Every modern phone system ships with call recording one toggle away, which is exactly the problem: the toggle is easy and the obligations it switches on are not on the same screen. Recording business calls is entirely legal in the UK when done properly, genuinely useful (disputes, training, order accuracy), and quietly non-compliant in a large share of the businesses doing it, usually because someone enabled the feature years ago and nobody has thought about it since.
This page covers what UK law expects of a business recording its calls, how to configure a cloud phone system to meet those expectations, and the sector add-ons that apply if you are regulated. One framing note before the detail: we configure the technology and the controls; the judgement calls about your specific legal position belong with your legal adviser, and the good news is that the compliant setup is mostly configuration, done once.
The legal frame, in plain terms
Two regimes matter for ordinary businesses:
- The lawful business practice rules (the regulations sitting under UK interception law) permit businesses to record their own calls without individual consent for defined purposes: evidencing transactions, compliance, quality and training, preventing crime among them. This is why “calls may be recorded” is lawful at all; the purposes are broad but not unlimited, and recording must be for your stated purpose, not general surveillance.
- UK GDPR treats a recorded call as personal data, which is where most of the practical obligations live. You need a lawful basis (for routine business recording this is usually legitimate interests, documented, rather than consent, which is hard to manage on a phone line); you must tell people (the announcement, plus your privacy notice); you must keep recordings only as long as the purpose justifies (a defined retention period, not forever-by-default); you must secure them (access-controlled, not an open shared folder of customer conversations); and callers hold their usual data rights, including asking for a copy of their own call.
The pattern to notice: none of this forbids recording. All of it forbids *casual* recording, which is precisely what the default toggle produces.
The five configuration decisions
Translating the law into phone-system settings, this is the whole project:
- Purpose and scope, written down. Which calls, why, and who may listen. Recording every call because the system can is the posture that fails; recording defined lines for defined purposes is the posture that passes. A one-page policy covers it.
- The announcement. The up-front message (“calls may be recorded for training and quality purposes”) on inbound, and equivalent awareness for outbound and internal calls where recorded. Modern systems attach announcements per queue and per line, so customer lines can carry it while internal lines skip recording entirely.
- Retention with an end date. Match the period to the purpose: order-dispute evidence might justify months; training snippets far less. Configure automatic deletion at the boundary; a retention policy the system enforces beats one a human is supposed to remember. This is the same retention discipline the rest of your data estate needs, applied to audio.
- Access control and audit. Recordings behind role-based access with logging of who listened, not a shared drive. Recordings are exactly the data class a breach notification letter is written about.
- The payment-card pause. If callers read out card numbers, PCI DSS rules effectively prohibit storing the security code in recordings: use pause-resume (automatic with compliant payment flows, or agent-triggered) so card details never land in the audio. Businesses taking phone payments without this are non-compliant in the most findable way.
An honest audit question for any business that has had recording on for years: could you state your retention period, name who can access recordings, and produce a specific call if a customer requested it? If any answer is a shrug, the toggle got ahead of the obligations, and a half-day of configuration closes the gap.
Regulated sectors: the stricter overlay
Two overlays matter locally:
- FCA-regulated activity. Firms within scope of the FCA’s recording rules (broadly, those involved in relevant financial trading and advice activity) face mandatory recording of in-scope communications, longer retention, and the duty to retrieve on demand, extending to mobiles and messaging apps used for business. If this is you, recording is not optional and the configuration standard rises accordingly; it is part of the compliance stack covered in our financial services sector page.
- Legal and professional privilege contexts. Law firms and practices handling privileged or clinically sensitive conversations need the scope decision made carefully: some calls are better deliberately not recorded, and the policy should say which.
Frequently asked questions
Is it legal to record business calls in the UK?
Yes, for legitimate business purposes, without needing each caller’s consent, provided the GDPR obligations are met: a documented lawful basis, informing callers, defined retention, and secured storage. The legality is settled; the compliance work is in the configuration.
Do we have to tell callers they’re being recorded?
Yes, transparency is required: the standard announcement on recorded lines plus coverage in your privacy notice. What you do not generally need is per-call consent, which is why the announcement wording says “may be recorded” rather than asking permission.
How long can we keep call recordings?
As long as your stated purpose justifies and no longer, which you define and document: common practice runs weeks to months for quality purposes and longer where recordings are transaction evidence, with regulated firms following their mandated minimums. The wrong answer is indefinitely-because-storage-is-cheap.
Can a customer request a copy of their recorded call?
Yes, a recording of them is their personal data, subject to the usual subject-access process (with other parties’ data handled appropriately). This is the request that exposes unindexed recording estates; a system that can search by number and date makes it routine.
Can we record staff calls for monitoring?
Within the lawful purposes and with staff informed, yes, proportionately: quality and training monitoring on customer lines is standard practice, covert or blanket surveillance is a different legal animal entirely. Put it in the policy staff actually see, and take advice before anything beyond the routine.
What about taking card payments on recorded lines?
The security code must not end up stored in a recording: pause-resume or a compliant automated payment flow is the fix, and it should be configured before the first phone payment, not after an audit finds the archive.
Get the toggle and the obligations aligned
If your phone system records calls today, the free IT health check will audit the setup against this page: announcement coverage, retention actually configured, access control, the card-payment pause, and the one-page policy drafted for your adviser to bless. If you are choosing a new phone system, we configure recording compliantly from day one. Get in touch; it is a tidy afternoon’s work this side of a complaint.