OPC Updates Canada Call Recording Guidance on Voiceprint Consent
Independently fact-checked against primary sources (last audited October 9, 2026). · 8 primary sources cited on this page. How we verify our legal content

OPC Updates Canada Call Recording Guidance on Voiceprint Consent
The Office of the Privacy Commissioner of Canada revised its guidance on recording customer telephone calls on October 8, 2026. Its release says the key updates relate to the collection of voiceprints from customers and the circumstances under which meaningful consent may be required under Canada's federal private-sector privacy law.
Information last verified on October 9, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This covers the obligations of organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law, when they record customer telephone calls, as the Office of the Privacy Commissioner of Canada interprets those obligations. It does not address the Criminal Code interception offence, which neither the OPC release nor the guidance discusses. Unless the personal information crosses provincial or national borders, it does not govern organizations operating entirely within Alberta, British Columbia or Quebec, which have their own private-sector statutes; federally regulated businesses operating in Canada are always subject to PIPEDA. For the wider federal and provincial picture, see our overview of recording laws across Canada.
What Happened
On October 8, 2026, from Gatineau, Quebec, the Office of the Privacy Commissioner of Canada (OPC) issued a news release titled "OPC updates guidance on safe handling of voice data when recording customer calls." The release states that the OPC has updated its guidance for organizations that record customer calls "to ensure alignment with best practices on the handling of biometric data and to clarify other considerations for businesses."
The release identifies the substance of the revision in a single sentence:
"Key updates relate to the collection of voiceprints from customers which are uniquely identifying voice characteristics that are considered sensitive biometric information, and the circumstances under which meaningful consent may be required."
The guidance itself sits on the OPC site under the title "Recording of Customer Telephone Calls" and carries a date modified of 2026-10-08, matching the release. Nothing in either document creates a new statute or regulation. The OPC is interpreting duties that already exist under PIPEDA, and the guidance frames itself that way: it outlines "what individuals can expect and how businesses subject to PIPEDA can comply," and says that "for those not subject to PIPEDA, the guidelines below are best practices."
The release restates two scope points. It says organizations subject to PIPEDA "must comply with the Act when recording calls, regardless of whether the customer or the organization initiated the call," and that Canadian businesses contracting out to call centres, telemarketers and similar services "must also ensure that third parties follow the rules." The guidance page states the first point in the present tense, saying businesses subject to PIPEDA must comply with the Act when recording calls "whether the customer or the organization initiates the call."
What the Revised Guidance Requires
The guidance opens by noting that organizations record customer calls for reasons including quality of customer service, dispute resolution, fraud prevention and staff training, and that those recordings involve the collection of personal information.
The guidance then explains that a recording captures more than the words spoken. It lists voice characteristics "such as tone or presence of a vocal disability," speech characteristics "such as an accent or presence of a speech disability," and "incidental personal information offered by the caller not relevant to the call."
On voiceprints specifically, the guidance states:
"Some businesses use recordings of customers' voices as a means of verifying their identity during future calls. When used for this purpose, voice recordings usually involve the collection of uniquely identifying voice characteristics (called 'voiceprints') from customers, which are a form of sensitive biometric information."
The guidelines that follow set out the obligations an organization needs to work through.
Appropriate purpose. The organization can only record a call for purposes a reasonable person would consider appropriate under the circumstances, the standard PIPEDA sets in section 5(3).
A narrow, specific purpose statement. The purpose should be stated as clearly and narrowly as possible, and should inform the customer of all purposes for which the recording may be used. The guidance also addresses purpose statements that do not match the use:
"An organization should not state that it is recording the conversation for security or quality assurance purposes if the recording will be used for marketing, customer profiling, or authentication."
Form of consent. On the form consent must take, the guidance states:
"In most cases, if the customer proceeds with the call knowing that the conversation is being recorded and why, their consent is implied. However, if the recording involves biometric voiceprints or other sensitive personal information, express consent may be required."
The qualifier is "may be required," not "is required." The guidance cross-references the OPC's "Guidelines for obtaining meaningful consent" and its "Guidance for processing biometrics" for how to make that determination.
More than one consent channel. The guidance says organizations should consider obtaining consent in multiple ways to help ensure it is meaningful, giving three examples: verbally, by the customer pressing a number on the keypad in the case of automated messages, and through clear messages on monthly statements.
Choice and alternatives. On choice, the guidance states:
"Customers must be given a choice about whether their voice is recorded during the call. If the recording is not integral to the product or service being provided, then the organization must provide customers with alternatives, unless an exception to consent applies under PIPEDA."
