Voice AI call recordings: a police disclosure guide
In short
When police, a regulator or a court ask for a call recording, a request is not an instruction to disclose. The DPA 2018 crime exemption is a shield, not a lawful basis. Dilr Voice gives the controller legal hold, an immutable disclosure log, and routing to the DPO who decides. It records disclosures; it does not authorise them.
DE
Dilr.ai EngineeringEngineering team
Published Aug 7, 2026Read 13 min
A police officer telephones your contact centre and asks for the recording of a call your voice AI handled last Tuesday. A regulator emails, wanting the audio and the transcript. A litigant's solicitor sends a letter before action. In every case the instinct is the same: someone official has asked, so you hand it over. That instinct is where enterprises get disclosure wrong, and where the fines start.
Voice AI is now mainstream. McKinsey's State of AI research (November 2025) found that 88% of organisations use AI in at least one business function, and a rising share of inbound calls are now answered and recorded by machine. Those records are vast, searchable and high-fidelity, and they are exactly what the police, regulators and courts come looking for. Most organisations have no standing process for a disclosure request, and the voice AI vendor holding the audio usually has even less.
The law is not vague on this. A request from a law enforcement authority is a permission to consider disclosing, not an obligation to disclose. Getting the distinction right protects the caller, protects your organisation, and keeps a real investigation from being tainted by an unlawful hand-off.
This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system for placing AI inside institutions that get audited.
What counts as a law enforcement request for a voice AI call recording?
A law enforcement request is any approach from a police force, an investigator or a prosecuting body asking you to hand over a stored call recording or transcript that your voice AI holds. It splits into three types: a voluntary request you may choose to answer, a court order or production order that legally compels you, and, separately, a live interception, which is a different regime entirely. Knowing which one you face decides everything that follows.
The three routes matter because they carry different duties. The ICO sets out that data sharing with law enforcement typically arises where you decide to report a crime, where you receive a request for data you already hold, or where a court order or another legal obligation compels you. Only the third is compulsion. The first two leave the decision, and the accountability, with you.
Two things sit outside this guide. Intercepting a live call, or obtaining communications data such as who called whom and when, falls under the Investigatory Powers Act 2016 and its own warrant regime, not the rules for a stored recording you already possess. Disclosure to the other side in civil litigation runs through the civil procedure rules and is led by your legal team, not the police. Where a financial regulator wants recordings under sector rules, read our guide to MiFID II call recording for investment firms, because the FCA access regime works differently. This post is about the stored recording, requested after the fact, by an authority investigating a crime.
Is a police request an instruction to disclose the recording?
No. A police request is not an instruction, and treating it as one is the classic mistake. The relevant exemptions permit disclosure in defined circumstances; they never compel it. Unless you are served with a court order, a production order or a statutory notice, you decide whether to disclose, and you must be able to show a lawful basis for doing so. The officer asking is not the person accountable if you get it wrong. You are.
These provisions do not force you to disclose personal data, but they do allow you to disclose personal data on a voluntary basis, provided that it is necessary and proportionate to do so.
Read that twice, because it inverts the reflex. A voluntary disclosure is one you are permitted to make, once you have satisfied yourself it is lawful, necessary and proportionate. That is a decision to be recorded, with a named decision-maker, not a reflex triggered by a phone call. Our field notes on placing AI inside enterprise systems keep returning to the same rule: the more sensitive the data, the more the process, not the request, has to govern the outcome.
The same discipline underpins our AI placement diagnostic, a fixed-fee assessment we run before any regulated deployment, which maps exactly who can release recorded data and on whose authority.
What is the DPA 2018 crime and taxation exemption, and what does it switch off?
The crime and taxation exemption sits in Schedule 2, Part 1, paragraph 2 of the Data Protection Act 2018. It is a shield, not a sword: it does not give you a reason to disclose. Instead it switches off certain duties, such as telling the caller and giving them access, but only to the extent that applying them would be likely to prejudice the prevention, investigation or detection of crime.
The Data Protection Act 2018 extends the same exemption to the apprehension or prosecution of offenders and the collection of tax. In plain terms, it lets you avoid tipping off a suspect. Normally your Article 13 transparency duties and a caller's right of access would require you to tell them their recording had been handed to the police. Where doing so would prejudice a live investigation, the exemption disapplies those duties for as long as the prejudice would last. It reaches nine listed UK GDPR provisions, from the transparency articles through the rights of access, rectification, erasure, restriction and objection, and it also disapplies the duty to notify the caller of certain breaches under Article 34, a point we cover in our guide to breach notification.
The exemption exists because UK GDPR Article 23 permits the Secretary of State to restrict those rights for public security and for crime prevention. What it does not do, and this is where organisations overreach, is hand you a lawful basis to disclose in the first place. The shield covers your silence about the disclosure. It says nothing about whether the disclosure itself is lawful. For that you need a basis under Article 6, which is the next question.
Who decides whether to disclose, the controller or the voice AI vendor?
