Call recording laws for small business: a plain-English guide
Matt Smith· 28 May 2026 · Compliance · Guides
You almost always need to tell the other person a call is being recorded. In 12 US states you need their active consent, not just a notice. This guide covers the UK, US and EU rules as of July 2026, in plain English. It includes the specific list of consent states and what a small business should actually put in place.
None of this is legal advice. Rules shift and enforcement varies by state and regulator. Treat this as a starting map, not a final answer for your business.
The UK rule, in one paragraph
UK businesses can record calls under the Telecommunications (Lawful Business Practice) Regulations 2000, for reasons like training, quality and dispute resolution. You still need a lawful basis under UK GDPR (usually “legitimate interests”). You must also tell callers at the start of the call that it’s being recorded, and store recordings securely with a defined retention period.
As of July 2026, the ICO’s updated guidance also expects a documented Legitimate Interest Assessment. It also expects separate disclosure if you use AI to transcribe or analyze calls, since that’s treated as its own processing activity.
The maximum PECR fine now sits at £17.5m or 4% of global turnover, whichever is higher. That means small businesses can’t treat this as optional because of their size. The ICO has repeatedly rejected the idea that small headcount exempts you from UK GDPR.
The US rule: one-party vs all-party consent
Federal law and 38 US states plus Washington DC use one-party consent. As long as one person on the call (you) knows it’s being recorded, that’s legal, even if the other party doesn’t know. But 12 states require all-party consent, meaning everyone on the call has to agree.
As of July 2026, the all-party consent states are:
- California
- Connecticut
- Delaware
- Florida
- Illinois
- Maryland
- Massachusetts
- Montana
- New Hampshire
- Oregon
- Pennsylvania
- Washington
A few of these have quirks worth knowing. Connecticut requires all-party consent for phone calls specifically but one-party for in-person conversations under its criminal statute. Oregon flips the other way for some communication types. Nevada isn’t on the all-party list above, but it has its own split rule (one-party in-person, all-party for phone calls). It’s worth treating as a de facto twelfth state to be careful with.
The practical fix that avoids the whole problem: play an automated notice at the start of every call (“this call may be recorded for quality and training purposes”). Treat continued participation as consent. Courts have generally accepted this pattern as valid consent in all-party states. It costs you nothing to apply it everywhere, so there’s no reason to run different rules by area code.
The EU basics
EU rules run through GDPR plus each member state’s own telecoms and labor law layered on top. The pattern is consistent with the UK: you need a lawful basis (legitimate interest is common for quality/training use cases), and you must inform participants before or at the start of the call. You must also apply data minimization, meaning don’t keep recordings longer than the stated purpose requires.
Some member states (Germany and France notably) have stricter workplace consent rules for recording employees specifically, separate from the customer-facing rules. A business recording both customer and internal calls should check both layers rather than assuming one policy covers everything.
What a small business should actually do
Four things cover the large majority of small business cases, regardless of country.
First, play a recorded notice at the start of every call, every time, everywhere. It satisfies UK/EU disclosure requirements and covers all-party consent in the strictest US states. It also removes the need to maintain a state-by-state or country-by-country routing rule.
Second, write down your retention period and stick to it. 30, 60 or 90 days is typical for quality and training use. Keep it shorter if you don’t have a specific dispute-resolution reason to hold longer. This is the single most commonly missed step in ICO guidance for UK small businesses.
Third, restrict who can access recordings and keep a call log of that access. This satisfies the UK GDPR “appropriate security” requirement. It also meets the practical need to answer a subject access request within the one-month window UK law allows.
Fourth, if you use AI to transcribe or summarize calls, say so in your privacy notice as a separate processing activity. Don’t fold it into a generic “we record calls” line. This is the specific gap the ICO’s 2026 guidance update called out.
Why enforcement risk is rising, not falling
The trend across all three jurisdictions this year points the same direction: higher maximum fines and more specific guidance around AI-assisted analysis. There’s also less tolerance for the “we’re too small to worry about this” argument. The UK’s PECR fine ceiling rise to £17.5m is one data point.
The other is the ICO’s specific attention to AI transcription and sentiment scoring as a distinct processing activity. That suggests regulators are watching how call data gets used after it’s recorded, not just whether it’s recorded at all.
For a small business, the practical read is this: treat recording as a data handling process with a beginning, middle and end (notice, storage, deletion). It’s not a one-time toggle you switch on and forget. Revisit the retention setting at least once a year. Check it again if you add an AI transcription or summary feature to your call system, since that’s the one change most likely to require a fresh disclosure update under current guidance.
Worked example
A 5-person sales team, three reps based in California (all-party), two in Texas (one-party), calling prospects across the US. Rather than build state-detection logic into the phone system, the team plays the same recorded consent notice on every outbound and inbound call. This happens regardless of caller location. Cost: zero extra engineering, and it covers the strictest state in the mix by default.
Where wlur fits
Getting the notice, retention and access-logging pieces right without hand-rolling them is exactly the kind of setup work a feature should handle for you. That’s what call recording does, rather than leaving it to a spreadsheet of state rules.
FAQ
Do I need consent to record my own outgoing sales calls?
If you’re calling into an all-party consent state, yes, you need the other party’s consent too. Just your own knowledge that the call is recorded isn’t enough. A recorded notice at call start, that the person continues the call after hearing, is the standard way small businesses handle this.
Is a recorded “this call may be recorded” notice legally enough on its own?
Courts in all-party states have generally treated continued participation after the notice as valid consent. But this isn’t guaranteed law in every jurisdiction. It’s the most practical baseline, not a guarantee. Pair it with the other three steps (retention limits, access control, AI disclosure) covered above.
What happens if a UK business ignores GDPR because it’s small?
The ICO has consistently rejected size-based exemptions. UK GDPR applies to any controller or processor handling UK residents’ personal data. PECR fines can reach £17.5m or 4% of global turnover.
Does call recording law cover text messages and SMS too?
This guide covers voice calls specifically. Business SMS has a separate compliance framework (opt-in consent, A2P registration in the US) that’s worth checking separately. See call recording laws for the terminology breakdown.
Do I need different recording settings for different states?
No, and building that is more work than it’s worth. Applying the strictest standard (all-party consent notice) universally is simpler to build, audit and defend. That beats routing logic based on area code or caller location.
About the author
Matt Smith· Founder, wlur. Matt builds wlur, the business phone system for solo founders and small teams. Before wlur he built mowt, a subscription analytics product, and spent years watching small businesses get sold call-centre software they didn't need.