The guidance footnotes section 7(1) of PIPEDA for those exceptions, and says alternatives to voice recording could include continuing the call without recording, visiting a retail outlet, writing an email or letter, and completing the transaction online.
Access, retention and use. Customers have a right to request access to the recording at a later date. How long an organization may keep a recording varies with the purpose of collection, whether the recording was used to make a decision about the individual, and any legal retention requirement. An organization may only use the information for the purposes specified, and the guidance reminds organizations that the rest of their PIPEDA obligations, including safeguards and limiting retention, apply to recordings as well.
What the Law Actually Says
PIPEDA applies, under section 4(1), to every organization in respect of personal information it collects, uses or discloses in the course of commercial activities, and to employee personal information at a federal work, undertaking or business.
Consent sits in Schedule 1, Principle 4.3, which provides that "the knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate." Section 6.1 of the Act then defines when that consent counts:
"For the purposes of clause 4.3 of Schedule 1, the consent of an individual is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting."
The express-consent point is anchored in Schedule 1 of the Act, though the wording there is carefully graded. Principle 4.3.4 provides that in determining the form of consent to use, organizations "shall take into account the sensitivity of the information." Principle 4.3.6 then adds: "An organization should generally seek express consent when the information is likely to be considered sensitive. Implied consent would generally be appropriate when the information is less sensitive." Section 5(2) of the Act provides that the word "should," when used in Schedule 1, "indicates a recommendation and does not impose an obligation," so 4.3.6 is framed as a recommendation while the duty to weigh sensitivity in 4.3.4 is mandatory. That grading is one plain reason the guidance says express consent "may be required" rather than is required.
The OPC's "Guidelines for obtaining meaningful consent" set out three circumstances in which organizations must generally obtain express consent: where the information is sensitive, where the collection, use or disclosure falls outside the reasonable expectations of the individual, and where it creates a meaningful residual risk of significant harm. The OPC's "Guidance for processing biometrics" supplies the classification step for voice data, stating that "biometric information that can uniquely identify an individual is sensitive information, regardless of the context in which it is collected, used, or disclosed." The call-recording guidance cross-references both of those documents on the question of what form consent must take.
The biometrics guidance also anticipates the exact disclosure most callers hear. It says that where an organization is collecting voiceprints from callers to its customer support line, "a generic statement like 'this call may be recorded for identification purposes' would generally not be sufficient to obtain valid consent," because it does not identify the type of biometric information collected, the purpose, the parties it is disclosed to, or any meaningful residual risk of significant harm.
The Criminal Code layer is separate
Two different Canadian rules bear on a recorded telephone conversation, and the OPC release and guidance address only one of them.
Section 184(1) of the Criminal Code, RSC 1985, c C-46, makes it an offence for a person who, by means of any electro-magnetic, acoustic, mechanical or other device, knowingly intercepts a private communication. The offence carries up to five years on indictment, or a summary conviction penalty. Section 184(2)(a) then carves out "a person who has the consent to intercept, express or implied, of the originator of the private communication or of the person intended by the originator thereof to receive it." That is the one-party consent rule: on the face of the provision, the consent of the originator or of the intended recipient takes the interception outside subsection (1).
The Justice Laws Website text of section 184, which the site states is current to 2026-09-21, records the section's amendment history as ending with 2019, c. 25, s. 64. The OPC release and the revised guidance address PIPEDA obligations and say nothing about the interception offence.
What the two layers do is stack. The Criminal Code asks whether an interception was consented to by a party. PIPEDA asks a different question: when a commercial organization collects personal information by recording a call, did it identify its purposes, obtain valid consent in the right form, limit its use, safeguard the recording and limit retention. An organization can satisfy section 184 and still fall short under PIPEDA. That distinction is the same one that governs recording in employment settings, which we cover in Recording Your Boss or a Workplace Meeting in Canada.
Where PIPEDA actually applies
The OPC's own summary of privacy laws is precise about reach. PIPEDA generally applies to private-sector organizations that are not federally regulated and conduct business in Manitoba, New Brunswick, Newfoundland and Labrador, the Northwest Territories, Nova Scotia, Nunavut, Ontario, Prince Edward Island, Saskatchewan and Yukon.
Unless the personal information crosses provincial or national borders, PIPEDA does not apply to organizations that operate entirely within Alberta, British Columbia or Quebec. Those three provinces have general private-sector laws that have been deemed substantially similar to PIPEDA, the mechanism for which is section 26(2)(b) of the Act, under which the Governor in Council may exempt an organization or class from Part 1 in respect of personal information collected, used or disclosed within that province. Provincial rules therefore carry the load for a purely local business, a point that runs through our coverage of Quebec's recording rules, how recording is treated in British Columbia and the position in Alberta.
