Legal bases, employee monitoring, prohibited emotion recognition, DPIAs, processor contracts and international transfers
YARD Law Co. · Legal status checked 31 August 2026
Recording a customer call and analysing that recording with AI are not one legal operation. A company may have a lawful reason to record calls and still need a separate analysis of what happens when those recordings are transcribed, scored, summarised, profiled or sent to an external AI provider.
The right compliance question is therefore not "can we use AI on our calls?" but: what data are we processing, for which purposes, on what legal basis, through which providers, with what consequences for customers and employees?
The dates matter here, because the obligations that apply to a contact centre today are not the ones most commentary describes.
Applying now: the Article 5 prohibitions, including workplace emotion recognition subject to the statutory medical and safety exception, and the Article 4 AI-literacy duty - both since 2 February 2025. Article 4, as amended by Regulation (EU) 2026/1744, requires providers and deployers to take measures to support the development of AI literacy among their staff and other persons dealing with AI systems on their behalf, and expressly does not require them to guarantee a specific level of AI literacy for any individual. General applicability of the Regulation, and the Commission's power to impose penalties, run from 2 August 2026.
Deferred: Regulation (EU) 2026/1744 rescheduled the core Chapter III obligations for high-risk systems classified under Article 6(2) and listed in Annex III from 2 August 2026 to 2 December 2027 under the amended Article 113, and those for high-risk AI embedded in products covered by Annex I to 2 August 2028. Our note on what applied and what slipped sets out the detail.
The practical consequence: the prohibition on workplace emotion recognition binds a contact centre now, while the high-risk regime for worker-evaluation systems is a 2027 problem to design for, not a 2026 one to panic about.
No. But recording a telephone conversation processes personal data whenever the recording relates to an identifiable person. The organisation must identify a lawful basis under Article 6 GDPR and comply with the principles of transparency, purpose limitation, data minimisation, retention and security.
The European Data Protection Board addresses call recording for service-quality purposes directly, and states that customers must be informed about matters including the purpose of the recording, the recipients, the right to object and the right of access.
Companies often reduce this to "do we need consent?". That is too simple a question to produce a reliable answer.
Not necessarily. The GDPR contains several possible bases, including consent, contractual necessity, legal obligation and legitimate interests. Which applies depends on why the call is recorded and what is done with the recording afterwards.
Where legitimate interests are relied on under Article 6(1)(f), the controller needs a defensible assessment of three things:
EDPB guidance treats this as a structured assessment, not a catch-all permission.
The right basis can also differ between purposes. Recording to evidence a regulated transaction is not the same purpose as recording every sales call so an AI system can score an employee's persuasion skills. They should not automatically be treated as one processing activity.
Assume a company already records calls lawfully, then introduces software that transcribes every conversation, summarises it, identifies topics, assesses sentiment, scores the salesperson, predicts whether the customer will buy, detects compliance failures and generates coaching recommendations.
That change can materially alter the nature, purposes and risks of the processing. The new processing should be mapped separately, rather than assuming that permission to record carries permission to do anything with the audio.
The GDPR's transparency requirements oblige the controller to tell individuals the purposes, legal basis and relevant recipients. If the AI use creates a new purpose or a materially different use of the data, the existing privacy information and legal-basis analysis may no longer be sufficient.
A contact-centre deployment usually processes two groups at once: customers, whose voices and statements are recorded, and agents, whose performance and conversations are continuously analysed. The second group is easy to overlook.
An AI quality-assurance platform may produce agent scores, rankings, behavioural profiles, compliance flags, recommended training, disciplinary triggers and inputs to promotion or dismissal. At that point the system is not merely analysing customers; it is monitoring workers. That raises the importance of proportionality, transparency, Bulgarian labour-law considerations and the AI Act.
This is the most immediate 2026 issue in contact-centre AI procurement. Article 5 of the AI Act prohibits AI systems intended to infer the emotions of natural persons in the workplace, except where the system is intended for medical or safety reasons. That prohibition is in force now.
Vendors therefore need examining carefully when they market features using language such as:
Not every system labelled "sentiment analysis" necessarily falls within the AI Act definition of emotion recognition. The technical function and intended purpose have to be examined. But the label the sales team uses is not decisive, and a company should understand what the model actually infers, and from which signals.
The AI Act also regulates certain systems used in employment and worker management. Annex III covers particular AI systems used in recruitment, and systems used to make decisions affecting work relationships, to allocate tasks based on personal characteristics or behaviour, and to monitor or evaluate workers.
The core Chapter III obligations for high-risk systems classified under Article 6(2) and listed in Annex III are scheduled to apply from 2 December 2027, following the amendment of Article 113 by Regulation (EU) 2026/1744. A worker-evaluation platform being procured now should still be classified and designed against them, because a system chosen in 2026 will normally still be running in 2027 - but the full high-risk compliance regime is not applicable in August 2026.
Whether a particular call-analysis platform falls into a high-risk category depends on its intended purpose and how it is used. A transcription tool that only creates searchable notes is very different from a system whose scores materially determine promotion, dismissal, task allocation or disciplinary treatment. The analysis should follow actual deployment, not the software's product category.
Potentially. Article 22 protects against decisions based solely on automated processing, including profiling, where the decision produces legal effects or similarly significantly affects the person.
This does not mean every AI-generated quality score breaches Article 22. But once automated scores determine significant decisions about customers or employees without meaningful human involvement, Article 22 has to be assessed. A manager clicking "approve" on whatever the algorithm recommends is not necessarily meaningful human decision-making.
