International Call Recording Compliance

Compliance -- Last reviewed 2026-08-22 recording compliance legal gdpr privacy Found this useful? Upvote it. ×

International Call Recording Compliance

Most call recording mistakes happen before anyone opens the legal handbook. The PBXPrivate Branch Exchange, a private telephone switch. Asterisk is a software PBX that routes calls between internal extensions and the outside world. starts writing audio, the files land in a shared folder, and only later does someone ask what the caller was told, why the call was recorded, how long the file should live, or whether the caller had a real choice.

This page is meant to prevent that problem. It is a practical compliance reference for Asterisk systems that use MixMonitor(), AMIAsterisk Manager Interface. A TCP socket API for monitoring events and issuing actions in Asterisk, commonly used by click-to-dial integrations and dashboards. recording actions, or any external recorder attached to SIPSession Initiation Protocol, the standard signaling protocol used to set up, manage, and tear down VoIP calls between Asterisk and phones or carriers./RTPReal-time Transport Protocol. Carries the actual audio (media) of a VoIP call after SIP signaling has set it up. media.

It is also the international companion to Call Recording Consent Laws by State.

Last reviewed: August 1, 2026

Not legal advice

This is a technical compliance reference for PBX administrators, not legal advice. Recording law changes by country, state, province, industry, call purpose, and participant location. Use this as an engineering checklist, then confirm the policy with counsel before recording production calls.

The safe engineering default

If your callers may be outside the United States, do not build the dialplanThe core call-routing configuration of Asterisk, written mostly in extensions.conf as contexts, extensions, and priorities that decide how every call is handled. Full definition → around one global consent rule. Build it around a documented recording purpose and a conservative routing decision.

A good default looks like this:

The notice matters. "This call may be recorded" is usually too thin by itself. A better notice says something like, "This call may be recorded for support quality and dispute resolution." That gives the caller a real explanation, and it gives the business a purpose that can drive retention and access control.

The policy engine should produce one of four explicit outcomes:

  1. Recording is allowed after notice under a documented non-consent basis.
  2. Recording is allowed only after affirmative consent.
  3. Recording may rely on implied consent under a specifically reviewed jurisdiction and call flow.
  4. Recording is required by law or regulation, with the required notice or documented exception.

These outcomes are not interchangeable. Continued participation may support implied consent under some laws, including Canadian privacy guidance, but it is not a dependable substitute for affirmative GDPR consent.

Quick jurisdiction map

Jurisdiction What matters most What the PBX should do
European Union GDPR governs the processing of the recording and metadata. National laws may also control the act of recording communications. Choose and document a lawful basis, give a clear notice, minimize recording, retain by purpose, and support data subject rights.
United Kingdom UK GDPR, the Data Protection Act 2018, the Investigatory Powers Act 2016, the 2018 business monitoring regulations, PECR, and amendments made by the Data (Use and Access) Act 2025 may apply. Use clear notices, record only for an authorized purpose, keep purpose and retention records, publish privacy information, and handle access and complaint workflows.
Canada Criminal Code section 184 and privacy-law consent are separate questions. PIPEDA expects meaningful notice, purpose, and consent for customer call recording. Do not rely only on one-party criminal consent. Announce the recording and purpose, capture implied or express consent, and offer another channelA single call leg passing through Asterisk. Channels represent connections to endpoints and are what dialplan applications act on. when needed.
Quebec Quebec Law 25 adds stronger transparency, governance, retention, destruction, anonymization, and cross-border assessment expectations. Store purpose and retention metadata. Review hosted recording storage outside Quebec before sending recordings there.
Australia The federal Telecommunications (Interception and Access) Act 1979, the Privacy Act where it applies, and all eight state or territory surveillance-device regimes may matter. For a national service, announce recording and obtain affirmative consent unless counsel has approved a narrower call flow. Do not assume the federal Privacy Act applies to every organization.
Cross-border calls Caller, agent, controller, processor, and recording storage may be in different places. Interception, privacy, transfer, and localization rules are separate questions. Use a conservative fallback when location is uncertain, but have counsel determine legal scope. Keep jurisdiction signals, storage-region, processor, and transfer-mechanism metadata.

