Vocalenda logoVocalenda

Running Your Business

Is an AI Receptionist UK GDPR Compliant? What Callers Must Be Told, and What Your Provider Owes You (2026)

An AI receptionist is legal in the UK, but only if three things are true: your callers are told at the moment they ring, you have a documented lawful basis that is not a fake consent tick, and your provider gives you the written Article 28 agreement the law requires. Here are the ICO's own rules, the one line every caller should hear, and seven questions to put to any provider before you connect your phone.

Radu, Vocalenda founder8 September 202624 min read
Is an AI Receptionist UK GDPR Compliant? What Callers Must Be Told, and What Your Provider Owes You (2026)

Every few weeks someone asks us a version of the same question, and it is a good one: "Is this even allowed? Someone rings my shop, a machine answers, their number and name go into a computer. Do I need a policy? Do I need their permission? Do I have to tell them?"

Most pages that answer it are written by lawyers for lawyers, or by vendors with an interest in the answer. This one is written by the person who had to work through it before Vocalenda could take its first real call, using the Information Commissioner's Office's own guidance, fetched and quoted on 2 September 2026, with a link on every claim so you can check the half that matters without trusting us.

The disclosure first, because it shapes the rest: we make an AI receptionist. So where this post describes what a provider should do, it also says plainly what ours does, including the places where our own setup is a trade-off rather than a clean win. We are also not solicitors, and nothing here is legal advice for your particular business. It is the law as the regulator publishes it, applied to a phone line, and it all hangs on one question: what does the caller hear in the first seconds of the call?

The short answer: yes, an AI receptionist can be UK GDPR compliant, and nothing in the law bans one. Three things must be true. Callers are told what is happening at the moment they ring. You have a documented lawful basis for their details, which for a booking is contract, not consent. And your provider gives you the written Article 28 agreement the law requires. Ask any provider to show you all three.

Is an AI receptionist legal under UK GDPR?

Yes. The UK GDPR does not regulate the technology that answers your phone. It regulates what happens to the personal data of the person on the other end: their number, their name, the fact that they want a fade on Thursday.

Two roles decide who is responsible for what, and it is worth getting them straight because everything else follows. The business the caller rang is the data controller: it decides why the details are collected and what happens to them. The company running the AI receptionist on the business's behalf is the processor. The ICO's guidance on contracts between the two says controllers "are primarily responsible for overall compliance with the UK GDPR", and that a processor "has some direct responsibilities under the UK GDPR" on top of its contract.

The principles are the ones GOV.UK lists on its data protection page: personal data must be "used fairly, lawfully and transparently", "used for specified, explicit purposes", "used in a way that is adequate, relevant and limited to only what is necessary", "accurate and, where necessary, kept up to date", "kept for no longer than is necessary", and "handled in a way that ensures appropriate security". An AI that takes a name and a number to book an appointment can meet every one of those. An AI that quietly keeps recordings forever and trains on them without telling anyone cannot.

Do you have to tell callers they are speaking to an AI?

In practice, yes. The interesting part is that the law never uses the word.

Article 13 of the UK GDPR is titled "Information to be provided where personal data are collected from the data subject". It lists what a person must be told, and there is no line in it that says "tell people they are talking to a machine". What it does require, in the ICO's words on its right to be informed page, is that "you must provide privacy information to individuals at the time you collect their personal data from them", and that the information "must be concise, transparent, intelligible, easily accessible, and it must use clear and plain language."

The same ICO page then addresses AI head on, under the heading "If you apply Artificial Intelligence (AI) to personal data": "Be upfront about it and explain your purposes for using AI." And its guidance on the transparency principle adds the test that matters for a phone line: transparency is about "being clear, open and honest with people from the start about who you are, how and why you use their personal information", and "if anyone is deceived or misled when the personal data is obtained, then this is unlikely to be fair."

