A Medicare broker in Phoenix recorded every intake call for three years. Standard QA practice. Except he was taking calls from California — a two-party consent state — and his IVR didn't disclose recording until after the call connected. One complaint to the California AG's office. Eighteen months of recordings. Do the math on $5,000 per violation.
He thought he was covered because Arizona is one-party consent. He wasn't wrong about Arizona. He was wrong about where his callers were sitting.
I wish I could say this was rare. It's not.
Call recording seems simple until the questions pile up. Which states require consent from both parties? How long do you keep recordings before they become liability instead of protection? What's the difference between storing audio versus transcripts? And what happens if those recordings get breached? (If you're new to pay-per-call altogether, our pay-per-call glossary covers the foundational terminology.)
These questions show up in every pay-per-call operation eventually. Usually after something's already gone sideways. (Ask me how I know.) So here's the FAQ we built from fielding these calls — organized by the questions that actually matter, not the compliance-speak that puts you to sleep.
1. Do I Need Consent to Record a Call?
Short answer: yes, but the type of consent depends on where the parties are.
One-party consent states (38 states plus DC) require only one person on the call to know about recording. Since you're recording, you know. You're covered. No disclosure required legally — though most operations disclose anyway for customer experience reasons.
Two-party consent states (also called "all-party consent") require everyone on the call to agree to recording. The twelve states: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, New Hampshire, Pennsylvania, and Washington. Miss the disclosure, and you're exposed to state wiretapping statutes — which carry per-recording penalties that add up fast.
Here's where it gets tricky. The stricter state controls. If you're in one-party Texas calling someone in two-party California, California law applies. If a California caller dials your Arizona call center, California law applies. The protection follows the more restrictive jurisdiction. For national call campaigns, this means treating every call as if it's two-party consent — the operational overhead is minimal compared to the exposure.
VeloCalls includes recording at 3¢/min as an add-on. The platform handles disclosure prompts before call connect, but you're responsible for configuring them. If your IVR doesn't include a recording disclosure before the first human interaction, fix that today. (Need help optimizing your IVR flow? Our IVR abandonment rate study shows where callers drop off.)
2. What Counts as Valid Consent for Recording?
Consent doesn't need to be written for call recording (unlike TCPA consent for autodialed calls). Verbal acknowledgment works. Implied consent from staying on the line after a disclosure works in most jurisdictions. But "works" and "bulletproof" aren't the same thing.
The standard disclosure: "This call may be recorded for quality assurance and training purposes." Play it at the top of the IVR, before any human interaction. The caller continuing past this point implies consent to recording.
Explicit opt-in (safer): "Press 1 to consent to recording, or press 2 to continue without recording." More friction, but documented consent. Useful for high-liability verticals like legal intake or healthcare.
What doesn't work: Recording without any disclosure and hoping no one from California, Florida, or Pennsylvania calls. A disclosure buried after the call has started. A disclosure so quiet or fast that no reasonable person would catch it. I've listened to call recordings where the "disclosure" was a half-second mumble at 0.5x normal speaking speed. That's not consent — that's a lawsuit waiting to happen.
Look, I get it. You don't want to slow down your call flow. But the two-second disclosure costs nothing. The lawsuit costs your entire operation.
For deeper TCPA consent requirements (different from recording consent), see our TCPA compliance FAQ. Recording consent and telemarketing consent are related but distinct compliance tracks.
3. Which States Have Two-Party Consent Laws?
Twelve states require all-party consent for call recording. Memorize these — or better, build your IVR to disclose recording on every call regardless:
| State | Statute | Notes |
|---|---|---|
| California | Cal. Penal Code § 632 | $2,500 per violation. California Invasion of Privacy Act is aggressively enforced. |
| Connecticut | Conn. Gen. Stat. § 52-570d | Includes electronic communications. |
| Delaware | Del. Code tit. 11 § 2402 | Requires consent of all parties. |
| Florida | Fla. Stat. § 934.03 | Criminal penalties possible. $1,000 civil damages minimum. |
| Illinois | 720 ILCS 5/14-2 | Two-party for private conversations. One-party for business calls in some interpretations — consult counsel. |
| Maryland | Md. Code, Cts. & Jud. Proc. § 10-402 | All-party consent required. |
| Massachusetts | Mass. Gen. Laws ch. 272 § 99 | Criminal statute. Felony potential. Don't mess around here. |
| Michigan | Mich. Comp. Laws § 750.539c | All parties must consent. |
| Montana | Mont. Code Ann. § 45-8-213 | Requires consent from all parties. |
| New Hampshire | N.H. Rev. Stat. Ann. § 570-A:2 | All-party consent. |
| Pennsylvania | 18 Pa. C.S. § 5703 | Criminal penalties. Excludes business extensions in some cases — still disclose. |
| Washington | Wash. Rev. Code § 9.73.030 | All-party consent. Criminal and civil penalties. |
Some states have nuances — business extension exemptions, different rules for in-person vs. phone conversations, interstate commerce carve-outs. But the safe play is always disclose. The two-second IVR prompt costs nothing. The lawsuit costs everything.
