RatedWithAI

RatedWithAI

Accessibility scanner

CCPA & AI DataAugust 24, 2026

Your Call Recorder Built a Consumer Profile of Every Buyer You Pitched

Revenue-intelligence platforms were bought as coaching tools. What they actually do is collect a person's voice, transcribe their words, infer their attitudes and store the result indefinitely — which is the textbook description of consumer profiling, applied to people who never signed up for anything.

B2B is in
The business-contact carve-out expired; your buyer is a consumer
9 copies
Audio, transcript, vector index, clips, CRM writeback, scores, digests
Reps too
Employee data is covered; scored call history is subject to access

The Category Error at the Root

Privacy programmes are usually built around the consumer-facing surface: the website, the app, the marketing database. Sales tooling sits outside that boundary because it was procured by revenue operations, points at companies rather than individuals, and feels internal. Nobody maps it because it does not look like a data product.

But every entry in a conversation-intelligence system is about a named human being. The account is a company; the record is a person. When the platform reports that a particular VP of Engineering spoke for thirty-one percent of the call, raised pricing objections twice, sounded negative in the final four minutes and is scored as a low champion probability, it has assembled a behavioural profile of an identifiable individual from their own speech.

Two things follow. The buyer has rights you have never operationalised, and the wiretap consent question — which most teams did address, because legal reviewed the recording disclosure years ago — is the smaller of the two issues.

What the Platform Is Actually Holding

Identifiers and audio

Name, title, employer, phone number, email address, calendar identity, and a voice recording of a specific person. Where voice fingerprinting or speaker-identification features are enabled, the processing moves toward biometric territory with its own heightened rules and its own state-law exposure outside California.

Why it creates exposure: Audio is the artefact everyone remembers to delete and the one most likely to be replicated into a coaching library or a shared clip that lives outside the retention policy.

Transcripts and their contents

A full speaker-attributed record of what the person said, which routinely includes far more than commercial discussion — health context explaining a delay, family circumstances, opinions about their employer, and candid remarks about colleagues who are not on the call.

Why it creates exposure: Transcripts convert an ephemeral conversation into a permanent, searchable, discoverable record. Categories of information you never intended to collect end up in it, and once indexed, they surface in semantic search results across the organisation.

Inferences and scores

Sentiment curves, engagement scores, buying-intent probabilities, competitor-affinity tags, personality-style classifications and deal-risk ratings — derived data reflecting a person's preferences, characteristics and attitudes.

Why it creates exposure: Inferences drawn to create a profile are expressly within the definition of personal information. They are also the artefact least likely to be included in a deletion routine, because teams think of them as analytics output rather than as data about the person.

Derived indices and model artefacts

Embeddings powering semantic search across the call archive, retrieval indices for AI assistants, summary objects written back into the CRM, and in some configurations, customer content used to improve the vendor's own models.

Why it creates exposure: These are the copies that survive a deletion request. An embedding is not obviously a copy of the conversation, which is exactly why it stays behind, and vendor model training is functionally irreversible once it has occurred.

Three Failures That Show Up in Every Assessment

  • Notice covers recording, not analysis. The spoken disclosure says the call may be recorded for quality and training purposes. It does not say that a model will transcribe it, score the speaker, extract topics and retain the profile. The recording consent is the easy part; the collection notice is a different obligation with different content requirements.
  • Retention is "forever" by default. Almost every deployment inherits the platform's default retention, which is indefinite, because the whole product value proposition is a searchable historical archive. Publishing a retention period you do not enforce is worse than the indefinite retention itself, because the discrepancy is provable from your own configuration.
  • No request path exists for non-customers.Rights requests are routed through a form on the website aimed at users and customers. A prospect who never bought — the majority of people in the call archive — has no obvious way to reach you, and when they do, support has no runbook because the person is not in the customer database.

The Employee Side Is a Second Programme

Every recorded call has at least two people in it. Your rep is subject to continuous measurement: talk ratio, filler-word counts, question rates, objection handling, adherence to a script, and a composite coaching score that appears in one-on-ones and, in many organisations, in performance reviews and territory decisions.

That triggers employee-facing notice at collection, access and correction rights over scored history, and — where the scores materially inform significant employment decisions — the additional layer of automated-decision-making obligations, including pre-use notice, an explanation of the logic, and in some circumstances a right to opt out or to request human review. A departing rep's access request that returns three years of sentiment-scored calls is a scenario worth walking through before it arrives, not after.

The Conversation Intelligence Compliance Checklist

Run this against every recording, transcription, meeting-assistant and revenue-intelligence tool connected to your calendar or dialer — including the free notetaker a rep installed that joins meetings automatically.

