Recording and listening to customer conversations to assess service quality and coach employees is permitted in principle, but only under strict conditions. The Litigation Chamber of the Data Protection Authority (DPA) makes this clear in its decision 102/2026 of May 12, 2026 against Société Wallonne des Eaux (SWDE). It imposes two administrative fines - EUR 85,000 for transparency and loyalty failures, and EUR 1,000 for the absence of a processing agreement - and confirms that Belgian telecommunications law and the General Data Protection Regulation (GDPR) should be applied cumulatively.
The facts
SWDE is the largest Walloon drinking water company. It serves about 67% of Walloon connections, with 1.1 million customers and 2.5 million end users. For its customer service, it has a general call number that connects to a central call center, divided into a Front Office (first line, short questions) and several Back Offices (more complex or dispute-related questions).
From November 2018 (Front Office) and March 2020 (Back Offices), the SWDE started recording incoming customer calls. The goal: evaluate the quality of responses, coach staff and improve service delivery. The recordings were hosted by a subcontractor (anonymized as “Z” in the decision).
In April 2020, a Back Office Contentieux employee filed a complaint with the DPA shortly after his supervisor announced by email that recordings would also be made in that department. He denounced three issues: inadequate information about the processing of his personal data, possible transfer of “personnel records” abroad and inadequate security of the recordings. The investigation that followed went far beyond these three grievances. The inspection report identified a dozen possible violations of the GDPR and of the Electronic Communications Act (hereinafter ECA) .
The decision
The Litigation Chamber first establishes a two-track legal framework. The recording of a telephone conversation is, on the one hand, a processing of personal data under the GDPR (basis of lawfulness, transparency, proportionality, retention period, processing agreement...) and, on the other hand, touches the principle of confidentiality of electronic communications as protected in Art. 124 ECA. In principle, both regimes apply side by side. However, for aspects that the e-Privacy Directive regulates exhaustively, Art. 95 GDPR excludes additional GDPR obligations. The Court of Justice confirmed this primacy of the e-Privacy Directive in its ruling of November 13, 2025 C-654/23 Inteligo Media.
Importantly, the employer himself cannot be considered a “directly or indirectly involved person” in the telephone calls made by his employees. In this regard, the Litigation Chamber explicitly refers to Cass. May 20, 2019, S.17.0089.F: an employee's communications, even if they are purely professional and take place through the employer's equipment, remain confidential with respect to that employer. Thus, in order to record conversations of staff members, the employer must be able to invoke an exception to the prohibition of Article 124 ECA.
For the inclusion of employees, the Litigation Chamber accepts that the “exception legal consent” (art. 125, § 1, 1° ECA), read together with employer authority from arts. 2 to 5 and 16-17 of the Labor Contracts Act (Law of July 3, 1978), constitutes a sufficient basis - as long as the recordings are not systematic, are limited to the general call number and fit within reasonably exercised employer authority. The recording of external callers, on the other hand, requires a separate GDPR legal basis.
Consent as a legal basis is rejected for the employees: according to the Litigation Chamber and the guidelines 5/2020 of the EDPB, free consent is virtually impossible in an employment relationship due to the imbalance of power. For callers, on the other hand, consent can work - they can refuse without negative consequences.
The Litigation Chamber accepts that the SWDE as a public entity can rely on Art. 6.1.e GDPR (task of general interest), read together with its legal mission under the Walloon Water Code, for the calls of its Front Office and Back Offices for service quality. In contrast, the three “test recordings” in the Back Office Contentieux were unlawful: they fell outside any statutory exception from the ECA and thus lacked any basis for lawfulness.
However, the heavy fine of 85,000 EUR does not strike at legality, but at transparency and loyalty (Art. 5.1.a, 12.1 and 13 GDPR, read together with Art. 128 ECA and from January 10, 2022 Art. 10/1, § 2 of the Law of July 30, 2018 - hereinafter DPA). The information provided by the SWDE to its employees and to its callers was, according to the Litigation Chamber, incomplete, spread over too many channels, insufficiently accessible and insufficiently comprehensible. Concrete shortcomings: missing mention of retention periods, inadequate information about international transfers, a privacy notice that required contacting the commercial service first before approaching the DPO (in violation of Art. 38.4 GDPR) and a systematic requirement to present an identity card when exercising rights.
The second fine of EUR 1,000 concerns the absence of a processing agreement with the external partner Z, in violation of Art. 28.3 GDPR.
In addition to the fines, the Litigation Chamber issues reprimands for a series of other breaches (exceeding retention periods, inadequate data protection impact assessment, failure to involve the DPO in a timely manner, inadequate processing register for incidents of unintentional recordings...). Finally, it decides that the decision will be published with the name of the SWDE: the public's interest in information about a service of general economic interest with 2.5 million end users outweighs the drinking water company's reputational interest.
Legal analysis and interpretation
The two-track approach to the GDPR and telecommunications law is much more than a formality
The significance of this decision lies not in the fine itself but in the sharpness with which the Litigation Chamber maps the interplay between the GDPR and the ECA. The reasoning builds on the Inteligo Media-ruling, in which the ECJ held that the GDPR does not impose additional obligations where the e-Privacy Directive already regulates exhaustively (Art. 95 GDPR). But the Litigation Chamber draws a particularly relevant conclusion from this: not every exception from the ECA falls under that exhaustive regulation. Only the “consent exception” (Art. 124 ECA) and the “business evidence exception” (today Art. 10/1, § 1 DPA, formerly Art. 128, § 1 ECA until January 10, 2022) are direct transpositions of the e-Privacy Directive and thus provide an autonomous basis for legitimacy.
