What gets processed
- Call audio — the caller’s voice, which in most jurisdictions is personal data in its own right and biometric data in some.
- Transcripts — the literal text of what was said, including anything volunteered.
- Action data — whatever is passed to your systems, which can include account numbers and addresses.
- Summaries — derived from the above.
Settle these before launch
What are callers told?
What are callers told?
Most jurisdictions require callers to be informed that a call is recorded or processed automatically, and many require it before the conversation begins. Requirements differ by country and sector — confirm what applies to yours.
How long is anything kept?
How long is anything kept?
Decide retention per data type. Audio, transcripts, and summaries do not need identical periods, and “keep everything indefinitely” is rarely defensible under data protection law.
Who can read it?
Who can read it?
Access to transcripts should be scoped to people with a reason to read them. Reviewing calls for quality is a legitimate reason; general availability across a company is not.
Where is it processed?
Where is it processed?
If your organisation has obligations about where data is processed, settle this during scoping rather than after building. It is the question most likely to force an architecture change late.See Deployment options.
What happens on a deletion request?
What happens on a deletion request?
Individuals can request erasure in many jurisdictions. Know how you would locate and remove one caller’s records across audio, transcripts, summaries, and anything your actions wrote downstream.
Minimise at the source
The cheapest data to protect is data you never collected.- Do not collect what the call does not need. If the agent never needs a national ID, do not ask for one.
- Avoid putting sensitive values into action parameters that get logged widely.
- Where verification is required, prefer confirming a detail the caller supplies over asking them to read out a full number.
Regional obligations
Saudi Arabia’s Personal Data Protection Law, and the equivalents across the Gulf, place specific requirements on processing personal data — including rules on transfers outside the country. If you operate under PDPL or a comparable regime, these constraints shape which deployment configuration is appropriate.Questions worth asking any vendor
Including us:- What exactly is retained, and for how long, per data type?
- Where is data processed, and does that change under load?
- Is call data used to train models? If so, can that be switched off?
- What certifications exist, and what is their scope?
- What are the notification commitments if there is a breach?
- What happens to data when the contract ends?
A vendor that answers these precisely and in writing is a different proposition from one that answers them warmly in a sales call. Ask for the written version.

