Skip to content
AI employeesPublished 9 min readBy 7 Minds Systems

Last updated

Call recording, consent and UK GDPR when an AI answers the phone

Consent is one lawful basis out of seven, and often the wrong one to choose. What the ICO actually requires when calls are recorded, what has to be said at the start, and what changes when a caller mentions their health.

Key takeaways

  • There are seven lawful bases under Article 6 of UK GDPR. The ICO states that no single basis is better or more important than the others, and that the one you need depends on your purpose and your relationship with the person.
  • The basis must be decided and documented before processing starts, and the ICO warns you cannot usually swap away from consent later.
  • Necessity is a real test: a basis does not apply where the purpose can reasonably be achieved by less intrusive means or by processing less personal information.
  • Privacy information must be given at the time the data is collected, which on a call means at the beginning of it.
  • The ICO endorses layering and just-in-time notices, so a short spoken line pointing to the full notice is a recognised approach.
  • Health details volunteered on a call are special category data and need an Article 9 condition on top of the lawful basis, documented in advance.

This is the first question every regulated buyer asks, and the common answer is wrong. Recording a call does not automatically require consent. Consent is one of seven lawful bases under UK GDPR, choosing it carries consequences most organisations have not thought through, and for routine call handling another basis is often the better fit. What is genuinely mandatory is telling the caller, at the start, in terms they can follow.

Consent is one lawful basis out of seven, and often it is the wrong one to pick. The ICO states that seven lawful bases are available under Article 6, that no single basis is better or more important than the others, and that the right one depends on your purpose and your relationship with the person. For a business recording calls to its own line the realistic choice is between consent and legitimate interests. Consent hands the caller genuine control and can be withdrawn; legitimate interests keeps the decision with the organisation and requires a documented assessment before anything runs. This is general information about published ICO guidance and not legal advice.

The ICO guide to lawful basis, last updated 2 April 2026, sets out the seven bases in Article 6: consent, contract, legal obligation, vital interests, public task, recognised legitimate interest, and legitimate interests. Its opening position is that no single basis is better or more important than the others and that the most appropriate one depends on your purpose and your relationship with the person. Recognised legitimate interest is a narrow list covering safeguarding, emergencies, crime and similar, so it does not reach ordinary call handling. That leaves the choice most businesses actually face.

Choosing consent has a consequence worth stating clearly. The ICO says you must determine your basis before you start and document it, and that you should not swap later without good reason, adding that you cannot usually move from consent to a different basis. Its worked example describes an organisation that relied on consent, had it withdrawn, and wanted to switch to legitimate interests; the ICO's conclusion is that the organisation must stop using the information, because leading people to believe they had a choice when they did not is unfair. Consent given at the start of a call is real consent, and it can be taken back.

The necessity test does independent work here. The ICO states that necessary means more than useful and more than standard practice, that it must be targeted and proportionate, and that a basis will not apply where the purpose could reasonably be achieved by less intrusive means or by processing less personal information. It adds that operating your business in a particular way is not itself an argument for necessity. Applied to a phone line, that is a hard question about whether a full audio recording is needed when a structured summary would serve, and it deserves an answer before the line goes live.

When does a caller have to be told the call is recorded?

At the point their information is collected, which on a telephone call means the beginning of it. The ICO guidance on the right to be informed states that where you collect personal data from the person it relates to, you must provide privacy information at the time you obtain their data. It also states that you must actively provide that information, and that publishing it on a website meets the requirement only where people are made aware of it and given an easy way to reach it.

The ICO guidance on the right to be informed is specific on timing: where personal data is collected from the person it relates to, privacy information must be provided at the time it is obtained. On a call there is no other moment that satisfies it. Telling someone at the end that the conversation was recorded informs them of something already done.

What has to be said at the start of an AI answered call?

Enough for the caller to understand who they are dealing with and what becomes of what they say. Articles 13 and 14 of UK GDPR set the minimum: who you are, the purposes, the lawful basis, who receives the data, how long it is kept, the rights available, the right to complain to the ICO, and the existence of any automated decision making. The ICO endorses a layered approach and just in time notices for this kind of moment, so a short spoken line can carry the essentials and say where the full notice sits.

