I've worked in the call recording industry for over 20 years. There's lots of speculation on this thread about what might be the law, so here's a few pointers.
1) The UK did havesingle party consent on call recording. Ofcom offered some fuzzy guidance thatrelated to how to inform callers if you wanted to record calls and mostorganisations have adapted that guidance to align with GDPR. When a largecompany calls you there is a very good chance you are being recorded eventhough they haven't told you. There's no illegal about that.
2) You do not haveto inform ALL callers they are being recorded. You should make "reasonableeffort" to inform callers. Try not to separate call recording from otherforms of data processing. For example, do you inform customers BEFORE theyemail you that you'll store those emails? Adding it to you website would beconsidered reasonable effort but you need to consider whether you want toinform as many parents as possible. If you do then there are clearly extralengths you could take.
3) It is not alegal requirement for insurance companies to record calls. Traders and some IFAare really the only sectors that have to do it.
4) Companies usetheir auto-attendant to announce calls are being recorded, not because theyhave to but because disputes tend to be reduced when customers know they arebeing recorded.
5) GrumbleDook iscorrect, if you have "legitimate interest" in recording clients youcan. If you want to tell parents it's required to protect staff and forms acrucial part of your business processes you can. Once that parents child is nolonger attending the school they have a right to ask for ALL their personaldata to be deleted, including emails etc.
6) Ditto iscorrect, GDPR refers to personal data being encrypted. If the recording isbuilt into your phone system it probably creates mp3 or wav files that aren'tencrypted. You may have to consider a bolt on that offers encryption.
There's still amisconception that stems back to the 90's that recording calls is somehow unlawfullycapturing personal information. Probably because phone systems never originallyincluded it. Consider how emails are viewed in comparison. You'd never expectan email to be deleted after you've read or sent it, but as you can see in thisthread, some people still don't view a telephone call comparably. GDPR doesn'tdistinguish between forms of personal data captured and stored using differentmethods, whether that be a phone call, email, letter received, online form etc.