MiFID II Call Recording: Requirements, Deadlines, and Audit-Proof Implementation
Was MiFID II bei der Telefonaufzeichnung verlangt: Anwendungsbereich, 5-Jahres-Aufbewahrung, revisionssichere Speicherung und die Umsetzung in Contact Centern.
Why MiFID II mandates call recording
Under the EU Markets in Financial Instruments Directive MiFID II (implemented in Germany in §§ 63 et seq. WpHG), financial service providers are subject to a clear obligation: telephone calls and electronic communications relating to transactions in financial instruments must be recorded and archived. The aim is investor and market protection — verifiable evidence of orders, advice, and conditions.
For contact centers and specialist departments, this means: recording is not a nice-to-have, but a documented, audit-proof obligation with clear deadlines.
Who is affected?
The recording obligation under Art. 16 para. 7 MiFID II applies to investment firms — in particular banks and savings banks with securities businesses, investment advisors and asset managers, brokers and institutions that accept, transmit, or execute client orders, as well as departments involved in proprietary trading. The decisive factor is the transaction-related nature of the conversation, not the department.
What exactly needs to be recorded?
All telephone conversations and electronic communications that are intended to lead to the acceptance, transmission, or execution of client orders, or that relate to proprietary trading, must be recorded — even if no transaction is completed. Mobile communications and relevant electronic messages are also explicitly covered. Purely private or non-transaction-related conversations are excluded.
Retention period: 5 years up to 7 years
The recordings must generally be kept for five years. The competent supervisory authority (in Germany, BaFin) can extend this period to up to seven years in individual cases. A copy must be provided to customers upon request.
Requirements for the recording
The supervisory authority demands quality and integrity. In practice, this means:
Completeness and accuracy: seamless recording of relevant conversations and channels.
Audit-proofing: storage on a durable medium, protected from alteration and deletion (tamper protection, audit trail).
Encryption and access control: protection against unauthorized access, documented authorizations.
Retrievability: fast, targeted retrieval of individual conversations for supervisory authorities or customer requests.
Organizational proof: policies ensuring that employees only communicate on transaction-related matters via recorded channels.
Thinking MiFID II and Data Protection (GDPR) together
MiFID recordings contain personal data. While the obligation under MiFID II provides the legal basis for processing, GDPR principles still apply: informing data subjects before recording, purpose limitation, deletion after expiry of the retention period, and access restrictions. Recording systems should automatically enforce retention periods and enable timely deletion.
Implementation in practice: a quick checklist
Define channels: Which telephone, mobile, and electronic channels are transaction-relevant?
Seamless capture: technical assurance that these channels are fully recorded.
Audit-proof storage: tamper-proof, encrypted storage with audit trail.
Automate deadlines: 5 (or 7) years of retention, followed by automated deletion.
Transparency: notification processes for customers, information for employees.
Test retrieval: practice retrieving individual recordings quickly.
How onsoft supports MiFID-compliant recording
onsoft provides solutions for legally compliant call and screen recording in contact centers — featuring encrypted, audit-proof storage, targeted retrieval, and automated retention periods. Combined with AI voice analysis and quality management, compliance proof and service quality can be mapped in a single system. Learn more about this on our page on call recording.
Frequently Asked Questions (FAQ)
Does the MiFID II recording obligation also apply if no business transaction takes place?
Yes. Conversations and messages intended to lead to a transaction are already covered — regardless of whether it is finalized.
How long must the recordings be kept?
Generally five years; the competent supervisory authority can request up to seven years in individual cases.
Are mobile phones and electronic messages also affected?
Yes, provided they are transaction-related. Such communication must only take place via recorded channels.
What does audit-proof mean?
Storage on a durable medium, protected from alteration and deletion, with access control and audit trail.
How does MiFID II align with the GDPR?
MiFID II provides the statutory basis; the GDPR additionally requires transparency, purpose limitation, access protection, and timely deletion.