The full Article 13 list runs longer than any opening line should: identity and contact details, the purposes, the lawful basis, the legitimate interests where those are relied on, recipients, transfers abroad, retention periods, the rights available, the right to withdraw consent, the right to complain to the ICO, whether providing the data is a statutory or contractual requirement, and the existence of automated decision-making including profiling. The ICO's answer to that length is technique rather than omission. It endorses a layered approach, just-in-time notices delivered at the point information is collected, and explicitly names voice alerts among the delivery methods available.

So the workable shape is a short spoken notice carrying the essentials, naming where the full notice lives, with the detail available to anyone who asks. Two points deserve care. The existence of automated decision-making is on the list, so a system making qualification decisions has more to disclose than one taking a message. And if legitimate interests is the basis, the ICO requires more detail in the privacy information, not less.

What happens if a caller mentions health details on an AI call?

The recording becomes special category data and needs a second justification on top of the lawful basis. The ICO states that to use special category data you must identify both a lawful basis and a separate condition under Article 9, and must document both. Health details arrive unprompted on calls to clinics and practices, which means that condition has to be settled before the line goes live. Collecting less is the dependable control: a system that takes a name, a number and a reason for calling avoids holding what it has no condition to hold.

This is the trap for clinics, dental practices and anyone in health or care. A caller explaining why they need an appointment will often volunteer a condition, unprompted, in the first fifteen seconds. The ICO's rule is that special category data needs a lawful basis and a separate Article 9 condition, both documented. The condition cannot be selected after the fact, so a practice recording calls has to settle it in advance, alongside a data protection impact assessment where the processing is high risk. Designing the system to capture a name, a number and a reason for calling, without inviting clinical detail, is the control that reduces the problem instead of managing it.

Is a privacy policy on your website enough for recorded calls?

On its own it falls short. The ICO states that you must actively provide privacy information, and that putting it on a website satisfies the requirement only where you make people aware of it and give them an easy way to access it. A caller who never visits the website has not been informed by it. The pattern that works is a spoken notice at the start of the call carrying the essentials and naming where the full notice sits, with that wording written down and identical on every call.

The ICO's wording is that you must actively provide privacy information, and that a website can carry it provided people are made aware of it and given an easy way to access it. The word doing the work is actively. A notice that exists is not a notice that has been given, and the caller who rang the number on a search result and never opened the site has received nothing.

A short checklist before a recorded line goes live

Six decisions, each of which the ICO expects to be documented rather than assumed.

  • Decide the lawful basis for recording and write down why it applies, before the first call.
  • Test necessity honestly: establish whether the purpose needs full audio, or whether less would do.
  • Write the opening notice, keep it short, and keep it identical on every call.
  • Settle the Article 9 condition if health or other special category details can reach the line.
  • Set a retention period and enforce it, because it is on the list of things callers must be told.
  • Check the supplier's terms on retention and model training, and get the answer in the contract.

None of this is exotic, and none of it is a reason to leave the phone unanswered. It is the ordinary work of putting a recorded line into service, and it is the same work whether the voice belongs to a person or to software. The sector-by-sector picture is in the rules on regulated AI intake, the SRA position for law firms is in AI client intake under SRA rules, and how an AI employee is scoped, disclosed and audited on our side is on how we work.

Where this leads

Where your data sits, who can reach it, how it is deleted, and who supervises the AI.

Or run your own figures and check the assumptions while you are there.

Written and published by

7 Minds Systems

The architecture is not improvised. It comes from KOVA Intelligence, the private institutional trading-intelligence platform our founder built, where eight cooperating engines work as specialist parts under a governance layer that holds final authority. 7 Minds Systems applies the same principle to your business: a department of cooperating AI agents that hand work between each other and to your people, with a named person in command, not a single bot bolted to a page.

We run this system inside our own group of operating companies. 7 Minds Systems holds no certificate, report or badge under Cyber Essentials, ISO 27001 or SOC 2 Type II, and the security page sets out what we do and do not hold.

Before you go

See the figure before you commit to anything.

Tell us the work you do and we will send the estimate written against it, with the assumptions printed so you can argue with them. One email, no sequence.

We use your address to send that one estimate, never share it, and delete it on request. Read the privacy policy.

See what this is worth to your business.

We name the workflow, the person who owns it, and the date it could be running.

Thirty minutes, no pitch. You leave with the workflow named, the person who signs it off named, and the figure attached.

Book a strategy call

Thirty minutes. A clear plan.

Thirty minutes on how the workforce would be run, who signs off what, and the figure it is priced at.

Book a thirty-minute call

Pick a time straight from the diary. If you would rather write first, email us and a person replies, usually the same working day.