Transcription and call-recording retention in the GCC: windows, deletion, redaction, audit trails

By Adnan Bassem — Founder, InfoDriven (Dubai). Building Arabic-first speech recognition for GCC call centers.Published June 10, 2026

ComplianceLast updated: June 10, 2026

How long must call recordings be kept in the GCC?

The anchored numbers come from sector regulators. In the UAE, TDRA Telecommunications Consumer Protection Regulations (v3.0, 2022) require licensed operators to retain customer-care call recordings at least one year for general calls and longer for disputed transactions. In the DIFC, DFSA COB Rule 3.4.6 requires authorised firms to retain telephone communications relating to client orders for a minimum of six years, with FSRA equivalents in ADGM. In Saudi Arabia, SAMA's Banking Consumer Protection Principles and the Insurance Authority's conduct-of-business rules set windows for KYC verbal-verification, investment-sales, and dispute calls typically running five to ten years, while CST rules scale general operator-call retention to interaction type.

Where no sector rule fixes a number — general retail support, internal QA on unregulated traffic — the data-protection laws supply the principle instead: keep personal data no longer than the purposes require. Defensible practice in unregulated GCC call-centre operations clusters around one to two years for QA recordings, with shorter windows (90 days is a common default) where the only purpose is coaching and quality sampling. The honest answer for any specific licence class is "check the current circulars with counsel" — windows are revised, and insurance, brokerage, and payments licences within one country can carry different numbers.

Do transcripts count as the same record as the audio?

Plan as if yes, with one asymmetry. A transcript of an identifiable caller is personal data carrying the same lawful-basis, transfer, and retention obligations as the recording. Where a regulator requires retention of "the communication" — DFSA client-order recording is the clearest case — conservative practice retains the audio as the primary record and treats the transcript as a derived working record, because the audio carries evidentiary weight (tone, interruptions, exact phrasing under dispute) the transcript summarises.

The asymmetry: nothing requires the two to share one retention window in the other direction. A common, sensible configuration keeps audio for the regulatory minimum while keeping the searchable transcript on the same or a shorter clock — and conversely, deleting audio at expiry must cascade to transcripts, embeddings, analytics extracts, and exports derived from it, or the deletion is incomplete. Inventory the derivatives: sentiment scores tied to a call ID, QA scorecards quoting transcript snippets, coaching evidence packs, CSV exports sitting in a BI tool. Retention policy that only covers the recording platform misses most of the copies.

When must recordings and transcripts be deleted?

Three deletion triggers operate in parallel. Expiry of the retention window: the storage-limitation principle in the Saudi PDPL, the UAE federal PDPL, and the DIFC and ADGM regimes means data kept past its justified purpose is itself a violation — regulatory minimums are floors, not licences to hoard. Data-subject erasure requests: the GCC data-protection laws grant erasure rights, qualified by legal-obligation carve-outs — a bank can decline to erase a KYC call inside its SAMA-aligned window, but must be able to explain the basis and delete once the window closes. Contract end: processor obligations in a DPA typically require deletion or return of all personal data on termination, which a controller should verify, not assume.

Make deletion a system behaviour rather than a calendar reminder: per-category retention rules with automated expiry deletion, deletion certificates or logs as evidence, and a tested workflow that locates everything tied to one caller across recordings, transcripts, and derivatives. CallScribe's configuration model reflects this — retention is set per project (30 days, 1 year, 5 years, 10 years, or indefinite with manual deletion), so a bank keeps general support calls one year and KYC calls ten without manual re-classification, and deletion at expiry covers transcript and analytics records together.

How should PII be redacted in transcripts?

Redaction is the control that makes long retention survivable. A six-year archive of searchable transcripts containing card numbers, Emirates IDs, and IBANs is a breach amplifier; the same archive with identifiers masked is a compliance asset. The standard pattern is masking at transcription time using a combined regex-and-NER pipeline: pattern-based detection for structured identifiers (card PANs, IBANs, SWIFT/BIC codes, Emirates ID and Saudi national ID formats, phone numbers) and named-entity recognition for unstructured ones — and for GCC traffic the pipeline must handle Arabic-script and code-switched content, including digits spoken in Arabic words, or it misses the half of the PII that occurs in Arabic segments.

Two design choices matter. First, mask the searchable transcript while retaining original audio under the retention rule — compliance can still pull the full call for an investigation, but everyday search, QA, and coaching surfaces never expose raw identifiers. Second, make redaction rules tunable per project: a healthcare project may need to retain the medical record number in the transcript because clinical workflow depends on it, while masking the Emirates ID; a collections project may need the opposite. Default-on redaction with per-project exceptions beats per-field opt-in, because opt-in redaction reliably lags new data categories.

What audit trails do regulators expect on recordings and transcripts?

