A call recording is personal data. That is the whole thing in one sentence, and almost everything else follows from it.
Kenya's Data Protection Act 2019 governs personal data about identifiable people. A recording of somebody's voice, giving their name and account number, is squarely inside that. So the same duties apply to it as to a customer database — and most businesses that record calls have thought hard about the database and not at all about the recordings.
Four things that follow
1. Tell people
Callers should know they are being recorded before it starts. In practice that is a line in your greeting: "This call may be recorded for training and quality purposes."
It has become background noise through repetition, which is unfortunate, but saying it is still better than not. If recording is on, the greeting should say so.
2. Have a reason
You need a lawful basis for holding the recording. For most call centres that is legitimate interest — quality monitoring, training, resolving disputes — or a legal obligation where a regulator requires it.
The test worth applying yourself: could you explain to the customer, in one sentence, why you kept this? If not, you probably should not have.
3. Do not keep them forever
This is where most businesses drift. Storage is cheap, so recordings accumulate, and a system that never deletes anything is holding thousands of conversations with no reason attached to any of them.
Set a retention period and enforce it automatically. Ninety days covers most quality and dispute needs. Some regulated sectors require longer — and where they do, that requirement is your reason for keeping them.
4. Control who can listen
Not everybody with a login should be able to play back a customer conversation. Access should follow the job: quality staff and supervisors, generally, and not every agent.
It is also worth logging who listened to what. If a recording ever leaks, the first question is who had access — and "everybody" is a bad answer.
What a subject access request looks like
Someone can ask what you hold about them, and that includes recordings of their calls. You have thirty days.
Thirty days sounds generous until you try it. If the answer involves someone searching by hand through months of files, you will not manage it. Being able to find every call from one number in a few seconds is the difference between a routine request and a crisis.
Registration
Data controllers and processors above certain thresholds must register with the Office of the Data Protection Commissioner. If you are recording customer calls at any volume, look into whether you need to — it is not expensive, and it is a poor thing to be found not to have done.
How this system handles it
- Recording is off unless you switch it on, and it is set per team rather than globally.
- You set a retention period; recordings are deleted automatically when it passes, and the call record stays so your reporting is not full of holes.
- Access is by role, and every playback is logged.
- Every call from a number can be found instantly, which is most of a subject access request.
- An export command produces contacts, calls and messages as files you can hand over.
None of that makes you compliant by itself — compliance is what your business does, not what your software allows. But it means the software is not the thing standing in your way.