ICO and UK GDPR: voice recordings, biometrics and AI processing
- CX directors
- Legal & Compliance
- Procurement / IT-Sec
Voice AI processing falls under UK GDPR and DPA 2018. Organizations must establish a lawful basis—typically contractual necessity or legitimate interests—and conduct a DPIA. If using voice biometrics, additional 'special category' protections apply, requiring explicit consent or a substantial public interest condition.
Lawful Bases for Voice AI Processing
Under UK GDPR Article 6, every processing activity requires a valid lawful basis. For voice AI in a customer service context, organisations typically rely on 'Contractual Necessity' (if the call is required to fulfil a contract with the user) or 'Legitimate Interests' (balancing the business need for automation against the individual's privacy).
However, 'Consent' is often the safest path, especially for outbound calls or when processing goes beyond simple transaction fulfillment. It is important to note that consent must be freely given, specific, informed, and unambiguous. Simply staying on the line after a 'calls are recorded' message may not meet the GDPR standard for AI-driven analysis or biometric profiling.
Voice Biometrics and Special Category Data
Voice data is unique. When used to identify an individual (e.g., voice-based authentication or 'voiceprints'), it constitutes biometric data. Under UK GDPR Article 9, biometric data used for identification is classified as 'Special Category Data', which is afforded higher levels of protection.
To process special category data, you must identify both an Article 6 basis and an Article 9 condition. In a commercial setting, this almost always requires 'Explicit Consent'. Enterprises must ensure that callers can opt-out of biometric identification without being denied access to the service, typically by providing an alternative verification method.
The Mandatory Data Protection Impact Assessment (DPIA)
The ICO mandates a DPIA for any processing that is 'likely to result in a high risk' to individuals. Voice AI almost always triggers this requirement because it involves 'new technologies' and often involves the 'large-scale processing' of sensitive personal data or the 'systematic monitoring' of individuals in public-access spaces (the telephony network).
A robust DPIA for voice AI should address the risks of AI hallucination, the potential for bias in the NLU (Natural Language Understanding) models, and the security of the data as it passes through third-party LLM providers. It is a 'living document' that must be updated as the AI model or the scope of the deployment changes.
Transparency and the Duty to Inform
Article 13 and 14 of the UK GDPR require organisations to be transparent about how personal data is used. For voice AI, this means clearly informing the caller that they are speaking to an automated system. The ICO’s guidance on AI transparency suggests that 'disclosure should be prominent and timely'.
This is not just a regulatory hurdle but a trust-building exercise. Callers should understand that their voice is being processed by AI, what data is being captured, and how they can request human intervention if the AI fails to meet their needs. Hiding the 'AI-ness' of the agent can lead to complaints and regulatory scrutiny.
Data Subject Rights and Retention
Voice AI deployments must be built to support data subject rights, including the Right of Access (SARs) and the Right to Erasure ('Right to be Forgotten'). This can be complex when personal data is embedded within call transcripts, audio recordings, and the hidden 'embeddings' of a vector database.
Retention policies must be strictly enforced. Organisations should only keep voice recordings and transcripts for as long as is strictly necessary for the purpose they were collected. Automated redaction of PII (Personally Identifiable Information) from transcripts is a highly recommended practice to minimise the risk and volume of data held.
- Voice AI deployments must have a clear lawful basis (Contract, Legitimate Interest, or Consent) before launch.
- Voice biometrics for identification require 'Explicit Consent' under Special Category data rules.
- A DPIA is mandatory for most enterprise voice AI due to the 'high risk' nature of the technology.
- Transparency is key: callers must be told they are speaking to an AI.
- Retention policies must apply to audio, transcripts, and any metadata containing personal information.
Frequently asked questions
- Is a voice recording always biometric data?
- No. A voice recording is personal data, but it only becomes 'biometric data' under GDPR if it is processed using specific technical means to identify or authenticate a person. However, even if not used for ID, voice recordings are sensitive and require high protection.
- Do we need a DPIA for a simple voicebot?
- Most likely, yes. The ICO considers AI to be a 'new technology' that often involves high-risk processing. Even a simple bot that handles personal data should be covered by a DPIA to ensure compliance.
- Can a caller refuse to be handled by an AI?
- Under UK GDPR Article 22, individuals have the right not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects. While most customer service calls don't reach this threshold, providing a route to a human agent is a best practice for compliance and CX.
- How does the 'Right to be Forgotten' work with LLM training?
- Personal data from calls should never be used to train foundation LLMs without extreme de-identification. If a customer requests erasure, you must be able to delete their transcripts and audio files from all storage and logs.
Terms used in this guide
- Voice AI— Voice AI is software that answers the phone, understands what the caller wants, and takes action — not just a smarter IVR.
- Voice biometrics— Voice biometrics confirms who the caller is by how they speak.
- Automated-system disclosure— Automated-system disclosure is telling the caller they are talking to a machine.
- LLM guardrails— LLM guardrails are the things the AI is not allowed to do.
Lewis Crook — 20 years in enterprise technology, from FTSE 100 voice deployments to over a million AI-handled minutes a month across Asia-Pacific. Buyer, builder, and now working with CX leaders on enterprise voice AI. Writes The Voice AI Brief. Connect on LinkedIn. More about Lewis.
Related guides
Plus the Voice AI Readiness Diagnostic in the welcome email.
Welcome email includes the Voice AI Readiness Diagnostic. No second list, no extra form.