Jump to content

Recommended Posts

Posted
2) You do not haveto inform ALL callers they are being recorded. You should make "reasonableeffort" to inform callers. Try not to separate call recording from otherforms of data processing. For example, do you inform customers BEFORE theyemail you that you'll store those emails?

 

I think the difference there is we know emails are routinely kept, same goes for hard copy post, because that's how the technology works. Phone calls are not routinely recorded - and certainly weren't at their inception - therefore people don't necessarily expect their calls to be recorded.

Posted

I'm not a lawyer, but I am a DPO and spent a lot of time going through Opendium's GDPR compliance when the new legislation came in. This is written from the perspective of GDPR compliance... a bit of Googling shows some websites suggesting that you don't have to inform people about the call being recorded so long as it is for certain purposes. However, I'm very suspicious about that since it doesn't seem to fit with requirements of GDPR.

 

In general, you do not want to use "consent" as a lawful basis for anything unless you absolutely have to - it introduces a whole load of requirements that you probably don't want to deal with, including having to handle opt-outs. You certainly can't argue that someone has consented just because you've posted a policy on your website - you've got no way to show that someone read and agreed to that policy before they called you. Consent has to be "informed" (i.e. the subject has to understand what they are consenting to and means that consent has to be an "opt in" process, not an "opt out" one), "freely given" (they can't be penalised in any way if they don't consent) and if you get challenged at a later date you've got to be able to prove that they gave that consent.

 

You can probably use "legitimate interests" as an appropriate lawful basis. If you did that, people can't just ask to opt out of being recorded when they make a phone call. The data subject may still be able to exercise their right to erasure and ask you to delete the recording, but that shouldn't be a problem since GDPR gives you a month to action that request, and you already said you auto-delete the data after a month.

 

Your legal basis, purposes for processing, rights the subject has, etc. should all be in your privacy policy. Publish that on your website and play a "calls may be recorded" notice at the start of every call, with the recording signposting people to the privacy policy on your website if they want more information.

 

Are you recording outbound calls as well? Playing a "calls will be recorded" notice on outbound calls sounds tricky.

  • Thanks 1
Posted

 

Are you recording outbound calls as well? Playing a "calls will be recorded" notice on outbound calls sounds tricky.

 

Yes we are at present - technically not possible for outbound with our system like many big businesses dont - so would staff have to inform the receiver that the call is being recorded for monitoring and training purposes? If they don't warn then it can't be used?

Posted
I think the difference there is we know emails are routinely kept, same goes for hard copy post, because that's how the technology works. Phone calls are not routinely recorded - and certainly weren't at their inception - therefore people don't necessarily expect their calls to be recorded.

I think there's a significant difference between communications (whether they be email or phone call) being kept by the recipient, and them being routinely kept by the organisation as a whole.

 

i.e. compare:

* You email [email protected], Bob reads your email and files it away in his "Archive" folder for his own future reference

vs

* You email [email protected], the mail system automatically archives a copy of the email. Bob's manager looks at the email copy for training purposes, etc.

 

I know that in the first example, technically Bob's manager could ask the sysadmin to pull the email out of Bob's archive, but the original intentions behind these situations are quite different. The first example is probably what most people expect to happen to email.

Posted
Yes we are at present - technically not possible for outbound with our system like many big businesses dont - so would staff have to inform the receiver that the call is being recorded for monitoring and training purposes? If they don't warn then it can't be used?

I think callcentres train their staff to inform the callee that they are being recorded... obviously that's a lot easier with callcentre staff who are following a script as their main job. You probably need to seek some legal advice from someone who's actually a lawyer, I'm afraid, because the whole area of call recordings seems to be covered by about 10 pieces of overlapping legislation.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...