When SAMA, the DFSA, a data-protection authority, or a court asks about a call, three questions follow the recording itself: who has accessed it, has it been altered, and can you produce it promptly. The corresponding controls are access logging (every transcript view and audio retrieval logged with user, time, and scope — with privileged compliance-team access logged separately), integrity protection (append-only storage so transcripts and logs cannot be silently edited; any redaction or correction recorded as a new auditable event), and retrievability (full-text search that finds the disputed call in seconds, not a week of manual trawling).

These mechanics also serve the data-protection side: access logs evidence that the purpose limitation is real (QA staff are not browsing celebrity callers), and deletion logs evidence that retention policy executes. CallScribe ships them as defaults — append-only storage, per-view transcript access logs, role-based access via PostgreSQL Row-Level Security, and per-project retention enforcement — but tooling only covers the operational half. The governance half (who is entitled to access, quarterly privileged-access review, how regulator requests are handled) belongs in your written procedures, and it is the half inspections ask about first.

Retention schedule starting points by sector

Starting numbers practitioners use when drafting a GCC retention schedule — every line should be confirmed against current circulars for your specific licence with counsel before adoption.

  • DIFC-authorised firms, client-order calls — minimum six years (DFSA COB Rule 3.4.6); FSRA equivalents for ADGM firms
  • Saudi financial services (KYC verbal verification, investment sales, disputes) — typically five to ten years under SAMA-aligned and Insurance Authority rules
  • UAE licensed telecom operators, customer-care calls — at least one year, longer for disputed transactions (TDRA v3.0, 2022)
  • Saudi licensed-service operator calls — retention scaled to interaction type under CST rules; disputes held longer than general support
  • Unregulated QA and coaching recordings — commonly 90 days to 2 years, set by documented purpose; CallScribe's platform default is 90 days, user-configurable
  • Healthcare-adjacent calls — follow health-data rules (in-UAE storage under Federal Law No. 2 of 2019) and provider record-keeping policy; commonly 5 years or more
  • Legal hold — any litigation or investigation suspends deletion for affected calls until the hold lifts; the hold workflow must override automated expiry
  • Transcripts and analytics derivatives — same clock as the source audio unless deliberately configured shorter; deletion cascades to all derivatives

Sources

  1. DFSA Rulebook, COB module, Rule 3.4.6 (six-year retention for client-order calls)
  2. SAMA Banking Consumer Protection Principles; Insurance Authority conduct-of-business rules (five-to-ten-year windows for financial-services calls)
  3. UAE TDRA Telecommunications Consumer Protection Regulations, Version 3.0 (2022) — one-year minimum operator retention
  4. Saudi PDPL, Royal Decree M/19 of 1443H (2021), amended by Royal Decree M/148 of 1444H (2023) — storage limitation and erasure rights
  5. UAE Federal Decree-Law No. 45 of 2021 — data-subject rights including erasure; UAE Federal Law No. 2 of 2019 (health-data storage)
  6. Saudi CST (formerly CITC) call-recording retention rules scaled to interaction type

Frequently asked questions

Is there one retention period that covers all GCC call recordings?

No. Retention is set per call category by the relevant sector regulator — six years for DIFC client-order calls under DFSA COB 3.4.6, five to ten years for SAMA-aligned financial calls, at least one year for UAE operator customer-care calls under TDRA rules — with data-protection storage-limitation principles capping anything not anchored by a sector rule. Build a per-category schedule, not a blanket window.

Can I keep recordings forever "just in case"?

No — the storage-limitation principle in the Saudi PDPL, UAE federal PDPL, and the DIFC and ADGM regimes makes retention beyond the justified purpose a violation in itself, and an over-retained archive enlarges your breach exposure. Indefinite retention should be a deliberate, documented exception (for example, a legal hold), not the default.

If a customer asks me to delete their calls, do I have to comply?

You must handle the request, but legal-obligation carve-outs apply: a SAMA- or DFSA-mandated record stays for its regulatory window, and you respond by explaining the basis and deleting at expiry. For data with no overriding obligation, erasure should execute across recordings, transcripts, and derivatives through one tested workflow.

Should PII be redacted from the audio or the transcript?

Standard practice masks the searchable transcript while retaining the original audio under the retention rule — investigations keep access to the full call, while everyday QA, search, and coaching surfaces never expose raw identifiers. For GCC traffic the redaction pipeline must handle Arabic-script and code-switched content, or it misses identifiers spoken in Arabic segments.

What audit evidence should I be able to produce about a specific call?

The recording and transcript themselves; a per-view access log showing who opened them and when; integrity evidence that nothing was silently altered (append-only storage, auditable redaction events); the retention rule applied to that call category; and, if it was deleted, the deletion log. That set answers most regulator and litigation requests without scrambling.

How do legal holds interact with automated deletion?

A legal hold must override the automated expiry for the affected calls — the hold workflow flags the relevant call population, suspends deletion, and logs the suspension. Automated retention without a hold mechanism is a liability in any operation that ever faces disputes, which is every operation.

Test it on your own Arabic calls

Dialect-aware transcription with diarization and sentiment — built for GCC call centers.

Try CallScribe free →

5 min/mo free · No credit card