International Call Recording Compliance
International Call Recording Compliance
Most call recording mistakes happen before anyone opens the legal handbook. The PBXPrivate Branch Exchange, a private telephone switch. Asterisk is a software PBX that routes calls between internal extensions and the outside world. starts writing audio, the files land in a shared folder, and only later does someone ask what the caller was told, why the call was recorded, how long the file should live, or whether the caller had a real choice.
This page is meant to prevent that problem. It is a practical compliance reference for Asterisk systems that use MixMonitor(), AMIAsterisk Manager Interface. A TCP socket API for monitoring events and issuing actions in Asterisk, commonly used by click-to-dial integrations and dashboards. recording actions, or any external recorder attached to SIPSession Initiation Protocol, the standard signaling protocol used to set up, manage, and tear down VoIP calls between Asterisk and phones or carriers./RTPReal-time Transport Protocol. Carries the actual audio (media) of a VoIP call after SIP signaling has set it up. media.
It is also the international companion to Call Recording Consent Laws by State.
Last reviewed: August 1, 2026
Not legal advice
This is a technical compliance reference for PBX administrators, not legal advice. Recording law changes by country, state, province, industry, call purpose, and participant location. Use this as an engineering checklist, then confirm the policy with counsel before recording production calls.
The safe engineering default
If your callers may be outside the United States, do not build the dialplanThe core call-routing configuration of Asterisk, written mostly in extensions.conf as contexts, extensions, and priorities that decide how every call is handled. Full definition → around one global consent rule. Build it around a documented recording purpose and a conservative routing decision.
A good default looks like this:
- Decide whether recording is authorized before starting it, unless a governing rule requires recording from the beginning.
- Announce the recording and its purpose before recording ordinary business calls.
- Do not confuse notice with consent. Capture an affirmative keypress or spoken agreement when consent is the lawful basis.
- Give the caller a reasonable unrecorded path when consent must be freely given or when policy promises one.
- Store enough metadata to prove the policy decision, notice, consent method, and recording lifecycle.
- Keep recordings only as long as the documented purpose requires, subject to approved legal holds.
- Encrypt recordings at rest and limit who can play, export, transcribe, analyze, or delete them.
- Treat health, biometric, financial, employment, child-related, and payment-card calls as higher-risk from the beginning.
- When location or applicable law is uncertain, apply a conservative policy while the legal question is escalated.
The notice matters. "This call may be recorded" is usually too thin by itself. A better notice says something like, "This call may be recorded for support quality and dispute resolution." That gives the caller a real explanation, and it gives the business a purpose that can drive retention and access control.
The policy engine should produce one of four explicit outcomes:
- Recording is allowed after notice under a documented non-consent basis.
- Recording is allowed only after affirmative consent.
- Recording may rely on implied consent under a specifically reviewed jurisdiction and call flow.
- Recording is required by law or regulation, with the required notice or documented exception.
These outcomes are not interchangeable. Continued participation may support implied consent under some laws, including Canadian privacy guidance, but it is not a dependable substitute for affirmative GDPR consent.
