GDPR and video calls: a 7-point checklist
Short answer
Video calls with customers are allowed under GDPR. You need a clear reason for the call, a data processing agreement with your vendor, a plan for recordings, and to tell customers what happens to their data. EU hosting and an EU vendor make the rest much simpler.
The checklist
- Where are calls hosted? Pick a vendor that runs calls in the EU.
- Who is the vendor? An EU company avoids questions about foreign laws, like the US CLOUD Act.
- Sign a DPA. A data processing agreement is required when a vendor handles personal data for you.
- Tell the customer. Say in your privacy notice and at the start of the call what you record and why.
- Record only when needed. Keep recording off by default. Turn it on when you have a clear reason.
- Decide how long to keep it. Set a retention period and delete recordings after it.
- Limit who can see it. Only people who need recordings should have access.
How FaceWithMe helps
Calls run in Brussels. Recording is optional, and recordings go to your own storage, so you control access and deletion. Guests join without an account, so you collect less data from them. Read more on recording video calls under GDPR.
This is general information, not legal advice. Talk to your data protection officer for your own case.
Quick questions
Do I need consent to video call a customer?You need a lawful basis. Often the customer asked for help, which is enough for the call itself. Recording may need more. Ask your DPO.
Is a video call personal data?Yes. A person’s face and voice are personal data under GDPR.
Video calls, hosted in the EU$15 per agent per month. Guests join free from the browser.
Start free trial