Additional country matrix

The following matrix extends the detailed sections below. It is a triage tool, not a substitute for country-specific advice. The PBX action is intentionally conservative.

Jurisdiction Principal issue Conservative PBX action
Germany Criminal Code section 201 protects the confidentiality of privately spoken words in addition to GDPR. Obtain affirmative agreement from all participants unless a specific statutory or regulatory basis has been approved.
France Penal Code article 226-1 restricts recording private or confidential words without consent. GDPR governs later processing. Give conspicuous notice and capture affirmative agreement before ordinary business recording.
Switzerland The Swiss data protection authority explains that participant recording normally requires permission from the other participants under Criminal Code articles 179bis and 179ter, subject to narrow exceptions. Treat as an all-participant-consent jurisdiction unless the exact business exception has been reviewed.
Brazil The LGPD governs purpose, legal basis, transparency, rights, security, retention, processors, and international transfers. Other privacy and communications rules can also apply to making the recording. Announce recording and purpose, document the LGPD basis, minimize retention, and record the approved international-transfer mechanism.
New Zealand The Privacy Act 2020 governs organizational collection, notice, use, access, retention, security, and overseas disclosure. Participant-recording rules do not remove those organizational duties. Notify at collection, state the purpose, provide access handling, and document overseas disclosures and vendors.
Singapore The PDPA generally imposes notification, purpose, consent or exception, protection, retention, access, and transfer-limitation obligations. Do Not Call rules separately affect marketing calls. Announce the purpose, document the applicable consent or exception, check marketing permissions, and review overseas storage protections.
Japan The APPI governs specified purposes, notice or publication, security, third-party provision, access, and cross-border transfers of personal information. Publish or deliver the recording purpose, restrict secondary use, and document vendors and cross-border disclosures.
South Africa POPIA governs lawful processing, notification, security, operator relationships, data-subject rights, direct marketing, and trans-border flows. Give notice, document the processing condition, execute operator controls, and validate section 72 transfer requirements.
Mexico The private-sector data protection framework requires a privacy notice, purpose and consent analysis, ARCO-rights handling, security, retention, and transfer controls. Provide a compliant privacy notice, record the purpose and consent basis, and document domestic and international recipients.
United Arab Emirates Federal data-protection, cybercrime, telecommunications, free-zone, and sector rules can overlap, and private recording can create criminal risk. Do not record silently. Require explicit local legal approval, affirmative participant consent where applicable, and an approved storage region.

For EU member states not listed separately, GDPR is only the processing layer. National criminal, employment, telecommunications, and evidence laws may independently determine whether the conversation can be recorded.

European Union: GDPR

In the EU, a call recording is usually personal data. The GDPR, Regulation (EU) 2016/679, controls the processing of the recording, but it does not answer every recording question, because member-state communications laws may still control whether the call may be recorded in the first place. The GDPR answers what happens once you collect, store, use, disclose, search, export, or delete the recording and its metadata.

That distinction is important for Asterisk administrators. A dialplanThe core call-routing configuration of Asterisk, written mostly in extensions.conf as contexts, extensions, and priorities that decide how every call is handled. Full definition → can satisfy a business workflow and still create a privacy problem if it records more than needed, keeps files too long, or cannot find a caller's recording when they make a request.

Under GDPR Article 6, the controller needs a lawful basis. Common candidates are:

Consent is not the easy button. It must be freely given, specific, informed, and unambiguous. Silence, inactivity, or merely staying on the line is not a reliable affirmative action under GDPR. If the caller cannot realistically refuse, consent may be the wrong lawful basis. In that case, document the actual basis and still tell the caller what is happening.