Two carve-outs cut the other way. All businesses that operate in Canada and handle personal information crossing provincial or national borders are subject to PIPEDA regardless of where they are based. And federally regulated businesses operating in Canada are always subject to PIPEDA, which the OPC's summary illustrates with banks, airlines and telecommunications companies.
An Earlier OPC Finding on a Voiceprint Program
The OPC has previously assessed a call-centre voiceprint program against PIPEDA's consent requirements. In PIPEDA Report of Findings #2022-003, dated March 30, 2022, the OPC investigated a complaint about Rogers Communications Inc.'s Voice ID program, which built algorithmic voiceprints by passively listening to callers in the background, a process Rogers called "tuning," before assigning a print to an account in a step it called "enrolment."
On purpose, the OPC sided with the company. It determined that Rogers was collecting and using personal information for a purpose a reasonable person would consider appropriate, describing Voice ID as an effective solution to a legitimate need for account authentication and security given the high-threat environment facing telecommunications service providers, and found that aspect of the complaint not well-founded.
On consent it did not. The OPC determined that Rogers failed to obtain valid and meaningful consent, reasoning that:
"express consent was required in advance of tuning, as well as enrolment, since: (i) voiceprints represent sensitive biometric information; and (ii) an individual would not, when calling Rogers, reasonably expect their voice to be captured and used to create a biometric representation of their voice."
The OPC also determined that Rogers did not provide a clearly explained and easily accessible option to opt out, the process having been mentioned only in a frequently-asked-questions document on the company's website, and that because the voiceprints retained after opt-out had never actually been used for security or any other purpose, Rogers should have deleted them at that point. Rogers agreed by September 30, 2022 to obtain express consent before tuning, to inform customers more clearly of the ability to opt out and delete voiceprints on opt-out, to delete the voiceprints of people who had previously opted out, to change its process documents, training and monitoring, and to reconfirm consent for previously enrolled individuals as they called in. On those commitments the OPC found the consent and retention aspects of the complaint well-founded and conditionally resolved.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The authorities behind the express-consent point all pre-date October 8, 2026. The reference point for express consent over sensitive information is Principle 4.3.6 of PIPEDA's Schedule 1, which has been in the Act since it was enacted and which section 5(2) frames as a recommendation rather than an obligation. The classification of uniquely identifying biometric information as sensitive regardless of context sits in the OPC's biometrics guidance, which carries a date modified of 2025-08-11. And the OPC held in Findings #2022-003, in March 2022, that express consent was required before a telecommunications provider built voiceprints from customer calls.
We could not retrieve any earlier version of the call-recording page, so we make no claim about which of its sentences are new. What the OPC itself says it updated is in the release: the key updates relate to the collection of voiceprints and the circumstances under which meaningful consent may be required.
Two of the OPC's documents, read together, put a sharp pairing in front of a compliance officer, and both engage with the same familiar object: the short recorded announcement that names quality assurance or security as the purpose. The call-recording guidance says an organization "should not state that it is recording the conversation for security or quality assurance purposes if the recording will be used for marketing, customer profiling, or authentication." Separately, the OPC's biometrics guidance says that where an organization collects voiceprints from callers to its customer support line, a generic statement such as "this call may be recorded for identification purposes" would generally not be sufficient to obtain valid consent, because it does not identify the type of biometric information collected, the purpose, the parties it is disclosed to, or any meaningful residual risk of significant harm. Those are two documents making two different points, and in our reading an organization that runs voice authentication behind a generic recorded announcement has to answer both.
The alternatives requirement is the one we expect organizations to spend the most time on. The call-recording guidance requires that customers be given a choice about whether their voice is recorded, and that where the recording is not integral to the product or service the organization provide alternatives, unless an exception to consent applies under PIPEDA. The four alternatives it names are alternatives to recording the call: continuing the call without recording, visiting a retail outlet, writing an email or letter, and completing the transaction online. The biometrics guidance makes a separate point about biometric programs specifically, saying that where biometric technology is used for non-integral or non-essential collections, uses or disclosures, an organization "must provide individuals with other means of access or participation," must communicate those options, and must "not create obstacles that would hinder access to such alternatives."
