Can you record phone calls and have AI summarise them?
Yes, you may record calls with your own customers: Article 139c of the Dutch Criminal Code only prohibits recording communication you are not a party to. That is not the end of it. You must announce in advance that you record and why, you need a lawful basis per purpose, you may not capture more than you need, and you set a retention period you can explain. If one of your own staff is on the call, the works council's right of approval applies too. Once the AI conducts the call itself, the notice duty in Article 50 of the AI Act is added.
Published on
Recording a phone call and having AI summarise it afterwards sounds like a small step. Technically it is. Legally it is not. The moment you record, you capture someone else's voice, and a voice is personal data. That brings three sets of rules into play at once: the Dutch Criminal Code, the GDPR, and — as soon as one of your own staff is on the call — employment law and the Works Councils Act. This page sets out what applies, in what order you should arrange it, and where things go wrong in practice.
Are you allowed to record a call with your own customer?
In principle yes, provided you meet the conditions. The starting point is Article 139c of the Dutch Criminal Code. It makes it an offence to intentionally and unlawfully use a technical device to record data that is not intended for you. That is classic eavesdropping: listening in on communication you are not a party to. If you are on the line yourself, or the call runs over a connection you are the authorised holder of, the call is intended for you and the prohibition does not apply.
The distinction matters. Recording a call between your own customer service team and your own customer is legally something quite different from listening in on a conversation between two other people. The moment you record calls your business is not a party to — for example by letting a system listen in on a line you do not control — you are on criminal law territory.
The fact that criminal law does not stand in your way only means the recording is not unlawful in that sense. It does not mean you are done. The GDPR adds its own requirements: you need a concrete purpose, a lawful basis, you have to give notice in advance, you may not capture more than you need, and you need a retention period you can explain. The two tracks run side by side. A recording can be entirely fine under criminal law and still breach the GDPR.
Also pay attention to what exactly you keep. The audio is personal data, but so are the transcript and the AI summary. A transcript is not a watered-down version of the recording. It is the same content, only searchable, copyable and easier to share. In practice the text version is often the bigger risk, because it ends up in a CRM that far more people can access.
What do you have to announce in advance, and to whom exactly?
Notice comes first, before anything is captured. And you announce two things: that you are recording and what you use the recording for. The Dutch data protection authority is explicit about calls made by employees: the person your employee is speaking to — the customer, in other words — must also be informed in advance that the call is being recorded and what the recording will be used for. Informing your own staff alone is not enough.
The standard announcement "this call may be recorded for training purposes" is therefore often too narrow. If you also use the recording to prove what was agreed, to handle complaints, or to produce an AI summary that ends up in the customer file, "training purposes" does not cover those aims. State the real purpose in the announcement, in plain language.
The full explanation does not have to fit into the announcement. Article 13 GDPR requires you to state both the purpose and the legal basis when you collect the data, but you can do that in layers. In practice: a short, clear announcement at the start of the call or in the menu, with a reference to your privacy statement where the whole story sits — which purposes, which basis, how long you keep it, who has access, and how someone requests access or deletion.
One misunderstanding needs clearing up straight away. An announcement is not consent. Carrying on talking after a notice is not an active, free choice; it is only evidence that the customer was informed. Informing people and having a lawful basis are two separate obligations. You can give perfect notice and still have no valid basis.
Quality or evidence: why the purpose decides everything
Almost every mistake with recordings comes down to one thing: no sharp purpose was written down. Yet the purpose is exactly what determines which basis fits, what you have to announce, how much you may record and how long you may keep it.
Recording for quality is about your own process: how do we run conversations, where do customers get stuck, where does an employee need coaching. For that purpose you rarely need every call. A sample is usually enough, and a sample is less intrusive. That difference counts legally, because you have to be able to show your purpose could not have been achieved by lighter means.
Recording as evidence is something else. There it is about one specific call in which an agreement is made: an order, a renewal, an acceptance of terms. That calls for a different regime. You have to be able to retrieve that recording per customer, you keep it as long as you need to be able to prove the agreement, and you announce that this is why you are capturing it.
You may not silently mix those two purposes. Purpose limitation means a recording made for quality cannot simply resurface later as evidence in a dispute, and vice versa. If you want to use a recording for a new purpose, you reassess whether that purpose is compatible with the original one, and usually you have to give notice again.