Where large-scale recording combines systematic monitoring, sensitive information, vulnerable callers, profiling, or new analytics, assess whether GDPR Article 35 requires a data protection impact assessment. Consult the supervisory authority's published DPIA list for the controller's member state.

What the announcement should say

The short audio prompt should cover the immediate facts and point to fuller privacy information. For a GDPR-style notice, include:

Example:

Calls to ExampleCo support may be recorded for support quality and dispute resolution. The recording is kept for 90 days unless needed for an active case. To continue without recording, press 2 or visit example.com/privacy for other contact options.

Retention and sensitive content

The GDPR does not set one fixed call-recording retention period. The period should follow the purpose. A support-quality recording kept for 30 days, a dispute-resolution recording kept for 90 days, and a regulated financial recording kept for years are different records with different justifications.

Voice recordings are not automatically biometric special-category data. They become biometric data under GDPR Article 9 when they are processed with technical means for unique identification. A normal support recording can still contain special-category data if the caller discusses health, religion, union membership, or other sensitive subjects. If that is likely in your environment, treat the recording path as higher-risk.

Data subject rights

A caller may have rights to access, erasure, restriction, objection, and portability depending on the lawful basis and facts. In PBX terms, the hard part is usually operational:

That is why the metadata design matters as much as the dialplan.

United Kingdom

The UK recording analysis has three layers. The Investigatory Powers Act 2016 and the Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 address when a business controlling a telecommunications system may intercept communications for specified monitoring and record-keeping purposes. UK GDPR and the Data Protection Act 2018 govern the resulting personal information. PECR separately matters for electronic communications and direct marketing.

The Data (Use and Access) Act 2025 amended the UK data-protection framework. Its data-protection provisions were fully in force by June 2026. Current policies should use current ICO guidance for lawful basis, complaints, access requests, purpose changes, and international transfers rather than relying on pre-2025 summaries.

ICO call-monitoring guidance is practical and direct: tell callers that calls are being recorded and explain why. A recorded message is good practice. Where that is not possible, staff should tell callers directly. Recording still needs to be necessary and proportionate for the documented purpose.

For sales, lead generation, debt collection, or campaign outreach, do not assume a generic quality-monitoring notice covers everything. Check PECR, suppression lists, opt-outs, campaign permissions, and the separate authority for recording.

For Asterisk, the UK-friendly implementation pattern is simple:

Canada: PIPEDA and provincial privacy laws

Canadian call recording is easy to oversimplify. Many administrators hear "one-party consent" and stop there. That is not enough for an organization recording customer calls.

For private-sector organizations under PIPEDA, the Office of the Privacy Commissioner of Canada says an organization should tell the customer the call is being recorded, clearly state the purpose, and ask for consent. If the customer continues after knowing that the call is recorded and why, consent may be implied. If the customer objects, the OPC expects an alternative, such as an unrecorded path, mail, online service, or an in-person option.

Use this mental model:

Those are different questions.

PIPEDA does not apply identically to every Canadian organization or activity. Its scope includes federal works and many interprovincial or international commercial data flows, while substantially similar provincial private-sector laws can govern other activity. Provincial health and employment laws may add another layer.

Provincial law can add obligations. Quebec Law 25 is the major one to watch because it strengthens governance, transparency, retention, destruction, anonymization, privacy impact assessment, and cross-border communication duties. Alberta PIPA and British Columbia PIPA may also apply depending on the organization and transaction.

Australia

Australia needs extra care because federal and state rules overlap.

At the federal level, the Telecommunications (Interception and Access) Act 1979 regulates interception of communications passing over a telecommunications system. State and territory surveillance-device statutes separately regulate listening devices, participant recording, later use, communication, and publication.

The Privacy Act 1988 and Australian Privacy Principles govern many organizations after the recording exists, but not every organization is covered. Turnover thresholds, small-business exceptions, employee-record rules, health-service coverage, contracting, and other exceptions require an applicability check. Where APP 11 applies, the organization must take reasonable security steps and destroy or de-identify information that is no longer needed unless another retention rule applies.

