Logo
Logo
Talk Now

Trusted by 10,000+ businesses

Voice & IVR

DPDP Act and Call Recording: What Voice Businesses Must Comply With

A focused look at how India's DPDP Act 2023 applies to recorded calls- the recording notice, how long to keep recordings, storage security, and handling deletion requests.

Get Click Media6 min read
DPDP Act and Call Recording: What Voice Businesses Must Comply With

Of everything the DPDP Act touches in a voice business, call recording is one of the most direct- you're capturing someone's voice, storing it, and holding onto data that clearly qualifies as personal information. If you haven't looked at your recording setup through that lens yet, this is the place to start. For the full compliance checklist covering IVR, DTMF data, and vendor agreements, see our DPDP Act Voice Compliance Guide. This post narrows in on the recording itself: the notice, the retention period, how it's stored, and what happens when someone asks you to delete it.

The Recording Notice- What's Expected

The standard, widely-followed approach is simple: give the caller a spoken notice at the start of the call- something like "this call may be recorded"- before recording actually begins. It's a clear notice that the conversation may be captured, delivered before capture starts, not buried in fine print after the fact or left out entirely.

The DPDP Act doesn't hand you an exact script to read. What it does expect, in general terms, is that a caller isn't recorded without any indication that recording is happening. A notice at the top of the call, paired with a documented basis for why you're keeping that recording, is the practice most businesses are building toward.

How Long Should You Keep a Recording?

This is the question we get asked the most, and the honest answer is: there's no single number in the Act that applies to every business. What the Act's general principles do point toward is a documented retention period- a stated answer to "why are we keeping this, and for how long"- rather than recordings piling up indefinitely with no stated reason.

Indefinite retention without a documented basis is exactly the kind of gap that becomes a real liability if a customer ever asks about it or a regulator ever asks about it. Decide on a retention window that matches your actual business need- a support quality-check period, a dispute-resolution window, a regulatory record-keeping requirement specific to your sector- write it down, and apply it consistently. If you're not sure what figure is right for your sector, that's a conversation for legal counsel, not a guess.

Storage Security and Access Control

Once a recording exists, where and how it lives matters. The Act doesn't prescribe a specific encryption standard or storage architecture, but secure storage and defined access controls are consistent with good-practice data handling- and they're the difference between a minor internal matter and a real breach if your storage is ever compromised.

In practice, that means: recordings sit in storage that isn't openly accessible by default, and only the people who genuinely need to play back or export a call- support leads, quality reviewers, compliance staff- can actually do so. If everyone with a login can pull up any recording at any time, that's a gap worth closing before it becomes a problem.

Handling a Deletion Request

Data Principals- the individuals whose data you hold- generally have rights to access, correct, and request erasure of their personal data under the Act, and a call recording is personal data like any other. When a customer asks you to delete a recording of their call, you need an actual process to point to, not something you're figuring out for the first time in the moment.

That process should cover: how the request gets logged, who has authority to act on it, how the recording gets located and removed from storage (including backups), and how you confirm back to the customer that it's done. Building this out ahead of time is far cheaper than reacting to your first real request under pressure.

Where Your Telephony Vendor Fits In

If a third-party telephony or IVR platform is capturing and storing your call recordings for you, a data-handling agreement with that vendor matters- it should spell out how they store recordings, who can access them, and what happens if something goes wrong on their end. But that agreement doesn't fully offload your responsibility. You're the business that collected the recording and put it to use, and that responsibility largely stays with you regardless of who's hosting the file.

For the fuller picture of how this fits alongside consent, IVR data capture, and caller ID handling, our DPDP Act Voice Compliance Guide covers the full six-area application scope and a practical compliance checklist.

Frequently Asked Questions

Do I legally need to tell a caller their call is being recorded?

In general practice, yes- the standard approach is to give a spoken notice at the start of the call, such as "this call may be recorded," before recording begins. This gives the caller notice up front and keeps you aligned with the DPDP Act's consent-first approach, even though the Act itself doesn't spell out an exact script you must use.

How long should a business keep call recordings?

There's no single figure written into the Act itself that applies to every business. The honest guidance is to define and document a retention period for your recordings rather than keeping them indefinitely by default- and to consult legal counsel for a figure specific to your sector and use case.

What happens if a customer asks for their call recording to be deleted?

Under the Act, individuals (Data Principals) generally have rights to access, correct, and request erasure of their personal data- and a call recording is personal data. Your business should have a documented process ready to handle a deletion request, rather than improvising one when a request actually comes in.

Are call recordings required to be encrypted or specially secured?

The Act doesn't mandate a specific technical standard for how recordings must be stored. That said, secure storage and defined access controls over who can play back or export a recording are consistent with good-practice data handling, and they meaningfully reduce your exposure if storage systems are ever compromised.

Who is responsible if a third-party telephony or IVR vendor mishandles a stored recording?

Your business should have a data-handling agreement in place with any telephony or IVR platform partner processing call data on your behalf. That said, having such an agreement doesn't fully offload your own responsibility as the business that collected and is using the recording in the first place.

Does Get Click Media store and manage call recordings on my behalf, and does that make GCM legally responsible for DPDP compliance?

Get Click Media provides secure recording storage practices and documentation support for the recordings captured through your IVR and call flows, but this is not a substitute for your own legal review- Get Click Media does not guarantee legal compliance with the DPDP Act.

For the complete compliance picture- consent notices, IVR data capture, caller ID storage, and vendor agreements all in one place- head to our DPDP Act Voice Compliance Guide. If your call recording currently runs through your IVR System, that's a natural place to review your recording notice and storage setup at the same time.

Not sure if your call recording setup holds up? Talk to Get Click Media's team and we'll help you review it.

dpdp act call recording rulesrecorded call notice requirement indiacall recording retention policy indiacall recording deletion request indiabusiness call recording law indiacall recording data security indiadata principal erasure request callscall recording compliance checklist india

Frequently Asked Questions

In general practice, yes- the standard approach is to give a spoken notice at the start of the call, such as "this call may be recorded," before recording begins. This gives the caller notice up front and keeps you aligned with the DPDP Act's consent-first approach, even though the Act itself doesn't spell out an exact script you must use.

There's no single figure written into the Act itself that applies to every business. The honest guidance is to define and document a retention period for your recordings rather than keeping them indefinitely by default- and to consult legal counsel for a figure specific to your sector and use case.

Under the Act, individuals (Data Principals) generally have rights to access, correct, and request erasure of their personal data- and a call recording is personal data. Your business should have a documented process ready to handle a deletion request, rather than improvising one when a request actually comes in.

The Act doesn't mandate a specific technical standard for how recordings must be stored. That said, secure storage and defined access controls over who can play back or export a recording are consistent with good-practice data handling, and they meaningfully reduce your exposure if storage systems are ever compromised.

Your business should have a data-handling agreement in place with any telephony or IVR platform partner processing call data on your behalf. That said, having such an agreement doesn't fully offload your own responsibility as the business that collected and is using the recording in the first place.

Get Click Media provides secure recording storage practices and documentation support for the recordings captured through your IVR and call flows, but this is not a substitute for your own legal review- Get Click Media does not guarantee legal compliance with the DPDP Act.

Related Articles

Voice OTP vs SMS OTP: When Each One Makes Sense
Voice & IVR

Voice OTP vs SMS OTP: When Each One Makes Sense

A practical breakdown of when to use Voice OTP versus SMS OTP for verification- how each channel actually works, and why most businesses should run SMS first with voice as an automatic fallback rather than picking one channel outright.

7 min read