Call recording data privacy: access, masking, retention
A call recording is full of the customer's name, phone number, sometimes a card number and health details, and the transcript and evaluation carry the same information. This article is a technical checklist, not legal advice: it covers the types of data in a recording, access rules, retention periods, why masking needs verification rather than promises, the deletion process and a seven-point list to complete before sending recordings to an analysis system, safe pilot transfers and transparency with agents.
Short answer
A call recording is full of personal data: the customer's name, phone number, address, sometimes a card number, health or financial circumstances. When recordings go into an analysis system, protecting them comes down to four questions: who can access which recording, how long it is kept, how you check that masking works if masking is used, and how and by whom a recording is deleted.
This article is a technical checklist, not legal advice. Requirements for recording calls, consent, retention periods and data transfer vary by country, sector and where the customer is. In Azerbaijan, personal data is governed by a dedicated law; check your specific obligations with a lawyer.
What data a call recording contains
- IdentifyingName, surname, phone, address, ID card number, date of birth.
- FinancialCard number, account number, debt amount, salary. Keeping card data in a call recording brings separate standards and risks.
- SensitiveHealth, illness, treatment, family situation — common on clinic, insurance and bank calls.
- The agent's dataThe agent's name, voice and performance are personal data too, and need protecting as well.
- Derived dataThe transcript, summary, evaluation and translation carry the same information as the audio file and must follow the same rules.
Access: who sees what
- Access to recordings and transcripts goes only to people who need it for their work — QA, team leads, specific managers
- Agents see the evaluations of their own calls, not other agents' calls — unless separately agreed for training
- Uploading and downloading recordings are separate permissions; a downloaded file leaves your control
- Access for an external contractor or a pilot is time-limited and closed when it ends
- Where possible, a record is kept of who looked at which recording
Retention period
Keeping recordings forever "just in case" is one of the most common risks. A purpose and a period should be written down for each type of data. The split below is an illustrative example:
- Audio fileAs long as needed for quality analysis and possible disputes. If a legal requirement demands longer, that is noted separately.
- Transcript and evaluationMay be kept longer than the audio for training and trend analysis — but still with a limit.
- Training examplesCall excerpts used in training material are cleaned of personal data as far as possible.
- Pilot dataDeleted within the agreed period after the pilot ends; the deletion is confirmed.
Masking: verify, don't promise
Masking (redaction) — hiding card numbers, phone numbers and other sensitive data in the transcript or the audio — is a useful tool, but not a full guarantee. AWS's documentation on sensitive data redaction also notes that automatic redaction may not find every instance, that the output should be reviewed, and that the original file remains the only complete record.
- What is maskedWhich data types are masked and which are not — a written list.
- Where it is maskedOnly in the transcript, or in the audio too? Where does the original audio file stay?
- How it is checkedA person regularly searches sample calls for unmasked sensitive data — especially where numbers are spoken as words.
- When it failsNumbers said in pieces, mixed languages, poor audio — where masking makes most mistakes.
The deletion process
- Who can delete, and whose approval deletion needs
- Deletion means removing the file itself, not just hiding it from a list — check this
- Are the transcript, translation, summary and evaluation deleted along with the audio file?
- What happens in backups, and when are they cleared?
- What steps are taken when a customer asks for their own data to be deleted?
Illustrative technical checklist
The list below is an illustrative example; write an answer to each point before sending recordings to an analysis system.
- Legal basisThe legal basis for recording and analysing calls, and the notice to customers, have been checked with a lawyer.
- Data locationWhere recordings and results are stored, in which country, and by whom.
- AccessRoles are written down, what each role sees is defined, time-limited access is closed.
- RetentionEach data type has a period and an owner.
- MaskingIf used, what it covers is written down and checked regularly; if not, that is openly known.
- DeletionThe deletion process has been tested: the file really is deleted.
- IncidentA plan exists for who does what if a recording reaches the wrong person.
Transferring recordings for a pilot
Most risk arises in the pilot stage: recordings are picked in a hurry, emailed and left on someone's laptop. Simple rules for a pilot:
- A minimal sampleAs many calls as the pilot needs — dozens, not hundreds. Calls on sensitive topics are left out where possible.
- A secure channelRecordings are transferred through a channel with restricted access, not personal email or an open link.
- A written agreementWhat the analysing party may do with the data, where it will be stored and when it must be deleted is written down.
- Confirmed deletionWhen the pilot ends, the audio files, transcripts and results are deleted, and this is confirmed in writing.
Transparency with agents
Agents take part in this process too, and their data is processed as well. Explaining in advance that calls are analysed with AI, what the results are used for and what they are not used for, and how to dispute an evaluation matters both ethically and practically. Analysis done quietly erodes trust and makes results harder to accept. It should also be said openly that an AI score will not be the sole basis for pay, discipline or dismissal.
Typical mistakes
- Sending pilot recordings by personal email or an open link
- Putting the customer's name and phone number in the file name
- Treating the transcript as less sensitive than the audio file
- Checking once that masking works and never looking again
- Forgetting recordings that look deleted but remain in a backup
Limits
- This list is not legal advice; consent, retention and transfer requirements must be checked with a lawyer for your country and sector
- No masking guarantees that it will find all sensitive data
- An analysis system does not automatically ensure compliance with any law; compliance comes from the company's processes
- The agent's voice and performance data are personal data that must be protected too
What Vexvon Audio Analyzer offers
- Call recordings and analysis results are stored separately per company
- When a call is deleted from the list, its audio file is deleted from storage too — the record is not merely hidden
- The file name is kept as the call's title and can be changed — so keeping personal data out of file names matters especially
- No automatic masking feature is offered; rules for sensitive data are set by your access and retention processes
More: Vexvon Audio Analyzer. Vexvon's general security approach is described on the security page, and recording fields in call recording metadata fields.
First step
Fill in the seven-point list above for your current call recordings and mark the points that have no answer. Those are the gaps to close before moving to an analysis system. This article belongs to the audio analysis implementation and reliability section. If you have questions, get in touch.
Further reading on this topic: financial services call quality monitoring, healthcare call center quality assurance.