All eight state and territory regimes need review:

State or territory Recording issue to review
Western Australia The Surveillance Devices Act restricts participant recording unless every principal party consents or a specific exception, including a lawful-interest exception, applies.
South Australia The Surveillance Devices Act restricts participant recording unless all principal parties consent or another exception applies.
New South Wales The Surveillance Devices Act contains consent and lawful-interest exceptions, plus separate restrictions on possession, use, and publication.
Australian Capital Territory The Listening Devices Act contains participant-consent and lawful-interest rules that must be checked for the call purpose and later use.
Tasmania The Listening Devices Act 1991 restricts participant recording subject to all-party consent and narrower exceptions.
Queensland A participant may generally record a private conversation, but later communication or publication and privacy duties remain separate.
Victoria The core listening-device offence focuses on non-participant recording, while use, communication, publication, workplace, and privacy rules can still apply.
Northern Territory The Surveillance Devices Act 2007 regulates installation and use as well as later communication and publication.

For a national Australian call center, announce recording and capture affirmative consent before starting MixMonitor() unless counsel has approved a narrower purpose-specific model. If the caller objects, route to an unrecorded path or stop recording. Do not rely on a simplified one-party or all-party label because recording, later use, workplace monitoring, and privacy obligations can produce different answers.

Cross-border calls and hosted storage

For VoIP systems, location is not just the PBX address. A single call can involve several relevant places:

Those locations are policy signals, not an automatic conflict-of-laws formula. A SIP carrier's location, for example, does not by itself make that country's recording law govern the call. Counsel should separately analyze authority to record, privacy-law scope, extraterritorial reach, international transfers, storage localization, and sector rules.

When the legal decision is not yet available, a conservative operational fallback usually means clear notice, affirmative consent where practical, an unrecorded alternative, restricted processing, and escalation of the unresolved jurisdiction. Describe this as company policy, not as a universal legal rule.

For EU personal data, sending recordings to another country may trigger Chapter V transfer rules. Depending on the destination and recipient, the organization may need an adequacy decision, EU Standard Contractual Clauses, a transfer impact assessment, and supplementary safeguards. UK restricted transfers use the separate UK framework. EU SCCs do not work alone for UK transfers; use a UK adequacy route, the International Data Transfer Agreement or UK Addendum, and the required data-protection test as applicable.

A recording stored in a US object-storage bucket can be a cross-border transfer even if the PBX is in Europe and the caller never leaves Europe.

Asterisk implementation pattern

1. Decide before the call whether recording is allowed

Do not start MixMonitor() and then decide later whether the recording was allowed. Route through a recording policy step first.

Useful policy inputs include:

The result should be an explicit policy decision, not only a country name. If location is unknown, choose the conservative fallback and log that uncertainty for review.

2. Play a purpose-specific announcement

Use different prompts for different purposes and languages. Do not reuse one vague prompt everywhere.

[recording-consent]
exten => s,1,NoOp(Recording consent gate for ${ARG1})
 same => n,Set(RECORDING_PURPOSE=${ARG1})
 same => n,Set(RECORDING_BASIS=consent)
 same => n,Set(RECORDING_NOTICE_VERSION=support-2026-08)
 same => n,Set(NOTICE_LANGUAGE=${IF($["${CHANNEL(language)}"=""]?en:${CHANNEL(language)})})
 same => n,Playback(custom/recording-notice-${NOTICE_LANGUAGE})
 same => n,Read(CONSENT_DIGIT,custom/press-1-to-consent,1,,1,8)
 same => n,GotoIf($["${CONSENT_DIGIT}"="1"]?accepted:declined)
 same => n(accepted),Set(RECORDING_CONSENT=yes)
 same => n,Set(RECORDING_CONSENT_AT=${STRFTIME(${EPOCH},,%Y-%m-%dT%H:%M:%S%z)})
 same => n,Return()
 same => n(declined),Set(RECORDING_CONSENT=no)
 same => n,Return()

This example is intentionally explicit. Provision every supported language and define a tested fallback prompt. If a specifically reviewed policy allows implied consent, log the legal jurisdiction and policy version that authorize it. Do not silently convert a missing prompt, playback failure, timeout, or invalid digit into consent.