The classic anti-pattern is: record everything, keep everything, we will work out later what it is good for. That is precisely what the GDPR rules out. No purpose up front means no basis, and without a basis the processing is unlawful.
Which lawful basis do you need for a recording?
Article 6 GDPR lists six bases. For call recordings in a small or medium-sized business, three realistically come into play.
- Legitimate interests (Article 6(1)(f)). The most commonly used basis for quality recordings. The text says the processing must be necessary for the purposes of your legitimate interests, except where the interests or fundamental rights of the data subject override them. That "except" is the heart of it: a balancing test always comes with it.
- Performance of a contract (Article 6(1)(b)). Fits where the recording is genuinely needed to perform or record the agreement, for instance with a contract concluded by phone.
- Consent (Article 6(1)(a)). Needed as soon as you do something the customer cannot reasonably expect. Think of using recordings to train an AI model.
For legitimate interests you have to answer three questions before you start. Is there a real, concrete interest — not "handy", but an interest you can name? Is recording necessary, or would a lighter means achieve the same, such as a call note, a sample or a satisfaction question? And do the rights of the customer and the employee not outweigh your interest? That assessment has to be made and documented before you begin. Working out afterwards why it was allowed does not count.
Consent sounds safer but is awkward over the phone. Consent must be freely given, specific, informed and unambiguous, and it must be withdrawable. Freely given means the customer can also say no without consequences — so you must be able to run the call without recording. If your system cannot do that, the consent is not free and you still have no valid basis. So build a route without recording, or pick another basis and document it.
If the call touches on health, religion, trade union membership or a criminal record, you are in a stricter regime with its own exceptions. A clinic or a healthcare practice therefore cannot stop at the reasoning above.
How long may you keep a recording?
The GDPR names no concrete number of days or months. The Dutch data protection authority says so itself: the GDPR contains no concrete retention period, organisations set it themselves, and other laws do contain concrete periods you have to comply with. The starting point is that you keep data no longer than necessary, and what is necessary depends on your situation — so you set the period and you must be able to explain it.
The practical route: tie the period to the purpose, not to how much storage you happen to have. You need a quality recording until the coaching or the analysis is done; after that it is redundant. A recording that serves as evidence of an agreement is kept for as long as you need to be able to prove that agreement. If the record forms part of your business administration, the statutory tax retention duty on that administration keeps running and you cannot delete it earlier just because the GDPR would prefer it.
Two things routinely go wrong here. First, clearing up stays manual work, and manual work does not happen. Put the period into the system, with automatic deletion. Second, only the audio gets wiped. The summary is still in the CRM, the transcript in the search index, a copy in the backup and log lines at your supplier. That is not deletion. Your retention period applies to every derivative of the recording, not just to the sound file.
| Purpose of the recording | Basis that fits | What you announce in advance | What the retention period depends on |
|---|---|---|---|
| Quality and coaching | Legitimate interests, with a balancing test documented up front | That you record, that it is for quality and training, and that employees are assessed on it | Until the analysis or the coaching is done; work with a sample instead of everything |
| Evidence of an agreement made by phone | Performance of a contract, or legitimate interests | That you capture the call in order to be able to prove the agreement | As long as you need to be able to prove the agreement; delete after that |
| Part of your business administration, such as an order or a payment | Legal obligation | That the record forms part of your administration | As long as the statutory retention duty on that administration runs |
| Complaint or dispute | Legitimate interests | That you keep calls about an open complaint until it is resolved | Until the file is closed; do not keep every call by default "just in case" |
| Training an AI model on your own recordings | Consent, asked separately for this purpose | That the recording is used to improve an AI system, and that refusing is allowed | Only while the consent stands; withdrawal has to have effect |
| Assessing individual employees | Legitimate interests, plus works council approval where there is one | To the employee: what is measured, how, and what happens with the outcome | As short as possible; keep the outcome, not the full audio by default |
What extra rules apply when an employee is on the call?
In customer contact there is almost always one of your own staff on the line. That gives you two data subjects in the same call: the customer and the employee. You have to inform both, and for the employee extra rules apply.
