First of all, recording business calls in the UK is lawful. It becomes lawful under three conditions, and most companies that get into difficulty have satisfied two of them.
- The recording serves a purpose the interception rules allow.
- Both audiences have been told: your own staff, and the person on the other end of the line.
- You hold a lawful basis under the UK GDPR, which is almost never consent.
The third one is where the trouble concentrates, so it is worth saying plainly at the outset: you do not need the caller’s permission to record a business call, and asking for it usually makes your position worse rather than better.
Condition one: a purpose the law allows
Section 3 of the Investigatory Powers Act 2016 makes it a criminal offence to intercept a communication in transmission without lawful authority. That catches business call recording, for a reason that is easy to miss. When your company records a conversation between an employee and a customer, the company is not a party to it. Both parties are on the line: the business is listening in on a system it controls.
Authorisation comes from the Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, made under section 46 of the Act. Most published guidance still cites the Telecommunications (Lawful Business Practice) Regulations 2000, which sat under the older RIPA framework. There is a quick diagnostic in that: if your call recording policy names the 2000 Regulations, it was either drafted before 2018 or copied from something that was.
Regulation 3 sets out the permitted purposes. The ones covering ordinary commercial practice are establishing the existence of facts, demonstrating the standards achieved by people using the system in the course of their duties, checking compliance with regulatory or self-regulatory procedures, preventing or detecting crime, investigating unauthorised use of the system, and securing its effective operation.
Quality monitoring, evidence of what was agreed, and sales coaching all fall inside that list. Recording because a manager is curious does not.
Regulation 4 adds three limits. The recording must be solely for communications relevant to the business, the system must be provided for that business, and the system controller must have made all reasonable efforts to inform every person who may use the system that communications may be intercepted.
Condition two: telling both audiences
That last requirement is the most misread sentence in UK call recording law. “Every person who may use the telecommunication system” means the people operating your phones. It is a duty owed to your workforce.
The duty owed to the customer comes from somewhere else entirely: Articles 13 and 14 of the UK GDPR, which require you to tell people whose personal data you process who you are, what you are doing, why, for how long and what rights they have.
Two obligations, two audiences, two documents. A privacy policy published on your website does not discharge the staff duty, and a line in an employment contract signed four years ago is unlikely to count as reasonable effort.
Neither law prescribes a method. There is no statutory beep tone in the UK and no mandated form of words. A spoken announcement before the call connects is the cleanest approach for callers, because it reaches people who have never visited your website and because it records itself into the file. A short standing notice, reissued when anything changes, covers the staff side.
Condition three: a lawful basis, and why it is not consent
Consent must be freely given to be valid. The Information Commissioner’s Office has been consistent that this rarely holds in an employment relationship, because an employee who fears the consequences of refusing has not freely agreed to anything.
The practical consequence is worse than the theoretical one. Consent can be withdrawn. Collect it from staff and any individual may revoke it, obliging you to switch recording off for that person while their colleagues remain recorded. Collect it from customers and you must honour a refusal, which leaves you either abandoning the recording or continuing unlawfully.
Legitimate interests under Article 6(1)(f) is the standard choice, supported by a written legitimate interests assessment. The assessment is twenty minutes of work: name the interest, show that recording is necessary to serve it, show the intrusion is proportionate. Keep it on file, because its absence is among the first things an investigation notices.
Firms regulated by the FCA sit differently. The taping rules in SYSC 10A require the recording of conversations relating to the reception, transmission and execution of client orders, which makes the basis legal obligation under Article 6(1)(c) and brings a five-year retention floor with it.
Two further data protection points apply regardless of basis. Calls capture special category data more often than people expect, and health information under Article 9 needs its own condition on top of the Article 6 basis. Where monitoring is systematic and covers a workforce, a Data Protection Impact Assessment is expected rather than optional.
Eleven situations and where each one stands
| Situation | Position |
|---|---|
| Recording your own sales and service calls | Permitted, with staff notice, caller notice and a lawful basis |
| Recording without a warning beep | Permitted. No UK statute requires a tone |
| Recording without the caller’s consent | Permitted, and usually correct. Consent is the wrong basis here |
| Recording staff calls without telling staff | Not permitted. Regulation 4 requires reasonable efforts to inform |
| Recording customers reading out card details | Permitted, but the security code must not be retained after authorisation |
| Keeping recordings indefinitely | Not permitted. The purpose must define the period |
| An employee covertly recording their manager | Not a criminal offence where it is for their own use. Tribunals have in some circumstances admitted such recordings |
| Covertly recording a disciplinary or grievance hearing as the employer | High risk and rarely defensible. Fairness obligations sit alongside data protection |
| Recording work calls on an employee’s personal mobile | Depends on who controls the system and what the BYOD policy says. Settle it in writing first |
| Sharing a recording with a third party | Only where consistent with the purpose you stated. Purpose limitation applies |
| Refusing a customer’s request for a copy of their own call | Not permitted. Subject access covers recordings, with third-party redaction as needed |
The wording
Three pieces of text do most of the work. Draft them once and the rest is configuration.