Quick jurisdiction map
| Jurisdiction | What matters most | What the PBX should do |
|---|---|---|
| European Union | GDPR governs the processing of the recording and metadata. National laws may also control the act of recording communications. | Choose and document a lawful basis, give a clear notice, minimize recording, retain by purpose, and support data subject rights. |
| United Kingdom | UK GDPR, the Data Protection Act 2018, the Investigatory Powers Act 2016, the 2018 business monitoring regulations, PECR, and amendments made by the Data (Use and Access) Act 2025 may apply. | Use clear notices, record only for an authorized purpose, keep purpose and retention records, publish privacy information, and handle access and complaint workflows. |
| Canada | Criminal Code section 184 and privacy-law consent are separate questions. PIPEDA expects meaningful notice, purpose, and consent for customer call recording. | Do not rely only on one-party criminal consent. Announce the recording and purpose, capture implied or express consent, and offer another channelA single call leg passing through Asterisk. Channels represent connections to endpoints and are what dialplan applications act on. when needed. |
| Quebec | Quebec Law 25 adds stronger transparency, governance, retention, destruction, anonymization, and cross-border assessment expectations. | Store purpose and retention metadata. Review hosted recording storage outside Quebec before sending recordings there. |
| Australia | The federal Telecommunications (Interception and Access) Act 1979, the Privacy Act where it applies, and all eight state or territory surveillance-device regimes may matter. | For a national service, announce recording and obtain affirmative consent unless counsel has approved a narrower call flow. Do not assume the federal Privacy Act applies to every organization. |
| Cross-border calls | Caller, agent, controller, processor, and recording storage may be in different places. Interception, privacy, transfer, and localization rules are separate questions. | Use a conservative fallback when location is uncertain, but have counsel determine legal scope. Keep jurisdiction signals, storage-region, processor, and transfer-mechanism metadata. |
Additional country matrix
The following matrix extends the detailed sections below. It is a triage tool, not a substitute for country-specific advice. The PBX action is intentionally conservative.
| Jurisdiction | Principal issue | Conservative PBX action |
|---|---|---|
| Germany | Criminal Code section 201 protects the confidentiality of privately spoken words in addition to GDPR. | Obtain affirmative agreement from all participants unless a specific statutory or regulatory basis has been approved. |
| France | Penal Code article 226-1 restricts recording private or confidential words without consent. GDPR governs later processing. | Give conspicuous notice and capture affirmative agreement before ordinary business recording. |
| Switzerland | The Swiss data protection authority explains that participant recording normally requires permission from the other participants under Criminal Code articles 179bis and 179ter, subject to narrow exceptions. | Treat as an all-participant-consent jurisdiction unless the exact business exception has been reviewed. |
| Brazil | The LGPD governs purpose, legal basis, transparency, rights, security, retention, processors, and international transfers. Other privacy and communications rules can also apply to making the recording. | Announce recording and purpose, document the LGPD basis, minimize retention, and record the approved international-transfer mechanism. |
| New Zealand | The Privacy Act 2020 governs organizational collection, notice, use, access, retention, security, and overseas disclosure. Participant-recording rules do not remove those organizational duties. | Notify at collection, state the purpose, provide access handling, and document overseas disclosures and vendors. |
| Singapore | The PDPA generally imposes notification, purpose, consent or exception, protection, retention, access, and transfer-limitation obligations. Do Not Call rules separately affect marketing calls. | Announce the purpose, document the applicable consent or exception, check marketing permissions, and review overseas storage protections. |
| Japan | The APPI governs specified purposes, notice or publication, security, third-party provision, access, and cross-border transfers of personal information. | Publish or deliver the recording purpose, restrict secondary use, and document vendors and cross-border disclosures. |
| South Africa | POPIA governs lawful processing, notification, security, operator relationships, data-subject rights, direct marketing, and trans-border flows. | Give notice, document the processing condition, execute operator controls, and validate section 72 transfer requirements. |
| Mexico | The private-sector data protection framework requires a privacy notice, purpose and consent analysis, ARCO-rights handling, security, retention, and transfer controls. | Provide a compliant privacy notice, record the purpose and consent basis, and document domestic and international recipients. |
| United Arab Emirates | Federal data-protection, cybercrime, telecommunications, free-zone, and sector rules can overlap, and private recording can create criminal risk. | Do not record silently. Require explicit local legal approval, affirmative participant consent where applicable, and an approved storage region. |
For EU member states not listed separately, GDPR is only the processing layer. National criminal, employment, telecommunications, and evidence laws may independently determine whether the conversation can be recorded.
