Your Voice Recordings Are Now “Sensitive Data” Under PDPA

If your business records phone calls, for training, quality checks, or dispute resolution, there’s a change you need to know about. Under Malaysia’s updated Personal Data Protection Act (PDPA), voice patterns are now classified as sensitive personal data, in the same category as fingerprints and facial recognition data.

This matters for almost every business that runs a call centre, a hotline, or an AI voice bot. That includes us, and probably you too.

What actually changed

The PDPA amendments that rolled out through 2025 expanded the definition of “sensitive personal data” to include biometric information. Voice is biometric. Your unique speech pattern, tone, and cadence can identify you just like a fingerprint can. So when a company records a call, keeps a voice sample, or uses voice to verify a customer’s identity, that recording now falls under stricter rules.

Before, most businesses treated call recordings like any other piece of customer data: store it, review it, delete it eventually. Now, sensitive personal data comes with extra requirements. Practically speaking:

  • You need clearer consent. Telling a caller “this call may be recorded for quality purposes” is standard practice, but with the new rules, businesses should be more precise about why the recording is kept and what it’s used for, especially if voice is ever used for identity verification.
  • You need tighter access controls. Fewer people should be able to pull up a raw recording. Access should be limited to those who genuinely need it, and every access should ideally be logged.
  • You need a real retention policy. Recordings can’t just sit in storage indefinitely because no one got around to deleting them. There should be a set period after which recordings are removed.
  • Breach notification rules apply harder here. If a sensitive data breach happens, say, voice recordings are exposed, the reporting obligations to the Personal Data Protection Commissioner are more serious than for a regular data leak.

Why this hits AI voice bots especially hard

AI voice bots and receptionist systems don’t just record calls. Many of them are built to recognise voices, learn from them, or use voice data to train the AI itself. That’s exactly the kind of use case the new PDPA rules are aimed at.

If your business uses an AI voice bot for customer service, appointment booking, or after-hours calls, it’s worth asking your vendor a few direct questions:

  • Where is the voice data stored, and for how long?
  • Is the recording used to train or improve the AI model, and did the customer agree to that?
  • Who can access raw voice recordings, and is that access tracked?
  • What happens to the data if the contract with the vendor ends?

If your vendor can’t answer these clearly, that’s a warning sign, not just for compliance, but for how seriously they treat your customers’ data.

What this means for your business

The good news is that none of this requires ripping up your current setup. It mostly means tightening what you likely already have in place:

  1. Update your consent language. Make sure it reflects that voice recordings may be treated as sensitive data.
  2. Review who has access to recordings. Limit it to people who actually need it for their job.
  3. Set (and follow) a retention schedule. Decide how long recordings are kept, and actually delete them after that point.
  4. Ask your call centre or AI voice bot provider how they handle this. If you outsource your calls, this becomes their responsibility too, but you’re still accountable for choosing a compliant partner.

The bigger picture

Malaysian businesses are under more pressure than ever to use AI and automation to handle calls efficiently. That’s a good thing: customers get faster answers, and businesses save time and cost. But as voice technology becomes part of everyday customer service, the data behind it needs to be treated with real care, not just filed away as routine information.

Treating voice recordings as sensitive data isn’t just about staying on the right side of the law. It’s a sign to your customers that their conversations with you are handled responsibly, whether they’re speaking to a human agent or an AI voice bot.

If you’re using outbound or inbound call services and aren’t sure whether your current setup meets these updated standards, it’s worth a quick review before it becomes a bigger issue.