4. How Long Should I Keep Call Recordings?
There's no single answer. Retention depends on your industry, what's in the recordings, and what you might need them for.
Baseline for pay-per-call (90 days): Covers most dispute resolution windows. Publisher claims a call was bad? Play the recording. Buyer disputes a conversion? Pull the audio. Ninety days handles 95% of operational disputes. After that, recordings become storage cost and potential liability — not assets.
TCPA litigation exposure (4 years): If you're keeping recordings as part of your consent documentation stack, the FCC's four-year retention requirement applies. The clock starts from the date of the call, not the date of consent. Our TCPA compliance FAQ breaks down the full record-keeping requirements.
PCI-DSS (don't store payment data): If callers give credit card numbers on recorded calls, you have a PCI problem. Pause recording during payment capture or mask/redact the audio. Storing full card numbers in call recordings violates PCI-DSS and creates breach exposure you don't want.
HIPAA (6 years): Healthcare-related calls fall under HIPAA retention requirements. Six years from the date the record was created or last in effect. And those recordings need to be encrypted, access-controlled, and auditable.
My recommendation for most operations: 90 days audio, indefinite transcripts. Audio is expensive to store and rarely needed after the dispute window. Transcripts are cheap, searchable, and useful for training and compliance audits years later. Honestly, I've seen ops keep audio for years and never pull a single file past the 90-day mark. That's just liability sitting on a server. For more on managing dispute resolution, see our guide on tracking ROI per publisher — recording retention ties directly into revenue attribution.
5. Should I Store Transcripts or Audio Recordings?
Both. But for different purposes and different timelines.
Audio recordings are the authoritative record. They capture exactly what was said — tone, pauses, stammering, the rep talking over the customer. Audio matters for dispute resolution, compliance investigations, and legal proceedings. But audio is expensive to store (figure 30-50MB per hour) and impossible to search at scale.
Transcripts are the operational workhorse. Searchable. Exportable. Analyzable with AI tools. You can scan 10,000 transcripts for compliance phrases in seconds. Try doing that with audio files. Transcription runs about 4¢/min on most platforms (VeloCalls charges exactly that for the transcription add-on). The searchability and QA value justify the cost.
The hybrid approach:
- Keep audio for 30-90 days (dispute resolution, immediate QA)
- Generate transcripts at time of recording
- Delete audio after the retention window
- Keep transcripts indefinitely (training, pattern analysis, compliance audits)
This balances storage costs against operational utility. Transcripts without audio are still useful. Audio without transcripts is a filing cabinet you can't search.
(I learned this the hard way after spending three hours hunting for one call in a folder of 40,000 unlabeled audio files. Never again.)
For AI-powered conversation intelligence (sentiment analysis, call summarization, AMD), VeloCalls offers these as add-ons: AI Call Summary at 10¢/call, Sentiment Analysis at 5¢/use. These generate structured data from recordings that's even more useful than raw transcripts for operations at scale. (Curious how AI qualification layers onto pay-per-call? Our breakdown of AI voice qualification economics covers when it saves money and when it doesn't.)
6. What's the Breach Exposure If Recordings Are Compromised?
Call recordings contain personal information. Phone numbers. Names. In some cases, social security numbers, health information, payment details. A breach triggers multiple notification requirements.
State data breach notification (all 50 states): If the recordings include personal information of state residents, you're notifying the AG and affected individuals under that state's breach law. "Personal information" thresholds vary but name + phone number qualifies in most states.