European Union: GDPR
In the EU, a call recording is usually personal data. The GDPR, Regulation (EU) 2016/679, controls the processing of the recording, but it does not answer every recording question, because member-state communications laws may still control whether the call may be recorded in the first place. The GDPR answers what happens once you collect, store, use, disclose, search, export, or delete the recording and its metadata.
That distinction is important for Asterisk administrators. A dialplanThe core call-routing configuration of Asterisk, written mostly in extensions.conf as contexts, extensions, and priorities that decide how every call is handled. Full definition → can satisfy a business workflow and still create a privacy problem if it records more than needed, keeps files too long, or cannot find a caller's recording when they make a request.
Under GDPR Article 6, the controller needs a lawful basis. Common candidates are:
- Consent, Article 6(1)(a): useful when the caller can freely refuse recording and still get a reasonable service path. Consent requires a clear affirmative action and a practical withdrawal process.
- Contract, Article 6(1)(b): possible only when recording is objectively necessary to perform the requested contract. Recording that is merely useful for quality, training, or evidence does not become necessary just because the organization puts it in its terms.
- Legal obligation, Article 6(1)(c): relevant where a law or regulator requires recording.
- Legitimate interests, Article 6(1)(f): possible for security, fraud prevention, dispute resolution, or quality control, but only after a balancing test and only when the caller would reasonably expect it.
Consent is not the easy button. It must be freely given, specific, informed, and unambiguous. Silence, inactivity, or merely staying on the line is not a reliable affirmative action under GDPR. If the caller cannot realistically refuse, consent may be the wrong lawful basis. In that case, document the actual basis and still tell the caller what is happening.
Where large-scale recording combines systematic monitoring, sensitive information, vulnerable callers, profiling, or new analytics, assess whether GDPR Article 35 requires a data protection impact assessment. Consult the supervisory authority's published DPIA list for the controller's member state.
What the announcement should say
The short audio prompt should cover the immediate facts and point to fuller privacy information. For a GDPR-style notice, include:
- That the call is being recorded or may be recorded.
- The purpose, such as support quality, transaction evidence, security, fraud prevention, or regulatory compliance.
- The organization responsible for the recording.
- Whether affirmative consent is required, and exactly how the caller provides or withdraws it.
- Where the caller can find the full privacy notice, including controller and DPO contact details, lawful basis, recipients, international transfers, retention, rights, complaint route, and any automated decision-making.
Example:
Calls to ExampleCo support may be recorded for support quality and dispute resolution. The recording is kept for 90 days unless needed for an active case. To continue without recording, press 2 or visit example.com/privacy for other contact options.
Retention and sensitive content
The GDPR does not set one fixed call-recording retention period. The period should follow the purpose. A support-quality recording kept for 30 days, a dispute-resolution recording kept for 90 days, and a regulated financial recording kept for years are different records with different justifications.
Voice recordings are not automatically biometric special-category data. They become biometric data under GDPR Article 9 when they are processed with technical means for unique identification. A normal support recording can still contain special-category data if the caller discusses health, religion, union membership, or other sensitive subjects. If that is likely in your environment, treat the recording path as higher-risk.
Data subject rights
A caller may have rights to access, erasure, restriction, objection, and portability depending on the lawful basis and facts. In PBX terms, the hard part is usually operational:
- Can you find the recording from a phone number, account, ticket, or date range?
- Can you identify all linked call legs after transfers?
- Can you separate the requester's voice from other participants if required?
- Can you delete the live file, archive copy, and backup copy when deletion is required?
- Can you prove what happened?
That is why the metadata design matters as much as the dialplan.
United Kingdom
The UK recording analysis has three layers. The Investigatory Powers Act 2016 and the Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 address when a business controlling a telecommunications system may intercept communications for specified monitoring and record-keeping purposes. UK GDPR and the Data Protection Act 2018 govern the resulting personal information. PECR separately matters for electronic communications and direct marketing.