Scope is the part of this we think is easiest to misread. PIPEDA is not a national rule for every Canadian organization: unless the personal information crosses provincial or national borders, a business operating wholly inside Alberta, British Columbia or Quebec answers to that province's private-sector statute instead. The OPC's own summary of privacy laws, though, names banks, airlines and telecommunications companies as federally regulated businesses that are always subject to PIPEDA, and the voiceprint authentication program the OPC examined in Findings #2022-003 was run by a telecommunications provider.
One detail in the guidance is easy to pass over. The personal information it says a recording can capture includes voice characteristics "such as tone or presence of a vocal disability," speech characteristics "such as an accent or presence of a speech disability," and "incidental personal information offered by the caller not relevant to the call." The guidance lists those characteristics; it does not set out separate obligations for them beyond the ones it states for recordings generally.
Finally, a guidance update adds no penalty. PIPEDA's enforcement path runs through an OPC complaint and report, then a complainant's application to the Federal Court under section 14(1), with section 16 allowing the Court, in addition to any other remedies it may give, to order an organization to correct its practices, to order it to publish a notice of corrective action, and to award damages to the complainant, including damages for humiliation.
How This Affects You
If you are a customer of a Canadian business that records calls, the guidance describes what you can expect: to be told that the call is recorded and why, in terms narrow enough to be meaningful; to be given a choice where recording is not integral to the service; and to be able to request access to a recording of your own call later. If voice authentication is involved, the guidance contemplates that you may be asked for express consent rather than having consent inferred from your staying on the line.
For organizations subject to PIPEDA, the guidance sets out what it expects: state the purpose of the recording as clearly and narrowly as possible and inform the customer of every purpose the recording may serve; do not describe a recording as being for security or quality assurance if it will be used for marketing, customer profiling or authentication; recognise that express consent may be required where the recording involves biometric voiceprints or other sensitive personal information; provide alternatives where recording is not integral to the product or service, unless an exception to consent applies under PIPEDA; and ensure that contracted call centres, telemarketers and similar services follow the rules, which the guidance makes the contracting business responsible for.
None of this is a substitute for advice on a specific program. The determinations the guidance calls for, in particular whether a given recording involves sensitive personal information and what form of consent is appropriate, are contextual, and the OPC's own consent guidelines frame them that way.
What Happens Next
The revised guidance is published and effective as the regulator's stated interpretation as of October 8, 2026. It is interpretive rather than legislative, so there is no coming-into-force date and no transition period attached to it.
For individuals, the guidance sets out a two-step path: raise a privacy concern with the business first, and, if the response is unsatisfactory, consider a formal complaint to the Office of the Privacy Commissioner of Canada. Under section 14(1) of PIPEDA, a complainant may apply to the Federal Court after receiving the Commissioner's report, and section 17(1) directs that such applications be heard without delay and in a summary way unless the Court considers it inappropriate.
We will update this article if the OPC revises the page again or publishes findings that apply it.
This is general legal information, not legal advice. It covers Canadian federal privacy law under PIPEDA and the federal Criminal Code, and reflects sources verified on October 9, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- Recording laws across Canada: federal and provincial rules
- Recording Your Boss or a Workplace Meeting in Canada
- How Ontario treats recorded conversations
Last updated: 2026-10-09. This is a developing story; details verified as of 2026-10-09.
Frequently Asked Questions
Did the OPC make it illegal to record customer calls in Canada?
No. The October 8, 2026 update is guidance, not legislation, and it does not prohibit call recording. The OPC guidance states that an organization 'can only record a call for purposes that a reasonable person would consider appropriate under the circumstances', which is the standard in section 5(3) of the Personal Information Protection and Electronic Documents Act (PIPEDA). Quality of customer service, dispute resolution, fraud prevention and staff training are the examples the guidance itself gives for why organizations record.
What is a voiceprint, and when does collecting one call for express consent?
The OPC guidance describes a voiceprint as the uniquely identifying voice characteristics collected when a business uses recordings of a customer's voice to verify identity on later calls, and it calls that a form of sensitive biometric information. On the form of consent, the guidance says that where 'the recording involves biometric voiceprints or other sensitive personal information, express consent may be required'. That tracks Schedule 1, Principle 4.3.6 of PIPEDA, under which an organization 'should generally seek express consent when the information is likely to be considered sensitive'.
Can a participant in a call in Canada still record it without telling the other person?
That question falls under a different statute, which the OPC update did not change. Section 184(1) of the Criminal Code makes it an offence to knowingly intercept a private communication by means of an electro-magnetic, acoustic, mechanical or other device, and section 184(2)(a) exempts 'a person who has the consent to intercept, express or implied, of the originator of the private communication or of the person intended by the originator thereof to receive it'. On the face of that text, the consent of the originator of the private communication, or of the person the originator intended to receive it, takes the interception outside subsection (1). PIPEDA is a separate layer that adds notice and consent duties when a commercial organization does the recording.