Now put yourself in the caller's position, which the ICO literally asks you to do. A person rings your number. They have not read your privacy policy. They are not going to read it. If the only place your business explains that an automated assistant answers the phone and writes down what they say is a page on your website, then at the moment their data is collected they have been told nothing. The ICO's own guidance on delivery methods says it is "good practice to use the same medium you use to collect personal data to deliver privacy information." For a phone call, that medium is speech.

That is why we treat the spoken line as the compliance mechanism and the privacy policy as its backing detail, not the other way round. One honest detail: the caller's number arrives with the call itself, from the telephone network, before anything is said. The spoken line comes at the first moment there is anyone to tell. Every Vocalenda call opens with one sentence before the business's own greeting:

"Just so you know, you're speaking with an AI assistant, and this call is transcribed."

It is applied when the call is set up, not typed into a greeting box, so no business can edit it out or switch it off. It is one sentence on purpose: a legal preamble in front of "Thanks for calling" would cost more bookings than it protects, and the ICO asks for concise.

For contrast, the EU went further and wrote the AI part into law. Article 50(1) of the EU AI Act, Regulation (EU) 2024/1689, requires that AI systems intended to interact directly with people are built so that "the natural persons concerned are informed that they are interacting with an AI system", and the Regulation applies from 2 August 2026. That Act does not bind a UK business serving UK callers. But it tells you where the direction of travel is, and a provider that already says it out loud has nothing to change.

Do you need a caller's consent to take their name and number?

No. And asking for it would be the wrong answer, not just an unnecessary one.

The UK GDPR gives seven lawful bases, and the ICO's guide to lawful basis, updated 2 April 2026, is blunt that "no single basis is 'better' or more important than the others" and that "you must determine your lawful basis before you start using the personal information and you must document it."

For a booking, the basis is contract, Article 6(1)(b). The ICO's contract page says you can rely on it "because they have asked you to do something before entering into a contract (eg provide a quote)", and "this applies even if they don't actually go on to enter into a contract with you, as long as the processing was in the context of a potential contract with that individual." A person ringing to book Thursday at four has asked you to take a step. You need their name and a number to take it. That is the whole test.

Consent is the basis people reach for because it feels polite, and the ICO's consent page explains why it is a trap here: "If you would still process the personal data without consent, asking for consent is misleading and inherently unfair." You cannot book someone who withdraws their name halfway through. So consent was never a real choice, and the ICO adds that "you can't usually swap from consent to a different basis" later if you get it wrong.

One more case, because it is common. A caller who rings with a question and does not book has not asked you to take a contractual step. For that, the honest basis is legitimate interests, Article 6(1)(f): running a reliable phone line for the business they chose to ring, balanced against their privacy by keeping no audio and using nothing for advertising. Relying on legitimate interests carries two duties the ICO's legitimate interests page spells out: you must "include details of your legitimate interests in your privacy information", and people have a right to object. Both bases, and the reasoning behind them, are written into our privacy policy so a business using Vocalenda inherits a documented answer rather than having to invent one.

If you are a dental practice, a massage therapist or a wellness business, there is an extra layer. Whatever a caller says about why they are booking may be health information, which the ICO treats as special category data needing a lawful basis and an additional condition. That condition is yours to establish as the practice, usually Article 9(2)(h), provision of health care, and any provider you use should handle what reaches it to the same standard as everything else. Ours does, and the DPA says so.

Is the call recorded, and do you have to say so?

Ask your provider this question directly, because the answers differ and the caller must be told whichever one is true.

Providers differ on this, so ask. Vocalenda does not keep audio. The audio is turned into text as the caller speaks so the assistant can understand and act, and it is not stored as a recording. What the business keeps is the written transcript, as part of its call history, and that is what the spoken line tells the caller: "this call is transcribed."

Whatever is kept, the ICO's storage limitation principle governs how long. The rule is simple: "You must not keep personal data for longer than you need it", and "the UK GDPR does not set specific time limits for different types of data. This is up to you, and will depend on how long you need the data for your specified purposes." The ICO also says that "personal data held for too long will, by definition, be unnecessary", and that "automated systems can flag records for review, or delete information after a pre-determined period."