The Data (Use and Access) Act 2025 amended the UK data-protection framework. Its data-protection provisions were fully in force by June 2026. Current policies should use current ICO guidance for lawful basis, complaints, access requests, purpose changes, and international transfers rather than relying on pre-2025 summaries.
ICO call-monitoring guidance is practical and direct: tell callers that calls are being recorded and explain why. A recorded message is good practice. Where that is not possible, staff should tell callers directly. Recording still needs to be necessary and proportionate for the documented purpose.
For sales, lead generation, debt collection, or campaign outreach, do not assume a generic quality-monitoring notice covers everything. Check PECR, suppression lists, opt-outs, campaign permissions, and the separate authority for recording.
For Asterisk, the UK-friendly implementation pattern is simple:
- Play the notice at the edge of the IVR, before recording starts.
- Use purpose-specific prompts instead of one vague prompt for every queueAn Asterisk call queue (app_queue) that parks incoming calls and distributes them to logged-in agents according to a chosen ring strategy..
- Link the prompt to a public privacy notice.
- Keep the recording purpose and retention period in metadata.
- Avoid routine personal-call or staff-call recording unless the purpose is strong and documented.
- Make subject access and data-protection complaint handling part of the recording workflow.
- Document the business-monitoring purpose authorized by the 2018 regulations.
- For restricted transfers, use a UK adequacy route, the UK IDTA, or the UK Addendum as applicable. EU SCCs alone are not valid for a UK restricted transfer.
Canada: PIPEDA and provincial privacy laws
Canadian call recording is easy to oversimplify. Many administrators hear "one-party consent" and stop there. That is not enough for an organization recording customer calls.
For private-sector organizations under PIPEDA, the Office of the Privacy Commissioner of Canada says an organization should tell the customer the call is being recorded, clearly state the purpose, and ask for consent. If the customer continues after knowing that the call is recorded and why, consent may be implied. If the customer objects, the OPC expects an alternative, such as an unrecorded path, mail, online service, or an in-person option.
Use this mental model:
- Consent under Criminal Code section 184 asks whether the recording is an unlawful interception.
- Privacy-law consent asks whether the organization may collect, use, retain, disclose, and dispose of the caller's personal information.
Those are different questions.
PIPEDA does not apply identically to every Canadian organization or activity. Its scope includes federal works and many interprovincial or international commercial data flows, while substantially similar provincial private-sector laws can govern other activity. Provincial health and employment laws may add another layer.
Provincial law can add obligations. Quebec Law 25 is the major one to watch because it strengthens governance, transparency, retention, destruction, anonymization, privacy impact assessment, and cross-border communication duties. Alberta PIPA and British Columbia PIPA may also apply depending on the organization and transaction.
Australia
Australia needs extra care because federal and state rules overlap.
At the federal level, the Telecommunications (Interception and Access) Act 1979 regulates interception of communications passing over a telecommunications system. State and territory surveillance-device statutes separately regulate listening devices, participant recording, later use, communication, and publication.
The Privacy Act 1988 and Australian Privacy Principles govern many organizations after the recording exists, but not every organization is covered. Turnover thresholds, small-business exceptions, employee-record rules, health-service coverage, contracting, and other exceptions require an applicability check. Where APP 11 applies, the organization must take reasonable security steps and destroy or de-identify information that is no longer needed unless another retention rule applies.
