Skip to main content
You are responsible for complying with local recording laws. This guide helps you configure Allo’s compliance features, but does not constitute legal advice. Consult legal counsel for your specific situation.

Allo’s compliance tools

Allo gives you four tools to stay compliant with recording laws. Mix and match based on your needs.

US recording laws

Federal law (one-party consent) allows recording if one party consents. But when calls cross state lines, the stricter state’s law applies. For outbound sales teams calling all 50 states, this matters.
If your team calls all 50 US states:
  1. Enable consent message for all inbound calls — covers you everywhere
  2. Enable privacy mode for outbound calls — no audio stored, transcripts + AI summaries still sync to your CRM
  3. Train your team to verbally disclose recording at the start of outbound calls to dual-consent states
This gives you the best of both worlds: full AI intelligence for sales coaching, zero audio liability.
Allo is building area-code-based compliance rules. This will let you automatically apply different recording settings based on the state you’re calling.Example: Calls to California numbers automatically use privacy mode, while calls to Texas numbers record normally.This feature is on the roadmap. Contact support for updates or to join the early access list.

EU & international

Recording requires a legal basis — typically consent or legitimate interest.Key requirements:
  • Inform callers before recording starts
  • Document your legal basis
  • Provide access to recordings on request
  • Honor deletion requests (right to erasure) — GDPR recommends 30 days
  • Data processing agreement (DPA) available from Allo
France (CNIL):
  • CNIL enforces strict consent rules
  • Consent must be freely given, specific, and informed
  • Recordings used for training must be anonymized or consented to separately
  • Allo’s Mistral AI option keeps processing with a European provider
Visit our Trust Center
Federal PIPEDA follows one-party consent for calls. But provincial laws add requirements:
  • Quebec — Stricter privacy law (Law 25). Consent required for recording.
  • British Columbia & Alberta — PIPA applies. Similar to PIPEDA but with provincial enforcement.
Recommendation: Enable consent message for all Canadian inbound calls.
Recording laws vary widely. For country-specific guidance:
  • Check local telecommunications authority rules
  • Consult legal counsel in target markets
  • Contact Allo support for configuration help
Allo supports numbers in 50+ countries. We can configure compliance settings per number.

AI & transcription compliance

Real-time transcription and AI analysis receive the same legal treatment as call recording. The same consent that covers recording also covers transcription. Key considerations:
  • BIPA (Illinois) — Speaker identification (voiceprints) may qualify as biometric data under BIPA. If you handle calls with Illinois residents, consult legal counsel about biometric consent.
  • AI disclosure laws — California (AB 2013) and Texas require disclosure when AI is used to analyze calls. Your consent message should mention AI analysis.
  • AI-generated summaries — Treated as derived data. Same retention and access rules apply as for recordings.

Data retention

Default: Recordings and transcripts are kept indefinitely in your Allo account. Custom retention: Contact Allo support to set auto-deletion after a specific number of days. Regulatory benchmarks:
RegulationGuideline
GDPRDelete when no longer necessary. 30 days recommended for call recordings.
CCPARespond to deletion requests within 45 days.
HIPAA6-year retention minimum. BAA available for healthcare customers.
SOX7-year retention for financial records including call records.
Need a HIPAA Business Associate Agreement? Contact support — available for healthcare customers on Business plan.

FAQ

Yes. Enable Privacy Mode — audio is never stored, but transcription and AI summaries work normally. Transcripts sync to your CRM as usual.
Not yet. This feature is on the roadmap. For now, contact support to configure privacy mode per line or user.
Not yet via an automated mechanism. Agents can manually note opt-outs. Contact support for custom workflows.
Encrypted at rest and in transit on Allo’s secure infrastructure. SOC 2 compliant. Visit our Trust Center for details.
Business Associate Agreements (BAA) are available for healthcare customers on the Business plan. Contact support to set one up.
Yes. Contact support to configure custom retention periods. Common settings: 30 days (GDPR), 90 days, or 1 year.

Need help?