Skip To Main
How-To Guides

AI Voice Privacy: Call Recording, Storage, and Compliance

7 min readexoserva
privacycompliancerecordingvoice-ai

AI voice receptionist records and transcribes every call. That's a feature — you get searchable call history, automatic CRM logging, and quality review capability. But it also creates compliance obligations that contractors need to understand before going live.

This guide covers the legal landscape for call recording, data storage requirements, customer rights, and practical steps to stay compliant.


TL;DR

  • Call recording consent laws vary by state: one-party consent (most states) vs. two-party/all-party consent (11+ states including California, Florida, and Illinois)
  • In all-party consent states, you must notify callers that the call is being recorded before recording begins
  • CCPA and similar state privacy laws give customers the right to access, correct, and delete their call data
  • Your AI voice provider's data practices affect your compliance posture — know where data is stored and for how long

Call Recording Consent Laws: The Basics

The United States does not have a single federal call recording law. Compliance is governed by the federal wiretapping statute (ECPA) and individual state laws. The key distinction:

One-party consent states (majority of US): Only one party to the call needs to consent to recording. If you (or your AI system acting as your agent) consent to recording, the recording is legal regardless of whether the caller knows.

Two-party (all-party) consent states: All parties to the call must consent to recording. In these states, you must notify callers that the call will be recorded and give them the opportunity to end the call. Proceeding without notification creates legal exposure.

All-party consent states as of 2026: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, Washington.

Note: This list evolves as state legislatures act. Verify current requirements for your state with legal counsel.

Interstate calls: When a caller in one state calls a contractor in another, apply the stricter standard. A California contractor receiving calls from nationwide customers should use all-party consent disclosure regardless of caller location.


Required Disclosure Language

For all-party consent states, your AI voice must include a disclosure before recording begins. Best practice: include it in your opening greeting.

Compliant opening example: "Thank you for calling [Company Name]. This call may be monitored or recorded for quality assurance and training purposes. How can I help you today?"

This is the standard you've heard from any call center. The caller has been informed; proceeding with the call implies consent.

What you cannot do:

  • Start recording before the disclosure
  • Bury the disclosure at the end of a long greeting
  • Use disclosure language that is ambiguous about what is being recorded

Best practice for all states: Even in one-party consent states, many contractors choose to include a disclosure. It signals professionalism, and it eliminates any ambiguity if call recordings are ever reviewed in a legal context.


AI Disclosure: Are You Required to Say It's an AI?

This is an evolving area of law. Currently:

Federal level: No federal law requires AI voice disclosure at the time of this writing, though the FTC has issued guidance indicating deception about the nature of an agent (human vs. AI) may constitute an unfair or deceptive practice under certain circumstances.

State level: California's AB 302 (signed 2019) requires that bots disclose they are not human when asked directly. Several other states have introduced or passed similar legislation.

Practical guidance:

  • Your AI should honestly answer "Are you a person?" or "Am I talking to a robot?" — never deny being an AI when directly asked
  • Including a subtle indicator in the greeting ("Hi, this is [Name], an automated assistant with [Company]...") pre-empts the question and demonstrates transparency
  • Document your disclosure practice in case of regulatory inquiry

CCPA and State Privacy Laws

The California Consumer Privacy Act (CCPA) and similar laws in Colorado, Virginia, Connecticut, and other states create rights for customers related to their personal data — which includes call recordings and transcripts.

Relevant rights for call data:

Right to know: Customers can request disclosure of what personal information you have about them, including call recordings.

Right to delete: Customers can request deletion of their personal information, including call recordings and transcripts.

Right to access: Customers can request a copy of their personal information.

Right to non-discrimination: You cannot penalize customers who exercise these privacy rights.

What this means operationally:

  • You need a process to respond to customer data requests (typically 30-45 day response window)
  • Your AI voice provider needs to support data deletion at your direction
  • You should have a written retention policy: how long are recordings kept, and when are they deleted?

Data Retention: How Long Is Too Long?