3. Start MixMonitor only after the policy step

[inbound-support]
exten => _X.,1,NoOp(Inbound support call)
 same => n,Gosub(recording-consent,s,1(support-quality))
 same => n,GotoIf($["${RECORDING_CONSENT}"!="yes"]?no_recording)
 same => n,Set(REC_DATE=${STRFTIME(${EPOCH},,%Y/%m/%d)})
 same => n,Set(REC_FILE=${REC_DATE}/${UNIQUEID}.wav)
 same => n,MixMonitor(${REC_FILE},b,i(MIXMONITOR_ID))
 same => n,Set(REC_FILE=${MIXMONITOR_FILENAME})
 same => n,UserEvent(RecordingPolicy,Uniqueid: ${UNIQUEID},Linkedid: ${CHANNEL(linkedid)},Decision: record,Purpose: ${RECORDING_PURPOSE},Basis: ${RECORDING_BASIS},NoticeVersion: ${RECORDING_NOTICE_VERSION},ConsentMethod: keypress,ConsentAt: ${RECORDING_CONSENT_AT},RecordingFile: ${REC_FILE},MixMonitorId: ${MIXMONITOR_ID})
 same => n(no_recording),Queue(support)

Create the date directories with the correct owner and permissions before calls arrive. Keep recordings outside the web root. MIXMONITOR_FILENAME is the authoritative path selected by Asterisk.

UserEvent() is only an example transport. It is durable only when a monitored AMI consumer commits the event successfully. For production, prefer a local ODBC write or a reliable local event service with retry and idempotency. Do not rely only on CDR(recording_file): not every CDRCall Detail Record. The per-call accounting data Asterisk writes (start, answer, and end times, duration, disposition) to files or databases. backend retains arbitrary custom fields, and a CDR cannot represent the whole consent and deletion lifecycle.

The b option records only while the channel is bridged, so the notice itself is not in the audio file. Prove notice delivery through the policy event, prompt version, timestamp, playback result, and consent event. If post-call dialplan logic immediately hashes, encrypts, uploads, or analyzes the file, call StopMixMonitor() first so the file handle is closed.

4. Store DSAR-ready metadata

A recording without useful metadata is a future support ticket waiting to happen. Store a small row for each recording in a database table or external system.

Field Why it matters
uniqueid Primary Asterisk call identifier.
linkedid Correlates transfers, Local channels, and multi-leg calls.
recording_file Physical path or object-storage key.
started_at and ended_at Retention, access requests, and incident investigation.
caller_number and account_id Search keys for access requests.
agent_id and queue Operational contextA named section of the dialplan that groups extensions. Calls enter a specific context and can only reach extensions visible from it, making contexts the basic unit of call routing and security. and internal access control.
purpose Retention and lawful-basis evidence.
lawful_basis GDPR or policy basis such as consent, contract, legal obligation, or legitimate interests.
notice_version Proves what the caller was told.
consent_method Keypress, spoken consent, continued participation, or legal obligation.
consent_at Timestamp for consent evidence.
retention_until Deletion target.
storage_region Cross-border transfer review.
controller and processor Responsibility, vendor, and contract tracking.
policy_version Reconstructs the rule that made the recording decision.
jurisdiction_signals Caller and agent locations, source, and confidence.
recording_started_at and recording_stopped_at Proves the actual capture window.
mixmonitor_id Supports pause, stop, and operational correlation.
integrity_hash Detects later alteration of preserved evidence.
legal_hold Prevents scheduled deletion when an approved hold applies.
deletion_status Tracks live file, replicas, vendor copies, backups, and completion evidence.
encryption_key_id Security and cryptographic-deletion workflows.

