Consent is not normally the right lawful basis for business call recording in the UK. Most contact centres record on legitimate interest, provided callers hear a clear announcement and the business documents that assessment. The one immediate step: turn on the pre-call notice now, log your lawful basis in writing, and disclose it plainly if AI is analysing the call.
TL;DR:
- Play a clear automated notice at the start of calls, informing callers about recording, AI analysis, and necessary disclosures, with logs kept separately.
- Rely on legitimate interest as the default lawful basis for recordings, documenting the purpose, necessity, and balancing test in an internal legit interest assessment.
- Automated outbound marketing calls require prior explicit consent under PECR, and calling numbers on TPS or CTPS is prohibited without consent.
- AI activities like transcription or sentiment analysis must be disclosed separately in your privacy notice and lawful interest assessment, with added focus on sensitive data.
- Vendors must provide written data processing agreements, encryption standards, automated deletion, and access logs before deployment, with staff trained on compliance procedures.
Table of Contents
- Call recording consent UK: the quick compliance checklist
- Consent vs legitimate interest vs legal obligation: which applies?
- PECR and automated or outbound marketing calls: stricter rules to watch
- AI voice agents and call analytics: what you must disclose
- Building the paperwork: LIA, DPA, retention and SARs
- What to demand from telephony and AI vendors before you sign
- Multi-party calls and cross-jurisdiction callers within the UK
- Training staff to keep call recording compliant day to day
- Compliant vs non-compliant: how the same call plays out two ways
- Template wording for a clear recording announcement
- FCA rules and what enforcement actually looks like
- Step-by-step: implementing compliant call recording from scratch
- How GMD Automation packages compliance into deployment
- See how compliant AI call handling actually runs
- Sources
Call recording consent UK: the quick compliance checklist
Get these controls live before you finish the paperwork behind them. They shrink your exposure while the governance catches up.
- Play an automated notice at call start: "This call is recorded for quality and training, and analysed using AI to support our team. Continue if you're happy to proceed."
- Screen every outbound marketing list against the Telephone Preference Service (TPS) and Corporate TPS (CTPS), and keep an internal suppression list for opt-outs.
- Turn on encryption at rest and in transit, and configure automated deletion at the end of your retention window rather than relying on manual purges.
- Keep recordings in searchable, indexed storage so a subject access request (SAR) can be answered within statutory timescales, not weeks of manual searching.
- Write down the lawful basis for every recording stream and file it alongside your Legitimate Interest Assessment (LIA).
Pro Tip: Record the AI disclosure line separately in your call flow logs, not just in the audio. If a regulator asks how many callers heard it, you want a timestamped answer, not a transcript search.
Consent vs legitimate interest vs legal obligation: which applies?
Consent under UK GDPR has to be freely given, specific, informed, and revocable at any point without penalty. That last part is the problem: a caller can withdraw consent mid-call, and you then have no lawful basis to keep recording a conversation you may need for a complaint or a contract dispute. Legal commentary on this is blunt: consent is not normally required for standard business call recording, and firms are better served relying on legitimate interests or lawful business practice rules, so long as callers are informed and the reasoning is documented.
Three lawful bases cover almost every scenario:
- Legitimate interest — the default for quality monitoring, training, and dispute evidence. Requires a documented LIA covering purpose, necessity, and a balancing test against caller privacy.
- Legal obligation — applies where a regulator mandates recording, such as FCA-regulated call handling, pension transfer advice, or claims management. This basis restricts your ability to delete recordings early and often extends retention.
- Consent — reserved for cases where no other basis fits, chiefly automated outbound marketing calls under PECR. Fragile, revocable, and needs a clean audit trail if you use it.
Map the purpose to the basis before you map the technology. A sales team recording cold calls for training sits on legitimate interest; the same team running automated dialling campaigns sits on PECR consent rules entirely.
PECR and automated or outbound marketing calls: stricter rules to watch
PECR is where most call recording programmes get tripped up, because it governs the call itself, not just the recording. Regulation 19 bans automated marketing calls without prior consent, full stop. Live marketing calls under Regulations 21, 21A and 21B are more flexible but still demand caller ID and TPS/CTPS screening.