Announcement to callers
This call may be recorded for training and quality purposes. Details of how we use recordings are in our privacy policy at [URL].
For firms under FCA taping obligations, a reference to training understates the position:
This call will be recorded and retained, as required by financial services regulation. A copy is available on request for five years. Our privacy policy at [URL] explains how we use recordings.
Privacy notice paragraph
We record telephone calls to and from our team. We do this to establish the facts of what was agreed, to maintain and improve the quality of our service, and to train our staff. Our lawful basis is legitimate interests, and our assessment of those interests is available on request. Recordings are kept for [period] and are accessible only to [roles]. You may request a copy of a call you took part in, and you may object to our processing.
Staff notice
Calls made and received on company numbers are recorded. Recordings are used to establish the facts of customer conversations, to review and improve service quality, and for coaching. They are reviewed by [roles] and retained for [period]. They are not used for [state any excluded purpose, for example performance management, if that is your position]. Questions about this should go to [name].
The bracketed decisions are the substance rather than the formatting. None of this is legal advice, and the final versions should be read by whoever owns your privacy notice.
Retention
There is no general statutory period. Article 5(1)(e) of the UK GDPR requires only that personal data is not kept longer than necessary, which means the purpose sets the clock.
| Purpose | Reasonable period |
|---|---|
| Quality monitoring and coaching | 30 to 90 days |
| Evidence of what was agreed | The contract term, considered against the six-year limitation period for simple contracts in England and Wales |
| FCA client order conversations | Minimum five years under SYSC 10A, extendable to seven at the FCA’s request |
| Card security codes | Never retained after authorisation, under PCI DSS |
The usual failure is an archive that grows because nobody ever chose a number. Pick the period, write it into the notices above, and make deletion automatic rather than a recurring task somebody will eventually stop doing.
Call recording: the mistakes that cause trouble
Collecting consent you cannot honour. The most widespread error, and one that suppliers propagate through their own marketing copy.
One notice doing double duty. The staff duty and the customer duty are separate, and a website privacy policy addresses only one of them.
Recording card security codes. A recording that captures a customer reading the three digits from the back of their card is storage of that code. Pause recording during payment capture, or move card entry off the voice channel.
No legitimate interests assessment. Twenty minutes of work whose absence undermines every other step.
An unsearchable archive. A subject access request gives you one month to find and supply a specific call. Where recordings cannot be retrieved by date, number and user, that month goes quickly.
Putting it in place
Most of this is configuration and paperwork, done once. The part that determines whether it holds is where the decision lives.
With Onoff Business, recording is switched on from the administration console rather than handset by handset, so the policy is enforced by the system instead of depending on whether each employee remembered. Recordings appear in a single list where they can be played, downloaded or deleted, which is also what makes a subject access request answerable inside the month.
The caller announcement belongs in the call flow rather than in an agent’s memory. The IVR feature is useful and plays a message before the call connects, which puts the notice in front of first-time callers and timestamps it into the recording.
For retention, the Onoff Business API exposes call metadata and recording downloads, so a deletion schedule can run automatically rather than relying on someone clearing the list each quarter.
Turn every call into a business opportunity
For business purposes, yes, where the recording falls within the purposes in the Investigatory Powers (Interception by Businesses etc.) Regulations 2018, both your staff and your callers have been informed, and you hold a lawful basis under the UK GDPR.
No, and consent is usually the wrong basis. Legitimate interests is the standard choice for UK businesses, supported by a written assessment.
Yes, under UK GDPR transparency requirements. No particular method is prescribed. An announcement before the call connects, supported by a privacy notice, is standard.
No. No UK statute requires a warning tone. The duty is to inform, which a spoken announcement or a written notice satisfies.
As long as the stated purpose requires. Coaching typically justifies weeks, evidence of agreement justifies longer, and FCA-regulated client order calls must be kept for at least five years.
Yes. Recordings are personal data and subject access applies, normally within one month. Third-party information in the same file may need redacting first.



