UKGI Compliance Manual

The rules and principle which apply 

This section explains the data protection requirements relating to telephone call recording and Closed-Circuit Television (CCTV) systems in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000, allows businesses to record calls for set purposes such as establishing facts, demonstrating regulatory compliance, maintaining quality, and training standards, preventing, or detecting crime, investigating unauthorised use, and ensuring effective system operation.

Regulation 3(2)(c) requires the system controller to have “made all reasonable efforts to inform every person who may use the telecommunication system” that calls may be intercepted. *(“interception” is understood as the act of monitoring, recording, or otherwise obtaining the contents of a communication that is transmitted by means of a telecommunications system)

Although the FCA does not require insurance broking firms to record telephone calls, they may do so if they wish, and where firms do so, the recordings become personal data and must be processed lawfully. The ICO provides guidance on how organisations should comply with these requirements in day-to-day operations. One of the key principles emphasised by the ICO is accountability which means that firms must be able to demonstrate that they have considered their obligations and implemented appropriate controls for call recording and CCTV this means firms should be able to evidence:

  • why recordings are necessary;
  • the lawful basis relied upon;
  • how privacy risks have been assessed;
  • who has access to the recordings;
  • how long recordings are retained;
  • how recordings are securely deleted; and
  • how staff have been trained in handling recorded information.

The ICO expects organisations to have determined an appropriate legal basis for call recording and CCTV processing and document these decisions, firms must also be fair and transparent with individuals when processing personal data in this way, which means telling individuals about the recording and observing individual’s rights.

Transparency also extends to employees. Where staff are monitored through telephone recording or CCTV, they should receive appropriate privacy information explaining the nature and purpose of the monitoring.

How this may affect firms

Call Recordings

The ICO explains that individuals should not be surprised that they are being recorded, recording should therefore be open and transparent. For telephone calls, firms should inform customers at the start of the call that conversations may be recorded and explain the purposes of recording through their privacy notice and terms of business.

The ICO advises organisations to define clearly why recordings are being made and to avoid using recordings for purposes that are incompatible with the original reason for collection. General insurance brokers typically record calls for:

  • Evidence of customer instructions
  • Complaint investigation
  • Quality assurance
  • Staff training
  • Fraud prevention
  • Regulatory compliance
  • Business continuity

Each purpose should be documented within the firms Record of Processing Activities (ROPA) (See Section K.6.1.1).

Lawful Basis

Before recording calls, a firm must identify an appropriate lawful basis under Article 6 of the UK GDPR. The most commonly used lawful bases for this purpose are:

  • Legitimate interests – to protect the firm, evidence customer instructions, quality monitoring, and fraud prevention
  • Contract – may apply where the recording is necessary to fulfil contractual obligations for example where recording itself forms the contractual record relied upon by both parties.

Firms should not rely too broadly on contract as a lawful basis and should consider whether the recording of the call is genuinely necessary, or whether the contract can be performed by other means such as maintaining an accurate written record.

Where call recordings are retained primarily to:

  • Defend potential legal claim/complaints
  • Monitor staff performance
  • Improve service quality
  • Provide training; or
  • Detect fraud

Legitimate interest will usually provide a more appropriate lawful basis, however bear in mind that reliance on legitimate interest means that customers have the right to object to call recording and to request the deletion of the recording.

Individuals Rights – Legitimate Interest

Where a firm relies on legitimate interests as its lawful basis for recording telephone calls, individuals have the right to object to that processing under Article 21 of the UK GDPR. An objection may be made at any time and does not need to follow a particular format. For example, a customer may state that they do not want their call to be recorded or that they object to the firm continuing to retain an existing recording.

If a caller objects, a broker is not automatically required to stop under UK law, If the objection is about privacy and the broker’s recording is lawful, the broker can continue but must still comply with GDPR and any contractual or regulatory obligations, however If the objection is because the recording is unlawful (e.g. without a lawful basis), the broker must stop.

It may not always be clear at the time the request is received what the appropriate response should be without further consideration, in these cases where a caller objects to a call being recorded it may be prudent to initially pause or explain that it is not possible to proceed with the call without recording and arrange to call the client back from an unrecorded line (if possible) or agree alternative means of communication.

A firm should neither automatically refuse the request or automatically stop processing, Instead, it should refer to the firm’s data protection officer, compliance  or other nominated senior manager to:

  • Consider whether the request is a ‘right to object, a ‘request for erasure’ or both and whether this relates to a single call in isolation or wider call history.
  • Assess whether the recording(s) remains necessary for the firm’s legitimate interests
  • Consider whether any article 17 exemption may apply – such as the defence of a legal claim.
  • Consider whether it is appropriate to offer alternative means of communication for future communications.
  • Respond within the statutory time limit explaining the decision and informing the customer of their right to complain to the ICO if the request is refused.

