GDPR came into force in May 2018. Most contact centers went through a compliance exercise around that time, updated their privacy notices, added consent language to their call recordings, and considered the matter largely addressed. The problem is that GDPR compliance is not a one-time implementation task. It is an ongoing operational discipline, and the gap between what contact centers did in 2018 and what they are required to do in 2026 has widened considerably in most organizations. The ICO’s enforcement activity continues to find that contact centers and the businesses they serve are making a consistent set of errors, many of which have been well-documented for years and are still not being adequately addressed.

Conflating Consent With Compliance

The most widespread GDPR misconception in contact center operations is treating the consent model as the primary or default legal basis for processing customer data. Many contact centers added consent language to their call recording announcements in 2018 and have treated this as their GDPR foundation ever since. The problem is that consent under GDPR is a specific and demanding legal basis that is often not the most appropriate one for contact center data processing, and relying on it incorrectly creates compliance exposure rather than resolving it.

Consent under GDPR must be freely given, specific, informed, and unambiguous. In most contact center contexts, customers do not have a genuine free choice about whether to consent to call recording: if they want to speak to the organization, they must accept the recording. This means the consent may not meet the GDPR standard for freely given consent, and an organization that has built its compliance framework on that consent may find its legal basis challenged.

The more appropriate legal basis for most contact center recording and data processing is either legitimate interests, where the processing is necessary for the organization’s legitimate business purposes and does not override the customer’s rights, or contractual necessity, where the processing is required to fulfill the contract with the customer. ICO guidance on lawful bases for processing sets out the conditions for each basis in detail. Contact centers that have not revisited their legal basis documentation since 2018 should do so as a priority.

Data Retention Policies That Exist on Paper But Not in Practice

Most contact centers have a documented data retention policy that specifies how long call recordings, transcripts, and associated data are retained before deletion. The gap that ICO audits consistently identify is between the policy on paper and the retention practice in the platform. Call recordings are retained for longer than the policy specifies because no one has implemented automated deletion, because the platform’s default retention settings were never updated to reflect the policy, or because a migration or platform change disrupted the deletion schedule without anyone noticing.

This gap matters because retaining personal data beyond the period justified by its original processing purpose is a GDPR violation, even if the data is never accessed or misused. The ICO’s position is that unnecessary retention of personal data is an inherent risk regardless of whether a breach occurs. Contact centers that cannot demonstrate that their actual retention practice matches their documented retention policy are in violation regardless of how well-written the policy is.

The practical remediation requires:

  • Auditing the actual retention settings in every platform that stores customer interaction data, including call recording platforms, CRM systems, analytics platforms, and any third-party tools that receive call data
  • Comparing actual retention against the documented policy and resolving any gaps
  • Implementing automated deletion where possible so retention compliance does not depend on manual processes
  • Documenting the audit and its outcomes so the organization can demonstrate it has taken active steps to ensure compliance

Subject Access Requests: Still Handled Poorly at Scale

GDPR gives individuals the right to request access to the personal data an organization holds about them. In a contact center context, this includes call recordings, transcripts, agent notes, CRM data, and any analytics outputs that contain or are derived from personal data. Subject access requests must be fulfilled within one calendar month of receipt without charge in most circumstances.

The challenge for contact centers is the complexity of locating all relevant personal data across multiple systems when a request is received. A customer who has called 15 times over three years may have data in the call recording platform, the CRM, the QA analytics platform, the agent guidance system, and potentially third-party tools. Finding all of it, reviewing it for third-party personal data that must be redacted before disclosure, and delivering it within the one-month deadline requires a process that most contact centers have not formally designed.

The most common failures in contact center subject access request handling include:

  • Missing data held in analytics or QA platforms because the SAR process was designed around the CRM and call recording system only
  • Failing to redact third-party personal data, such as information about people mentioned by the customer during a call, before disclosing recordings or transcripts
  • Missing the one-month deadline because the request was not recognized as a formal SAR when it was received
  • Charging for SARs in circumstances where GDPR does not permit a charge

Contact centers that have not recently reviewed their SAR process against their current platform landscape are likely to have gaps that would be exposed if a formal request were submitted or if the ICO investigated.

Third-Party Data Processor Agreements

Every platform vendor, managed service provider, or analytics partner that processes personal data on behalf of a contact center is a data processor under GDPR. The contact center, as data controller, is required to have a written data processing agreement in place with each processor that meets the specific requirements of Article 28 of GDPR. These agreements must specify the subject matter, duration, nature, and purpose of the processing, the type of personal data involved, and the obligations and rights of the controller.

The gap that many contact centers have is either missing agreements entirely for some processors, or having agreements that were signed in 2018 and have not been reviewed since the relationship or the processing activities changed. A managed support provider that has been given access to call recordings and analytics data is processing personal data in a way that requires a current, compliant data processing agreement. A speech analytics platform that processes call transcripts requires the same. If those agreements do not exist or do not reflect the current scope of processing, the contact center is in violation regardless of whether the processing itself is otherwise compliant.

Data Breach Response: Planning That Has Not Been Tested

GDPR requires organizations to report certain types of personal data breaches to the ICO within 72 hours of becoming aware of them. In a contact center environment, breaches that could trigger this obligation include unauthorized access to call recordings, a misconfiguration that exposed customer data, a ransomware attack affecting systems that hold personal data, or a processor breach affecting data the contact center has shared.

Most contact centers have a documented breach response procedure. Far fewer have tested that procedure under conditions that reflect how a breach would actually be discovered in their environment. The 72-hour reporting window runs from the point the organization becomes aware of the breach, not from the point the breach occurred. If the breach is discovered by a junior IT team member at 6pm on a Friday and the procedure requires escalation to a data protection officer whose contact details are not readily accessible, the 72 hours can elapse before the organization has even decided whether a reportable breach has occurred.

Contact centers that have not run a tabletop exercise against their breach response procedure in the past 12 months should treat this as an urgent operational gap. The ICO’s guidance on breach reporting provides the framework against which the procedure should be tested. If you want to understand how ChorusCX supports GDPR-compliant data handling for contact center operations, explore our security page or speak with the team.