5. Test transfers, conferences, and outbound calls

The example attaches MixMonitor() to the inbound caller channel. That does not prove that every real call flow records the intended media.

6. Protect payment and other sensitive segments

Do not record card verification codes, PIN blocks, passwords, recovery codes, or unnecessary health information. PCI DSS prohibits storage of sensitive authentication data after authorization even when encrypted. Use a validated payment flow that keeps payment audio and DTMFDual-Tone Multi-Frequency, the touch-tone signals phones send for digit input during a call, used by IVRs and feature codes. out of the recorder, or pause and resume recording through a controlled service tied to the MixMonitor ID.

Log each pause and resume event, test that both audio directions are suppressed, and verify that transcripts, stereo legs, screen recordings, backups, and third-party analytics do not preserve the sensitive segment. Never depend on an agent remembering to mute the recorder without monitoring and exception reporting.

7. Encrypt recordings at rest

Asterisk does not encrypt MixMonitor() output by itself. Put controls around the storage:

For higher-risk recordings, encrypt per tenant, per purpose, or per retention class so access control and deletion are easier to prove.

8. Prune by purpose, not by one global age

Different purposes need different retention periods. Avoid one global retention value unless every call really has the same purpose.

A simple daily pruning job can work if the metadata already separates recordings by purpose:

find /var/spool/asterisk/recording/support-quality -type f -mtime +90 -name '*.wav' -delete
find /var/spool/asterisk/recording/training -type f -mtime +30 -name '*.wav' -delete

For production, prefer a retention worker that deletes by database metadata, logs the deletion, and marks the row as deleted. Filesystem age alone does not prove the purpose or legal basis.

Deletion must honor an approved legal or regulatory hold. The worker should cover the live PBX file, object-storage replicas, exports, vendor copies, search indexes, transcripts, and backup lifecycle. If a backup cannot be edited safely, prevent restoration into active use and expire it under a documented schedule. Record partial failures and retry them rather than marking the recording deleted prematurely.

9. Make access requests boring

A DSAR or privacy access request should not turn into a manual hunt through recording folders. Build the lookup path now:

  1. Verify the requester and record the authority for any representative.
  2. Search by caller number, account, date range, ticket, or email-linked account.
  3. Match candidate calls by uniqueid and linkedid.
  4. Review whether the recording contains third-party voices or sensitive information.
  5. Export only what the requester is entitled to receive.
  6. Redact or withhold where required by the applicable law.
  7. Log the request, decision, export, and deletion if deletion is required.

10. Treat transcription and AI analysis as new processing

Speech-to-text, summaries, sentiment scoring, quality scoring, topic extraction, and voice authentication are not merely storage formats. They create additional personal information, purposes, vendors, access paths, and error risks.

A practical policy matrix

Use this as a starting point for the internal recording policy that your dialplan enforces.

Call type Sensible default
Support quality Announce, record only after consent or documented legitimate-interest review, short retention.
Sales or marketing Announce, check marketing-specific consent and opt-out rules, keep retention short.
Financial or regulated service Announce unless legally exempt, record where required, suppress payment credentials, retain for the regulatory period, and apply legal holds.
Healthcare or sensitive support Avoid recording by default. If recording is necessary, use explicit consent and stronger access control.
Employee monitoring Publish internal policy, perform a proportionality review, avoid routine personal-call recording.
Fraud or abuse investigation Use a documented lawful basis, restrict access, and separate from routine quality recording.
Cross-border or unknown location Use the conservative fallback, announce, capture affirmative consent when practical, offer an unrecorded route, and escalate the unresolved jurisdiction.

Official sources used

User Notes

Know a tip or gotcha for this topic? Share it below and help others.

Contribute a note

Share a tip, gotcha, or practical example. Keep it under 2000 characters. No questions (use the Asterisk community forums for support). Wrap code in backticks.

Moderated before publishing. Email never shown.
Related Snippets