021 Commission SCCs and that its DPA applies them automatically when customer data is transferred outside the EEA.
    General Data Protection Regulation (GDPR) Center · section on the AWS GDPR DPA and SCCs · Checked 2026-10-01
  6. 6
    AWS states it may use three types of sub-processors: AWS entities providing the underlying infrastructure, AWS entities supporting specific services, and contracted third parties for specific services, depending on region and services used.
    General Data Protection Regulation (GDPR) Center · section on sub-processors · Checked 2026-10-01
  7. 7
    Because consent is withdrawable at any time and must be demonstrable, while legitimate interests is subject to a right to object, a contact center choosing a lawful basis for call recording is choosing which caller opt-out mechanism it must operate, not whether one exists.inferred
    Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Articles 6(1), 7(1), 7(3) and 21(1) read together · Checked 2026-10-01
  8. 8
    GDPR defines biometric data as personal data from specific technical processing of physical, physiological or behavioural characteristics that allow or confirm unique identification of a person.
  9. 9
    GDPR Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a natural person unless an Article 9(2) exception, such as explicit consent, applies.
  10. 10
    The CNIL page states that callers must be told orally at the start of the conversation that the system exists, its purpose, and that they can object.
    L'écoute et l'enregistrement des appels sur le lieu de travail · section 'L'information des personnes' · Checked 2026-10-01
  11. 11
    The CNIL page states that employers may not set up permanent or systematic call listening or recording except where the law requires it.
    L'écoute et l'enregistrement des appels sur le lieu de travail · section 'Quelles limites à ces dispositifs ?' · Checked 2026-10-01
  12. 12
    The CNIL's guidance page on listening to and recording workplace calls is dated 5 May 2009 and carries a CNIL banner stating the page is obsolete and being updated.
    L'écoute et l'enregistrement des appels sur le lieu de travail · page header and status banner · Checked 2026-10-01
  13. 13
    The CNIL page states that call recordings may be kept for at most six months.
    L'écoute et l'enregistrement des appels sur le lieu de travail · section 'Quelles garanties pour la vie privée ?' · Checked 2026-10-01
  14. 14
    In Amazon Connect, when a customer is on hold the agent is still recorded, and the conversation between agents during a transfer is recorded.
    Data handled by Connect Customer · section 'Call recordings and screen recordings', bullet list · Checked 2026-10-01
  15. 15
    AWS recommends placing the recording block in an inbound or outbound whisper flow, because in a queue flow it may run after the agent joins and the call may not be recorded as intended.
    Flow block in Connect Customer: Set recording and analytics behavior · section 'Flow types', Tip · Checked 2026-10-01
  16. 16
    In Amazon Connect, voice recording is enabled per contact by placing a Set recording and analytics behavior block in the flow, which can record agent and customer, agent only, or customer only.
    Enable contact recording · 'To set up recording of conversations', steps 4-5 · Checked 2026-10-01
  17. 17
    Amazon Connect delivers call and screen recordings to the customer's own Amazon S3 bucket, encrypted with the KMS key configured at instance creation, after holding them intermediately during and after the contact.
    Data handled by Connect Customer · section 'Call recording and screen recording storage' · Checked 2026-10-01
  18. 21
    GDPR Article 35(1) requires a data protection impact assessment before processing likely to result in a high risk, and Article 35(4) requires supervisory authorities to publish lists of operations that need one.
  19. 22
    Responses to data subject requests are free of charge, but for manifestly unfounded or excessive requests, particularly repetitive ones, the controller may charge a reasonable fee or refuse to act.
  20. 23
    Where the controller has reasonable doubts about the requester's identity it may ask for additional information needed to confirm it.
  21. 24
    GDPR Article 12(3) requires the controller to act on a data subject request under Articles 15 to 22 without undue delay and in any event within one month of receipt.
  22. 25
    The one-month period may be extended by two further months where necessary, and the controller must tell the data subject of the extension and reasons within the first month.
    Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 12(3), second and third sentences · Checked 2026-10-01
  23. 26
    The EDPB's final guidance on the right of access is Guidelines 01/2022, version 2.1, dated 17 April 2023 on the EDPB site.
    Guidelines 01/2022 on data subject rights - Right of access · landing page header (document type, date, version) · Checked 2026-10-01
  24. 27
    The EDPB adopted Opinion 22/2024 under Article 64 on obligations arising from reliance on processors and sub-processors, dated 9 October 2024 on the EDPB site.
  25. 28
    The erasure right does not apply to the extent processing is necessary to comply with a Union or Member State legal obligation or for the establishment, exercise or defence of legal claims.
  26. 29
    GDPR Article 17(1) gives the data subject a right to erasure without undue delay on listed grounds, including that the data is no longer necessary, consent is withdrawn, or an objection succeeds.
  27. 30
    Infringements of the basic principles, lawful-basis and consent rules, data subject rights in Articles 12 to 22 and transfer rules carry administrative fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.
  28. 31
    Genesys states its GDPR API cannot be used for bulk requests, cannot search file attachment contents, and cannot discover data not associated with External Contacts profiles.
    Genesys Cloud and GDPR compliance · caveats and configuration guidance sections · Checked 2026-10-01
  29. 32