1. Inventory and Mapping
  • List every tool that joins, records, transcribes or analyses calls and meetings, including individually installed assistants
  • Map the full artefact fan-out per call: audio, transcript, index, clips, CRM writeback, scores, digests, exports
  • Record which artefacts the vendor's deletion API actually removes and which require a manual process
  • Identify whether voice fingerprinting or speaker identification is enabled anywhere in the stack
  • Add sales tooling to the data map maintained by the privacy programme, not only to the IT asset register
2. Notice and Choice
  • Disclose recording, transcription and AI analysis at the start of every call, not only the first in a sequence
  • State the categories collected, the purposes, and the retention period or the criteria for setting it
  • Mirror the disclosure in the calendar invite and as an in-meeting indicator for video
  • Provide a working path for a participant to decline analysis, and honour it without abandoning the call
  • Publish a rights-request route that a non-customer can find and use without an account
3. Retention and Deletion
  • Set an enforced retention period in the platform configuration and verify deletion actually occurs
  • Build a deletion runbook that reaches transcripts, indices, clips, scores and CRM summaries, not only audio
  • Contractually confirm customer content is excluded from vendor model training, and get it in the order form
  • Test a deletion request end to end and record the evidence, before a real one arrives
  • Define a lawful-hold exception narrowly so it does not swallow the retention policy
4. Employees and Vendors
  • Issue an employee-facing notice at collection covering recorded calls, scoring and retention
  • Determine whether call scores feed significant employment decisions and apply the automated-decision rules if so
  • Give reps access to their own scored history and a documented correction path
  • Execute service-provider terms restricting the vendor to processing for your business purposes only
  • Review sub-processor lists for transcription and model providers sitting behind the platform

Frequently Asked Questions

We already play a recording disclosure at the start of every call. Isn't that enough?

It covers one obligation and not the other. A recording disclosure exists to satisfy call-recording consent rules, which are about the act of capturing the conversation. Notice at collection is a privacy-law obligation about what information you collect, why, how long you keep it and what rights the person has — and it has to be given at or before collection in a form the person actually encounters. A single sentence about quality and training purposes does not describe AI transcription, profiling, scoring or indefinite retention. In practice the fix is small: extend the automated disclosure by two sentences and point to a short URL with the full notice. The reason it is worth doing precisely is that the recording disclosure is the artefact an investigator will read first, and its silence about analysis is what suggests the rest of the programme was not scoped either.

Our platform says it is a service provider. Does that resolve the vendor question?

It resolves it only if the contract contains the required restrictions and the vendor's actual conduct matches them. Service-provider status depends on a written agreement prohibiting retention, use or disclosure of the personal information for any purpose other than performing the specified services, prohibiting combination with other sources except as permitted, and obliging the vendor to assist you with rights requests. Read the order form and terms for the exception that matters most in this category: a right to use customer content to improve or train the vendor's models. That use is frequently framed as product improvement and it sits uneasily with service-provider status. Ask for it to be switched off contractually, get confirmation of the tenant-level configuration, and keep both.

Can we keep transcripts if we remove the names?

Only if the result is genuinely no longer capable of being associated with the person, and a sales-call transcript rarely clears that bar. The content itself identifies the speaker: their employer, their role, their project, the deal, the date and the other participants are all in the conversation, and the record remains linked to an opportunity in your CRM. Deidentification is a defensible route for aggregate analytics — talk-ratio benchmarks across a team, objection frequency by segment — where you can strip to statistics rather than to redacted text. If you rely on deidentification, the standard also requires reasonable technical safeguards against reidentification, a public commitment to maintain the data in deidentified form, and contractual obligations on anyone you share it with. Doing that properly is more work than honouring the deletion request.

A prospect who was never a customer asked what we hold on them. What do we actually owe?

The same as any other consumer: the categories collected, the sources, the business purposes, the categories of third parties it was disclosed to, and on request the specific pieces of personal information. In this context that means the call recordings and transcripts they appear in, the inferences and scores attached to them, and the CRM records built from those calls. Two practical notes. First, verify identity proportionately — you are handing over a recording of someone's voice, so a low-friction verification standard is the wrong choice here. Second, the response will surprise them, and it is worth having someone who understands the tooling review the export before it goes out, not because you should withhold anything, but because a raw dump of internal deal-risk commentary about a named person is a relationship event as well as a compliance one.

Where does this sit relative to two-party consent recording laws?

They are parallel regimes with different failure modes and you need both. Consent statutes govern whether you may capture the conversation at all, carry criminal exposure and private rights of action in several states, and turn on where each participant is physically located rather than where your company is. Privacy law governs what happens to the data afterwards: notice, retention, rights, vendor terms and profiling. A company can be fully compliant on consent and completely exposed on retention and rights, which is the common pattern precisely because consent was reviewed by counsel at purchase and the data lifecycle was never reviewed by anyone. Treat the consent analysis as the entry condition and the data-lifecycle analysis as the ongoing programme.

Test the Deletion Path Before Someone Else Does

Pick one call from six months ago and delete every artefact derived from it. Time the exercise and write down which systems required a manual step. Most teams discover that the audio goes in seconds, the transcript in a minute, and the search index, shared clips and CRM summary never go at all.

That result is the compliance gap, stated in operational terms rather than legal ones. Fix the runbook first, then the notice, then the retention configuration — in that order, because the first is the one you cannot improvise under a deadline.