Is Your Business Phone System Compliant? Call Recording, Privacy and Record-Keeping Rules for 2026
Most business owners choose a phone system on price and features. Almost nobody asks whether it keeps them on the right side of the law. Yet the moment your phone system records a call, saves a voicemail, or stores customer details, it starts collecting information that Australian law has rules about. Get those rules wrong and a recorded call becomes a liability instead of an asset. A compliant Australian business phone system needs three things: consent to record calls (all-party consent in NSW, WA, SA, Tasmania and the ACT), secure and lawful handling of call data under the Privacy Act, and a sensible retention policy for recordings and records. The phone system itself does not make you compliant. How it is configured does. Most breaches come from recording without notice, storing call data insecurely, or keeping it forever. What makes a business phone system compliant in Australia? Compliance sits on three pillars, and a VoIP or hosted phone system touches all three. The first is consent. If you record calls, you need the right consent for your state. The second is privacy. Call recordings, voicemails and contact records are personal information under the Privacy Act, so they have to be collected fairly, used only for their purpose, and stored securely. The third is record-keeping. You should keep call data only as long as you have a reason to, then delete it. Miss any one of these and the system that was meant to help you becomes a risk. Do you need consent to record calls on a business phone system? Usually, yes. And the rule changes depending on where you are, which trips up businesses that take calls across state lines. Australia has no single national law for recording calls you take part in. Each state and territory has its own surveillance or listening-devices legislation, and they fall into two groups. In New South Wales, Western Australia, South Australia, Tasmania and the ACT, every party to the call must consent. In Queensland and Victoria, a participant can record a call they are part of, but there are strict limits on sharing or using that recording. For a business that fields calls from all over the country, the safe approach is simple. Treat all-party consent as your default everywhere. The fix is one your phone system can handle automatically: a short message at the start of the call telling the caller it may be recorded. Set it once, and every call carries the notice. Does the Privacy Act apply to call recordings and voicemail? If your business is covered by the Privacy Act, then yes. A call recording that identifies a person is personal information. So is a voicemail, a saved contact, or a note attached to a customer record in your phone system. Your business is generally covered if it has an annual turnover of $3 million or more, or if it is a health service provider of any size, along with a few other categories. When the Act applies, you have to protect that data with reasonable security, use it only for the purpose you collected it, and let people know you are collecting it. The practical points that follow from this are worth writing down. Call recordings need secure storage with access controls, not a shared folder anyone can open. You should know who can listen to recordings and why. And you need to be able to delete a customer’s data if the situation calls for it. How long should you keep call recordings? Only as long as you have a reason to. The Privacy Act works on a simple principle: do not keep personal information once you no longer need it. There is no single legal retention period for general business call recordings. Common practice sits between 30 days and a few years, depending on why you record. A sales team confirming orders might keep recordings for a short window. A financial or healthcare business with record-keeping obligations will keep them far longer. The point is to set a policy and stick to it, rather than letting recordings pile up forever. Indefinite storage is a quiet liability. Every recording you hold is data you have to protect, and data that could be exposed in a breach. What about AI features and call transcripts? More phone systems now add AI: automatic transcription, call summaries, sentiment analysis, and AI voice agents that answer calls. These are useful, and they raise the same compliance questions in new forms. A transcript counts as a recording, so the same consent rules apply. AI-generated notes are personal information, so the Privacy Act covers them. And if you use an AI voice agent to answer calls, best practice is to tell callers they are speaking with an automated system, which also supports your privacy-notice obligations. New transparency rules around automated decision-making are due to expand these duties from December 2026, so the direction is toward more disclosure, not less. Where phone system compliance usually goes wrong? In practice, the same handful of gaps come up again and again. Recording without notice is the most common. A system records every call, but no consent message ever plays, which puts the business offside in all-party states. Insecure storage is the next: recordings sitting in a folder half the office can open, with no record of who listened. Then there is indefinite retention, where nobody ever set a deletion policy. And finally, offshore data, where a cheap overseas VoIP provider stores your call data in another country, raising Privacy Act and data-sovereignty problems. None of these is hard to fix. But they rarely get fixed on their own, because the person who set up the phones was thinking about call quality, not compliance. How to make your business phone system compliant? Here is the practical checklist. Byteway Expert Insight When we review phone systems for Melbourne businesses, the pattern is almost always the same. The system is capable of doing everything correctly, but nobody switched the