A firm must assess whether it has compelling legitimate grounds for retaining a call recording which override the individual’s interest, rights, and freedoms, or whether the processing is necessary for the establishment, exercise, or defence of legal claims.

For general insurance brokers, compelling legitimate grounds may include:

  • maintaining an accurate record of customer instructions;
  • investigating and resolving complaints;
  • responding to inquiries from the Financial Ombudsman Service;
  • preventing and detecting fraud;
  • demonstrating compliance with FCA regulatory requirements;
  • protecting the firm against allegations of negligence or professional misconduct; and
  • establishing, exercising, or defending legal claims.

Where these grounds exist, the firm may continue to retain and use the recording despite the individual’s objection. The decision should be documented, and the individual should be informed of the reasons for refusing the objection, together with their right to complain to the ICO. Conversely, if the firm cannot demonstrate that its legitimate interests override the individual’s rights and freedoms, it should cease the processing and, where appropriate, erase recording(s).

In practice, whether a firm may continue to record or retain a call will depend on the nature and content of the call, and whether there are alternative ways to continue dealing with the customer if they object to future call recording. This assessment must be made on a case-by-case basis, and a firm should not unreasonably refuse a customer’s request unless it has a compelling legitimate reason for doing so, and that reason should be clearly explained to the customer.

Firms should also remember that call recordings are personal data and may need to be included in subject access requests. For example, an individual may specifically request copies of their call recordings, or a broader request may require the firm to include call recordings within a reasonable search for relevant personal data. We have provided a guidance document on dealing with Subject Access Requests that can be accessed here.

Access and retention controls

Cal recordings should only be accessible to authorised personnel. Access should be restricted to role, such as:

  • Compliance
  • Senior Management
  • Complaints
  • Quality Assurance
  • Information Security

Access logs should be retained where technically possible.

Call recordings should not be kept indefinitely, and retention periods should reflect normal FCA record keeping requirements, legal obligations and operational necessity in accordance with the firms record keeping policy. The only exception to this is where it may be necessary to retain records for longer because of a known or suspected litigation issue.

Call recording should be reviewed and cleansed in accordance with set review periods and procedures should be in place for deletion and back up handling.

Closed-Circuit Television (CCTV)

CCTV should only be installed where there is a genuine business need. Examples include:

  • Staff safety
  • Customer safety
  • Crime prevention
  • Protection of company assets
  • Investigation of incidents

You will typically need to complete a Data Protection Impact Assessment (DPIA) before introducing CCTV (see Section XX for more information DPIA’s), particularly where surveillance could significantly affect and individuals’ privacy. The assessment should consider:

  • Necessity
  • Proportionality
  • Privacy risks
  • Mitigation measures
  • Alternatives considered

Clear and visible signage should inform individuals that CCTV operates. Signs should explain who operates the system, the purpose of the monitoring, contact details and where further information can be found.

Cameras should only monitor areas necessary for legitimate business purposes, for example you should avoid recording toilets, changing rooms, prayer rooms or private rest areas and it is of note that monitoring staff continuously without justification may breach UK GDPR Principles for the following reasons

  • Monitoring staff continuously without a specific, proportionate purpose may lack a lawful basis
  • CCTV must only be used for the specific purposes stated at the time of installation (e.g. crime prevention, safety) and could also lead to a firm collecting , using it for unrelated or ongoing surveillance without a stated need violates this principle.
  • Only the minimum amount of data necessary for the stated purpose should be collected. Continuous, blanket monitoring of all staff areas without justification captures more data than needed, breaching this principle
  • Footage should be retained only as long as necessary for the purpose. Continuous recording without defined retention limits risks unlawful storage
  • Continuous, unexplained monitoring without notice breaches this transparency requirement

Audio recording through CCTV significantly increases privacy risks unless there is a compelling justification audio recording should generally be disabled.

Where CCTV is used to monitor employee performance you must be transparent and explain this to staff. Covert monitoring should only occur in exceptional circumstances where criminal activity is suspected and should be carefully documented. We recommend that firms obtain independent legal or HR advice before engaging in any such activity.

Security

Both CCTV footage and call recordings should be protected using appropriate technical and organisational measures e.g. encryption, strong authentication and access controls, audit logging etc. more information on data security can be found in Section K.6.2..

Any third-party suppliers providing services in relation to CCTV and call recording activity should be subject to appropriate due diligence and contractual arrangements and firms should note that where cloud providers store recordings, firms remain responsible as data controllers. More information on contracts, supplier risk and outsourcing can be found in Section K.6.3..