All eight state and territory regimes need review:
| State or territory | Recording issue to review |
|---|---|
| Western Australia | The Surveillance Devices Act restricts participant recording unless every principal party consents or a specific exception, including a lawful-interest exception, applies. |
| South Australia | The Surveillance Devices Act restricts participant recording unless all principal parties consent or another exception applies. |
| New South Wales | The Surveillance Devices Act contains consent and lawful-interest exceptions, plus separate restrictions on possession, use, and publication. |
| Australian Capital Territory | The Listening Devices Act contains participant-consent and lawful-interest rules that must be checked for the call purpose and later use. |
| Tasmania | The Listening Devices Act 1991 restricts participant recording subject to all-party consent and narrower exceptions. |
| Queensland | A participant may generally record a private conversation, but later communication or publication and privacy duties remain separate. |
| Victoria | The core listening-device offence focuses on non-participant recording, while use, communication, publication, workplace, and privacy rules can still apply. |
| Northern Territory | The Surveillance Devices Act 2007 regulates installation and use as well as later communication and publication. |
For a national Australian call center, announce recording and capture affirmative consent before starting MixMonitor() unless counsel has approved a narrower purpose-specific model. If the caller objects, route to an unrecorded path or stop recording. Do not rely on a simplified one-party or all-party label because recording, later use, workplace monitoring, and privacy obligations can produce different answers.
Cross-border calls and hosted storage
For VoIP systems, location is not just the PBX address. A single call can involve several relevant places:
- Caller physical location.
- Agent physical location.
- Organization location.
- SIP trunkA connection between Asterisk and another PBX or an ITSP/carrier, used to send and receive external calls. provider location.
- PBX location.
- Recording storage location.
- Backup and analytics provider location.
- The country whose residents are being targeted by the service.
Those locations are policy signals, not an automatic conflict-of-laws formula. A SIP carrier's location, for example, does not by itself make that country's recording law govern the call. Counsel should separately analyze authority to record, privacy-law scope, extraterritorial reach, international transfers, storage localization, and sector rules.
When the legal decision is not yet available, a conservative operational fallback usually means clear notice, affirmative consent where practical, an unrecorded alternative, restricted processing, and escalation of the unresolved jurisdiction. Describe this as company policy, not as a universal legal rule.
For EU personal data, sending recordings to another country may trigger Chapter V transfer rules. Depending on the destination and recipient, the organization may need an adequacy decision, EU Standard Contractual Clauses, a transfer impact assessment, and supplementary safeguards. UK restricted transfers use the separate UK framework. EU SCCs do not work alone for UK transfers; use a UK adequacy route, the International Data Transfer Agreement or UK Addendum, and the required data-protection test as applicable.
A recording stored in a US object-storage bucket can be a cross-border transfer even if the PBX is in Europe and the caller never leaves Europe.
Asterisk implementation pattern
1. Decide before the call whether recording is allowed
Do not start MixMonitor() and then decide later whether the recording was allowed. Route through a recording policy step first.
Useful policy inputs include:
- DID or campaign.
- Queue or department.
- Caller account country.
- Caller IDThe calling party number (and optionally name) presented on an outbound call, set from the endpoint or manipulated in the dialplan. country as a weak signal.
- Agent location.
- Language.
- Recording purpose.
- Whether the call is regulated, support, sales, emergency, employment, healthcare, or payment-card related.
- The policy version and the confidence and source of every jurisdiction signal.
The result should be an explicit policy decision, not only a country name. If location is unknown, choose the conservative fallback and log that uncertainty for review.
2. Play a purpose-specific announcement
Use different prompts for different purposes and languages. Do not reuse one vague prompt everywhere.
[recording-consent]
exten => s,1,NoOp(Recording consent gate for ${ARG1})
same => n,Set(RECORDING_PURPOSE=${ARG1})
same => n,Set(RECORDING_BASIS=consent)
same => n,Set(RECORDING_NOTICE_VERSION=support-2026-08)
same => n,Set(NOTICE_LANGUAGE=${IF($["${CHANNEL(language)}"=""]?en:${CHANNEL(language)})})
same => n,Playback(custom/recording-notice-${NOTICE_LANGUAGE})
same => n,Read(CONSENT_DIGIT,custom/press-1-to-consent,1,,1,8)
same => n,GotoIf($["${CONSENT_DIGIT}"="1"]?accepted:declined)
same => n(accepted),Set(RECORDING_CONSENT=yes)
same => n,Set(RECORDING_CONSENT_AT=${STRFTIME(${EPOCH},,%Y-%m-%dT%H:%M:%S%z)})
same => n,Return()
same => n(declined),Set(RECORDING_CONSENT=no)
same => n,Return()
This example is intentionally explicit. Provision every supported language and define a tested fallback prompt. If a specifically reviewed policy allows implied consent, log the legal jurisdiction and policy version that authorize it. Do not silently convert a missing prompt, playback failure, timeout, or invalid digit into consent.
