Back to Blog
Compliance8 min read1,620 words

Personal Data in Call Transcripts: Redaction, Consent and India's DPDP Act

What personal data ends up in call recordings and transcripts, and how India's data protection law shapes how it should be handled.

Abstract cover of a green transcript-like block of lines with several segments softly masked out

A single customer service call can contain more personal information than a signup form. In a few minutes a caller may give their full name, mobile number, delivery address, date of birth, a PAN or Aadhaar number, and sometimes details about their health or finances. When that call is recorded and transcribed, all of that information becomes stored, searchable data.

For Indian businesses, the Digital Personal Data Protection Act, 2023 (DPDP Act) turns the handling of that data into a clear legal responsibility. This post explains what personal data typically appears in calls, summarises the Act's core principles, and describes general approaches to consent, redaction, retention and access control.

What Personal Data Shows Up in Calls

It is easy to underestimate how much personal data flows through ordinary conversations. Common categories include:

  • Identity details: names, dates of birth, gender, family members' names.
  • Contact details: mobile numbers, alternate numbers, email addresses.
  • Location details: home and delivery addresses, landmarks, pin codes.
  • Government identifiers: Aadhaar numbers, PAN, voter ID, passport or driving licence numbers.
  • Financial details: bank account numbers, UPI IDs, card numbers, loan amounts, income.
  • Health information: symptoms, prescriptions, diagnoses, especially in clinics, pharmacies and insurance.
  • Incidental information: things callers volunteer without being asked, such as "my father is in hospital, that is why I missed the payment".

Two points matter. First, personal data appears in several forms at once: the audio recording, the transcript, any summaries or extracted fields, analytics, and logs. Second, much of it is unsolicited. Even a business that never asks for Aadhaar numbers will receive them from callers who assume they are needed.

The DPDP Act in Brief

The DPDP Act, 2023 is India's comprehensive law governing digital personal data. Its key concepts include the following.

Roles

  • Data Principal: the individual to whom the personal data relates, such as the caller.
  • Data Fiduciary: the entity that determines the purpose and means of processing, typically the business.
  • Data Processor: an entity that processes data on behalf of a Data Fiduciary, such as a service provider.
  • Significant Data Fiduciary: a Data Fiduciary notified by the government based on factors such as the volume and sensitivity of data processed. Such entities face additional obligations, including appointing a Data Protection Officer based in India, appointing an independent data auditor and conducting periodic Data Protection Impact Assessments.

Core Principles

  • Consent and notice. Processing generally requires consent that is free, specific, informed, unconditional and unambiguous, given through a clear affirmative action and preceded by a notice describing the personal data and the purpose. The Act also recognises certain "legitimate uses" where processing may occur without consent, for example where a person voluntarily provides data for a specified purpose.
  • Purpose limitation. Data should be processed for the purposes for which consent was given or a legitimate use applies.
  • Data minimisation. Consent is limited to personal data necessary for the specified purpose.
  • Accuracy and security. Data Fiduciaries must make reasonable efforts to ensure accuracy where data is used for decisions, and must take reasonable security safeguards to prevent breaches.
  • Retention and erasure. Personal data should be erased once the purpose is no longer being served or consent is withdrawn, unless retention is required by law.
  • Breach notification. Personal data breaches must be reported to the Data Protection Board of India and to affected Data Principals.

Data Principal Rights

Individuals have rights including access to information about processing, correction and erasure of their data, grievance redressal, and nominating another person to exercise their rights in case of death or incapacity. Consent can be withdrawn, and withdrawing should be comparable in ease to giving it.

Enforcement

The Act establishes the Data Protection Board of India to handle complaints, inquire into breaches and impose penalties. Penalties set out in the Act's schedule are substantial, reaching up to ₹250 crore for certain failures such as not taking reasonable security safeguards.

The DPDP Rules

The Digital Personal Data Protection Rules were notified in November 2025, with obligations coming into force in phases rather than all at once. Details such as notice content, consent manager requirements, breach reporting procedures and timelines are set out in the Rules. Because phased dates and any subsequent amendments or clarifications matter a great deal in practice, businesses should verify the current status from official government sources or with counsel rather than relying on summaries, including this one.

Recording Disclosure on Calls

Telling callers that a call is recorded is a long-established practice in customer service, and under a consent-and-notice framework it becomes more important. General good practice includes:

  • Disclose at the start, before substantive personal information is exchanged.
  • Be specific about purpose. "This call may be recorded for quality and training purposes" is familiar, but if recordings or transcripts are also used for analytics or automated processing, the notice should reflect that.
  • Disclose automation. Where callers speak to an AI agent, being transparent about that is widely regarded as good practice and builds trust.
  • Use the caller's language. A disclosure in English to a caller who speaks Gujarati is unlikely to be "informed" in any meaningful sense.
  • Offer a path. Consider what happens if the caller objects, such as continuing without recording where feasible or offering another channel.

Redaction Approaches

Redaction reduces the amount of personal data that is stored, viewed and analysed. There are two broad families of technique, usually combined.

