The Knesset passed an amendment to the Consumer Protection Law which not only permits businesses to record their calls with consumers – in defined circumstances it requires them to record such calls, to preserve those recordings, and to hand them over to the consumer on request. For many businesses, the instinctive reaction (“great, another compliance checkbox”) badly understates the impact. Mandatory recording reaches straight into your privacy policy, your marketing and sales scripts, your data-retention practices, and – perhaps most surprisingly – your litigation strategy.
What the Law Actually Requires
On their face, the core obligations are straightforward. A business (“osek”) must record telephone calls it conducts with a consumer for the types of transactions listed in the newly added Ninth Addendum, in such cases when the total transaction price is at least NIS 750. Importantly, the NIS 750 test is not limited to one-off deals: for long-term transactions – whether for a fixed term or an indefinite term – the threshold is assessed by reference to the aggregate value of the transaction, so recurring or open-ended engagements can readily cross the line even where each individual payment looks modest. During such a call the business must announce, at the outset, that the call is being recorded and that the consumer is entitled to receive the recording. On the consumer’s request, the business must provide both the recorded call itself and a log of the call dates/times.
Retention is time-boxed: the recording must be kept for two years from the date of the call if the transaction was completed, or for six months if the transaction was not completed. The teeth are in the enforcement mechanism – more on that below.
Why This Is Not Just an IT Ticket – Four Places It Bites
- Your Privacy Policy and Notices Need to Catch Up – You are now collecting, on purpose, a rich stream of personal data – voice recordings, which frequently sweep in sensitive details, payment information and off-script disclosures. That means your privacy notice and any call-opening script must clearly disclose the recording, its purpose, the retention periods, the legal basis, and the consumer’s rights (including the right to receive the recording). A policy that still says “we may record calls for quality assurance” no longer reflects reality and can itself become a liability if practice and policy diverge. A subtle trap deserves special attention: the new law compels the recording but does not itself define the permissible “purpose” for which those recordings may be used. That gap does not give you a free hand – Israel’s Protection of Privacy Law continues to apply in full, including its purpose-limitation principle, which restricts you to using the recording only for the specific, legitimate purpose disclosed at the time of collection. In practice this may mean the recording cannot simply be repurposed (for marketing, profiling, training or unrelated uses) just because you were obliged to make it. The purpose you articulate in your notice therefore has to be defined narrowly and carefully.
- Your Marketing and Sales Practices Are Now Evidence – Every recorded sales call is a permanent, disclosable record of exactly what your representatives promised. Aggressive scripts, “soft” representations, verbal add-ons and pressure tactics are all captured and can be requested by the consumer. This is a strong incentive to tighten scripts, train teams, and ensure marketing claims made by voice match your written terms. Handled well, the recording is also an opportunity: clean, compliant recordings can protect you as much as expose you.
- Your Data-Retention Policy Must Be Rebuilt Around Fixed Clocks – The law imposes specific retention periods (two years / six months) keyed to whether a transaction closed. That requires you to tag each recording to a transaction outcome, run automated retention and deletion, and reconcile these periods against other obligations that may pull in different directions. Over-retention and under-retention both create exposure, so retention can no longer be a loose “keep everything” or “delete when we remember” arrangement.
- Your Litigation Strategy and Defense Posture Change Overnight – This is the sharpest edge. Under the amendment, if a business fails to provide the recording or the call log to a consumer who requested it, then in civil proceedings the business will be treated as having admitted the consumer’s version regarding the content or the very existence of the call. Worse, the business will be barred from submitting the recording, the transcript, or the call log as evidence in that civil proceeding, except with the court’s approval. In other words: lose the recording (or fail to produce it) and you may lose the factual narrative before the case even begins. Recording discipline is now a core component of defensibility.
The GDPR Trap – “Where Is Your Customer Sitting?”
Here is the twist that catches multinational and online businesses off guard. Israeli law is about to require recording in defined cases. The EU’s General Data Protection Regulation (GDPR), by contrast, treats voice recording as processing of personal data that must have a lawful basis and comply with the principles of data minimization, purpose limitation, storage limitation, and transparency – and it generally treats recording as intrusive, to be done only where genuinely justified and proportionate. The two regimes can therefore point in opposite directions: one nudging you to record, the other constraining when and how you may.
It is worth clarifying that this “legal obligation” basis is Israel-specific and cannot be relied upon to justify recording calls with individuals located elsewhere, such as in the EU. On a conservative reading, the GDPR recognizes a “legal obligation” basis only where it arises under Union or Member State law, but not the law of a third country.
The practical consequence is that you cannot apply a single, one-size-fits-all recording rule. You need to know where the individual on the other end of the line is located, because that may determine which regime applies. A consumer physically in Israel may fall squarely within the Israeli mandatory-recording regime; a data subject in the EU/EEA may bring you within GDPR, where recording is more restricted and subject to additional conditions, disclosures and safeguards. Many businesses will find themselves operating under two parallel regimes – one comparatively permissive (indeed compulsory), one more limited – and will need to segment their call flows, notices and retention accordingly, rather than assume that complying with one automatically satisfies the other.
Action Points
We recommend that businesses (a) map which of their transactions fall both within the Ninth Addendum and also within the NIS 750 threshold; (b) update call-opening scripts, privacy notices and marketing materials to reflect the recording, purpose and consumer rights; (c) implement outcome-based retention and automated deletion for the two-year / six-month clocks; (d) build a reliable, auditable process for retrieving and delivering recordings and call logs on request – since failure to do so can forfeit both your evidence and your factual case; and (e) introduce location-based segmentation so that EU/EEA-facing calls are handled under a GDPR-appropriate framework, rather than the Israeli one.
Getting this right is as much an opportunity as an obligation – done properly, mandatory recording can strengthen your compliance story, sharpen your sales practices, and hand you a powerful defensive tool. Done carelessly, it can quietly gift your factual case to the other side. If you would like us to assess how the amendment applies to your business, review your scripts, notices, and retention policy, or design a workable Israel/GDPR framework, we would be delighted to help – do not hesitate to contact us.