The controller decides. In almost every voice AI deployment the enterprise is the controller and the voice AI vendor is the processor, holding the audio on your behalf. A processor has no authority to release recordings to a third party on its own judgement. If an officer serves the vendor directly, the correct answer is not to comply and not to refuse, but to route the demand to the controller's data protection officer, who owns the decision.
This is not a courtesy. It is the law. UK GDPR Article 28(3)(a) binds a processor to act only on the controller's documented instructions, "unless required to do so by domestic law; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest." So a mere request served on your vendor changes nothing: the vendor still needs the controller's instruction. Only an order that legally compels the processor itself can override that, and even then the vendor must tell you, unless a tipping-off restriction prevents it.
When a demand is served on the voice AI vendorThe processor has no standing to disclose on its own authority. It routes, and complies only under legal compulsion.
This is why the contract matters as much as the technology. Your data processing agreement should say, in writing, that the vendor forwards any third party demand and never discloses unilaterally. Our guide to the processor and controller split under Article 28 covers the clauses that make this enforceable, and pairs with the AI operating model work we do to fix accountability before production.
What lawful basis do you need to disclose a call recording?
You need a lawful basis under Article 6 before you release anything, and which one depends on how the request arrived. Where a court order, production order or statutory notice compels you, the basis is Article 6(1)(c), compliance with a legal obligation. Where you are choosing to help a voluntary investigation, there is no legal obligation, so you must rely on a different basis and show the disclosure is necessary and proportionate.
The ICO puts the burden squarely on the discloser. You must be satisfied that sharing personal data with a law enforcement authority is lawful, which means you must have a lawful basis under Article 6 before you share. For a genuine emergency where a life is at risk, Article 6(1)(d) vital interests can apply, but the ICO limits this to a very narrow range of circumstances and it is not a general route for routine police requests. Guessing at a basis after the fact is not a basis.
Call recordings raise a further trap. A voice AI conversation frequently captures special category data: a caller mentions a health condition, a disability, or their trade union membership. Under Article 9 you then need both an Article 6 basis and a separate Article 9 condition before you disclose, which our guide to special category data on calls works through in detail. Skip the Article 9 step and even a well-intentioned disclosure to the police becomes unlawful processing of the most sensitive data you hold.
How do you disclose a recording without over-disclosing?
You disclose the minimum that answers the lawful request, and nothing more. Over-disclosure is the most common way a compliant intent becomes an unlawful act. If the police want one caller's recording from a named date, you send that recording, not the whole call queue, not the surrounding conversations, and not the internal notes of unrelated customers. Data minimisation is not optional politeness; it is a principle you are accountable against under Article 5.
Practically, that means redaction and scoping before release. Strip or mask third party personal data caught incidentally in the audio, hold back the parts of a transcript outside the request, and where a recording is under a retention and legal hold you must preserve rather than delete it. A disclosure request and a right to erasure request can collide on the same recording, and the legal hold wins. The workflow below is the shape every enterprise should run without improvising.
Handling an inbound disclosure requestA repeatable path from request to release, each step recorded so the decision survives later scrutiny.
Building this once, as a runbook rather than a scramble, is exactly the sort of thing an AI execution office exists to standardise across a large estate. It also keeps the exemption honest: you can only claim the crime exemption disapplied a caller's transparency rights if you actually recorded that you relied on it and why.
How do you log a disclosure so it survives an ICO audit?
You keep an immutable disclosure log that records every request and every decision, whether you disclosed or refused. For each event, capture who asked and their authority, the date, the lawful basis you relied on, exactly what you released, who approved it, and whether you invoked the crime exemption to withhold notification from the caller. If a disclosure is later challenged, that log is the difference between a defensible decision and an unexplained data leak.
The stakes are set by the penalty regime. Because an unlawful disclosure breaches the lawfulness principle in Article 5 and the basis requirement in Article 6, it falls in the higher enforcement band, not the lower one.
What getting a disclosure wrong can costMaximum UK GDPR fines in pounds millions; an unlawful disclosure breaches the lawfulness principle and sits in the higher band, or 4% of total worldwide turnover if that figure is greater. Source: UK GDPR Article 83, as modified by the Data Protection Act 2018
The higher maximum is 17.5 million pounds or 4% of total worldwide annual turnover, whichever is greater, under Article 83 as modified by the DPA 2018. Your record of processing activities should reference the disclosure log, and the log itself should be write-once, so nobody can quietly tidy a decision after a complaint. Regulators do not expect zero requests; they expect that every one was handled the same disciplined way.
What is the best way to handle police requests for voice AI recordings in 2026?
The best approach depends on your volume and your risk. For a single site with low request volumes, a well-drilled manual process and a named DPO can be enough, and a do-it-yourself stack built on a developer platform like Vapi, Retell AI or Bland AI can work, provided you accept that you own every control: the legal-hold logic, the redaction, the disclosure log and the Article 28 terms. Those platforms give you the pipes, not the governance.