"As long as necessary" is not a retention period, and "for as long as you have an account" means forever for a business that stays. So here are ours, in numbers, enforced by a job that runs every day rather than by anyone remembering:

WhatHow long Vocalenda keeps it
Call audioNever stored. Text as you speak, then gone.
Call transcripts24 months, then deleted automatically. The booking itself stays.
Appointments, customer records, messagesWhile the business has an active account.
A closed account's data6 months, with a warning email 30 days before permanent deletion.
Invoices and billing records6 years, because UK tax law requires it.

A caller can ask for their information to be deleted sooner than any of that, and the ICO is clear that "individuals have a right to erasure if you no longer need the data."

Where does your callers' data actually go?

Here is the concession, and it is one you should demand from every provider rather than take from us alone.

No AI receptionist is one company. Behind ours sit a telephony carrier, a speech provider, a language model, a database, a billing processor and a few more. The ICO's guidance on the right to be informed says "you must tell people who you are giving their information to", and that "you can tell people the names of the organisations or the categories that they fall within; choose the option that is most meaningful." We name them all in the privacy policy, with what each one sees.

The part to look hardest at is geography. Everything Vocalenda stores, the appointments, transcripts, customer records and messages, lives in the EU, in Ireland. But the live call itself is handled in the United States: the speech provider that turns voice into text and back, the language model that works out what the caller asked for, and the carrier that connects the call. If a business owner turns on mobile alerts, the push notification services that deliver them may also process a caller's name outside the UK and EU. We looked at moving speech processing to an EU region, which our provider offers, and today it would mean a noticeably worse assistant, so we have kept the quality and said so in writing rather than quietly making the trade.

Sending data outside the UK is what the ICO calls a "restricted transfer", and its brief guide to international transfers, last updated 15 January 2026, says every one "must be covered by one of the following transfer mechanisms: UK adequacy regulations; appropriate safeguards; or an exception (called a "derogation" in the legislation)." For the US that means either the UK Extension to the EU-US Data Privacy Framework, where the receiving business is on the DPF list with an active status, or contractual safeguards such as the International Data Transfer Agreement or Addendum. Each of our providers is under a data processing agreement that carries one of those. What that does and does not mean is worth stating plainly: it does not mean the data is unprotected once it leaves, it means each provider is contractually held to UK-equivalent standards.

The second trade-off is the one we would rather tell you than have you find. Our speech provider runs a programme in which customer audio is used to improve the accuracy of its speech models, and we take part, because it is what keeps a service like this affordable at a small business price. That is the only place anything is used for a purpose beyond running the call. Nothing in our database, no transcript, no phone number as contact information, and nothing is used to profile, advertise to or identify anyone by voice. A caller can object to it: they tell the business they called, or email us, we add the number to our exclusion list, and from their next call onwards their audio is marked so it is not kept or used for improvement, at every business they ring. We treat that as an Article 21 objection and honour it whatever the lawful basis, which is a commitment rather than a legal entitlement: the ICO's guidance on the right to object says the right "only applies in certain circumstances", that an objection "can be made verbally or in writing", and gives "one calendar month to respond". Ours acts from the next call.

What must your provider give you? The Article 28 test

This is the section to bring to any sales call.

The ICO's guidance on contracts opens with the rule: "Whenever a controller uses a processor, there must be a written contract (or other legal act) in place." Not a privacy policy, not a line in the terms saying "we take your privacy seriously". A contract that sets out "the subject matter and duration of the processing; the nature and purpose of the processing; the type of personal data and categories of data subject; and the controller's obligations and rights", and that includes, in the ICO's checklist:

  1. The processor "must only act on the controller's documented instructions".
  2. It "must ensure that people processing the data are subject to a duty of confidence".
  3. It "must take appropriate measures to ensure the security of processing".
  4. It "must only engage a sub-processor with the controller's prior authorisation and under a written contract".
  5. It "must take appropriate measures to help the controller respond to requests from individuals to exercise their rights".
  6. It "must assist the controller in meeting its UK GDPR obligations in relation to the security of processing, the notification of personal data breaches and data protection impact assessments".
  7. It "must delete or return all personal data to the controller (at the controller's choice) at the end of the contract".
  8. It "must submit to audits and inspections".

