There is no single GDPR retention period for call logs or recordings in France. Retention must be purpose-based and documented in the register of processing, following CNIL guidance and, for healthcare calls, the PDSA arrêté or Samu-Urgences France recommendations, which often push retention well beyond standard call center norms.
TL;DR:
- Call logs should be retained for six months to one year, with extensions justified by specific internal control needs or security requirements.
- Medical regulation recordings must be kept for at least five years, with longer retention up to twenty years when they serve as part of the patient’s medical record.
- Retention of call recordings related to clinical decisions or emergencies extends until the legal or medical dispute is resolved, often surpassing standard call center norms.
- Data automation, role-based access, encryption, and strict documentation of retention policies are essential to enforce GDPR compliance effectively.
- Outsourcing call handling to specialized healthcare call services can help practices maintain lawful retention and deletion practices without internal system management.
Table of Contents
- What Counts as a Call Log Versus a Call Recording Under GDPR?
- How Long Must Medical Practices Keep Call Recordings in France?
- What Does CNIL Recommend for Call Log Retention Periods?
- How Do You Build a Defensible Call Log Retention Policy?
- What Technical Controls Actually Enforce Retention Rules?
- Sample Retention Matrix for Call Data in France
- How a Medical Answering Service Handles Retention in Practice
- Compliant Call Handling Without Building the System Yourself
- Sources
- FAQ
What Counts as a Call Log Versus a Call Recording Under GDPR?
GDPR treats call metadata and call audio as two distinct categories of personal data, and confusing them is the single most common compliance mistake among practices outsourcing telephone reception. A call log is metadata: caller number, timestamp, duration, call outcome, and routing information. A call recording is content: the actual audio, or a transcript derived from it. The distinction matters because content carries far more sensitive information, including details that qualify as health data under Article 9 in a medical context.
Each type justifies a different retention logic tied to its purpose:
- Security and technical logs (call routing, connection metadata) typically support fraud detection or system troubleshooting and warrant short retention.
- Recordings for quality assurance or staff training serve an internal, time-limited purpose and rarely justify retention beyond several months.
- Recordings kept as contract proof (confirming a booking, a cancellation, or informed consent) can justify longer retention tied to civil prescription periods.
- Recordings tied to a medical consultation or triage decision may need to be preserved far longer, sometimes as part of the patient’s medical file itself.
Operationally, this classification determines how data gets stored and indexed. Metadata can sit in a searchable database with automated purge rules. Recordings require access controls, encryption, and a documented justification the moment they exceed a few months, because a regulator reviewing a complaint will ask exactly why a given recording still exists.
How Long Must Medical Practices Keep Call Recordings in France?
Healthcare call handling in France operates under stricter rules than general customer service, and the starting point is a specific legal text: the Arrêté of 20 October 2011 on recordings of régulation médicale within the Permanence des Soins Ambulatoires (PDSA). That text sets a five year floor for these recordings.
Statistic Callout: The PDSA arrêté sets a minimum five year retention period that is suspended if any recourse or litigation is introduced, so retention is extended until the matter concludes.
Professional bodies go further than the legal floor. Guidance associated with Samu-Urgences France recommends retaining medical regulation recordings for at least ten years, and some institutions extend that to twenty years when a recording becomes evidence within the patient’s medical file, aligning it with medical record retention rather than ordinary call data.
That last point is the one DPOs miss most often: once a recording documents a clinical decision, triage advice, or an emergency dispatch, it stops being “just a phone call” and becomes part of the medical record. Practical triage looks like this:
- Keep recordings tied to a clinical decision, dispatch, or refusal of care as part of the medical file.
- Keep recordings under active dispute or complaint until the matter is legally closed.
- Delete routine appointment confirmations and rescheduling calls once the operational purpose (the CNIL’s short baseline windows) has passed.
What Does CNIL Recommend for Call Log Retention Periods?
For journalisation, the logging of technical events like call connections, access attempts, and system actions, the CNIL recommends a baseline of six months to one year. That range covers most security and audit-trail purposes for call systems.

Extending retention beyond baseline periods may be permissible with documented justification for specific internal-control needs. Following the CNIL’s recommended ranges carries a real practical benefit: it creates a presumption of compliance, shifting the burden of proof away from the practice if a regulator ever asks why data was kept.
A workable approach for most practices:
- Set journalisation logs to auto-purge at six months unless a specific control need is documented.
- Reserve the one to three year extension for cases like recurring fraud investigation or contractual dispute patterns.
- Review the chosen window annually and log that review, since an undocumented policy ages into a liability even when the original decision was sound.
How Do You Build a Defensible Call Log Retention Policy?
Documentation is what separates a defensible retention choice from a guess, and CNIL’s own guidance on defining retention periods lays out the discipline DPOs need to apply.
- Map every purpose a call log or recording serves: security, billing proof, quality control, contract evidence, or medical documentation.
- Identify the legal trigger for each purpose, whether that is a civil prescription period, the PDSA arrêté’s five year floor, or a sector-specific obligation.
- Choose a start and stop event for the retention clock. Common triggers include call end, contract termination, or last patient contact, and each needs a clear technical marker in the telephony system.
- Decide archive versus delete. Data that must be preserved for legal reasons moves to a restricted archive; everything else gets a hard deletion date.
- Record the decision in the Article 30 register: legal basis, retention period, justification, and the date of the next review.