3. Start MixMonitor only after the policy step
[inbound-support]
exten => _X.,1,NoOp(Inbound support call)
same => n,Gosub(recording-consent,s,1(support-quality))
same => n,GotoIf($["${RECORDING_CONSENT}"!="yes"]?no_recording)
same => n,Set(REC_DATE=${STRFTIME(${EPOCH},,%Y/%m/%d)})
same => n,Set(REC_FILE=${REC_DATE}/${UNIQUEID}.wav)
same => n,MixMonitor(${REC_FILE},b,i(MIXMONITOR_ID))
same => n,Set(REC_FILE=${MIXMONITOR_FILENAME})
same => n,UserEvent(RecordingPolicy,Uniqueid: ${UNIQUEID},Linkedid: ${CHANNEL(linkedid)},Decision: record,Purpose: ${RECORDING_PURPOSE},Basis: ${RECORDING_BASIS},NoticeVersion: ${RECORDING_NOTICE_VERSION},ConsentMethod: keypress,ConsentAt: ${RECORDING_CONSENT_AT},RecordingFile: ${REC_FILE},MixMonitorId: ${MIXMONITOR_ID})
same => n(no_recording),Queue(support)
Create the date directories with the correct owner and permissions before calls arrive. Keep recordings outside the web root. MIXMONITOR_FILENAME is the authoritative path selected by Asterisk.
UserEvent() is only an example transport. It is durable only when a monitored AMI consumer commits the event successfully. For production, prefer a local ODBC write or a reliable local event service with retry and idempotency. Do not rely only on CDR(recording_file): not every CDRCall Detail Record. The per-call accounting data Asterisk writes (start, answer, and end times, duration, disposition) to files or databases. backend retains arbitrary custom fields, and a CDR cannot represent the whole consent and deletion lifecycle.
The b option records only while the channel is bridged, so the notice itself is not in the audio file. Prove notice delivery through the policy event, prompt version, timestamp, playback result, and consent event. If post-call dialplan logic immediately hashes, encrypts, uploads, or analyzes the file, call StopMixMonitor() first so the file handle is closed.
4. Store DSAR-ready metadata
A recording without useful metadata is a future support ticket waiting to happen. Store a small row for each recording in a database table or external system.
| Field | Why it matters |
|---|---|
uniqueid |
Primary Asterisk call identifier. |
linkedid |
Correlates transfers, Local channels, and multi-leg calls. |
recording_file |
Physical path or object-storage key. |
started_at and ended_at |
Retention, access requests, and incident investigation. |
caller_number and account_id |
Search keys for access requests. |
agent_id and queue |
Operational contextA named section of the dialplan that groups extensions. Calls enter a specific context and can only reach extensions visible from it, making contexts the basic unit of call routing and security. and internal access control. |
purpose |
Retention and lawful-basis evidence. |
lawful_basis |
GDPR or policy basis such as consent, contract, legal obligation, or legitimate interests. |
notice_version |
Proves what the caller was told. |
consent_method |
Keypress, spoken consent, continued participation, or legal obligation. |
consent_at |
Timestamp for consent evidence. |
retention_until |
Deletion target. |
storage_region |
Cross-border transfer review. |
controller and processor |
Responsibility, vendor, and contract tracking. |
policy_version |
Reconstructs the rule that made the recording decision. |
jurisdiction_signals |
Caller and agent locations, source, and confidence. |
recording_started_at and recording_stopped_at |
Proves the actual capture window. |
mixmonitor_id |
Supports pause, stop, and operational correlation. |
integrity_hash |
Detects later alteration of preserved evidence. |
legal_hold |
Prevents scheduled deletion when an approved hold applies. |
deletion_status |
Tracks live file, replicas, vendor copies, backups, and completion evidence. |
encryption_key_id |
Security and cryptographic-deletion workflows. |
5. Test transfers, conferences, and outbound calls
The example attaches MixMonitor() to the inbound caller channel. That does not prove that every real call flow records the intended media.
