The Practice |
The customer support centre records all inbound and outbound calls for 'quality and training purposes.' Recordings, which often include the customer's name, account number, and sometimes payment or health-related details discussed during the call, are stored indefinitely on the telephony vendor's platform with broad access for supervisors and quality analysts.
Questions Raised for Compliance Review |
- Does indefinite retention of call recordings containing personal and occasionally sensitive data meet DPDP's requirements?
- What risks arise from broad internal access to recordings and third-party telephony vendor storage?
- What is the compliant approach to call recording practices in a support centre environment?
Is This Permitted Under DPDP? |
Conditionally permissible — recording itself is a common and reasonable practice, but the current retention and access model is not compliant.
Recording calls for quality and training is a legitimate and widely accepted purpose, provided customers are clearly informed at the start of the call and the resulting data is handled proportionately. Indefinite retention with broad, unrestricted internal access goes beyond what is necessary for that stated purpose and creates exposure disproportionate to the operational benefit.
Where the Breach Risks Sit |
- Retention with no defined end point — Recordings kept indefinitely, rather than for a defined quality-review window, have no ongoing lawful basis once the immediate training or quality purpose has been served, and represent an accumulating liability with no corresponding operational benefit.
- Sensitive data incidentally captured — Calls that touch on payment details, health conditions relevant to a service request, or family circumstances mentioned in the course of resolving a complaint are all captured and retained at the same standard as routine calls, without any process to flag and handle these recordings with elevated care.
- Broad, undifferentiated internal access — If any supervisor or quality analyst can access any recording regardless of whether they were involved in that specific call or review cycle, the organisation has not applied data minimisation to who can hear a customer's sensitive disclosures.
- Vendor-hosted recordings with unclear terms — Recordings stored on the telephony vendor's platform are subject to that vendor's own retention, security, and access practices, which may not be governed by a data processing agreement addressing DPDP-specific obligations.
The Ideal Compliant Approach |
- Define and enforce a specific retention period. Set a defined retention window for call recordings — sufficient for the quality and training purpose, typically a matter of weeks to a few months — with automatic deletion thereafter, retaining specific calls beyond that only where a documented, escalated need exists (e.g., an active dispute).
- Restrict access on a role and need basis. Limit recording access to the specific quality analysts and supervisors reviewing that call or that agent's cycle, rather than granting blanket access across the support organisation.
- Flag and handle sensitive-content calls distinctly. Where feasible, implement a tagging process for calls identified as containing sensitive data (payment, health) so these can be subject to shorter retention or additional access restriction.
- Formalise the telephony vendor relationship under a DPA. Ensure the vendor agreement explicitly addresses retention limits, deletion obligations, security standards, and breach notification for call recording data specifically.
DPDP Risk Summary
| Element | Status | Recommended Action |
|---|---|---|
| Recordings retained indefinitely | No lawful basis beyond stated purpose | Define retention window with automatic deletion |
| Sensitive data captured without differentiated handling | Elevated exposure, no safeguard | Tag and apply shorter retention to sensitive-content calls |
| Broad internal access to all recordings | No data minimisation | Restrict access on role/need basis |
| Vendor-hosted recordings without DPDP-specific DPA | Vendor / Processor Risk | Update telephony vendor agreement with DPDP terms |
| Customers not clearly informed calls are recorded and retained | Transparency obligation | Confirm clear, audible recording disclosure on every call |