What UK GDPR requires when an AI answers your phone
Transcripts are personal data, call recordings usually aren't biometric data, and the retention question is the one that bites. A practical read of the rules.
- compliance
- UK GDPR
- data protection
Do I need to do anything special under UK GDPR if an AI answers my calls?
The same duties you already had for phone enquiries: a lawful basis, a retention period you enforce, and the ability to delete one caller's data on request. What changes is volume: an agent that answers every call writes down every call, and records are easier to keep than to justify keeping.
In short
- A call transcript is personal data. So is a caller's phone number, and the message they left.
- A voice recording is personal data, but it is not automatically special category biometric data. It becomes that only when it's processed to identify or verify who is speaking.
- Handling an inbound call you were rung on generally rests on legitimate interests. It does not need consent, and a consent notice on an inbound call is usually theatre.
- Storage limitation is where most setups fail: keeping transcripts indefinitely because nobody chose a period is a breach of a principle, not a filing habit.
- Ask any supplier where processing happens, not just where storage happens. Both need to be somewhere you can defend.
Most of what you read about AI and data protection is written for the case where AI makes a decision about someone: a loan, a job application, a benefits claim. Answering the phone isn’t that. Nobody’s rights are being determined by whether the agent offered Tuesday or Thursday.
Which means the obligations here are the ones you already had for phone enquiries. What changes is the volume of written record, and that turns out to be the whole story.
What is personal data on a phone call?
More than people expect, and it starts before anyone gives a name.
The transcript is personal data whenever the caller is identifiable from it, which on a business enquiry they nearly always are: by name, by the number they rang from, by the address they gave you for the job. The caller’s number is personal data on its own. So is the message they left, and any note attached to it.
The practical move is to treat all of it as personal data by default rather than adjudicating case by case. The cases where it genuinely isn’t are rare enough that the sorting effort costs more than it saves.
The biometric claim, checked
You’ll be told (sometimes by us, in an earlier version of one of our own pages) that recording calls drags you into a biometric-data problem. That’s stronger than the ICO actually says, and it’s worth getting right.
A voice recording is personal data. It becomes special category biometric data under Article 9 when it’s technically processed in a way that identifies or verifies who is speaking: enrolling voices, building templates, matching a caller against them. Capturing a voice and not analysing it that way doesn’t cross the line.
So recording calls does not automatically create a special category problem. It creates an ordinary personal data problem, at volume, with an indefinite shelf life if nobody sets one.
That’s a smaller claim than the scary version, and still a good enough reason to avoid it if you don’t need it. We transcribe as the call happens and keep no audio, not because audio would be radioactive, but because the safest data is the data you never held. There is no recording to leak, to hand over, or to forget to delete.
Which lawful basis?
For handling an inbound call: legitimate interests, almost always.
Someone rings your business to book a job. Handling that enquiry, writing down what they need, and putting it in the diary is exactly what they rang for. You don’t need to ask permission to do the thing you were contacted to do, and a consent gate on an inbound call is usually a supplier covering itself rather than a requirement.
Consent becomes the relevant question when you start doing something the caller wouldn’t anticipate from a phone call: recognising them by voice across calls, say, or feeding their words into something unrelated to answering them. Those are decisions you’d make deliberately rather than drift into.
The one that catches people out: retention
Storage limitation says you keep personal data no longer than you need it for the purpose you collected it. There’s no number in the legislation, which is why this is where setups fail.
Failure looks mundane: transcripts accumulate because deleting them was nobody’s job, and three years later you hold a searchable archive of every conversation anyone had with your business, justified by nothing in particular. Nobody decided to do that. It’s what happens when the default is “keep”.
The fix is to choose a period, write down why, and make it automatic. We settled on 90 days for transcripts, caller numbers and messages, deleted on a schedule rather than a reminder. Call durations survive for invoicing, with nobody attached to them. Your period might be different and that’s fine. The point is having one that runs without you.
Questions worth asking a supplier
Ask these before you sign, and be unsatisfied with vague answers. They’re the same three we suggest asking anyone in this market, including us.
- Where is the data processed, and where is it stored? Not one or the other. A provider that stores in the UK or EU but sends the audio somewhere else for transcription has answered half the question.
- Is any audio retained? If yes: for how long, who can play it back, and what happens to it when you leave. If no, several other questions stop mattering.
- Can you delete one caller? A caller exercising erasure rights is a normal request, not an incident. If the honest answer is “we’d delete your whole account”, you’ve inherited a problem you’ll only discover under time pressure.
Two more worth adding if you’re in a regulated setting: who counts as controller and who as processor, and whether their sub-processor list is published.
What’s coming
The Information Commissioner has been placed under a statutory duty to produce a code of practice on AI and automated decision-making. The regulations creating that duty came into force on 12 May 2026.
The code itself hasn’t been published, and the regulations set no deadline for it, so anyone currently telling you what the ICO code requires is describing a document that doesn’t exist. When it does arrive it will be worth reading closely, and it will be about personal data rather than about telling callers they’re speaking to a machine. That’s a separate question with a separate answer.
Why this is easier than the notepad it replaced
Your obligations don’t change because software answers instead of a person. What changes is that a defined retention period, an erasure function, and a searchable record of what was said are all things you can point at. That’s more than most businesses could manage when the record was a name on a pad by the phone, and someone asked six months later what you held on them.
Sources
- Biometric recognition — Information Commissioner's Office, 2026.The ICO's own guidance on when biometric data becomes special category data. The distinction it draws (processing for unique identification) is the one most vendor copy skips.
- What is special category data? — Information Commissioner's Office, 2026.Definitional. Useful for checking claims that a given data type is automatically 'sensitive'.
- The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 — UK Statutory Instruments, SI 2026/425, 2026.In force 12 May 2026. Obliges the Commissioner to prepare an AI code of practice; the code itself is not yet published.