    Genesys states it needs no longer than 14 days to remove or anonymise personal data on a GDPR forget-me request, and typically 1-2 days for access requests.
    Genesys Cloud and GDPR compliance · question 'How long will it take Genesys Cloud to respond to a GDPR data subject request?' · Checked 2026-10-01
  30. 33
    Genesys Cloud provides a GDPR API with a subjects endpoint for finding a person by identifiers such as name, phone or email, and a requests endpoint for export (access), update (rectification) and delete (erasure) requests.
    Genesys Cloud and GDPR compliance · question headings on the GDPR API · Checked 2026-10-01
  31. 35
    Under ICO guidance for the UK GDPR, if the organisation asks the requester for clarification the one-month subject access time limit pauses and resumes the day after the clarification is received.
    A guide to subject access · section on time limits and clarification · Checked 2026-10-01
  32. 36
    GDPR Article 6(1) permits processing of personal data only where at least one of six lawful bases applies: consent, contract, legal obligation, vital interests, public task, or legitimate interests.
  33. 37
    When personal data is collected from the data subject, as when a caller is recorded, GDPR Article 13(1) requires the controller to give the prescribed information at the time the data is obtained.
  34. 38
    The Article 13 notice must state the controller's identity and contact details, the purposes and legal basis of processing, and the legitimate interests pursued where Article 6(1)(f) is relied on.
  35. 39
    The Article 13 notice must name the recipients or categories of recipients and, where applicable, the intended transfer to a third country and the safeguards relied on.
  36. 40
    The Article 13 notice must state how long the data will be stored or, if that is not possible, the criteria used to determine that period.
  37. 41
    Where processing rests on legitimate interests or public task, GDPR Article 21(1) lets the data subject object, after which the controller must stop unless it shows compelling legitimate grounds or needs the data for legal claims.
  38. 42
    GDPR Article 28(3) requires a binding contract under which the processor acts only on documented instructions, binds staff to confidentiality, secures the data, assists with data subject requests, deletes or returns data at the end, and allows audits.
    Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU) · Article 28(3)(a), (b), (c), (e), (g) and (h) · Checked 2026-10-01
  39. 43
    GDPR Article 28(1) requires a controller to use only processors that provide sufficient guarantees of appropriate technical and organisational measures.
  40. 44
    The Commission's modernised standard contractual clauses were issued on 4 June 2021 by Implementing Decision 2021/914 and cover controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.
    Standard contractual clauses (SCC) · section on the modernised SCCs · Checked 2026-10-01
  41. 45
    Without an adequacy decision, GDPR Article 46(2)(c) allows transfers under standard data protection clauses adopted by the Commission, provided enforceable rights and effective remedies are available.
  42. 46
    GDPR Article 5(1)(e) requires personal data, including recordings, to be kept in identifiable form no longer than necessary for the purposes of processing.
  43. 47
    A processor such as a CCaaS provider may not engage a sub-processor without the controller's prior specific or general written authorisation.
  44. 48
    Under a general written authorisation the processor must inform the controller of intended additions or replacements of sub-processors, giving the controller the opportunity to object.
  45. 49
    A processor must impose the same data protection obligations on its sub-processors by contract and remains fully liable to the controller for a sub-processor's failure.
  46. 50
    The Commission renewed the United Kingdom's GDPR adequacy decision by a decision dated 19 December 2025.
    Adequacy decisions · entry 'United Kingdom' · Checked 2026-10-01
  47. 51
    The Commission's adequacy finding for the United States covers only commercial organisations participating in the EU-US Data Privacy Framework, under a decision adopted on 10 July 2023.
    Adequacy decisions · list of adequacy decisions, entry 'United States' · Checked 2026-10-01
  48. 52
    Voice-biometric caller authentication such as Amazon Connect Voice ID, which builds a voiceprint to authenticate the caller, is likely to fall within Article 9 as biometric data processed to uniquely identify a person, and so needs an Article 9(2) exception.inferred
    Data handled by Connect Customer · section 'Voiceprints and Voice ID audio recordings', read with GDPR Articles 4(14) and 9(1) · Checked 2026-10-01
  49. 53
    The Webex Contact Center retention article describes only age-based automatic purge, so per-caller erasure of an individual recording appears to need a separate mechanism that this packet did not verify.inferred
    Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · whole article (absence of per-request deletion) · Checked 2026-10-01
  50. 54
    In Webex Contact Center, existing organisations keep recordings indefinitely until an administrator configures a retention period.
    Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · section on default retention periods · Checked 2026-10-01
  51. 55
    In Webex Contact Center, the default retention period for call recordings and transcripts in new organisations is 1,095 days.
    Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · section on default retention periods · Checked 2026-10-01
  52. 56
    Webex Contact Center administrators can set one retention period, from 7 to 3,600 days, that applies to both call recordings and transcripts.
    Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · section on administrator configuration · Checked 2026-10-01
  53. 57
    Cisco warns that setting a Webex Contact Center retention period of 180 days or less may affect the performance and availability of certain AI-driven features.
    Manage Retention and Purge Recordings and Transcripts in Webex Contact Center · note on retention and AI features · Checked 2026-10-01