The ICO adds that "processors remain liable to the controller for the compliance of any sub-processors they engage."

Two of those clauses deserve a closer look. On breaches, the ICO's personal data breaches guide says a controller must report a notifiable breach to the ICO "not later than 72 hours after becoming aware of it", and that a processor "must inform you without undue delay as soon as it becomes aware." The 72-hour clock is yours, and it starts when your provider tells you. "Without undue delay" is a phrase, not a number, so ask for a number. Our DPA commits to emailing you within 24 hours of becoming aware, with what we know even while we are still working out the full picture, so that your 72 hours are never spent waiting on us.

On sub-processors, the ICO says a processor "may not engage a sub-processor's services without the controller's prior specific or general written authorisation." That is why the provider's privacy policy has to name every company that touches the data, and why you should be told before one is added or replaced, with the right to object. Ours does both, and if you object and we cannot offer a reasonable alternative, you can end your subscription without penalty for the remainder of the term you paid for.

The practical upshot: any provider that cannot hand you a data processing agreement is asking you to break the law on their behalf. Ours ships as a page rather than a PDF to chase and sign, forms part of the terms every business accepts at sign-up, and is written in plain English because the reader is the sole trader running the business, not their counsel. If your accountant, your insurer or a client ever asks whether you have a data processing agreement with your phone provider, the answer is yes, and it is at vocalenda.com/dpa.

What happens when a caller asks for their data, or to be forgotten?

You answer them, on a clock, and your provider helps. Four clocks matter, and since 19 June 2026 there is a new one.

The caller saysWhat it isYour deadline, per the ICO
"What do you have on me?"Subject access request, Article 15One month; extendable by two months if complex
"Delete my details"Right to erasure, Article 17Without undue delay, and within one month
"Stop using my voice for that"Right to object, Article 21One month; Vocalenda acts from the next call
"I want to complain about how you handled my data"Data protection complaint, new dutyAcknowledge within 30 days, then respond without undue delay

The ICO's guidance on recognising a subject access request, updated 7 April 2026, says "there are no formal requirements for a valid request. A person can make a SAR verbally or in writing", "to any part of your organisation", and "the person does not have to include the phrases 'subject access request', 'right of access' or 'article 15 of the UK GDPR' in their request." So a customer saying "can you tell me what you've got written down about me?" at the counter is a valid request, and the ICO's guidance on responding gives you "at the latest within one month of receipt". Its page on what the right of access is confirms who does the work: "Controllers are responsible for complying with SARs. If you use a processor, you must have a contractual agreement in place to make sure that you can deal with SARs properly." The right to erasure works the same way: a request "verbally or in writing", answered "without undue delay and at the latest within one month".

The new one is the complaints duty. The ICO's how to deal with data protection complaints guidance, published 12 February 2026, says data protection law now requires you to "give people a way of making data protection complaints to you", to "acknowledge receipt of complaints within 30 days", and to "tell people the outcome of their complaints" without undue delay, and that "there are no exemptions to this." The ICO's news release of 23 June 2026 confirms it applies to "all organisations" from 19 June 2026, the day the last of the Data (Use and Access) Act 2025 came into force. It also reports ICO research finding that more than two in three businesses aware of the Act "either don't know or incorrectly think the law change doesn't apply to them." It applies to a one-chair barbershop. Practically, an email address you actually read, and a note in your privacy information saying complaints go there, meets the "give people a way" part.

One caveat the table cannot carry: neither the right to erasure nor the right to object is absolute. The ICO's guide to lawful basis sets out which rights apply under which basis, and where your basis is contract, as it is for a booking, the right to object does not apply. Honouring an objection anyway, as we do for the audio programme, is a choice rather than a duty.

For all four, a provider's job is to make the answer possible. Ours puts customer records, searchable by name or number, and the call log with its transcripts in the business's dashboard, and a deletion request is one email to us, which the privacy policy commits us to act on.

