Contact Centres · BPO · Systems Integrators

Every call you record is personal information.

And it is never only the recording. The transcript, the quality-assurance extract, the CRM note, the screen capture and the analytics index are separate copies of the same conversation, usually in separate systems, usually with different people able to reach them.

We map where all of it actually goes, prove what a compromise would cost you, and specify the fix. Platform-independent, and we sold you none of it.

Why this sits unexamined

The platform was procured. The data flow never was.

Contact centre platforms are bought on routing, reporting and agent productivity. The compliance question that arrives with them — what is now being captured, where it lands, who can reach it and for how long — is rarely part of that evaluation, because it is nobody's line item.

The integrator delivered what was specified. The vendor is responsible for its platform, not for your processing. And the operator is the responsible party under POPIA regardless of who configured what.

The uncomfortable arithmetic: a mid-sized operation taking a few thousand calls a day accumulates hundreds of thousands of recordings a year, each one identifying a person and capturing whatever they were willing to say to someone they could not see.

That is a large breach radius accruing quietly, in a system bought for a different reason.

Who this is for

Whoever answers when the Regulator asks.

Contact centre operators

You are the responsible party. The recordings, the retention and the access list are yours to justify, whoever built the platform.

Business process outsourcers

You process on your client's instruction, which makes the operator agreement and the cross-border position the first things anyone will ask for at renewal.

Systems integrators

You won the deployment and inherited a compliance question you were not scoped to answer. We work as your subcontractor, under your client relationship.

Operations and risk directors

You need to know the exposure before someone else discovers it, and in a form your board and your insurer will accept.

What we actually look at

We follow one call all the way through.

From the moment it connects to the moment the last copy is destroyed — if it is destroyed. That single trace surfaces more than a platform configuration review, because it crosses the systems nobody owns end to end.

Capture — what is taken, and with what notice

  • What the caller is told at the start of the call, and whether it states purpose and retention or only that the call "may be recorded"
  • What happens when a caller objects to being recorded
  • Whether screen capture runs alongside audio, and what is on those screens
  • Whether voice authentication or voiceprint enrolment is enabled — and whether it was ever treated as a distinct processing purpose
  • Card capture: pause-and-resume or DTMF suppression, whether it is configured, and whether it actually fires

The copies nobody counts

  • Transcripts and the speech-analytics index built from them
  • Quality-assurance extracts, coaching clips and calibration libraries
  • CRM notes and case attachments holding the substance of the call
  • Anything exported to a spreadsheet for reporting and never deleted
  • Backups and platform-side archives, including vendor-held copies

Access — who can hear a stranger's conversation

  • Which roles can search, play and export recordings, and how many people that is in practice
  • Whether playback and export are logged, and whether an export can be traced to a person
  • Vendor and integrator support access, standing or on request
  • What an agent can retrieve about a caller they are not currently serving

Residency and cross-border

  • Where the platform tenant physically stores audio, transcripts and backups
  • Offshore or work-from-home agents listening to South African callers
  • Vendor support reaching data from another jurisdiction
  • Whether the section 72 position was ever established, or assumed

Retention

  • The stated retention period per stream, and whether the platform enforces it or simply never deletes
  • Recordings kept for a dispute that closed years ago
  • Whether deletion removes the transcript and the analytics index too, or only the audio

Breach radius — our signature analysis

  • For each store: how many data subjects, which categories, and whether special personal information is present
  • The worst realistic compromise — exported QA library, compromised supervisor account, vendor-side incident
  • Whether it would trigger notification to the Regulator and to every affected caller
  • The three changes that shrink the radius most, ranked by cost

What it costs

One entry product. No new price list.

Call Recording & Contact Centre Data Audit

From R35,000

One operation and the platform behind it

Deliberately scoped to a single operation so the first engagement is finite and specific.

