FieldRegister
Every field · Communications

Call recording or transcript

Recordings capture voice (a biometric in some regimes) and whatever was said, including other people's data. Feeding them to a model is high-risk processing.

personal data
personal data?
confidential
sensitivity
never
AI use
consent (two-party consent in many places) or legitimate interest with a notice
lawful basis usually relied on

Keep it how long

Short and fixed: 30 to 90 days unless a dispute holds it.

The gap we see most

AI note-takers writing transcripts into the CRM with no recording notice to the other party.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Free text and attachments GDPR Art.5 · GDPR Art.15 · ISO/IEC 27701:2019 7.4.1 · ISO/IEC 27701:2019 7.4.7
GDPR Art.5 Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, e...

Evidence an auditor accepts: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose
GDPR Art.15 Right of access by the data subject

On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisation...

Evidence an auditor accepts: The search methodology showing every system, archive and unstructured store searched, and how completeness was assured; A worked response covering all the supplementary information items, not only the copy of the data; The redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction
ISO/IEC 27701:2019 7.4.1 Limit collection

The organization must limit collection of personal data to the minimum that is adequate, relevant, proportional and necessary for the identified purposes, including data collected indirectly through means such as web and system logs, and where any optionality in collection and processing exists each...

Evidence an auditor accepts: Field level justification linking each item collected to an identified purpose; Assessment of indirectly collected data such as logs, telemetry and tracking; Evidence optional collection is off by default, captured from the live configuration
ISO/IEC 27701:2019 7.4.7 Retention

The organization must not retain personal data longer than the purposes for which it is processed require, developing and maintaining retention schedules that take account of legal, regulatory and business requirements and, where those requirements conflict, taking and documenting a business decisio...

Evidence an auditor accepts: Retention schedule covering every category of personal data, with the period and its justification; Evidence the schedule is enforced, not merely published; Documented risk based decisions where legal, regulatory and business requirements conflicted
Call recordings and AI transcripts GDPR Art.13 · GDPR Art.35 · ISO/IEC 27701:2019 7.2.5 · ISO/IEC 27701:2019 7.3.10
GDPR Art.13 Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis...

Evidence an auditor accepts: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule
GDPR Art.35 Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operat...

Evidence an auditor accepts: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval
ISO/IEC 27701:2019 7.2.5 Privacy impact assessment

The organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever new processing of personal data or a change to existing processing is planned, determining the elements the assessment needs, which can include the types of personal data processed...

Evidence an auditor accepts: Documented trigger criteria for when an assessment is required, including the mandated cases; Screening records showing the need was assessed even where no assessment followed; Completed assessments with data types, storage locations, transfers and data flows
ISO/IEC 27701:2019 7.3.10 Automated decision making

The organization must identify and address the obligations, including legal obligations, that it owes to individuals arising from decisions it makes about them based solely on automated processing of their personal data, taking account of jurisdictions that impose specific obligations where such dec...

Evidence an auditor accepts: Inventory of decisions made solely by automated processing, with their effect on individuals assessed; Obligations register per jurisdiction for those decisions; Notification content disclosing the existence and logic of automated decision making

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Rights request or deletion flag · Lead score, propensity or ranking