- Test blind and attended transfers. Audiohooks can remain on a discarded channel during channel replacement unless the design handles inheritance correctly.
- Test queues and
Localchannels with and without optimization. - For outbound calls, deliver the notice at the beginning of the connected call before ordinary recording starts. A privacy policy published elsewhere is not a substitute for call-time notice where notice is required.
- When a new participant joins a conference, decide whether to notify that participant, stop recording, or require new consent.
- Re-run the jurisdiction decision when a call transfers to an agent or site in another country.
- Test supervisor monitoring, whisper, barge, callback, and external-recorder paths separately.
- Confirm that direct-media and media-proxy behavior still permits Asterisk or the external recorder to capture the intended audio.
6. Protect payment and other sensitive segments
Do not record card verification codes, PIN blocks, passwords, recovery codes, or unnecessary health information. PCI DSS prohibits storage of sensitive authentication data after authorization even when encrypted. Use a validated payment flow that keeps payment audio and DTMFDual-Tone Multi-Frequency, the touch-tone signals phones send for digit input during a call, used by IVRs and feature codes. out of the recorder, or pause and resume recording through a controlled service tied to the MixMonitor ID.
Log each pause and resume event, test that both audio directions are suppressed, and verify that transcripts, stereo legs, screen recordings, backups, and third-party analytics do not preserve the sensitive segment. Never depend on an agent remembering to mute the recorder without monitoring and exception reporting.
7. Encrypt recordings at rest
Asterisk does not encrypt MixMonitor() output by itself. Put controls around the storage:
- Put recordings on an encrypted filesystem or encrypted object-storage bucket.
- Use restrictive filesystem permissions for the Asterisk process and retrieval service.
- Separate PBX operators from recording reviewers.
- Log every playback, export, and deletion.
- Keep recordings out of normal web-accessible paths.
- Rotate keys and document the recovery process.
For higher-risk recordings, encrypt per tenant, per purpose, or per retention class so access control and deletion are easier to prove.
8. Prune by purpose, not by one global age
Different purposes need different retention periods. Avoid one global retention value unless every call really has the same purpose.
A simple daily pruning job can work if the metadata already separates recordings by purpose:
find /var/spool/asterisk/recording/support-quality -type f -mtime +90 -name '*.wav' -delete
find /var/spool/asterisk/recording/training -type f -mtime +30 -name '*.wav' -delete
For production, prefer a retention worker that deletes by database metadata, logs the deletion, and marks the row as deleted. Filesystem age alone does not prove the purpose or legal basis.
Deletion must honor an approved legal or regulatory hold. The worker should cover the live PBX file, object-storage replicas, exports, vendor copies, search indexes, transcripts, and backup lifecycle. If a backup cannot be edited safely, prevent restoration into active use and expire it under a documented schedule. Record partial failures and retry them rather than marking the recording deleted prematurely.
9. Make access requests boring
A DSAR or privacy access request should not turn into a manual hunt through recording folders. Build the lookup path now:
- Verify the requester and record the authority for any representative.
- Search by caller number, account, date range, ticket, or email-linked account.
- Match candidate calls by
uniqueidandlinkedid. - Review whether the recording contains third-party voices or sensitive information.
- Export only what the requester is entitled to receive.
- Redact or withhold where required by the applicable law.
- Log the request, decision, export, and deletion if deletion is required.
