Call recording is switched on in most companies running cloud telephony, usually from a single toggle in the admin console, and almost always in the “all calls, all the time” position. For a business that operates in more than one state, that is the configuration most likely to create exposure.
The topic deserves better than a reflex of caution, because well-scoped recording has real value: coaching, dispute resolution, script improvement. What is regulated is not the tool. It is who consented, what you kept, and for how long.
This guide covers the consent framework, the interstate rule that catches most companies, the data that must never end up in a stored file, and a compliance checklist.
The consent framework
The federal floor
The federal Wiretap Act, 18 U.S.C. § 2511, establishes one-party consent as the national baseline. If you are a party to the conversation, you may record it, or authorize someone else to record it, without informing the other participants.
That is the floor, not the ceiling. States may be stricter, and eleven of them are.
The all-party states
Around eleven states require every participant to be notified and to consent. The list most commonly cited:
California, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, Washington.
Three more sit in a grey zone depending on the situation: Connecticut, where the all-party rule is civil rather than criminal; Oregon, whose all-party requirement applies to in-person conversations; and Michigan, whose classification is contested in the case law.
The interstate rule that catches everyone
Here is the point most companies miss. When the parties are in different states, courts generally apply the stricter law.
The leading authority is Kearney v. Salomon Smith Barney (2006), in which the California Supreme Court held a firm operating lawfully under its home state’s one-party rule to California’s all-party standard for calls into California.
The practical consequence is blunt: if you take calls from, or place calls into, any all-party state — and virtually every business does — the one-party baseline is not the rule you operate under. Plan for all-party and the problem disappears.
A multi-state business does not really have a consent choice. It has an all-party obligation and a paperwork question about how to satisfy it cleanly.
CIPA, the California Invasion of Privacy Act (Cal. Penal Code § 632), is the statute that most often reaches out-of-state companies, and it carries statutory damages that make aggregation attractive to plaintiffs. Financial institutions have paid substantial settlements over calls recorded without adequate consent. You do not need a California office to be exposed — you need California callers.
Announcing it properly
An announcement that satisfies all-party consent has to do more than exist. Four elements:
| Element | What to say |
|---|---|
| The fact of recording | Unambiguously, not buried in a longer greeting |
| The purpose | Quality assurance, training, transaction records |
| How to decline | A real path, not a theoretical right |
| Where to learn more | A page carrying retention, rights and contact details |
Twelve seconds is enough:
“This call may be recorded for quality assurance and training. If you’d prefer we don’t record, just let the representative know and we’ll stop. Details are in our privacy policy.”
Two things make this real rather than decorative:
The opt-out must work. If a caller declines, the agent must be able to stop recording mid-call. A platform that cannot do that turns your announcement into a false statement, which is worse than no announcement.
Implied consent has limits. Continuing the call after a clear announcement is generally treated as consent in most all-party states — but that depends on the announcement being clear, early and audible. An announcement after the conversation has started, or buried in hold music, does not carry the same weight.
Employees are the second audience
Almost every company handles the caller correctly and forgets the workforce.
Several states impose notice obligations for electronic monitoring. New York requires notifying employees at hiring; Connecticut requires prior written notice. Beyond specific statutes, recording staff without telling them undermines any use you might later want to make of the recording in a coaching, performance or disciplinary context.
The practical baseline: written notice at hire, written notice again at deployment, and a plain description of what is recorded, why, who can listen and for how long. If your organization is unionized, involve the bargaining representative before deployment rather than after.
What must never be in a stored recording
Card data. Under PCI DSS, sensitive authentication data — the CVV above all — must not be retained after authorization, and a stored audio file is retention. The expected control is pause-and-resume: the recording stops while card details are spoken or keyed, then resumes.
Protected health information, if you are a covered entity or business associate under HIPAA. A recording containing PHI inherits the full HIPAA regime — access controls, audit logging, business associate agreements, breach notification.
Credentials and security answers. Passwords, PINs, security question answers. They should not be spoken aloud at all, and certainly not stored for six months.
Retention: tie it to a purpose
There is no single federal retention period for call recordings. The defensible approach is to derive the duration from a stated purpose.
| Purpose | Typical duration | What justifies it |
|---|---|---|
| Coaching and quality review | 6 to 12 months | Beyond that it has no coaching value |
| Dispute and transaction evidence | The applicable limitations period | Only for calls where a transaction occurred |
| Sector-specific obligation | As the rule requires | Financial services and healthcare have their own; cite the rule |
Two practical rules:
One duration per purpose, not one duration for everything. Companies that keep everything for the longest period are, in effect, applying the evidence retention period to coaching recordings. That is the easiest finding to make in any review.
Deletion must be automatic and must reach backups. A manual purge “when someone remembers” is an intention, not a retention policy. Verify six months later that the files are actually gone.
Transcription and AI analysis: a second processing activity
Transcribing and then analyzing a call does not extend the recording activity. It creates a new one, with three consequences.
Its own retention period. Text weighs almost nothing compared to audio, which makes indefinite retention tempting — and that is precisely what a purpose-bound approach rules out.
A heavier regime if it evaluates people. Per-agent quality scores, rankings and automated script-adherence detection are workforce monitoring. Notify individually, and never let an automated score be the sole basis for a decision affecting someone. Keep a human in the loop who can be challenged.
Vendor diligence. If transcription runs through a third party, that vendor is processing your call content: contract, data location, security commitments, and deletion on termination. Settle that before deployment, not after.
Compliance checklist
Map where your callers actually are
If any meaningful share sits in an all-party state — and California alone usually settles it — you operate under all-party rules. That single determination simplifies every decision that follows.
Write the purpose, then scope the recording to it
One sentence per purpose. If you cannot write it without “just in case”, the purpose does not exist and neither should that recording.
Fix the announcement and verify the opt-out works
Four elements in the greeting, detail on a linked page, and an agent-side control that actually stops recording mid-call. Test it yourself before signing off.
Notify employees in writing
At hire and at deployment. Document the date and the content — that is what gets asked for in a dispute.
Configure pause-and-resume for payment data
In the platform and in the script. Then sample recordings to confirm it is happening in practice.
Set retention per purpose and confirm deletion
Automatic deletion, backups included, verified after the first cycle rather than assumed.
The 5 most common gaps
- “All calls, all the time.” The default setting in many platforms, and the hardest to defend when the consent question arises.
- Assuming the one-party baseline applies. It does not, the moment a caller is in an all-party state.
- An announcement with no working opt-out. Worse than silence, because it is a representation you cannot honor.
- Employees never formally notified. Fine until the day you want to rely on a recording in a performance discussion.
- No pause on payment data. A PCI problem hiding in an audio archive nobody has listened to.
What to take away
Call recording is not a yes-or-no question, it is a question of scope, consent and retention. For a multi-state business, three decisions cover most of the exposure: operate as if all-party consent applies, make the opt-out genuinely work, and tie every retention period to a written purpose.
The rest — pause-and-resume, employee notice, vendor diligence — is ordinary implementation once those three are settled.
And if your reason for recording is to understand how the phone is performing, a good deal of what you are looking for is visible in your call metrics, without keeping a single audio file.