Guides

Call log retention: how long to keep call data under the GDPR

Call logs, metadata and recordings each need their own retention period. This guide shows how to set them by purpose, who owns each one, and what happens when someone deletes a call in an app.

Call logs, metadata and recordings shown as three separate kinds of call data, each with its own retention period

A salesperson hands back their company mobile on their last day. A receptionist spots a sensitive call still showing on a shared screen. Someone asks IT to wipe the call history, and everyone assumes the problem goes away with one tap.

Call log retention sets how long your business keeps a record of each call and who's allowed to end that record. This guide is for IT managers, telecom resellers and integrators who run a cloud phone system for a small or mid-sized company. It treats the call log, the metadata behind it and the recordings as separate data, because under the GDPR each one runs on its own clock.

What call log retention means

Call log retention is the period a phone system keeps its record of calls, plus the rules that end that period. Each log entry holds metadata. That covers the date, time and duration, the numbers on both ends, the extension or queue involved and the outcome of the call. Recordings and transcripts are content, and they carry their own retention period.

Retention is set on the platform. When a user deletes an entry in their app, their own screen changes. The platform's record keeps to whatever schedule the administrator has set for it. Most confusion about call history begins when those two actions get treated as one.

Your business decides one thing for every type of call data: hide it, delete it, archive it, or keep it for a specific obligation. If you skip that decision, you'll end up thinking data is gone when only the display has changed.

Deleting call history on the user side

User-side deletion is useful for privacy at the desk. Examples include a returned mobile, a reassigned reception phone, or a test call left over from go-live. In each of these cases, removing the entry does exactly the job that's needed.

In a browser or Windows softphone, the log usually sits under recent calls. Most apps offer both a single-entry delete and a clear-all action. Mass deletions tend to start in two places. One is a filtered view that hides part of the list. The other is a shared PC where someone else's account is still signed in. Deleting one entry at a time is the safer habit for a single sensitive call.

On an iPhone, the Recents tab in the Phone app lets you swipe left on one call or tap Edit to clear the list. The filter matters here too, since "Missed" and "All" show different lists. On Android, the path depends on the handset maker and the dialler app. Support staff save time by asking the user to describe their screen before any bulk wipe.

Everything on this side of the system affects one person's view. It has no effect on the company's retention policy, which lives with the administrator.

Setting a call data retention policy by purpose

Table of four purposes for call data, with the retention logic and the admin action for each one

An administrator works across three layers: what users see, what the platform stores, and who governs the data. Keeping those layers apart from day one prevents most retention mistakes. The admin policy covers logs, exports, any recordings, access rights and the purge at the end of each retention period.

Purpose drives the period. A log used for day-to-day support gets different treatment from a recording used for training, and different again from evidence tied to a contract. When all of them share one rule, the business either keeps data too long or purges it too early.

PurposeRetention logicAdmin action
Training or quality assuranceShort period, with deletion scheduled at the endSchedule the purge and restrict who can listen
Analysis of work activityLimited period, controlled access, kept apart from individual performance reviewsIsolate the data you need, log who opens it, purge on the internal schedule
Sales follow-up after a contract endsLonger period where the purpose and lawful basis justify itMove it out of the live log into a dedicated archive
Contractual evidenceHeld apart from daily use, with tighter access rightsArchive outside the operational views and limit manual deletion

Roles: who deletes and who keeps

Three roles in order: the user manages their display, the supervisor sees team data, the administrator owns retention

The setup that holds up over time gives each role one job. Users manage their own display. Supervisors see the data they need to run their team. The administrator owns retention, export, archiving and purging.

Removing a call from a view leaves the related metadata on the platform. In the other direction, an admin purge can reach further than intended if nobody has decided in advance which data serves daily operations, which serves as evidence and which serves quality control.

Weekly manual clean-ups create drift between teams and make audits harder. They also leave plenty of room for human error. A written retention rule, applied per user profile and per data type, is far easier to defend in the EU, where you'll need to explain the reasoning behind each period.

