Skip to content
QASignal Room

Notes  /  Compliance

Retention: Recordings, Transcripts and Indexes

Deleting a recording deletes one copy. The transcript, the analytics index, the summary and the backup are separate objects and they are usually forgotten.

Section
Compliance
Type
Procedure

Retention policy in a speech analytics estate has to cover more objects than most policies name.

The objects that exist

The audio recording.

The transcript, derived from it.

The analytics index, which holds searchable text and features.

Category and score determinations, stored per interaction.

Summaries, where generated.

CRM notes containing content from the call.

Screen recordings, where captured.

Backups of all of the above.

Vendor-side copies, if processing happens off-premises.

A retention policy naming only the recording deletes one of nine things.

Setting periods by purpose

Different purposes justify different periods, and stating them separately is what makes a policy defensible.

Dispute and transaction evidence. Determined by the relevant limitation period or regulatory requirement, frequently the longest driver.

Regulatory record-keeping. Some sectors require recordings of specific transaction types for defined periods.

Quality and training. Short. A recording used for coaching is useful for weeks, not years.

Analytics and trend. The aggregate data can be retained after the underlying recording is deleted, which is usually the right arrangement.

Fraud investigation, which may justify longer for flagged interactions specifically.

Set the shortest period each purpose requires, per data type, rather than one period for everything. A single long period applied to all recordings because one regulation requires it for a subset is the common and indefensible arrangement.

Deletion that actually works

Test it. Delete a recording and then search for its content in the analytics index. In many deployments it is still there.

Propagation to derived objects has to be designed. Transcripts and index entries do not delete themselves.

Backups. Deletion from the live system with an indefinite backup is not deletion for most purposes, though a defined backup expiry is generally accepted.

Vendor-side copies. What does the contract say about deletion on your instruction and on termination?

Aggregate data is usually fine to keep, provided it cannot be re-identified. Category counts and trend series do not need to expire with the recordings.

Legal hold

Must be able to override deletion selectively, and it must have been built rather than assumed.

Applied to a defined set — a customer, a period, an agent, a case.

Released explicitly, or holds accumulate and the retention policy stops operating.

Test that a hold survives the automated deletion job. This is the failure that only becomes visible during litigation.

The subject access request

An agent or a customer asks what you hold about them.

The answer includes the recordings, the transcripts, the scores, the evaluator comments and the analytics determinations.

Locating all of it requires knowing where it all is, which is the argument for the inventory of objects above.

Evaluator comments are frequently the awkward part, because they were written informally and are disclosable.

Train evaluators accordingly. A comment written about a person will be read by that person.

The accumulation problem

Storage is cheap, so nothing is deleted.

An estate holding years of recordings of every conversation is a large liability: a breach target, a discovery burden, and a growing subject access obligation.

The volume argument for retention is weak. The value of a recording falls sharply after the dispute window, and the analytics aggregate retains the operational insight without the personal data.

Deleting on schedule is the single measure that reduces exposure most, and it is the one most often deferred because nobody owns it.

The deletion test

A quarterly test that establishes whether deletion propagates, which it frequently does not.

Select a recording past its retention period and confirm it has gone from the primary store.

Then search the analytics index for a distinctive phrase from it. This is where it usually still is.

Check the transcript store.

Check any summary or CRM note derived from it.

Check the screen recording.

Check the vendor side, which requires asking rather than testing.

Check a backup, or confirm the backup expiry schedule.

Document the result. A retention policy that has never been tested is a statement of intent, and the difference between intent and practice is exactly what a subject access request or a regulatory enquiry exposes.

External reference: FTC privacy and security guidance.