- Automated marketing calls (recorded messages, AI-voiced outbound campaigns) need explicit prior consent under Regulation 19, no exceptions for "soft opt-in".
- Live calls must display a valid caller ID and give the recipient contact details for opting out.
- Numbers on the TPS or CTPS register cannot be called for marketing purposes unless the individual has separately consented.
- Recent ICO enforcement against firms running automated calling and avatar-driven campaigns shows fines running into hundreds of thousands of pounds, with director liability tightening under new legislation.
If you're running outbound AI voice agents for anything that could be read as marketing, treat Regulation 19 as a hard stop rather than a grey area. Our own breakdown of outbound calling AI covers where the inbound/outbound distinction actually bites.
AI voice agents and call analytics: what you must disclose
An AI transcript, sentiment score, or voice-cloned agent is not covered by the same lawful basis as the recording itself. The ICO treats AI-assisted analysis as a separate processing purpose, which means it needs its own line in your LIA and its own sentence in your privacy notice. Recording a call and then feeding it through a sentiment model without saying so is two processing activities disclosed as one.
- Update your LIA to name every AI use: transcription, sentiment scoring, voice cloning, automated summarisation.
- State AI processing in plain language in the pre-call announcement, not buried in a website privacy policy nobody reads.
- Build in human escalation for any AI voice agent handling a distressed, vulnerable, or underage caller.
- Keep model provenance and testing logs so you can show what the AI was trained to do if a regulator asks.
Outbound AI avatars carry the highest risk here, because they combine PECR's consent requirement with the ICO's AI disclosure expectation in a single call. Get legal sign-off before scaling an outbound AI pilot, and see our guide to AI function calling for where consent bites differently depending on how the AI is triggered.
Pro Tip: If your AI agent handles anything touching health, finance, or a child's data, double your documentation. Sensitive categories under UK GDPR mean the ICO expects a tighter balancing test, not the standard LIA template.
Building the paperwork: LIA, DPA, retention and SARs
The documents matter as much as the technology, because an auditor reads the LIA before they listen to a single call.
- Write a specific LIA, not a generic template. Name the exact purpose (quality assurance, fraud prevention, AI sentiment analysis), test necessity against alternatives, and record the balancing outcome against caller privacy.
- Negotiate a Data Processing Agreement (Article 28 DPA) with every cloud telephony or AI vendor, covering subprocessor lists, breach notification timescales, and explicit AI processing clauses.
- Set retention windows by purpose. General QA recordings commonly sit around 90 days; FCA-regulated advice calls need considerably longer, sometimes years, under sector rules. Automate deletion at the end of each window rather than relying on staff to remember.
- Index recordings for SARs from day one. A searchable, tagged store with redaction options turns a SAR from a week-long manual search into a same-day export.
Practical guidance on call recording setup for 2026 reinforces the same four pillars: LIA, AI disclosure, automated deletion, and searchable storage. Miss one and the other three don't hold up under scrutiny.
What to demand from telephony and AI vendors before you sign
Procurement teams should treat the DPA as a negotiating document, not a formality to accept as-is.
- Ask for explicit AI processing clauses in the DPA: what the vendor's models do with your call data, and whether they train on it.
- Request security attestations covering encryption standards, ISO 27001 or SOC 2 reports, and confirmation of UK/EEA data residency.
- Insist on automated deletion proof and access logs you can pull on demand, not just a promise in a sales call.
- Set incident response SLAs in writing, including breach notification timelines that match your own regulatory obligations.
A structured vendor procurement checklist saves weeks of back-and-forth with legal, and our notes on PCI-compliant call payments show how the same vendor-questioning discipline applies to payment data captured over the phone.
Multi-party calls and cross-jurisdiction callers within the UK
A three-way call between an agent, a customer, and a supervisor listening in still only needs one disclosure, provided it covers everyone on the line. The rule is simple in principle and messy in practice: every participant needs to be made aware recording is happening before they carry on speaking, and that includes anyone patched in mid-call. If a supervisor joins after the initial announcement, play a short secondary notice, or have the agent state out loud that a colleague has joined and the call remains recorded.