- Test the deletion automation. A policy on paper that the phone system does not actually enforce is not a policy, it is a liability waiting for an audit.
Pro Tip: Tie retention triggers to events your telephony or scheduling platform already logs automatically, such as appointment closure in Doctolib or a call ending in your VoIP system, rather than relying on staff to manually flag records for deletion.
What Technical Controls Actually Enforce Retention Rules?
A documented policy only holds up if the underlying systems enforce it automatically. CNIL guidance on data lifecycle management points to a consistent set of controls that make retention rules real rather than aspirational.
- Lifecycle automation: telephony and VoIP platforms should apply automatic deletion rules matched to each data category, with backup retention aligned to the same schedule so a backup does not quietly outlive the primary record.
- Access restriction: recordings and logs need role-based access, with archived data held under the same security conditions as active data, never looser ones.
- Encryption: at rest and in transit, non-negotiable for any recording that could contain health information.
- Access logging: every access to a recording should itself be logged, since that audit trail is often what proves compliance during a CNIL inquiry.
Pro Tip: When litigation triggers a legal hold, scope it narrowly to the specific caller, date range, or incident, and document the hold’s legal basis and expected expiry. An unscoped hold quietly becomes indefinite retention, which is exactly what Article 30 documentation is meant to prevent.
Sample Retention Matrix for Call Data in France
The ranges mentioned are illustrative and based on CNIL guidance plus sector practice summaries. Every practice must adapt them to its own processing activities and document the reasoning in its register.
| Purpose | Indicative retention range | Governing source or reference | Adaptation note |
|---|---|---|---|
| Security and technical logs (journalisation) | 6 months to 1 year, up to 3 years for internal control | CNIL journalisation recommendation | Extend only with documented internal-control justification |
| Quality assurance / staff training recordings | typically retained for a limited period of several months, often less than a year | Industry practice aligned with CNIL referentials | Delete once the training or QA cycle closes |
| Contract proof (booking confirmation, cancellation) | retention periods aligned with applicable civil prescription periods, generally lasting several years | General CNIL retention principles | Confirm exact duration against the specific contractual obligation |
| Medical regulation (PDSA) recordings | 5 years minimum, suspended by litigation | Arrêté of 20 October 2011 | Floor only, not a ceiling |
| Recordings integrated into the medical file | 10 to 20 years per professional guidance | Samu-Urgences France / DAJDP guidance | Treat as part of medical record retention, not ordinary call data |
How a Medical Answering Service Handles Retention in Practice
Retention discipline only works when it is built into daily operations, not bolted on afterward. That means mapping every call flow through Doctolib, LibreRDV, or Maiia to a specific retention trigger the moment an appointment closes or a patient contact ends, rather than leaving deletion to manual review. Coordinating emergency triage calls alongside routine scheduling calls, each under different retention logic, is where most in-house teams lose consistency. Practices weighing whether to manage this internally or through a specialized partner should look closely at how call classification and automated lifecycle rules get enforced day to day.
— Rudolph
Compliant Call Handling Without Building the System Yourself
The practical alternative to managing retention rules, deletion triggers, and access logs in-house across a growing volume of calls is to use a specialized medical secretariat service that handles call reception, appointment coordination, and emergency triage with retention practices built around the CNIL-anchored logic covered in this article.

For practices organizing phone duty across a team or a group practice, the guide to organizing phone duty for healthcare teams walks through how call handling and appointment integrations fit together operationally. Practices further along, looking to tighten appointment workflows specifically, can also review the specialty medical appointment management guide. The next step is straightforward: request a quote from a medical answering service to see how call handling and retention controls would map onto your specific practice.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- La CNIL publie une recommandation relative aux mesures de journalisation | CNIL
- DAJDP fiche: règles de communication et de conservation des bandes d’enregistrement d’un SAMU/SMUR
FAQ
What does GDPR say about data retention?
GDPR requires that personal data be kept no longer than necessary for the purpose it was collected for, a principle called storage limitation. There is no universal number of months or years; the controller must define and document a retention period per purpose, ideally using a CNIL referential where one exists.
What is the 7 year retention policy?
There is no single GDPR-mandated retention rule for call logs or recordings. Retention periods vary by purpose and sector: CNIL recommends 6 months to 1 year for journalisation, while PDSA medical regulation recordings carry a 5 year legal floor under the Arrêté of 20 October 2011, and some professional guidance recommends 10 to 20 years when recordings join the medical file.
Am I entitled to a copy of a recorded telephone call?
Individuals generally have a right to access their own personal data, including recordings, under GDPR’s access right. For recordings held by public health services, communication may involve redaction to protect other individuals or professional secrecy, as reflected in CADA opinions on this type of request.
What is the General Data Protection Regulation (GDPR) in France?
GDPR is the European Union regulation setting rules for how personal data is collected, stored, and processed, enforced in France by the CNIL. French practices handling patient calls must apply GDPR’s core principles, including purpose limitation and storage limitation, alongside sector-specific rules like the PDSA arrêté for medical regulation recordings.
How can a practice keep call retention compliant without managing it internally?
Working with a specialist medical answering service like Clicfone shifts the operational burden of classification, deletion triggers, and access control onto a partner already built around healthcare call handling. This is particularly useful for practices lacking a dedicated IT resource to configure automated lifecycle policies across telephony and scheduling platforms.