Onsoft

Solutions

References

Resources

Company

Contact

MiFID II Call Recording: Requirements, Deadlines, and Audit-Proof Implementation

What MiFID II requires for telephone recording: scope of application, 5-year retention, audit-proof storage, and implementation in contact centers.

Why MiFID II mandates call recording

Under the EU Markets in Financial Instruments Directive MiFID II (implemented in Germany in §§ 63 et seq. WpHG), financial service providers are subject to a clear obligation: telephone calls and electronic communications relating to transactions in financial instruments must be recorded and archived. The objective is investor and market protection — providing traceable evidence of orders, advice, and conditions.

For contact centers and specialized departments, this means that recording is not a nice-to-have, but a documented, audit-proof obligation with clear deadlines.

Who is affected?

The recording obligation under Art. 16 para. 7 MiFID II applies to investment firms — in particular banks and savings banks with investment businesses, investment advisors and asset managers, brokers and institutions that receive, transmit, or execute client orders, as well as departments involved in proprietary trading. The decisive factor is the transaction-related nature of the conversation, not the department.

What exactly needs to be recorded?

All telephone calls and electronic communications intended to lead to the receipt, transmission, or execution of client orders, or relating to proprietary trading, must be recorded — even if no transaction is concluded. This explicitly includes mobile communications and relevant electronic messages. Purely private or non-transaction-related conversations are not covered.

Retention period: 5 years up to 7 years

The recordings must generally be kept for five years. The competent supervisory authority (in Germany, BaFin) can extend this period to up to seven years in individual cases. Customers must be provided with a copy upon request.

Requirements for the recording

The regulator demands quality and integrity. In practice, this means:

  • Completeness and accuracy: gapless recording of relevant conversations and channels.

  • Audit-proof archiving: storage on a durable medium, protected against modification and deletion (tamper protection, audit trail).

  • Encryption and access control: protection against unauthorized access, documented permissions.

  • Retrieveability: fast, targeted recovery of individual conversations for regulatory or customer requests.

  • Organizational proof: policies ensuring that employees only communicate about transactions via recorded channels.

Aligning MiFID II and Data Protection (GDPR)

MiFID recordings contain personal data. While the obligation from MiFID II provides the legal basis for processing, GDPR principles still apply: informing the data subjects prior to recording, purpose limitation, deletion after expiration of the retention period, and access restrictions. Recording systems should automatically enforce retention periods and enable timely deletion.

Implementation in practice: a quick checklist

  1. Define channels: Which telephone, mobile, and electronic channels are transaction-relevant?

  2. Gapless recording: technical assurance that these channels are fully recorded.

  3. Audit-proof archiving: tamper-resistant, encrypted storage with an audit trail.

  4. Automate retention periods: 5 (potentially 7) years of retention, followed by automated deletion.

  5. Transparency: notification processes for customers, information for employees.

  6. Test retrieval: practice the rapid provisioning of individual recordings.

How onsoft supports MiFID-compliant recording

onsoft provides solutions for legally compliant call and screen recording in contact centers — featuring encrypted, audit-proof storage, targeted retrieval, and automated retention periods. Combined with AI voice analysis and quality management, compliance verification and service quality can be mapped in a single system. Find out more on our page about call recording.

Frequently Asked Questions (FAQ)

Does the MiFID II recording obligation also apply if no transaction takes place?

Yes. It already covers conversations and messages that are intended to lead to a transaction — regardless of whether it is concluded.

How long must the recordings be kept?

Generally five years; the competent supervisory authority can demand up to seven years in individual cases.

Are mobile phones and electronic messages also affected?

Yes, provided they are transaction-related. Such communication must only take place via recorded channels.

What does audit-proof mean?

Storage on a durable medium, protected against modification and deletion, with access control and an audit trail.

How does MiFID II align with the GDPR?

MiFID II provides the legal basis; the GDPR additionally requires transparency, purpose limitation, access protection, and timely deletion.

→ Call Center Quality Management: Fundamentals, Key Metrics & Software


Give your call center a fresh boost

Discover the potential of your data! Use our analysis and quality management tools to lead your call center to success.

Give your call center a fresh boost

Discover the potential of your data! Use our analysis and quality management tools to lead your call center to success.