Business Call Recording Policy Template for SMEs
by PBX.lu Editorial on July 2, 2026
This template is a starting point, not legal advice. Adapt it to your processing purpose, sector and applicable Luxembourg employment/data-protection requirements.
Every business that records calls needs a written policy before the first recording starts. Without one, you risk enforcement action from your national data protection authority, employee disputes, and recordings that cannot be used as evidence because no one can prove they were made lawfully. In Luxembourg, the CNPD (Commission nationale pour la protection des données) expects organisations to document not just what they record, but why, for how long, and who can access those recordings. This template gives you a clause-by-clause starting point you can adapt to your situation.
The template covers the Greater Region: Luxembourg, Belgium, France, and Germany. Where national rules diverge from the baseline, notes flag the difference. The legal basis you choose shapes every other clause, so the template begins there.
Before you write: pick your legal basis
Two grounds under GDPR Article 6 apply to most SME call recording scenarios. The one you choose determines how you draft the announcement clause and the consent documentation.
Legal basis is the GDPR term for the lawful reason that permits you to process personal data, in this case a voice recording. Choosing the wrong basis, or choosing none, makes the recording unlawful regardless of any other precaution you take.
Legitimate interest (Article 6(1)(f)) means your organisation has a genuine business reason to record that is proportionate to the caller's privacy rights. A Legitimate Interest Assessment (LIA) is a short written document where you weigh your business purpose against the impact on the caller, and conclude that your interest prevails. The CNPD expects to see a completed LIA if you rely on this basis.
🟢 Legitimate interest works when the recording has a clear, predictable business purpose (quality control, dispute evidence, compliance audit); you have completed and dated a Legitimate Interest Assessment; the outcome would not surprise a reasonable caller; and the calls do not routinely involve special-category data such as health information or legal advice.
🟡 You need explicit consent when the service involves sensitive topics (health queries, debt counselling, HR grievances); you cannot demonstrate a business purpose that outweighs the caller's privacy interest; the recordings will be used beyond the original call (for example, marketing analysis or AI training); or you operate in France, where CNIL guidance sets a higher bar for legitimate interest in B2C recording contexts.
The CNPD does not prescribe a single legal basis for call recording, but its published guidance on employee monitoring and its Article 30 template for records of processing activities both require that the chosen basis is documented before processing begins. A policy that sits in a drawer, unsigned, is insufficient. The policy must be communicated to employees before they handle recorded calls, and to callers before recording begins.
The policy: 8 clauses
Each clause follows the same structure: a plain-language explanation of what the clause does, followed by a copyable draft clause in a gray callout. Replace all bracketed placeholders with your own details.
Clause 1: Purpose and scope
A narrow, specific purpose is easier to defend to a regulator than a broad catch-all statement. If you record for quality training, say so. If you also record for dispute resolution, list both purposes explicitly. The clause also defines which lines are covered so that agents on unrecorded lines do not have to apply recording procedures.
📄 Draft clause: Purpose and scope
"[Organisation name] records telephone calls received and made on the following lines: [list lines, extensions, or departments]. Recordings are made for the following purposes only: [quality monitoring and agent training / evidence in contractual disputes / regulatory compliance: delete as appropriate]. Calls on lines not listed above are not recorded. This policy applies to all employees, contractors, and third-party agents who handle calls on those lines."
Clause 2: Legal basis
This clause states the GDPR Article 6 basis you have chosen and, where relevant, the Article 9 basis if special-category data arises. If you rely on legitimate interest, reference the Legitimate Interest Assessment you have completed. If you rely on consent, reference the consent mechanism. Never leave this clause blank or generic.
📄 Draft clause: Legal basis
"Call recordings constitute personal data under GDPR Regulation (EU) 2016/679 and, where applicable, the Luxembourg Data Protection Act of 1 August 2018. [Organisation name] processes this data on the basis of legitimate interest (Article 6(1)(f)), as documented in the Legitimate Interest Assessment dated [date], reference [LIA-001]. / [Organisation name] processes this data on the basis of the caller's explicit consent (Article 6(1)(a)), obtained via the announcement described in Clause 3. [Delete whichever basis does not apply.]"
Clause 3: Caller announcement
The announcement must play before any substantive conversation begins. If a caller objects to recording, the agent must either transfer to an unrecorded line or end the call. The three scripts below are one-line examples: adapt length to your IVR system or agent opening script. All three languages are provided because many businesses in the Greater Region receive calls in more than one language.