Conference and warm-transfer scenarios are where most contact centres slip. A call transferred from sales to billing, then to a specialist, technically restarts the disclosure requirement each time a new recording system or purpose kicks in, unless your platform treats the whole journey as one continuously recorded session with one notice at the start. The safest approach is a single, unified recording environment across departments, so the caller hears one announcement rather than three overlapping ones from different systems.
Jurisdiction inside the UK rarely varies for data protection purposes, since UK GDPR and PECR apply uniformly across England, Scotland, Wales, and Northern Ireland. Where it does matter is sector regulation: a call answered by a Scotland-based team advising on regulated financial products still falls under FCA rules regardless of where the caller is physically located, because the obligation attaches to the regulated activity, not the geography. Northern Ireland callers occasionally raise questions about parallel Irish data protection rules if the call crosses into a cross-border service, but for a UK business recording UK callers, the layered framework of LBPR, UK GDPR, and RIPA applies consistently regardless of which UK nation the caller is dialling from.

Training staff to keep call recording compliant day to day
Policy documents don't stop a tired agent from skipping the announcement on a busy Friday afternoon. Compliance lives or dies on habit, and habit needs deliberate training, not a one-off induction slide.
New starters should hear the recording announcement played back to them before they ever take a live call, so they understand exactly what the customer hears and when. Build a short monthly spot-check into team leader routines: pull five random calls, confirm the notice played, confirm it played in full, and confirm any AI disclosure line was included where relevant. This catches configuration drift, such as a script update that accidentally dropped the AI mention, long before it becomes a pattern across thousands of calls.
Give agents a clear script for the awkward moment when a caller objects to being recorded. Under legitimate interest, a caller can raise an objection, and staff need a rehearsed, calm response rather than an improvised one, such as offering to continue the call unrecorded where operationally possible, or escalating to a supervisor who can explain the lawful basis in more detail.
Refresh training whenever the lawful basis or vendor changes. Switching telephony providers, adding an AI sentiment tool, or expanding recording to a new department are all points where the announcement script, the LIA, and the staff briefing need to move together. Treat compliance training the same way you'd treat a fire drill: infrequent enough not to be annoying, frequent enough that nobody's first real test of it is during an ICO investigation.

Compliant vs non-compliant: how the same call plays out two ways
A retail energy supplier records inbound billing queries, plays a clear notice at call start ("this call is recorded for training and quality purposes"), documents legitimate interest in an LIA, and deletes recordings after 90 days unless flagged for a complaint. An agent mentions the call may be reviewed by an AI tool for tone analysis, matching what the privacy notice says. That's compliant: transparent, documented, time-limited.
Contrast that with a mortgage broker recording advice calls but never mentioning it, relying on legal obligation without confirming which specific FCA rule applies, and keeping every recording indefinitely on an unencrypted shared drive. No notice, no LIA, no retention policy, no SAR-ready storage. Any one of those gaps is a problem; together they're the profile of an ICO enforcement case waiting to happen.
A subtler failure: a contact centre does everything right on the human call, but bolts on an AI transcription tool without updating the privacy notice or LIA. The recording itself was lawful. The new processing purpose, silently added on top, wasn't disclosed anywhere the caller could see it. That's the gap the ICO's AI guidance specifically targets, and it's the easiest one for a growing business to miss because nothing about the phone call itself changed. The lesson: compliance isn't a single decision made once at setup. It's a live setting that has to be checked every time a new tool touches the call.
Template wording for a clear recording announcement
Keep the wording short, specific, and honest about what happens to the recording. A workable baseline: "This call may be recorded for training, quality, and dispute resolution purposes. We may also use automated tools to analyse this call. If you'd rather not continue on a recorded line, let us know and we'll do our best to assist another way."
For outbound marketing calls where PECR consent is required rather than assumed, the wording needs to ask, not inform: "We'd like to record this call and use automated analysis to improve our service. Is that alright with you before we continue?" That's a genuine consent request, not a notice, and it needs a clear yes captured and logged.