Documents

tier 1 standards and regulators

A guide to subject access

Information Commissioner's Office (UK) · 2026-07-16 · accessed 2026-10-01

tier 1 standards and regulators

Adequacy decisions

European Commission · accessed 2026-10-01

tier 1 standards and regulators

Guidelines 01/2022 on data subject rights - Right of access

European Data Protection Board · 2023-04-17 · accessed 2026-10-01

tier 1 standards and regulators

L'écoute et l'enregistrement des appels sur le lieu de travail

Commission nationale de l'informatique et des libertés (CNIL) · 2009-05-05 · accessed 2026-10-01

tier 1 standards and regulators

Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)

European Data Protection Board · 2024-10-09 · accessed 2026-10-01

tier 1 standards and regulators

Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU)

The National Archives (legislation.gov.uk) · 2016-05-04 · accessed 2026-10-01

tier 1 standards and regulators

Standard contractual clauses (SCC)

European Commission · accessed 2026-10-01

tier 2 current vendor documentation

Data handled by Connect Customer

Amazon Web Services · accessed 2026-10-01

tier 2 current vendor documentation

Enable contact recording

Amazon Web Services · accessed 2026-09-25

tier 2 current vendor documentation

Flow block in Connect Customer: Set recording and analytics behavior

Amazon Web Services · accessed 2026-10-01

tier 2 current vendor documentation

General Data Protection Regulation (GDPR) Center

Amazon Web Services · accessed 2026-10-01

tier 2 current vendor documentation

Genesys Cloud and GDPR compliance

Genesys · accessed 2026-10-01

tier 2 current vendor documentation

Manage Retention and Purge Recordings and Transcripts in Webex Contact Center

Cisco Systems, Inc. (Webex Help Center) · 2026-06-04 · accessed 2026-09-05

Cite this page

APA

WarmTransfer. (2026, October 1). GDPR for contact centers and call recording. WarmTransfer. https://warmtransfer.net/knowledge/gdpr-contact-center

BibTeX

@misc{warmtransfer-gdpr-contact-center,
  title  = {GDPR for contact centers and call recording},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/gdpr-contact-center},
  note   = {Verified 2026-10-01}
}