📄 Draft clause: Caller announcement
"Callers are informed of recording before the call is connected to an agent, via an automated announcement on the following lines: [list lines]. The announcement plays at the point of queue entry / answer [delete as appropriate]. Where a caller objects to recording, the agent will [offer transfer to an unrecorded line / end the call: specify]. The announcement wording is reviewed annually and updated whenever the recording purpose or legal basis changes."
Announcement scripts, one per language:
"This call may be recorded for quality and training purposes."
"Cet appel peut être enregistré à des fins de qualité et de formation."
"Dieses Gespräch kann zu Qualitäts- und Schulungszwecken aufgezeichnet werden."
🌐 Do callers need to actively accept, or is announcing enough?
If your legal basis is legitimate interest, announcing the recording before the call begins is generally sufficient: the caller can end the call if they object. If your legal basis is consent, you need a positive action from the caller, such as pressing a key to accept, before the recording starts. France requires a more explicit consent mechanism in B2C scenarios even where legitimate interest might otherwise apply. Check with a local legal advisor if you serve significant volumes of French consumers.
Clause 4: Retention
The general data minimisation principle (GDPR Article 5(1)(e)) requires that you do not keep recordings longer than necessary. Different purposes justify different periods. Set your Cloud PBX platform to delete recordings automatically at the end of each period rather than relying on a manual deletion task. See the retention guidance section below for typical periods by purpose.
📄 Draft clause: Retention
"Recordings are retained for the following maximum periods by purpose: [Quality monitoring and training: 30 days / Dispute resolution: 12 months from the date of the relevant transaction / Regulatory compliance obligation: [X] years as required by [name the regulation]: complete as applicable]. Recordings are deleted automatically at the end of the applicable retention period via [describe your Cloud PBX platform setting]. Recordings required as evidence in an active legal dispute may be retained beyond the standard period until the dispute is resolved, documented under reference [case or ticket number]."
Clause 5: Access and security
Access should be role-limited: not everyone who handles calls should be able to replay all recordings. The level of security should match the sensitivity of the content. If your recordings are stored by a Cloud PBX provider, verify that their data processing agreement confirms storage within the EEA and that they hold an appropriate security certification such as ISO 27001.
📄 Draft clause: Access and security
"Access to call recordings is limited to: [list roles, for example: team leaders for quality review / HR for disciplinary purposes / legal counsel for dispute evidence / IT administration for system maintenance]. Access is authenticated via [describe: role-based access in the Cloud PBX platform / separate credentials / audit log]. All access is logged. Recordings are stored [in the Cloud PBX provider's encrypted storage / on-premises at [location] with encryption at rest]. [Organisation name] has reviewed the Cloud PBX provider's data processing agreement and confirmed that recordings are stored within the EEA."
🔐 What to check in your Cloud PBX provider's data processing agreement
The data processing agreement (DPA) is the contract between you (the data controller) and your Cloud PBX provider (the data processor). For call recordings, it should confirm: the storage location and that it is within the EEA; the provider's sub-processor list; the provider's deletion timeline once you terminate the service; and the provider's security certifications. If your provider cannot supply a signed DPA on request, that is a significant compliance risk. The Voxbi Cloud PBX platform stores recordings within the EEA and provides a DPA to customers on request.
Clause 6: Employee notification
Recording employees without their knowledge is unlawful in all four Greater Region countries. This clause documents how and when employees are informed, and where the policy is accessible to them. New employees must be informed before they handle any recorded line, not at the end of the onboarding week.
📄 Draft clause: Employee notification
"All employees, contractors, and agents who work on recorded lines are informed of this policy before they begin handling calls on those lines. Notification is given via [written confirmation in the employment contract / onboarding documentation / signed policy acknowledgement: specify]. This policy is accessible to all staff at [intranet location / shared drive path / policy register reference]. Changes to this policy are communicated in writing with a minimum of [14 / 30] days notice before taking effect."
Clause 7: Data subject requests
Callers whose voices are recorded are data subjects with GDPR rights: access, erasure, rectification, and objection. This clause defines how your organisation handles those requests and within what timeframe. The standard GDPR response window is one calendar month from receipt of the request.