The right to privacy applies on the work floor too. An employer may not simply monitor staff, and monitoring has to be necessary: you must not be able to achieve your purpose in a way that is less intrusive for your people. A system that captures and rates every call by every employee, while a sample would give the same insight, fails that test.
On top of that comes the Works Councils Act. Article 27 gives the works council a right of approval for any arrangement concerning facilities that are "aimed at or suitable for observing or monitoring the attendance, behaviour or performance" of the people working in the business. Note the word suitable. Your intention is not decisive. A system that records, transcribes and scores employees' calls is suitable for monitoring behaviour and performance — even if you introduce it to help customers faster. That brings it within the right of approval.
Approval is more than advice. The works council has to agree to the arrangement before you introduce it. If you skip that step, the decision can lose its effect once the works council invokes that in writing. You then have a system in place that you formally may not use. So involve the works council early, with a concrete set of rules: which calls, what purpose, who listens in, what happens with the outcome, and how long it stays.
If you have no works council, Article 27 falls away but the GDPR requirements do not. Record in writing what is recorded and why, discuss it with your team, and put it in the staff handbook. And bear in mind that home working gives you no extra room: the same rules apply to remote monitoring as to monitoring in the office.
What changes when an AI listens in instead of you listening back afterwards?
Listening back afterwards is human work: someone picks a handful of calls, after the fact, for a reason. An AI listening in is different in kind: every call, in full, automatically, permanently. Five things shift as a result.
From a sample to everything
Because it costs nothing technically to process everything, that is what happens. But the necessity test only gets stricter as a result. "We do everything because we can" is not necessity. Anyone having a hundred per cent of calls analysed has to explain why a portion would not have been enough.
An extra notice duty as soon as the AI speaks itself
If the AI only listens in while a human runs the call, you stay with the GDPR notice about the recording and its purpose. If the AI system conducts the call itself, the transparency duty from the AI Act comes on top. Article 50 provides that this information must be given at the latest at the time of the first interaction, in a clear and distinguishable manner. So right at the start of the call, not halfway through and not only at the bottom of the privacy statement.
From observing to assessing
An AI that summarises calls is one thing. An AI that gives employees a score, ranks them or flags who deviates from the script is a staff monitoring system in the fullest sense. That puts you in the track described in the previous section, and in the employment context the AI Act imposes heavier requirements as well. Assess that separately before you switch such a feature on.
The summary is itself personal data
An AI summary is not a neutral rendering. It is a new piece of data about a person, produced by a model, and it can be wrong. A customer has the right to see what you have recorded about them and to have it rectified if it is incorrect (Articles 15 and 16 GDPR). So make sure summaries are retrievable per customer, recognisable as machine-generated, and correctable. A wrong summary that stays in your file as fact is a problem that grows.
The supplier joins the picture
As soon as an external party processes the audio, that party is a processor and you need a processing agreement (Article 28 GDPR). Look at three things: where the audio is processed and stored, how long it stays there, and whether the supplier uses your calls to improve its own models. That last one is a purpose of the supplier's own and cannot quietly ride along on your quality purpose. Beyond that, an AI that systematically analyses calls from customers and employees is exactly the kind of new technology for which Article 35 GDPR requires an assessment beforehand. Do it before you go live, not when the regulator calls.
What do you arrange concretely before switching the recording function on?
- Write down, per type of call, what the purpose of the recording is. One line per purpose, in plain language.
- Pick a lawful basis per purpose and document the balancing test in writing, before you start.
- Draft the announcement for the start of the call, and update your privacy statement with purpose, basis, retention period and rights.
- Set a retention period per purpose and put it into the system, including transcripts, summaries, backups and logs.
- Decide who may hear or read the recordings and summaries, and actually restrict that access.
- Arrange the processing agreement with your supplier and record that your calls are not used for its model training, unless you explicitly want that and arrange it separately.
- Inform your employees in writing and start the works council process if you have one.
- Set up a route for access, correction and deletion requests that also covers the summaries.
- Carry out the prior assessment under Article 35 GDPR, and keep the outcome. That is also your evidence that you thought it through.
Anyone with these nine points on a single sheet can show, within a minute, what happens and why it is allowed — whether the question comes from a customer, an employee or the regulator. That is ultimately the difference between a recording that helps you and a recording that becomes a problem.