Data security in conversation intelligence: the questions to ask before you connect

    Basics6 min readPublished

    TL;DR

    • Recordings and transcripts are personal data in every sense: privacy law and data security regulations apply, and preparedness is a duty, not a suggestion.
    • The four security pillars to check with a vendor: encryption in transit and at rest, access control and permissions, retention and deletion policy, and a commitment not to use your data to train external models.
    • Tiered permissions are the internal defense line: a rep sees their own calls, a manager their team, and access to sensitive calls is logged and audited.
    • Good security is also a sales argument: customers and enterprises increasingly ask about it, and an orderly answer builds trust.

    Connecting a conversation intelligence system means entrusting it with a sensitive asset: everything your customers say. A single call can contain an ID number, a medical condition, income details and an address, sometimes all together. That is not a reason to avoid call analysis; it is a reason to choose a vendor with open eyes and put your own house in order. This guide covers what to check, in manager language, not sysadmin language.

    What the law says, broadly

    In Israel, recordings and transcripts identifying a person are personal data under the Privacy Protection Law, and the data security regulations set management, security and documentation duties by database sensitivity. A floor that records and analyzes calls almost always holds a database at a sensitivity level requiring orderly procedures: who accesses, how it is secured, when it is deleted. The recording basics themselves, disclosure duty and party-to-the-call principle, are covered in the recording guide; here we focus on the layer above: what happens to the data after it is captured.

    The four vendor-check pillars

    • End-to-end encryption: traffic encrypted (TLS) and storage encrypted (at rest). This is the starting point, not an achievement.
    • Access control: role-based tiered permissions, strong authentication, and access logging, who opened which call and when. Without an access log there is no incident investigation.
    • Data life cycle: how long recordings and transcripts are kept, what is deleted automatically, and how on-demand deletion works, when a customer requests it or a contract ends.
    • Data usage: a contractual commitment that your calls are not used to train models outside your account and are not sold. This question became critical in the AI era, and a mumbled answer to it is a red flag.

    Permissions: the defense most organizations neglect

    Most leakage incidents come not from a breach but from overly broad internal access. The principle: every role sees the minimum it needs. A rep sees their own calls; a team lead their team; compliance sees slices per need; and especially sensitive calls, medical details for example, open only to dedicated permissions with logging. A system offering only "manager sees everything, rep sees nothing" reveals immaturity: reality demands resolution.

    Questions worth asking during selection

    Alongside the ten general questions, five security-focused ones: where the data physically lives and on which clouds; what certifications the vendor and infrastructure hold; what the retention policy and deletion defaults are; how a security incident is handled and what the reporting duties are, theirs and yours; and what happens to the data when the contract ends. A serious vendor answers all five in writing, without squirming. It is also the right moment to bring your security consultant or DPO into one call, at the stage where it is cheap.

    Security as a business argument

    The other side of the coin: a floor that gets call security in order gains a sales argument. Business customers now ask "how do you protect the recordings", and tenders demand orderly answers. An organization that can answer with one tidy page, encryption, permissions, deletion, vetted vendors, sails through that question while competitors stammer. The security investment returns through the sales door too.

    Frequently asked questions

    Is running AI on calls even permitted under privacy law?

    Processing calls for the business's legitimate purposes, quality control, service improvement, documentation, rests on the same framework that governs the recording itself, subject to disclosure and the declared purposes. What matters is that processing serves the stated purposes and access to outputs is controlled. For wording precise to your organization, it is one agenda item with your legal counsel.

    Which is better, a cloud system or our own servers?

    For most organizations, a serious vendor's managed cloud is more secure than a local installation, because it is maintained, patched and monitored at a level hard to replicate internally. The right questions are not "cloud or not" but where the data lives, who accesses it, and what certifications the infrastructure holds.

    Can sensitive details be hidden from transcripts?

    Yes, a capability called masking or redaction: automatic detection of credit card numbers, ID numbers and other sensitive details, replaced with a label. If you take payment details on calls, ask about this capability explicitly: in some contexts it is a regulatory requirement.

    Instead of reading about it, see it on one of your own calls.