📄 Draft clause: Data subject requests
"Any individual whose voice is recorded may submit a data subject request to [data protection contact name or role] at [email address], referencing the approximate date and time of the call and the number called. [Organisation name] will respond within one calendar month of receipt. Requests for erasure will be fulfilled unless the recording is retained under a legal obligation or as evidence in an active dispute, in which case the requester will be informed of the reason for retention. All requests are logged in the data subject request register."
Clause 8: Exclusions
Certain call types must never be recorded. Payment card calls fall under PCI DSS rules that prohibit storing sensitive card data. Calls covering special-category topics are disproportionate to record under GDPR Article 9 unless a specific Article 9(2) basis exists and is documented. List your exclusions explicitly so agents know when to pause or avoid recording.
📄 Draft clause: Exclusions
"The following call types are excluded from recording: (a) calls during which the caller provides full payment card details (card number, CVV, expiry date), in compliance with PCI DSS requirement 3.2; agents handling such calls must pause recording before the caller reads card details aloud, using [describe pause mechanism in your Cloud PBX platform]; (b) calls handled by [legal / HR / occupational health: specify] that routinely involve special-category data under GDPR Article 9; (c) calls to or from [list any specific lines excluded for operational reasons]. Where an agent is uncertain whether a call falls within an exclusion, the default is not to record."
⏸ How call recording pause works in practice
Most Cloud PBX platforms allow agents to pause and resume recording mid-call via a softphone button or keyboard shortcut. The pause creates a gap in the recording file: the gap itself is not stored. Some platforms also support automatic pause triggers based on DTMF tones, which can pause recording the moment the IVR switches to a card-entry keypad. If your platform does not support pause-and-resume, the safest approach is to transfer card payment calls to an unrecorded IVR flow before any card data is spoken. Confirm your platform's capabilities with your Cloud PBX provider before drafting this clause.
Retention guidance by purpose
Retention periods depend on why you made the recording. There is no single correct number: the right period is the shortest one that still serves the documented purpose.
🟦 Quality monitoring and agent training
Typical period: 30 to 90 days. Most organisations find that recordings older than 90 days have no remaining training value. Automated deletion at day 30 is common in Cloud PBX platforms. The shorter the period, the easier it is to defend to a regulator.
🟦 Dispute resolution and contractual evidence
Typical period: 12 months from the transaction date, aligned with standard limitation periods for operational contract disputes. Retain beyond 12 months only if litigation has started and the recording is named as evidence.
🟦 Regulated sector compliance: financial services and insurance
MiFID II requires investment firms to retain telephone records for a minimum of 5 years (7 years on CSSF request in Luxembourg). Check your sector regulator's current guidance before setting this period, as it overrides general GDPR data minimisation for regulated records.
🟦 Healthcare and social services
Avoid recording calls that routinely cover diagnosis, treatment, or care plan details unless you have a documented legal basis under GDPR Article 9(2) and a specific retention period set by your sector regulator. Where doubt exists, exclude the line from recording scope entirely. See the Cloud PBX for Healthcare and Medical page for further context.
🚫 Common mistakes
Setting a blanket retention period (for example, "5 years for all recordings") without a documented purpose that justifies the length.
Playing the announcement after the call connects to an agent, not before, meaning the recording has already started.
Granting all team members access to all recordings rather than limiting access by role.
Forgetting to pause recording during card payment collection, exposing the organisation to PCI DSS non-compliance.
✅ Good practice
Run a Legitimate Interest Assessment before you go live, document it, date it, and store it alongside this policy.
Set your Cloud PBX platform to delete recordings automatically at the end of the retention period rather than relying on a manual deletion task.
Include a recording policy acknowledgement in your standard employment onboarding pack.
Review this policy annually, or whenever you add a new recorded line or change your Cloud PBX provider.
Before adopting this template, have it reviewed by a legal advisor qualified in data protection law in your operating country.
📚 Explore related resources on pbx.lu
Read how Cloud PBX platforms handle Call Recording technically, or look up key GDPR terms including Call Recording Consent in the Regulatory and Compliance glossary. If your project also involves defining service requirements, the Phone System Requirements Template is a useful companion. Common questions about recording obligations are answered in the FAQ.
📅 Ready to explore Cloud PBX for your business?
A short conversation with an independent consultant often saves weeks of evaluation. The session is free and takes about twenty minutes.