← Blog

Where your business calls actually live: UK data residency

Axel Molist·4 September 2026
Where your business calls actually live: UK data residency

If you run a UK business and somebody asked you where your last customer call is sitting right now, could you answer? Not "in the cloud". The real answer: which company, which country, under what law. Most people can tell you their porting date and their monthly bill and can't tell you that. It made our list of questions to ask before switching, and it deserves more than a bullet point, because UK data residency for calls is one of the few questions where a lot of providers would have to go and check.

In short: UK GDPR doesn't require your call recordings, transcripts or summaries to sit on a server inside the UK. It cares who can reach that data and under what legal protection. If it goes to a separate organisation outside the UK, that's a restricted transfer, and you need a lawful basis for it, such as an adequacy decision.

Why a call is a bigger deal than the rest of your software

A CRM holds names, emails, maybe a deal value. A call holds someone's actual voice, and increasingly a word-for-word transcript: the price you quoted, the complaint, the thing a client mentioned in confidence, a colleague's tone on a bad day. When a provider records and transcribes your calls, that's what sits on their servers.

An on-premise system was at least something you could point at. The cloud took that away, and the question went with it. People now ask about porting and price and take it on faith that the cloud is somewhere sensible. It usually is. But "usually" isn't "checked", and a call is personal data at a level your other software rarely reaches.

Why I had to answer it myself

I've spent the years since 2012 selling and installing business phone systems, since 2015 at circle.cloud, the UK telecoms company I started that installs and supports phone systems for small businesses, and I had to answer this question for my own product. A lot of telecoms providers resell someone else's platform, and the transcription and summary layer on top is often a third party's again. Each hop is another company holding your customers' voices.

So when we designed how Olatti handles voice, we made one decision that everything else follows from: voice, transcription and call summaries run on We UC's own infrastructure, in our own data centres, not on a third-party AI vendor's. The conviction behind it is vertical integration, the more of the stack you control, the better the service. When a customer asks me where their conversations live, the answer has to be mine to give, not passed up a chain of vendors.

That's the lens for the rest of this: not the postcode of a data centre, but whether somebody can give you a straight answer.

What does UK GDPR actually require about UK data residency?

Here's the bit that surprises people: UK GDPR doesn't say your data has to sit on a server physically inside the UK. There's no "British data, British soil" rule. What it cares about is who can reach the data and under what legal protection, not which country the rack is bolted to the floor of.

The concept is a "restricted transfer": sending personal data to a separate organisation outside the UK. The ICO's own guidance sets out a three-step test for whether you're making one: does UK GDPR apply to the data, are you sending it to an organisation outside the UK, and is that organisation legally separate from you. Three yeses and the transfer rules apply. You then need a lawful basis: an adequacy decision (the receiving country is officially recognised as offering equivalent protection), or a safeguard like the UK's International Data Transfer Agreement.

For most UK businesses the EU is the one that comes up. The European Commission renewed its adequacy decision for the UK in December 2025, running to December 2031, so data keeps flowing between the UK and the EEA without extra paperwork. If your team works with EU clients, that's one thing you don't have to solve.

None of this means you must host in the UK. It means that if your recordings, transcripts or summaries are processed by a vendor outside the UK, or by a third-party AI service your provider plugs in behind the scenes, somebody in your business should be able to say who that vendor is, where they operate and what legal basis covers the transfer. If nobody can, that's the gap.

I'm not a data protection lawyer. Everything above is the ICO's framing rather than mine, and anything with real risk attached deserves a conversation with someone who is.

Reading the small print on where call data goes.

How long are you keeping it?

Residency is where. The other question is how long, and UK GDPR is clear on it: personal data should be kept no longer than necessary for the purpose you collected it for. There's no fixed retention period in law for call recordings, which people tend to read as "keep everything, just in case". It's the opposite. Without a retention policy you're expected to review what you hold and delete or anonymise what you no longer need. "Just in case" isn't a purpose.

For a small business that comes down to two questions for your provider: what's the default retention period for recordings and transcripts, and can you delete something before that period ends. A provider who can't answer either is deciding for you. If whether to record at all is still the open question, what searchable call recording actually needs to work covers the consent and monitoring side.

Four questions that get you a straight answer

The recording question has two halves: is a UK business allowed to make the recording, and where does it go once it exists. This post is the second half, and four questions get you most of the way:

  • Is voice, transcription and summarisation done on your own infrastructure, or handed to a third-party AI vendor? This is the fork in the road. A provider who owns the stack can tell you exactly where processing happens. A provider reselling someone else's AI layer often can't, because they don't fully know either.
  • If data leaves the UK, what's the legal basis? Adequacy decision, standard contractual clauses, something else. A straight answer is a good sign. A shrug isn't.
  • What's the default retention period, and can we shorten it? Ask for a number.
  • Who inside your company can actually open a transcript? A support engineer chasing a bug is a very different answer to "nobody outside an automated pipeline".
Where the conversations actually live.

Where that leaves you

Your conversations should stay as private and as yours as they've always been, and you should be able to point at where they went. It's the same instinct as running your calls somewhere that works anywhere without becoming a black box.

This is general guidance, not legal advice: talk to a solicitor or your data protection lead for anything that needs a definitive answer. And if you'd rather have a provider who can tell you where your conversations live without going to check, the Olatti waitlist is open.

Somebody asks where your last customer call is sitting right now. The answer should be yours to give.