At enterprise scale, across many sites, high call volumes and regulated data, the DIY route quietly becomes the risk. Governed platforms such as Dilr Voice and PolyAI are built so that legal hold, minimisation, routing of third party demands and an immutable audit trail are part of the product rather than something a team wires together under pressure. Where the telephony layer runs through a provider such as Twilio, that governance has to span the whole chain, not just the model. The honest concession is that a small, low-risk, single-use-case deployment does not need this, and paying for it there is overkill. The moment your recordings are sensitive, numerous and legally interesting, the process has to be engineered in, not bolted on. That is the line our DATS methodology is built to hold, and where our team is happy to tell you honestly whether you have crossed it.
Can a voice AI vendor hand a recording straight to the police?
No. A voice AI vendor is a processor and has no authority to disclose on its own judgement. Under Article 28(3)(a) it may act only on the controller's documented instructions, unless domestic law compels the processor directly, in which case it must inform the controller first where permitted. Faced with a police request, the vendor's correct move is to route it to the controller's DPO, not to release the audio.
Do we have to tell the caller we gave their recording to the police?
Usually yes, because transparency and access rights normally apply. But the DPA 2018 crime and taxation exemption can disapply those duties to the extent that telling the caller would be likely to prejudice the investigation, for example by tipping off a suspect. The exemption is time-limited to the prejudice it prevents, and you must record that you relied on it, so notification resumes once the risk has passed.
Is intercepting a live call the same as disclosing a recording?
No. Intercepting a live conversation, or obtaining communications data about who called whom, is governed by the Investigatory Powers Act 2016 and needs its own warrant. Disclosing a recording you already hold is a data protection matter under the UK GDPR and the DPA 2018. This guide covers only the stored recording requested after the call, which is the situation an enterprise voice AI platform actually faces.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed. This guide is general information, not legal advice; take advice on your specific facts.
voice AI law enforcement disclosurepolice request call recording GDPRDPA 2018 Schedule 2 crime exemptiondisclosing call recordings to police redditbest voice AI compliance platform 2026voice AI complianceDilr Voice
Questions this article answers
What counts as a law enforcement request for a voice AI call recording?
A law enforcement request is any approach from a police force, an investigator or a prosecuting body asking you to hand over a stored call recording or transcript that your voice AI holds. It splits into three types: a voluntary request you may choose to answer, a court order or production order that legally compels you, and, separately, a live interception, which is a different regime entirely. Knowing which one you face decides everything that follows.
Is a police request an instruction to disclose the recording?
No. A police request is not an instruction, and treating it as one is the classic mistake. The relevant exemptions permit disclosure in defined circumstances; they never compel it. Unless you are served with a court order, a production order or a statutory notice, you decide whether to disclose, and you must be able to show a lawful basis for doing so. The officer asking is not the person accountable if you get it wrong. You are.
What is the DPA 2018 crime and taxation exemption, and what does it switch off?
The crime and taxation exemption sits in Schedule 2, Part 1, paragraph 2 of the Data Protection Act 2018. It is a shield, not a sword: it does not give you a reason to disclose. Instead it switches off certain duties, such as telling the caller and giving them access, but only to the extent that applying them would be likely to prejudice the prevention, investigation or detection of crime.
Who decides whether to disclose, the controller or the voice AI vendor?
The controller decides. In almost every voice AI deployment the enterprise is the controller and the voice AI vendor is the processor, holding the audio on your behalf. A processor has no authority to release recordings to a third party on its own judgement. If an officer serves the vendor directly, the correct answer is not to comply and not to refuse, but to route the demand to the controller's data protection officer, who owns the decision.
What lawful basis do you need to disclose a call recording?
You need a lawful basis under Article 6 before you release anything, and which one depends on how the request arrived. Where a court order, production order or statutory notice compels you, the basis is Article 6(1)(c) , compliance with a legal obligation. Where you are choosing to help a voluntary investigation, there is no legal obligation, so you must rely on a different basis and show the disclosure is necessary and proportionate.
How do you disclose a recording without over-disclosing?
You disclose the minimum that answers the lawful request, and nothing more. Over-disclosure is the most common way a compliant intent becomes an unlawful act. If the police want one caller's recording from a named date, you send that recording, not the whole call queue, not the surrounding conversations, and not the internal notes of unrelated customers. Data minimisation is not optional politeness; it is a principle you are accountable against under Article 5.
How do you log a disclosure so it survives an ICO audit?
You keep an immutable disclosure log that records every request and every decision, whether you disclosed or refused. For each event, capture who asked and their authority, the date, the lawful basis you relied on, exactly what you released, who approved it, and whether you invoked the crime exemption to withhold notification from the caller. If a disclosure is later challenged, that log is the difference between a defensible decision and an unexplained data leak.
What is the best way to handle police requests for voice AI recordings in 2026?
The best approach depends on your volume and your risk. For a single site with low request volumes, a well-drilled manual process and a named DPO can be enough, and a do-it-yourself stack built on a developer platform like Vapi, Retell AI or Bland AI can work, provided you accept that you own every control: the legal-hold logic, the redaction, the disclosure log and the Article 28 terms. Those platforms give you the pipes, not the governance.
DE
Dilr.ai Engineering
Engineering team
Compliance
Deploy voice AI without failing an audit
Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.