Skip to content
← All articles

Call recording and Saudi PDPL compliance

Published2 min read
PDPLData protectionCompliance
Call recording and Saudi PDPL compliance

Recording calls is long-standing practice in contact centres, but Saudi Arabia's Personal Data Protection Law changed the question. It is no longer "do we record?" but "on what basis, stored where, and for how long?"

This article is explanatory and is not legal advice. For obligations specific to your business, consult your legal counsel.

A voice recording is personal data

The caller's voice, their number, and anything they mention about themselves during the call are all personal data. A recording collects all of it into one file — and where you operate in healthcare or finance, it can capture considerably more sensitive material.

Notice before recording

The caller needs to know they are being recorded and why. The line played at the start of a call is not a formality; it is part of the disclosure. What matters is that it is clear, understandable, and in the language the caller actually speaks.

Where the data is really processed

This is the point most vendors move past quickly. Any voice solution passes through several processors: speech-to-text, a language model, text-to-speech, and storage. Each of those can sit in a different country.

The right question isn't "is our data in Saudi Arabia?" It's: "give me the list of every processor call data passes through, and where each one processes it." A serious vendor already has that list and can hand it over on request.

Retention

Keeping recordings "indefinitely" is not a policy — it is the absence of one. You need a defined period, automatic deletion at the end of it, and the ability to show the deletion actually happened.

In Saut Najdi, recording retention follows the plan terms confirmed at activation: 90 days for Essential, 180 for Growth, 365 for Expansion, and by contract for Enterprise. An append-only audit log records access to the data.

Questions to put to a vendor

  1. Give me your sub-processor list and processing locations — in writing.
  2. What is the default retention period? Can I change it? Is deletion automatic?
  3. Which of your staff can access my customers' recordings, and how is that access logged?
  4. If a customer requests deletion of their data, what is the process and how long does it take?
  5. Can the audit log be edited from your side?

If a vendor answers those five clearly and in writing, you are dealing with a partner who understands this market. If the answer is generalities about "world-class security", you also have your answer.

Want to see this in practice?

Book a 30-minute demo and test the agent in your customers' dialect, with your own questions.

Our newsletter

Saut Najdi updates and the AI news that matters in Saudi Arabia and beyond — one short email, no noise.

By subscribing you agree to receive our emails. Unsubscribe any time — privacy policy