PCI-DSS breach: If recordings contain payment card data (and you shouldn't be storing it — see above), notify the card brands. Expect fines, forensic audit requirements, and potential loss of payment processing privileges.
HIPAA breach: Health information in recordings? HHS notification required. Individual notification required. If more than 500 individuals are affected in a state, media notification required. The OCR will investigate.
TCPA exposure: If breach exposes consent records, you may have trouble proving consent for calls you made. This isn't a breach notification requirement — it's a litigation exposure that compounds breach costs.
The stack of requirements is why encryption matters. Recordings should be encrypted at rest (AES-256) and in transit (TLS 1.2+). Access should be role-based and logged. Don't store data you don't need — redact payment info, consider whether you actually need to retain call audio past your dispute window.
For fraud detection on the traffic sources feeding your call campaigns, ClickzProtect catches invalid clicks before they burn ad spend. And JustAnalytics tracks session behavior that can help identify suspicious lead submissions.
7. Can Employees Listen to Call Recordings?
Yes, with appropriate access controls and business justification. Call monitoring for QA and training purposes is standard practice and legally permissible — you're not wiretapping if you're a party to the call or have disclosed recording.
But "legal" and "wise" aren't always the same.
Limit access by role. QA managers need recording access. New sales reps don't need access to every call in the system. Build role-based permissions.
Log access. Every time someone plays a recording, log who, when, and which recording. This matters for internal investigations and breach forensics. (JustBrowser can help isolate session access for compliance-sensitive review workflows.)
Don't let recordings leave the system. Downloading recordings to laptops, emailing them, uploading to Dropbox — all of these create breach surface. Keep recordings in the platform with streaming playback only. Yes, your QA manager will complain about the inconvenience. They'll complain less than they would during a breach investigation.
Respect sensitive data. If a call contains health information or payment details, limit access to personnel with specific need-to-know and appropriate training (HIPAA for health, PCI for payment).
8. How Should I Handle Call Recording for Regulated Verticals?
Some verticals have recording requirements beyond general consent laws.
Medicare/insurance: CMS guidelines require specific disclosures for Medicare Advantage and Part D enrollment calls. Recordings must be kept for ten years for CMS audit purposes. Agents must identify themselves and the plan they represent within the first few seconds. If you're running Medicare campaigns, the Medicare AEP calendar covers seasonal compliance considerations.
Legal intake: Attorney-client privilege concerns. Some firms don't record intake calls, period. Others record with explicit disclosure and stop recording before privileged discussion. If you're handling legal intake, coordinate with the buyer's compliance team.
Debt collection: FDCPA and Reg F requirements layer on top of general recording rules. Mini-Miranda disclosures at call start. State-specific debt collection statutes. This is specialist territory. (Related: our DNC scrubbing guide covers the Do Not Call compliance layer that applies alongside recording rules.)
Healthcare: HIPAA requires BAAs with anyone handling recordings that contain PHI. Encryption, access controls, breach notification protocols — all required. Don't touch healthcare calls without compliance infrastructure in place.
9. What's the Cost of Call Recording?
Costs break into two buckets: per-minute recording fees and storage.
Recording fees vary by platform — some bundle it, some charge separately. VeloCalls charges 3¢/min for recording as an add-on to the base per-minute rate. Check what you're actually paying; this stuff adds up faster than you'd expect.
Storage costs accumulate over time. Cloud storage runs $0.02-0.03/GB/month on major providers. One hour of audio is roughly 30-50MB (compressed). Over a 90-day retention window at 1,000 hours/month, you're looking at $30-50/month in raw storage — plus whatever your platform charges for access and management.
Transcription is often more useful than audio long-term. VeloCalls charges 4¢/min for transcription. Transcripts are searchable, smaller to store, and easier to analyze at scale.
AI analysis add-ons (summarization, sentiment) add incremental cost but generate structured data that's more actionable than raw recordings. Whether it's worth it depends on your volume and QA needs. At low volume? Probably overkill. At 10,000+ calls/month? The pattern detection alone pays for itself.
For a breakdown of VeloCalls' full per-minute pricing, see the pricing page. The per-minute model (Managed from 4¢/min, BYOC from 2¢/min, both dropping as volume scales) means recording costs are predictable as a percentage of total platform spend.