Pattern-Based Detection

Many identifiers have recognisable formats. PAN follows a fixed pattern of letters and digits. Aadhaar numbers are twelve digits. Indian mobile numbers are ten digits with known leading digits. Card numbers have characteristic lengths and pass the Luhn checksum. Regular expressions and validation rules can catch these reliably in clean text.

Pattern-based methods are fast, predictable and auditable, but they only work when the text looks the way the pattern expects.

Named Entity Recognition

Names, addresses, organisations and free-form health details do not follow fixed patterns. Named entity recognition (NER) models, including those built on modern language models, identify such entities from context. They generalise better than patterns but are probabilistic: they can miss entities, particularly in Indian names, transliterated text and code-mixed sentences, and they can over-redact ordinary words.

In practice, a layered approach, patterns for structured identifiers and models for unstructured entities, with conservative defaults for high-risk categories, tends to work better than either alone.

Why Spoken Numbers Are Hard

Transcripts of speech are not clean text. Consider a caller giving a mobile number:

"Mera number hai nau aath saat, ek minute, nau aath saat chhe, double five, teen shunya..."

A pattern looking for ten consecutive digits sees nothing. The number is split across words in two languages, includes a correction, uses "double five", and is interrupted by filler. Speech recognition may render parts as digits ("987") and parts as words ("double five"), or insert punctuation between groups. Numbers may also be spoken in Gujarati ("nav aath saat") or as English words.

Robust handling typically involves normalising spoken numbers into digits before pattern matching, tolerating gaps and corrections, and considering conversational context: if the agent just asked for a phone number, the next few seconds deserve extra scrutiny.

Redacting Audio as Well as Text

Masking a transcript does not remove the personal data from the recording. If recordings are retained, the same information is still audible. Approaches include:

  • Audio redaction: using word-level timestamps from transcription to replace sensitive spans in the audio with silence or a tone.
  • Pause and resume recording around sensitive collection steps, such as payments.
  • Separate handling of sensitive steps: for card payments, directing callers to secure channels designed for that purpose rather than capturing card details in a general recording. Payment card data is additionally subject to industry standards such as PCI DSS.
  • Shorter retention for audio than for redacted text, where business needs allow.

Timestamp-based audio redaction inherits any errors from transcription and detection, so it is best treated as risk reduction rather than a guarantee.

Access Control, Retention and Audit

Redaction is one layer. Other controls matter as much.

  • Least privilege: most staff reviewing calls for quality do not need raw identifiers. Unredacted access should be restricted to roles that genuinely require it.
  • Audit trails: record who accessed which recordings or transcripts, and when, so that access can be reviewed and misuse detected.
  • Defined retention: decide how long recordings, transcripts and derived data are kept for each purpose, then enforce deletion automatically. Remember derived copies such as exports, summaries and analytics datasets.
  • Processor oversight: where service providers process call data, contracts and technical controls should reflect the Data Fiduciary's obligations.
  • Rights handling: have a workable process to locate a caller's recordings and transcripts when they request access, correction or erasure.
  • Breach readiness: know in advance how a breach involving call data would be assessed and reported.

Looking Ahead

Voice AI increases both the volume of call data and its usefulness: every call can now be transcribed, summarised and analysed. That makes privacy practices more important, not less. The DPDP Act's principles of notice, purpose, minimisation and erasure align well with good engineering practice: collect what you need, protect it, and delete it when its purpose is served.

Businesses should treat compliance as an ongoing process. Map where personal data flows in your calls, decide what truly needs to be retained, test redaction on real Indian speech, and keep track of the phased implementation of the Rules as they take effect. At Cirio, we believe privacy-conscious design is a basic expectation of any system that listens to customers, and it is worth reviewing your own call data practices with qualified legal advice.

Frequently Asked Questions

Does the DPDP Act apply to call recordings and transcripts?

Call recordings and transcripts that identify or relate to an identifiable individual contain personal data, and the Digital Personal Data Protection Act, 2023 applies to digital personal data. Businesses that decide why and how such data is processed are Data Fiduciaries under the Act and carry the associated obligations.

What is PII redaction in call transcripts?

PII redaction is the process of detecting personal information such as names, phone numbers, addresses, identity numbers and card numbers in transcripts or audio and masking or removing it. It reduces exposure when transcripts are stored, analysed or shared with staff who do not need the raw details.

Why are spoken numbers hard to redact?

Callers say numbers as words, often in mixed languages, with pauses, repetitions and corrections, such as "nau aath saat, sorry, nau aath chhe". Speech recognition may output these as words, digits or a mixture, so simple digit patterns miss many of them.

When do the DPDP Rules take effect?

The DPDP Rules were notified in November 2025 with a phased implementation, where different obligations take effect at different times. Businesses should check the current official notifications or consult legal counsel for the exact dates that apply to them.

Put Voice AI to work for your business

Deploy an AI agent that handles calls in Hindi, English, and more in under a minute.

Start free: it's instant →