In a recent interview with Red Box Recorders CEO, Richard Stevenson, UC Today opened up a discussion into what impact the GDPR will have on call recording compliancy in business, how resellers and end users will be affected by it and what steps they must take to ensure they are covered once the regulations begin.
As of 25th May 2018, the GDPR will be implemented to fortify data protection for all individuals in the EU and, as a result, is putting huge pressures on businesses who risk facing huge fines should they fail to comply after that date.
Amongst other things, one of the major concerns for businesses, specifically with regards to call recording, is the new “right to be forgotten” regulation that allows people to request that any of their personal data (that is stored without any compelling reason) be erased from a company’s records.
As you may imagine, this can be extremely problematic for any businesses that have been keeping ongoing records of their conversations with clients and many business owners and call recording providers are concerned with how they will be able to overcome this issue.
In order to try and clear up some of the confusion and help our readers find a solution, we spoke with Red Box Recorders’ CEO, Richard Stevenson, a man who has a wealth of experience in dealing with data regulation practices, and picked his brain on what advice he could give to all of those who are uncertain about GDPR and how it will impact their business.
GDPR and Call Recording for Business Owners
Firstly, we thought it would be good to start off by looking at the GDPR from the perspective of business owners so we asked Stevenson what advice he could give to people in that position.
Interestingly enough, his first response was that technology, “though somewhat important, is not the complete solution.” As it stands, there is no audit or certification that can be given to a call recording solution to label it as GDPR compliant and, therefore, the solution must begin with the people themselves which is then supported by the tools they use.
“First of all, you must ensure that every employee understands your business’s privacy policy and how that will impact their day to day work, the processes they follow, the outcomes they are trying to achieve and get them to think every single day – “what type of data am I utilising?””
For Stevenson, it is essential that businesses provide extensive training programmes on their data privacy policies, ensuring that each employee is fully aware of what data they’re permitted to use and whether or not it conflicts with said policies.
He also stresses the importance of including data mapping exercises to ensure that all information is securely stored in a specific location and that all staff members know exactly where those locations so that it can be quickly accessed by authorised individuals whenever necessary.
Another interesting point he raised with regards to the GDPR deadline and the pressures businesses face to be fully compliant by that date was that, for many businesses, this goal is largely unrealistic.
“Like any regulation the GDPR has cost associated with it and being a fully compliant business that makes no money is not a great position to be in.”
Instead, he argues that business owners must take a more pragmatic approach to GDPR and understand to what extent they are going to put forward a solution that delivers for their customers without damaging their business.
GDPR for Call Recording Resellers
After looking at GDPR from business owner’s perspective, Stevenson then moves on to the perspective of a supplier, opening with the statement that, he believes:
“GDPR has completely changed the landscape for infrastructure in general” and suppliers can no longer afford to put infrastructure in silos."
All data must be easily accessible and if it is locked, or if the supplier is unable to port that data to anybody else that requires it, it could lead to disastrous consequences and regulators will show little mercy for those unable to perform this task.
“One of the worst things you can do with any regulator on any issue is state that you are doing something and they find out that you are not”
Likewise, if a business is responsible for capturing call recordings and they are unable to provide that data on request, or deliver sub-par, low-quality recordings that do not deliver what they claimed to, regulators are likely to clamp down heavily on them for their negligence.
In regard to the right to be forgotten, one thing we have come to know about call recording solutions is that they will typically encrypt all of the information they store and deleting calls from them was usually not possible without a great deal of time an effort – which, as we touched upon earlier, is not always an option for the majority of businesses.


GDPR- it's getting closer and is less than a year away[/caption]