Where AI voice agents are handling the call entirely, disclose that upfront rather than letting the caller work it out from a stilted voice: "You're speaking with an AI assistant today. This call is recorded and analysed to help us respond accurately. A human colleague can join at any point if you ask."
Avoid vague catch-alls like "calls may be monitored" with no mention of recording, AI, or purpose. It technically says something, but it doesn't meet the ICO's transparency bar, and it gives a caller nothing to object to or ask about, which is itself a sign it's not doing its job.
FCA rules and what enforcement actually looks like
Financial services firms carry an extra layer on top of UK GDPR and PECR: FCA taping rules require certain regulated calls, particularly those involving execution of client orders, to be recorded and retained for a set period, commonly five years for some MiFID-scoped activities. That's a legal obligation basis, not legitimate interest, and it removes the option to delete early even if a customer asks.
Outside financial services, enforcement risk sits mostly with PECR breaches on automated and marketing calls. The ICO's enforcement pattern shows fines reaching into the hundreds of thousands of pounds for firms running automated or avatar-driven outbound campaigns without proper consent, and the direction of travel under the Data (Use and Access) Act points toward tighter penalties and clearer director liability rather than looser enforcement.
The ICO has also flagged that its live call marketing guidance is under review following that legislation, so treat current thresholds as a floor, not a ceiling. Building compliance with headroom now is cheaper than rebuilding it after guidance tightens.
Step-by-step: implementing compliant call recording from scratch
Roll this out roughly in order, since each step depends on the one before it.
- Map every call flow that gets recorded: inbound support, outbound sales, transfers, AI-handled calls. Different flows can need different lawful bases.
- Choose and document the lawful basis for each flow, defaulting to legitimate interest unless PECR or a sector rule forces consent or legal obligation.
- Write the LIA for legitimate interest flows: purpose, necessity, balancing test, mitigations.
- Draft the announcement script, including AI disclosure where applicable, and get it legally reviewed once rather than repeatedly.
- Configure the technical controls: encryption, automated retention and deletion, searchable indexing for SARs.
- Sign DPAs with every telephony and AI vendor before recordings start flowing through their systems.
- Screen outbound lists against TPS/CTPS and maintain your internal suppression list.
- Train staff on the script, objection handling, and what to do if a caller withdraws agreement mid-call.
- Set a review cadence, at minimum annually or whenever a new tool or vendor is added, to re-check the LIA and privacy notice still match reality.
Skipping the mapping step is the most common shortcut, and it's the one that causes the most rework later, because you end up retrofitting disclosure onto call flows nobody separately assessed.
How GMD Automation packages compliance into deployment
We build compliance into the subscription rather than treating it as a separate project. Every deployment ships with a documented LIA template, an Article 28 DPA, encryption by default, and automated retention rules configured before go-live, not bolted on afterwards. Clients get the PCI-compliant call payments playbook and a procurement checklist as standard reference material. The trade-off worth knowing upfront: broader AI analysis scope (sentiment scoring on top of transcription, for instance) adds a short review cycle, because each new processing purpose needs its own line in the paperwork before it goes live.
— Ravi
See how compliant AI call handling actually runs
Gmdautomation is the practical alternative to building this in-house or bolting AI onto a legacy phone system: one monthly subscription covers the LIA documentation, the DPA, the encryption, and the automated retention rules described throughout this guide, with zero upfront build cost.

Rather than assembling compliance piecemeal across a telephony vendor, a separate AI provider, and your own legal team, you get one managed system where implementation, ongoing operation, and optimisation are already priced into the subscription. That matters most for teams who don't have a dedicated data-protection resource to chase vendor DPAs and retention settings every quarter. If you're weighing up whether your current setup would survive an ICO audit, book a demo with Gmdautomation and walk through how a compliant AI voice deployment looks in practice, or start with a readiness conversation before you commit to a build.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Telephone marketing | ICO
- Call recording – consent is not normally required | Mishcon de Reya
- ICO, PECR enforcement and automated calls | Handley Gill