Do you need to pay the ICO fee?

Probably, and it is owed whether or not you use an AI. It is worth a paragraph because many small businesses do not know it exists.

The ICO's fee page states that "under the Data Protection (Charges and Information) Regulations 2018, organisations (including sole traders) that use personal information need to pay a data protection fee, unless they are exempt." Its guide to the fee puts tier 1, "a maximum turnover of £632,000 for your financial year or no more than 10 members of staff", at £52 a year, with "an automatic discount of £5" for paying by direct debit. The exemptions cover businesses processing personal data only for purposes such as "staff administration", "accounts and records" and "advertising, marketing and public relations", so some small businesses genuinely owe nothing. Read the word "only" carefully, though: keeping customer booking records is a purpose beyond that list, so a business running a phone line that books appointments is unlikely to be exempt. The ICO's self-assessment "takes about 10 minutes" to tell you which side of the line you are on, and the same page adds that even if you are exempt from the fee, "you still need to comply with your other data protection obligations." Not paying when you should is a breach in its own right, with a maximum penalty of £4,350.

Seven questions to ask any AI receptionist provider

Every item below is something the ICO's guidance above requires or expects, and it applies to a human answering service as much as to an AI one, which is worth remembering if you are still weighing a virtual receptionist against an AI receptionist or working through the UK options. The right-hand column is our answer, stated so you can check it against our privacy policy and DPA rather than take it on trust.

Ask themWhy it mattersVocalenda's answer
What does the caller hear, and can I edit it out?Article 13 requires privacy information at the point of collection, and a website cannot deliver it to a caller.One sentence before your greeting on every call, applied at setup, not editable.
Do you keep audio recordings? For how long?Storage limitation: a defined, justified period, not "as long as necessary".No audio kept. Transcripts 24 months, then automatic deletion.
What is your lawful basis for callers' details?Must be decided and documented before processing; consent is the wrong one for bookings.Contract for bookings, legitimate interests for enquiries, stated in the privacy policy.
Will you give me a written Article 28 agreement?The ICO: "there must be a written contract" whenever a controller uses a processor.Yes, published at /dpa, part of the terms from day one.
Who else touches the data, and where?You must be able to tell callers the recipients; overseas transfers need a mechanism.Every sub-processor named with what it sees; storage in the EU, live call in the US, disclosed.
Is my callers' data used to train anything?Purpose limitation and transparency; any further purpose must be told up front.Speech audio helps improve our speech provider's models; callers can object and it is honoured from the next call.
How fast do you tell me about a breach?Your 72-hour ICO clock starts when you become aware; "without undue delay" is not a number.Within 24 hours of us becoming aware, with updates as we learn more.

Our own limits, stated plainly so the table above is not the last word. The live call runs in the United States on contractual safeguards, not in the UK. Our speech provider improves its models with call audio unless the caller objects. The plan's 500 call minutes a month pause the line when exhausted rather than billing more, which is a billing fact rather than a privacy one, but you will find it anyway. And we are a software company, not a law firm: the ICO's pages linked above are the authority, and for anything unusual about your own business, a solicitor is.

What to do this week

  1. Ring your own number and listen to the first six seconds as a stranger would. If nothing tells the caller what is answering and what is kept, that is the gap, whatever your website says.
  2. Ask your provider the seven questions above, in writing, and keep the answers. Question four is the one that decides whether you keep them.
  3. Write down your lawful basis for booking calls, one line, dated. "Contract, Article 6(1)(b): we need a name and number to take the booking the caller asked for." The ICO requires the decision to be documented, and that sentence is a document.
  4. Give people a way to complain about data handling and make sure someone reads it. Since 19 June 2026 that is a duty with no exemptions, and acknowledgement is due within 30 days.
  5. Spend ten minutes on the ICO fee self-assessment. Either you owe £52 a year or you can prove you do not. Both are better than not knowing.