Call history with Microsoft Teams

With telephony connected to Microsoft Teams, a user often sees two histories. Teams shows its own call list inside Microsoft 365, and the phone platform keeps a fuller telecom record. The link between them depends on how you've connected the two, as covered in Teams Direct Routing vs Operator Connect.

A salesperson calling from Teams tends to treat the Teams list as the whole record. For governance, the metadata and some call traces sit on the phone platform, so deleting a call in one interface leaves the other untouched. Support tickets drop when you train people on what each view covers, record deletions that matter, and write down which interface is the reference.

If nobody says which view is the record, users improvise, and improvisation produces tickets instead of compliance.

Tell users from the start that display, telephony and retention may live in different layers. Once that's understood, support knows where to look, users know what they can delete, and the administrator knows what has to stay.

Call recording retention and the GDPR

The GDPR's storage limitation principle in Article 5(1)(e) of the regulation says personal data may be kept only as long as its purpose requires. Call logs, metadata and recordings all count as personal data once they can be linked to a person, so each needs a stated purpose and a period that follows from it.

Treat three objects separately:

  • the call log a user sees in their app,

  • the metadata, such as date, duration, number, status, extension or queue,

  • the content itself, meaning recordings and any transcripts derived from them.

A quality recording, proof that a call was handled, a fraud trace and a convenience entry on a screen each justify a different period. Recording brings its own rules on lawful basis and notice to callers, which call recording and GDPR walks through. Your carrier may also hold traffic data under its own national telecom rules. That copy sits outside your company's retention policy, whatever a user deletes.

Controller, processor and the cloud

A cloud phone service and Teams running side by side raise questions an auditor will ask early. Who sets the purpose, who stores the data, who deletes it, and who answers an erasure request? Your company is usually the controller. A provider can act as a processor, or share more of the responsibility, depending on how the service is used. The European Data Protection Board sets out how to tell these roles apart in its Guidelines 07/2020 on the concepts of controller and processor.

In practice, you'll want four answers on file. You need to know where the recordings are stored and who holds the metadata. You also need to know what Teams keeps, and which interface counts as the reference when someone makes a GDPR request. Hosting in the European Union makes transfers and contracts easier to read. A lawful basis, a defined retention period and a working erasure procedure are still your company's responsibility.

Call log retention checklist

Numbered checklist of six call log retention practices, from naming the layer to training Teams and mobile users

  • Name the layer. Smartphone, Windows app, webphone, Teams or admin console. The layer tells you what a deletion will reach.

  • Pick single delete or bulk purge. On a personal device, deleting entries one at a time carries the least risk.

  • Assign the roles. Retention obligations belong to the administrator, who also holds the policies and access rights.

  • Separate log, metadata and recordings. Each follows its own life cycle.

  • Write the purpose down. An auditor will ask you to justify each period against it.

  • Keep a trace of admin actions. In a dispute, you'll need to show who deleted, archived or let data expire.

  • Train Teams and mobile users first. Those two environments produce most of the misunderstandings.

  • Check hosting and cloud roles. Confirm where the data lives and what each party's contract says it does.

Mistakes that cost time

The most common mistake is one rule for every call. A well-run SME usually applies several rules in parallel. One covers the user display, one covers quality recordings and one covers contract archives.

The second mistake treats deletion as a one-off act. Without an internal procedure, users wipe entries on one side while the company keeps data elsewhere with no framework. That gap is what sets IT, business teams and compliance against each other.

Voxbi is a cloud PBX hosted in the European Union, with calls, rights and data managed from one admin console in Voxbi Cockpit. To see how its call logs and recordings would fit your retention policy, write to hello@voxbi.com, and bring your purpose table so the conversation starts from your own rules.

See Voxbi in your business.

Talk to us or to a certified Voxbi partner.