Knowledge Hub · Voice

Which regulations does FirstNet's call recording platform support, including PCI-DSS and GDPR?

Compliant Call Recording & Analytics · Answered by FirstNet Technology Services

Short answer

FirstNet Compliance Recording supports compliance programmes for POPIA, FAIS, FICA, PCI-DSS, MiFID II, Dodd-Frank, HIPAA, GDPR and CCPA. Final compliance still depends on your own policies, settings and duties.

In detail

What each set of rules typically covers:

  • POPIA, FAIS and FICA: South African rules on data protection, financial advice and financial intelligence.
  • PCI-DSS: teams that handle cards, wherever cardholder data passes over recorded phone lines.
  • MiFID II and Dodd-Frank: duties to record lines and keep records in financial markets.
  • HIPAA and similar laws: keeping health information safe.
  • GDPR and CCPA: data protection for firms that operate in the EU or California.

The controls start with tamper-proof storage, with AES-256 rotating encryption at rest and in transit. They also include MFA, fine-grained permissions, retention you can set, legal hold, defensible deletion, compliant call sharing and audit logs. The Conversation Analytics tier adds automatic redaction. It removes card data, personal information and health data from audio and transcripts.

If you must meet rules in more than one jurisdiction, you can manage them all from one archive. You can set retention per call type or business unit. FirstNet confirms your retention policy and the terms for processing your data in writing before any recording starts.

Source: FirstNet Compliant Call Recording & Analytics service page →

Didn’t answer your question?

Call