Often the answer should be yes, before deployment rather than after something goes wrong. Article 35 GDPR requires a DPIA where processing, particularly involving new technologies, is likely to create a high risk to individuals' rights and freedoms.
Large-scale AI analysis of recorded conversations can involve several risk-increasing factors at once:
A DPIA is not a formality. A useful one forces the business to answer what the system is doing, what data enter and leave it, what outputs are created, who sees them, how long they are kept, which decisions rely on them, what can go wrong and what safeguards reduce that risk.
This matters especially where a contact centre handles calls for several clients. The roles cannot be settled by contract labels alone. One company may be controller for one purpose and processor for another.
A client may determine why its customer calls are made and recorded, while the contact centre processes the recordings on that client's instructions. But if the contact centre independently decides to use all recordings, across clients, to train its own analytics system, that is a materially different role analysis.
Where an AI vendor processes personal data on behalf of a controller, Article 28 GDPR requires an appropriate processor arrangement, and obliges controllers to use processors that provide sufficient guarantees. The vendor contract therefore matters.
Before signing, the company should know the answers to these:
A general assurance that the platform is "GDPR compliant" is not a substitute for answering these.
Many AI providers, or their sub-processors, operate outside the European Economic Area. That does not prohibit using the service. But the controller must identify whether a transfer occurs and, where it does, establish the appropriate GDPR transfer mechanism and safeguards.
This should be mapped before deployment, because a European-looking SaaS provider may itself rely on infrastructure or sub-processors elsewhere.
There is no universal GDPR retention period. The period must be tied to the purpose, and indefinite retention will generally be difficult to justify for a narrowly defined quality-control purpose.
The analysis should also distinguish between the different artefacts a single call now produces:
Deleting the audio while retaining a permanent employee profile is not, in any meaningful compliance sense, deleting the call data.
The weakest approach is to buy the AI product and write the privacy notice afterwards. A better sequence:
| Phase | What it covers |
|---|---|
| 1. Map the current recording | Who records, why, on which basis, with which notices and retention periods. |
| 2. Map the AI system | Inputs, outputs, model functions, vendors, sub-processors, transfers and decision uses. |
| 3. Assess bases and roles | Controller/processor positions, the Article 6 basis, employee issues, Article 22 and AI Act classification. |
| 4. Complete the DPIA | Where required, before the high-risk processing starts. |
| 5. Update contracts and transparency | Article 28 agreements, privacy information, internal policies, vendor terms. |
| 6. Restrict access and retention | Define who can see audio, transcripts, scores and profiles, and for how long. |
| 7. Train the people using it | The Article 4 AI-literacy duty has applied since 2 February 2025. As amended, it calls for measures that support the development of AI literacy among staff and others handling AI systems on the company's behalf, rather than a guaranteed level for any one individual. |
For companies introducing AI into sales or contact-centre operations, our review can cover whether the existing call recording has a defensible GDPR basis; customer and employee transparency notices; controller and processor allocation; AI vendor and sub-processor contracts; international transfers; retention; legitimate-interest assessments; DPIA requirements and drafting; profiling and automated decision-making; employee monitoring; AI Act classification and prohibited-practice screening; and internal AI-use policies.
The objective is not to stop the business using AI. It is to identify which parts of the proposed system can be deployed normally, which need safeguards, and which features should not be switched on at all.
See also our notes on the AI Act in August 2026 and our data protection practice.
Not necessarily. The GDPR offers several possible legal bases and the correct one depends on why the call is recorded and what is done with the recording afterwards. Whichever basis applies, customers must still receive the required information about the processing.
Not automatically. AI analysis can introduce new purposes, new recipients, profiling, new risks and international transfers. Those need their own assessment rather than being treated as covered by the original decision to record.
A DPIA is required under Article 35 GDPR where the processing is likely to result in a high risk to individuals. Large-scale systematic analysis of recorded conversations, profiling and worker evaluation are the kinds of factors that make that likely.
Article 5 of the AI Act prohibits AI systems intended to infer the emotions of natural persons in the workplace, except for medical or safety reasons. That prohibition has applied since 2 February 2025 and is not affected by the 2026 postponement of the high-risk rules.
Not necessarily. What matters is the technical function and the intended purpose of the system, not the words used in the vendor's marketing. The actual inference the model makes, and the signals it makes it from, have to be examined.
Possibly, but systems that monitor or evaluate workers can engage the GDPR, Bulgarian labour law and the AI Act at the same time. How significant the score is, and what employment decisions rest on it, are the decisive questions.
Potentially, but the processor arrangement under Article 28 GDPR and any transfer of personal data outside the EEA must be assessed before deployment, including transfers made by the vendor's own sub-processors.
No. The business deploying the system remains responsible for its own purposes, legal bases, transparency, role allocation and use of the outputs. A vendor cannot be compliant on your behalf.
This article is general information as at 31 August 2026 and is not legal advice on a specific case. AI systems differ substantially in technical function and intended purpose, and legal classification must follow the system actually being deployed. AI Act application dates are staged and were amended by Regulation (EU) 2026/1744; the position should be confirmed against the operative text at the time of acting. Prepared by the legal team at YARD Law Co., a law firm based in Sofia, Bulgaria.
Introducing AI into your call recording?
Legal bases, DPIAs, employee monitoring, AI Act screening and vendor contracts.