  • A data flow map for one call, end to end, across every system it touches
  • Inventory of every copy — audio, transcript, analytics index, QA extract, CRM note, screen capture, backup
  • Access review: who can play, search and export, and whether that is logged
  • Residency and cross-border position, established rather than assumed
  • Retention findings per stream, and whether deletion actually deletes
  • A breach-radius note with the notification question answered
  • A prioritised remediation list, costed in three bands, and a one-page board summary

Excludes: platform reconfiguration, legal opinion, staff training and card-scheme certification.

Where the audit uncovers work beyond the assessment, it scales into the existing Regulator Readiness Pack tiers rather than into a separate price list. Fixed fee against a written scope with a named exclusion list — never hourly.

Where we stop

Four things we will not sell you.

We do not sell, resell or implement contact centre platforms. Not Genesys, not Avaya, not NICE, not Amazon Connect, not anything else. We hold no vendor partnership and take no referral commission. That independence is the product: we are not assessing a deployment we sold you, and we have nothing to protect if the finding is that the platform was configured badly.
We cannot be your Information Officer. Under POPIA the head of the body is the Information Officer, and where another person acts they must be authorised from within the organisation. We prepare the instruments, make the registration and support the person appointed — the role stays inside your business.
We do not certify you against the card schemes. Where cardholder data is spoken on a recorded call we report findings of fact about the controls and the recordings. Formal certification is a Qualified Security Assessor's work, and we will say so rather than imply our report substitutes for it.
We do not give legal advice or advise on insurance. Legal opinions on lawful basis, liability and cross-border position go to a data protection law firm. On insurance we produce the technical evidence an underwriter asks for and hand it to your own licensed broker. ASi Imperium is not an authorised financial services provider.

Common questions

Straight answers.

Is a recorded call personal information under POPIA?

Yes. A recording identifies the person speaking and captures whatever they said, which routinely includes account numbers, identity numbers, health details and financial circumstances. It is personal information from the moment it is captured, and where the caller discusses health or finances it may be special personal information, which carries a higher bar. The recording is rarely the only copy: transcripts, quality-assurance extracts, CRM notes and screen captures are all separate stores of the same conversation.

Does call recording count as biometric processing?

Recording a call is not automatically biometric processing. Using a voiceprint to identify or authenticate a caller is. POPIA defines biometrics as a technique of personal identification based on physical, physiological or behavioural characterisation, and voice recognition falls inside that definition. So the question is not whether you record, but whether anything downstream turns the recording into an identifier. Many operations have enabled voice authentication without treating it as a separate processing purpose requiring its own justification.

Our agents are offshore. Does that change anything?

It adds section 72, which restricts transferring personal information outside South Africa. An agent in another country listening to a South African caller, or a platform tenant hosted in another region, is a cross-border flow whether or not anyone calls it that. The same applies to a cloud contact centre whose data residency sits outside the country. We establish where the data physically is, which is often not where people assume.

Do you work with Genesys, Avaya, NICE or Amazon Connect?

We assess the data flows, whichever platform produces them, and we are not a reseller or implementation partner for any vendor. That independence is the point: we are not assessing a deployment we sold you. Where a finding requires a platform change, we specify the outcome the configuration must achieve and your integrator or vendor implements it.

What about card numbers spoken on a call?

If cardholder data is spoken and the call is recorded, the recording is in scope for the card schemes' requirements as well as POPIA, and stored card data attracts obligations most operations are not resourced to meet. The common control is pause-and-resume or DTMF suppression during payment capture. We check whether it is configured, whether it actually fires, and what is in the recordings made before it was enabled. We report findings of fact; formal card-scheme certification is a QSA's work, not ours.

What does the audit cost?

A Call Recording and Contact Centre Data Audit starts at R35,000 for one operation and the platform behind it, quoted as a fixed fee against a written scope after a short call. Where it uncovers work beyond the assessment, it scales into the Regulator Readiness Pack rather than into a new price list. Never hourly.

Who does this work. An engineering-led practice, certified in cybersecurity, cloud and networking, working to named standards rather than adjectives. Every engagement is scoped and authorised in writing before it starts. See our credentials. Our own PAIA manual is published.