Does a 'this call may be recorded for quality assurance' message cover voice authentication?
The OPC guidance addresses this directly, stating that an organization 'should not state that it is recording the conversation for security or quality assurance purposes if the recording will be used for marketing, customer profiling, or authentication'. The OPC's separate 'Guidance for processing biometrics' uses the same scenario, saying that where an organization collects voiceprints from callers to its customer support line, a generic statement such as 'this call may be recorded for identification purposes' would generally not be sufficient to obtain valid consent.
Must a business offer a way to do business without being recorded?
The guidance says customers must be given a choice about whether their voice is recorded during the call, and that where the recording is not integral to the product or service being provided, the organization must provide alternatives 'unless an exception to consent applies under PIPEDA'. The guidance footnotes section 7(1) of PIPEDA for those exceptions. The alternatives it says could be used include continuing the call without recording, visiting a retail outlet, writing an email or letter, and completing the transaction online.
Does PIPEDA apply to a business that operates only in British Columbia?
Generally not, with important exceptions. The OPC's summary of privacy laws states that unless the personal information crosses provincial or national borders, PIPEDA does not apply to organizations that operate entirely within Alberta, British Columbia or Quebec, because those three provinces have general private-sector laws that have been deemed substantially similar to PIPEDA. Section 26(2)(b) of PIPEDA is the provision that allows that exemption. Federally regulated businesses operating in Canada, which the OPC lists as including banks, airlines and telecommunications companies, are always subject to PIPEDA regardless of province.
Has the OPC previously found a call recording voiceprint program in breach of PIPEDA?
Yes. In PIPEDA Report of Findings #2022-003, dated March 30, 2022, the OPC examined Rogers Communications Inc.'s Voice ID program. The OPC found the purpose itself appropriate and that part of the complaint not well-founded, but found that Rogers failed to obtain valid and meaningful consent, concluding that 'express consent was required in advance of tuning, as well as enrolment, since: (i) voiceprints represent sensitive biometric information; and (ii) an individual would not, when calling Rogers, reasonably expect their voice to be captured and used to create a biometric representation of their voice'. The consent and retention aspects were found well-founded and conditionally resolved after Rogers made commitments.
What recourse does a customer have if a business recorded their voice without proper consent?
The OPC guidance directs customers to raise the concern with the business first, and says that a customer who is not satisfied with the response may be able to file a formal privacy complaint with the Office of the Privacy Commissioner of Canada. Under section 14(1) of PIPEDA, a complainant may then apply to the Federal Court for a hearing, but only on the matters that provision lists, which include the consent clause of Schedule 1 as modified or clarified by the Act and the appropriate-purposes requirement in subsection 5(3). Section 14(2) requires the application within one year after the report or notification is sent. Section 16 allows the Court to order an organization to correct its practices, to order it to publish a notice of corrective action, and to award damages to the complainant, including damages for humiliation. This is a description of the process, not advice about any particular situation.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Office of the Privacy Commissioner of Canada, news release, 'OPC updates guidance on safe handling of voice data when recording customer calls' (October 8, 2026, Gatineau, Quebec)(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada, 'Recording of Customer Telephone Calls' (guidance, date modified 2026-10-08)(priv.gc.ca).gov
- Personal Information Protection and Electronic Documents Act, SC 2000, c 5, ss 4(1), 5(3), 6.1, 7(1), 14(1), 16, 17(1), 26(2)(b) and Schedule 1, Principles 4.3, 4.3.2, 4.3.4, 4.3.6(laws-lois.justice.gc.ca).gov
- Criminal Code, RSC 1985, c C-46, s 184 (interception of private communications; saving provision at s 184(2)(a)), as last amended by 2019, c 25, s 64(laws-lois.justice.gc.ca).gov
- Office of the Privacy Commissioner of Canada, 'Summary of privacy laws in Canada' (scope of PIPEDA; substantially similar provincial private-sector laws in Alberta, British Columbia and Quebec)(priv.gc.ca).gov
- PIPEDA Findings #2022-003, 'Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program' (Office of the Privacy Commissioner of Canada, March 30, 2022)(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada, 'Guidance for processing biometrics, for businesses' (date modified 2025-08-11)(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada, 'Guidelines for obtaining meaningful consent' (date modified 2025-08-11)(priv.gc.ca).gov