10. Treat transcription and AI analysis as new processing
Speech-to-text, summaries, sentiment scoring, quality scoring, topic extraction, and voice authentication are not merely storage formats. They create additional personal information, purposes, vendors, access paths, and error risks.
- Document a separate purpose and lawful basis for each analysis.
- Do not assume consent to recording also authorizes training, profiling, biometric identification, or generative-AI processing.
- Perform a DPIA or equivalent assessment when the scale, sensitivity, profiling, or technology creates elevated risk.
- Apply retention and deletion to transcripts, embeddings, summaries, model inputs, evaluation datasets, and vendor logs.
- Provide a human review and correction path before using automated scores for employment, eligibility, fraud, or other consequential decisions.
A practical policy matrix
Use this as a starting point for the internal recording policy that your dialplan enforces.
| Call type | Sensible default |
|---|---|
| Support quality | Announce, record only after consent or documented legitimate-interest review, short retention. |
| Sales or marketing | Announce, check marketing-specific consent and opt-out rules, keep retention short. |
| Financial or regulated service | Announce unless legally exempt, record where required, suppress payment credentials, retain for the regulatory period, and apply legal holds. |
| Healthcare or sensitive support | Avoid recording by default. If recording is necessary, use explicit consent and stronger access control. |
| Employee monitoring | Publish internal policy, perform a proportionality review, avoid routine personal-call recording. |
| Fraud or abuse investigation | Use a documented lawful basis, restrict access, and separate from routine quality recording. |
| Cross-border or unknown location | Use the conservative fallback, announce, capture affirmative consent when practical, offer an unrecorded route, and escalate the unresolved jurisdiction. |
Related Asterisk references
MixMonitor()records and mixes call audio.StopMixMonitor()stops a recording and closes the file handle.MIXMONITOR()retrieves MixMonitor instance data.- Selective Call Recording shows a practical recording toggle pattern.
- Call Recording Consent Laws by State covers US state consent rules.
Official sources used
- GDPR, Regulation (EU) 2016/679
- European Data Protection Board: legal basis
- European Data Protection Board: standard contractual clauses
- UK Investigatory Powers Act 2016
- UK 2018 business monitoring and record-keeping regulations
- UK Data (Use and Access) Act 2025
- ICO: UK IDTA and Addendum
- ICO: specific data protection considerations for monitoring workers
- ICO: Guide to PECR
- UK Data Protection Act 2018
- UK PECR statutory instrument
- Canada PIPEDA
- Canada Criminal Code, section 184
- Office of the Privacy Commissioner of Canada: Recording of Customer Telephone Calls
- Alberta Personal Information Protection Act
- British Columbia Personal Information Protection Act
- Quebec CAI: principal changes under Law 25
- Quebec CAI: retention and destruction of personal information
- Quebec Act respecting the protection of personal information in the private sector
- Australian Telecommunications (Interception and Access) Act 1979
- Australian Privacy Act 1988
- OAIC: APP 11 security of personal information
- Western Australia Surveillance Devices Act 1998
- Queensland Invasion of Privacy Act 1971, section 43
- Victoria Surveillance Devices Act 1999
- South Australia Surveillance Devices Act 2016
- NSW Surveillance Devices Act 2007
- Tasmania Listening Devices Act 1991
- Northern Territory Surveillance Devices Act 2007
- Germany Criminal Code section 201
- France Penal Code article 226-1
- Swiss data protection authority: recording conversations
- Brazilian LGPD, official English translation
- New Zealand Privacy Act 2020
- Singapore PDPC: individuals overview
- Japan APPI, official English translation
- South Africa POPIA
- PCI SSC: audio recordings and sensitive authentication data
User Notes
Know a tip or gotcha for this topic? Share it below and help others.
Contribute a note
Share a tip, gotcha, or practical example. Keep it under 2000 characters. No questions (use the Asterisk community forums for support). Wrap code in backticks.