Guide
GDPR and AI phone calls: what UK businesses need to know.
An AI receptionist doesn't sit outside data protection law — the same UK GDPR and PECR rules that govern a human answering your phone apply here too. This is the practical version, not the legal-team version.
The basics
Nothing about using AI removes your obligations.
If your business already answers calls from UK customers, you already have obligations under UK GDPR and the Privacy and Electronic Communications Regulations (PECR) — a lawful basis for processing what's said, limits on how long you keep it, and rights for the caller to ask what's held about them. Putting an AI system on the line doesn't remove any of that. It usually adds one more party to think about: the AI provider itself, and what role they play in processing your customers' data.
What actually needs checking
Four things to get right.
The recording and AI disclosure
Callers should be told plainly, near the start of the call, that they may be speaking to a digital assistant and that the call may be recorded. This shouldn't be optional or something a business can quietly switch off.
Who's the controller, who's the processor
Your business is normally still the data controller for your own customers. The AI receptionist provider is a processor, and should be willing to sign a data processing agreement and name their own subprocessors.
Where the data actually goes
Ask specifically which country the calls and any transcripts are processed and stored in, and under what safeguard if it leaves the UK or EEA.
Retention and deletion
Ask how long call data and transcripts are kept, and what happens to them if you cancel — data that keeps sitting on a server after you've left is a liability nobody wants.
How SIMCOAI approaches this
What we actually do, not a general promise.
The disclosure is enforced, not optional
Every answered call opens with a notice that it's answered by a digital assistant and may be recorded. This cannot be switched off by a customer.
UK GDPR by design
SIMCOAI LTD is a UK company built around UK GDPR, PECR and Ofcom requirements from the outset, with subprocessors named on the GDPR page.
Escalation for anything sensitive
Safety, medical, legal and payment-card topics are routed to a person rather than handled by AI — see how escalations work.
This page is general information, not legal advice. Full detail on lawful basis, retention, subprocessors and rights is on the GDPR and privacy pages.
Common questions
What businesses ask.
Do I need to tell callers an AI is answering?
Yes, in practice — transparency is core to UK GDPR. SIMCOAI's disclosure is enforced automatically and cannot be switched off.
Who's the data controller?
Usually your business, with the AI provider as processor under a data processing agreement. Check any provider will sign one.
Does GDPR apply differently to AI than a human receptionist?
The law is the same. What changes is the practical detail — where the AI logs the conversation and which subprocessors are involved.
Read the detail
See exactly how SIMCOAI handles this.