Most contact centres keep call recordings for as long as storage is cheap, which is to say indefinitely. That is a decision, even when nobody made it deliberately, and it is usually the wrong one.
Recordings are among the most sensitive data a contact centre holds: voices, names, account details, sometimes payment information and health details. Every additional month you keep them is a month they can be breached, subpoenaed or mishandled.
What actually drives the number
Four forces pull in different directions, and the right answer is wherever they balance for your business:
| Driver | Pushes retention | Typical reasoning |
|---|---|---|
| Regulatory requirement | Longer | Sector rules may mandate a minimum period |
| Dispute resolution | Longer | Recordings settle billing and commitment disputes |
| QA and coaching | Shorter | A recording older than a quarter has little coaching value |
| Privacy and breach exposure | Shorter | Data you no longer hold cannot be leaked |
Note that the QA argument for long retention is weaker than people assume. Coaching an agent on a call from fourteen months ago is not useful to anyone. Once the score and the analysis are stored, the audio itself has a short useful life.
Separate the recording from the analysis
This is the distinction that resolves most retention arguments. The audio and the derived data do not need the same lifetime.
- The recording is the sensitive asset. It contains the voice, the personal details, and everything you would rather not hold longer than necessary.
- The score and analysis are derived, far less sensitive, and where the long-term value sits. Trends, parameter pass rates and agent history are all preserved without keeping the audio.
A twelve-month view of an agent's performance does not require twelve months of audio. It requires twelve months of scores.
"Deleted" should mean deleted
Ask any vendor precisely what happens at expiry. There are two very different answers:
- The recording is removed from storage. It is gone, and cannot be produced by anyone.
- The recording is hidden from the interface but retained in the underlying store.
The second is not retention management; it is a display filter. If you are answering a security questionnaire or a data subject request, it will not hold up. Xperia's retention window deletes recordings from storage rather than concealing them, and changing the window is an explicit confirmed action so it is not adjusted by accident.
The identifiers hiding in your file names
A frequently missed exposure: recording file names routinely contain a phone number, an account reference or a customer ID. Retention policy covers the audio and often ignores the name attached to it.
That matters because file names are visible far more widely than recordings — in call history, in dashboards, in exported reports. Anyone who can see a scorecard can see the identifier. Masking all but the trailing characters solves it without changing anything upstream.
Practical starting points
Not legal advice — your regulator and your counsel decide the floor. But as a shape for the conversation:
- Establish the regulatory minimum for your sector and jurisdiction first. That is a floor, not a target.
- Ask how far back disputes realistically reach. For many businesses this is months, not years.
- Set audio retention near the longer of those two, not comfortably beyond it.
- Retain scores and analysis for longer, since they carry the reporting value at a fraction of the sensitivity.
- Confirm expiry means deletion from storage, and test it once.
Who should be able to change it
Retention should not be editable by anyone who can log in. It is an administrator-level control, changes should be deliberate and confirmed, and the people who can alter it should be a short list you could name.
Indefinite retention is not caution — it is unexamined risk accumulating monthly. Recordings have a genuine useful life measured in months for most businesses, and the derived analysis carries the long-term value at far lower sensitivity.
Decide the number, confirm expiry actually deletes, and check whether your file names are quietly publishing customer identifiers to everyone with a login.
