Recording calls is normal, useful and entirely legal for a UK business. What trips people up is not whether they may record — it is what they have to say first, how long they may keep it, and what happens when a caller asks for a copy.
This is a practical summary, not legal adviceRecording touches data protection law, and the details depend on your sector and what you do with the recordings. Treat this as the list of questions to take to your own adviser, not as a substitute for one.
You may record. You may not do it silently
A business recording its own calls is lawful in the UK. The obligation is transparency: people on the call need to know it is happening, why, and broadly what you will do with the recording.
The familiar “this call may be recorded” announcement exists to satisfy that. What matters is that it is genuinely heard before anything is recorded — an announcement that plays after the greeting, or that a caller can skip past into a queue, is doing less than people assume.
Say why, not just that
“Calls are recorded” on its own is thin. “Calls are recorded for training and to confirm order details” tells the caller the purpose, which is the part that actually matters.
Pick the real reasons and keep them short. If you later use recordings for something outside that list, the original notice no longer covers it.
Outbound calls need it too
This is the most common gap. Businesses put an announcement on the inbound IVR and forget that outbound calls carry the same obligation — and outbound has no IVR to carry it.
The answer is a scripted line the agent says at the start, or an automatic announcement injected on outbound calls. Whichever you choose, it has to actually happen on every call, not just when the agent remembers.
Keep it only as long as you need it
There is no single legal retention period; the principle is that you keep recordings only as long as the stated purpose requires, then delete them. Sectors with their own rules — financial services in particular — have longer specified periods that override the general principle.
The practical failure is having no policy at all: recordings accumulate indefinitely because deleting them was never anybody's job. Decide a period, configure it, and let the system enforce it rather than relying on someone remembering.
Someone will ask for their recording
A caller can request a copy of a recording of themselves. Two things make that answerable rather than alarming:
- You can find it. Recordings need to be searchable by number and time, not sitting in a folder of timestamped filenames nobody can query.
- You can supply just theirs. If a recording contains other people's personal data, that has to be handled before the copy goes out.
Store it properly
Recordings are personal data, and often sensitive: card details, health information, complaints. They deserve the same handling as any other sensitive store.
- Encrypted at rest, not sitting readable on a PBX with a default password
- Access restricted to people who need it, and logged
- Backed up, and the backups covered by the same retention rule
- Actually deleted when the period expires, backups included
Pause it when you take a card
If you take card payments over the phone, recording through the card number is a problem you do not need. Pause-and-resume — automatic on the payment step, or a button the agent presses — keeps the card data out of the recording entirely.
Automatic is better than manual for the same reason as the outbound announcement: it does not depend on anyone remembering under pressure.
A short checklist
- Announcement plays before recording starts, on inbound and outbound
- It states the purpose, not just the fact
- A retention period is decided and configured
- Recordings are searchable by number and time
- Storage is encrypted and access is restricted and logged
- Recording pauses around card payments
- Someone owns this, and it is written down
Every call recorded, stored where you can reach it, on the managed plan.
See pricing