The other exceptions in the ECA - including the “good network functioning exception” and, remarkably, also the “Call Center exception” (today Art. 10/1, § 2 DPA) - are not, according to the Litigation Chamber. They merely make the recording not criminally prohibited, but do not in themselves provide a GDPR legal basis. The controller must therefore always surface a basis from Art. 6.1 GDPR on top of it. This is an important refinement: those who rely in practice on the call center exception alone remain vulnerable to a legality allegation.
EUR 85,000 fine shows how expensive sloppy privacy notices are
The vast majority of the fine was not assigned to legality, but to transparency and loyalty. This is consistent with previous decisions in which the Litigation Chamber treats transparency as a separate and separately finable basis. For example, in its decision 99/2026 of May 8, 2026 , it imposed a fine of 2,520 EUR solely for violations of Art. 5.1.a, 12 and 13 GDPR, in addition to a separate fine of 2,400 EUR for violation of the right of access.
What makes this decision extra instructive is the concatenation of classic errors that recur in virtually every privacy statement: multiple layers of information that do not converge in one place, missing or incomplete retention periods, vague formulations about international transfer, and - above all - procedural barriers to exercising rights (mandatory intermediary step via a commercial service, automatic identity card request). The latter practices - automatic identity card demand and filtered DPO access - already clashed directly with the text of the GDPR itself: art. 12.6 GDPR only allows to ask for an additional proof of identity when there is “reasonable doubt” about the identity of the requester, and art. 38.4 GDPR guarantees that data subjects can directly contact the DPO on all matters concerning their rights.
Consent as legal basis in employer-employee context: the door remains closed
The Litigation Chamber reiterates - with support in EDPB Guidance 5/2020 - that consent in an employment relationship is not a valid legal basis because of the power imbalance. It is not a new position, but it confirms that employers who base their data processing of staff members on “employee consent” (at the time of hiring, in the labor regulations or via clickable forms) are building on quicksand. The correct legal basis lies elsewhere: usually Art. 6.1.b (performance of the contract), Art. 6.1.c (legal obligation), Art. 6.1.e (public interest) or Art. 6.1.f GDPR (legitimate interest) - in each case together with a legal or conventional basis in labor law.
Specifically, what does this mean?
For companies with a call center or customer service. The decision makes clear that recording customer calls for quality control purposes is an intervention that must be justified on two fronts. A Belgian company must (i) be able to invoke an exception in the ECA/DPA and (ii) identify a separate GDPR legal basis - both for the employee and for the external caller. Those who rely solely on Article 10/1, § 2 DPA (“Call Center Exception”) as a legal ground are not adequately insured, according to the Litigation Chamber. Practical: for each call recording, document two things - the telecommunications exception that circumvents the ban, and the GDPR legal basis. Moreover, limit the recordings: not systematically, not on direct lines, not on conversations between colleagues.
For information. The duty to inform is not fulfilled by a general privacy statement on a website. The information must be complete (retention period, recipients, legal basis, international transfer, rights), gathered in one accessible place, drafted in clear language, and proactively communicated whenever changes are made. Those who provide the first level of information to the caller via a recorded tape (“this call is being recorded”) should supplement that message with a clear reference to the full privacy notice and with an immediate reference to the purpose, retention period and right to object. Nor are employment regulations or an ICT policy sufficient as any employee support: evidence of effective, individual notice must be retained.
For the relationship with subcontractors. A fine of only EUR 1,000 for the lack of a processing agreement seems mild, but the symbolic value is great. For those who have voice recordings stored, have quality coding done, or hire AI transcription services: a Section 28.3 GDPR-compliant contract is not an administrative formality. In any new supplier relationship, verify the presence and content of a DPA, with attention to instructions, security obligations, sub-processing and international transfer.
For public entities in particular. The Litigation Chamber accepts without much resistance that a public undertaking like the SWDE relies on Art. 6.1.e GDPR (public interest task) for quality recordings. This is interesting for any entity with a statutory mission of general interest - public administrations, intermunicipal companies, public institutions - but it does not open a free pass: the necessity and proportionality tests still apply, and the publication of the decision with identity shows that a public mission does not protect against image damage.
Frequently asked questions (FAQ)
May my employer record my phone calls at work for quality control purposes?
In a call center context, this is possible, subject to strict conditions. The employer must clearly and fully inform you in advance (possibility and purpose of the recording, retention period, your rights), the recordings must be limited in number and scope, and they must not take place on your direct internal line or on conversations between colleagues. Your consent is not a valid basis - the power differential in the employment relationship precludes free consent.
Does the statement “this call may be recorded for quality purposes” suffice when I call a company?
No. At most, that message is a first layer of information. The law requires that in an easily accessible place you also receive information about the legal basis, the retention period, the possible transfer to third parties, your rights and your option to object. One isolated communication on a tape does not comply with Art. 13 GDPR and Art. 10/1, § 2 DPA.
Does a company need a processing agreement with a vendor that stores or analyzes calls?
Yes. Any external party processing personal data on behalf of the controller is a processor within the meaning of Art. 28 GDPR. The relationship must be established in writing in a processor agreement with the content required by Art. 28.3 GDPR. The lack thereof is in itself a separate breach and can be fined, even if the fine amount in this case remained symbolic.
Conclusion
This decision is more than a finger pointing to a Walloon drinking water company. It confirms that the recording of telephone conversations in a Belgian call center requires a two-track legality story: setting aside the confidentiality prohibition from telecommunications law as well as identifying an GDPR legal ground. She makes visible how costly an incomplete or clumsily organized privacy notice can become, even when the processing is substantively defensible. And she reminds companies that a processor agreement with external partners is not an administrative formality.