The short version

The law is not really about the AI. It is about what the caller hears in the first seconds, and whether the paperwork behind that sentence is real. Do not take our word for how it sounds in practice: the demo line is our own test barbershop's number, it is live, and it opens the way every Vocalenda call does. Call +44 7888 866273, listen to the first sentence, then try to book something. If the honesty holds up, read the privacy policy and the DPA with this post beside you, or start the 30-day free trial at £49 a month on the founding rate, open to the first ten businesses, with a standard price of £69 after that.

Common questions

Is an AI receptionist GDPR compliant in the UK?

It can be, and nothing in UK data protection law bans one. The UK GDPR does not regulate the technology, it regulates what happens to the caller's personal data: their number, their name and what they say. Compliance rests on the business as data controller and the provider as processor, and on three things being true: callers are told at the point of collection, there is a documented lawful basis for handling their details, and there is a written contract between business and provider that contains the terms Article 28 requires. Ask any provider to show you all three before you connect your phone.

Do you have to tell callers they are talking to an AI in the UK?

Yes in practice, though not through a clause that names AI. Article 13 of the UK GDPR requires people to be given privacy information at the time their personal data is collected, and the ICO's right-to-be-informed guidance, checked 2 September 2026, says that if you apply AI to personal data you should be upfront about it and explain your purposes for using it. A caller never visits your website before ringing, so a privacy page on its own cannot do that job. The ICO calls it good practice to deliver privacy information in the same medium you collect the data in, which for a phone call means saying it out loud. Vocalenda says one sentence before your greeting on every call: that the caller is speaking with an AI assistant and that the call is transcribed.

Do you need a caller's consent to take their name and phone number for a booking?

No, and the ICO says asking for consent when you would process the data anyway is misleading and inherently unfair. The right lawful basis for a booking is contract, Article 6(1)(b): the ICO's guidance says you can rely on it when someone has asked you to do something before entering a contract, such as provide a quote, and taking a booking is exactly that step. Consent is for situations where the person has a real choice, and a caller cannot be booked without giving a name and a number. Decide the basis before you start, document it, and state it in your privacy information.

Is the call recorded, and does that need a separate warning?

That depends on the provider, so ask. Some keep an audio recording of every call. Vocalenda does not: the audio is turned into text as the caller speaks and is not stored as a recording, and the written transcript is what the business keeps in its call history. Either way the caller must be told what is being kept and for how long, because the ICO's storage limitation principle says you must not keep personal data for longer than you need it and must be able to justify the period. Vocalenda's transcripts are deleted automatically after 24 months while the booking record itself stays.

Who is the data controller when an AI answers my business phone?

You are. The business the caller rang decides why their details are collected, so it is the controller, and the AI receptionist company handling those details on the business's behalf is the processor. The ICO's guidance on contracts says that whenever a controller uses a processor there must be a written contract in place, and it lists what that contract must contain: acting only on your documented instructions, confidentiality, security, prior authorisation of sub-processors, help with individuals' rights requests, help with security, breach notification and impact assessments, deletion or return of the data at the end, and audits. Vocalenda's version is published at vocalenda.com/dpa and forms part of the terms every business accepts at sign-up.

How long should call transcripts be kept?

There is no number in the law. The ICO says the UK GDPR does not set specific time limits, that you must be able to justify how long you keep personal data, and that you should erase or anonymise it when you no longer need it. Forever is not a retention period. Vocalenda keeps call transcripts for 24 months and then deletes them automatically, keeps the booking and customer record while the business has an active account, and holds a closed account's data for 6 months with a warning email 30 days before it is permanently deleted. Call audio is never stored.

Tags
UK GDPRData ProtectionAI ReceptionistICOComplianceSmall BusinessUK Business

Want more guides like this in your Google results? Add Vocalenda as a preferred source.

Add Vocalenda on Google

Ready to stop missing bookings?

Vocalenda answers your phone 24/7 and books straight into your Google or Outlook calendar. £49 a month on the founding rate, the first 30 days free, cancel anytime, no contract. Or hear it first: call the demo line on 07888 866273.

Start your free trial