10. What Metadata Should I Capture With Each Recording?
The recording itself is only useful if you can find it. Capture metadata that lets you retrieve specific calls on demand.
Minimum metadata:
- Call ID / unique identifier
- Caller phone number (ANI)
- Called number (DNIS)
- Timestamp (start and end, with timezone)
- Duration
- Recording file location / URL
- Consent status at time of recording
Operational metadata:
- Campaign or publisher source
- Lead ID (links recording to lead record)
- Agent ID (who handled the call)
- Disposition / outcome
- IVR path taken
- Transfer events
QA metadata:
- Quality score (if evaluated)
- Compliance flags
- Escalation notes
Store metadata in a searchable database linked to lead records. When a publisher disputes a chargeback or a compliance auditor asks for "all calls to California in March 2026," you need to pull those recordings in hours, not weeks. I've seen audits go sideways because someone couldn't produce a specific call. Don't be that operation.
Honorable Mentions
State-specific recording laws beyond two-party consent. Some states have additional quirks — workplace recording exceptions, public vs. private conversation distinctions, telephonic vs. in-person differences. If you're operating heavily in a specific state, read that state's statute directly.
Recording outbound vs. inbound calls. The consent analysis is the same, but operational workflows differ. For outbound, disclosure at call start. For inbound, disclosure before the caller reaches a live agent — typically in the IVR.
Cloud vs. on-premise storage. Cloud is standard in 2026. On-prem makes sense only for specific compliance requirements (some government contracts, certain healthcare scenarios). The management overhead of on-prem rarely justifies the control benefits. And honestly? I haven't seen a new pay-per-call operation go on-prem in years. For teams managing multiple SaaS products with varied compliance needs, DevOS can help orchestrate infrastructure across environments.
Quick Verdict
If you take one thing from this FAQ: disclose recording on every call, regardless of where you think the caller is. The two-party consent states create exposure that's easy to avoid and expensive to get wrong.
Configure your IVR with a front-loaded disclosure. Keep audio for 90 days. Keep transcripts indefinitely. Don't store payment data in recordings.
That covers 90% of call recording compliance for pay-per-call operations. The other 10%? That's where you talk to a lawyer who specializes in your vertical.
For everything else — TCPA consent (different from recording consent), DNC scrubbing, litigator number suppression — see the related guides in our compliance pillar.
Frequently Asked Questions
Do I need consent to record a call?
It depends on where the parties are located. In one-party consent states (38 states plus DC), only one person on the call needs to know about the recording — that's you, so you're covered. In two-party (all-party) consent states like California, Florida, and Pennsylvania, everyone on the call must consent before recording starts. The safest approach is always disclosing recording upfront with a prompt like "This call may be recorded for quality assurance" before the conversation begins.
How long should I keep call recordings?
The answer varies by industry and use case. TCPA litigation requires consent records for four years from the call date. PCI-DSS prohibits storing payment card data in recordings past authorization. HIPAA-covered entities must retain records for six years. For general pay-per-call operations without specific regulatory requirements, 90 days covers most dispute resolution needs. Keep recordings tied to lead records so you can produce specific calls on demand.
Should I store transcripts or audio recordings?
Both serve different purposes. Audio recordings are the authoritative record — they capture tone, pauses, and exactly what was said. Transcripts are searchable, cheaper to store, and easier to review at scale. Most operations keep audio for 30-90 days (dispute resolution window) and transcripts indefinitely (for training, QA, and compliance audits). Transcription runs about 4 cents per minute on most platforms — the searchability alone is worth it.
What happens if call recordings are breached?
A breach of call recordings triggers notification requirements in all 50 states if the recordings contain personal information (name plus phone number qualifies). If recordings include payment card data, you're looking at PCI-DSS breach notification to card brands. If recordings contain health information, add HIPAA breach notification (HHS, affected individuals, potentially media). The regulatory exposure stacks. Encrypt recordings at rest and in transit, limit access, and don't store sensitive data you don't need.
Try VeloCalls for Your Vertical
AI calling + pay-per-call platform built for HVAC, plumbing, roofing, PI lawyers, Medicare brokers, and insurance. Smart routing, real-time bidding, visual IVR builder, AI conversation intelligence. Per-minute pricing — Managed starts at 4¢/min, BYOC at 2¢/min, both drop as you scale.