Call recording or transcript
Recordings capture voice (a biometric in some regimes) and whatever was said, including other people's data. Feeding them to a model is high-risk processing.
Keep it how long
The gap we see most
AI note-takers writing transcripts into the CRM with no recording notice to the other party.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Field Register.
Free text and attachments GDPR Art.5 · GDPR Art.15 · ISO/IEC 27701:2019 7.4.1 · ISO/IEC 27701:2019 7.4.7
GDPR Art.5 Principles relating to processing of personal dataProcess personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, e...
GDPR Art.15 Right of access by the data subjectOn request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisation...
ISO/IEC 27701:2019 7.4.1 Limit collectionThe organization must limit collection of personal data to the minimum that is adequate, relevant, proportional and necessary for the identified purposes, including data collected indirectly through means such as web and system logs, and where any optionality in collection and processing exists each...
ISO/IEC 27701:2019 7.4.7 RetentionThe organization must not retain personal data longer than the purposes for which it is processed require, developing and maintaining retention schedules that take account of legal, regulatory and business requirements and, where those requirements conflict, taking and documenting a business decisio...
Call recordings and AI transcripts GDPR Art.13 · GDPR Art.35 · ISO/IEC 27701:2019 7.2.5 · ISO/IEC 27701:2019 7.3.10
GDPR Art.13 Information to be provided where personal data are collectedWhere personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis...
GDPR Art.35 Data protection impact assessmentWhere a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operat...
ISO/IEC 27701:2019 7.2.5 Privacy impact assessmentThe organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever new processing of personal data or a change to existing processing is planned, determining the elements the assessment needs, which can include the types of personal data processed...
ISO/IEC 27701:2019 7.3.10 Automated decision makingThe organization must identify and address the obligations, including legal obligations, that it owes to individuals arising from decisions it makes about them based solely on automated processing of their personal data, taking account of jurisdictions that impose specific obligations where such dec...
Do this for your whole CRM
Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.
Build my field registerRights request or deletion flag · Lead score, propensity or ranking