There is no universal legal requirement on call recording retention duration for service contractors. But your retention policy should balance business needs against privacy obligations:

Business reasons to retain:

  • Dispute resolution: a recording from 6 months ago can resolve a customer claim
  • Quality assurance: reviewing call handling over time
  • Training: using real calls for staff development
  • Legal documentation: evidence of what was communicated

Reasons to limit retention:

  • Reducing exposure if a breach occurs
  • Lower storage costs
  • Compliance with customer deletion requests
  • General privacy best practice (minimize data you don't need)

Reasonable retention policy for contractors:

  • Call recordings: 12–24 months
  • Transcripts and summaries: 24–36 months
  • Customer contact data: active customer lifecycle + 3 years post-last-contact

Document your policy in writing and apply it consistently.


Vendor Due Diligence: Your Provider's Practices Matter

Your AI voice provider handles your call data. Their security and privacy practices directly affect your compliance posture.

Questions to ask your AI voice vendor:

Data storage:

  • Where are recordings and transcripts stored? (US-only, specific cloud region?)
  • Are recordings encrypted at rest and in transit?
  • Who at the vendor has access to your call data?

Data handling:

  • Do they use your call data to train their AI models? (If yes, ensure your customer data is excluded)
  • What happens to your data if you cancel the service?
  • What is their data retention policy, and can you configure it?

Breach notification:

  • What is their incident response process for data breaches?
  • How quickly do they notify customers?
  • What regulatory notifications do they make on your behalf?

Compliance certifications:

  • SOC 2 Type II
  • HIPAA Business Associate Agreement (if you serve any healthcare facilities)
  • ISO 27001

Get vendor commitments in writing. Your privacy policy needs to accurately describe where data goes.


Customer-Facing Practices

Beyond the legal baseline, these practices build customer trust:

Transparent privacy policy: Your website privacy policy should describe that you record calls, why, how data is stored, and how customers can exercise their rights. Most states require this for businesses above minimum size thresholds.

Easy opt-out for non-emergency matters: Some customers will not want their call recorded. Having a process to handle these requests (transfer to a non-recorded line, or accommodate the request and keep only a manual log) demonstrates good faith.

Security for transcripts: Call transcripts contain personal information: names, addresses, payment conversations, health or safety information. Restrict access to people who need it; don't store transcripts in unsecured shared drives.


TCPA Considerations for Follow-Up Communications

AI voice often triggers follow-up text messages (confirmations, reminders, notifications). The Telephone Consumer Protection Act (TCPA) governs automated text messages to consumers:

  • Sending automated texts to numbers on the National Do Not Call Registry requires express written consent
  • Transactional messages (appointment confirmation) have different treatment than marketing messages
  • Opt-out requests for texts must be honored immediately

If your AI voice system sends follow-up texts, verify that your text messaging practices comply with TCPA and your AI provider's compliance framework addresses this.


FAQ

What if a customer in a two-party consent state refuses consent and the call was already recording? If you're using proper disclosure in your greeting (before recording begins), this shouldn't arise — the disclosure happens before any recording. If you've already started recording and a customer objects mid-call, stop the recording if technically possible and note the objection in the call log.

Does HIPAA apply to contractor calls? HIPAA applies to covered entities (healthcare providers, insurers) and their business associates. Most contractors are not HIPAA-covered unless they provide services to healthcare facilities as part of a formal Business Associate Agreement. That said, calls involving medical information (elderly customer's medical equipment failing) should be handled with appropriate discretion.

What about calls from business customers rather than consumers? Business-to-business calls have less regulatory complexity. CCPA applies to consumers, not businesses. However, state wiretapping laws still apply to B2B calls — consent and disclosure requirements don't distinguish between consumer and business callers.


Compliance Is an Ongoing Practice

Privacy law in this area is evolving rapidly. The current framework described here reflects 2026 requirements, but state legislatures continue to act on AI disclosure, data privacy, and recording consent. Review your compliance posture annually, or when you expand to new states.

For the full overview of AI voice capabilities and how they connect to your business operations, see the voice AI guide. For CRM integration and how call data flows into customer records, see AI voice and CRM integration.