Key takeaways
- On October 8, 2026, the OPC updated its guidance for organizations that record customer calls. Voiceprints, uniquely identifying voice characteristics collected from customers, are now explicitly treated as sensitive biometric information, with clarified rules on when meaningful consent is required.
- The generic “this call may be recorded” notice does not cover biometric collection. The OPC’s position, built on its biometrics guidance and the Rogers Voice ID findings, is that callers must be told separately and explicitly that biometric information will be collected, used, or disclosed.
- PIPEDA applies to recorded calls regardless of who initiated them, and if you outsource to call centres or telemarketers, you are on the hook for making sure those third parties follow the same rules.
What the OPC actually said on October 8
The news release is short, which is usually when you should read carefully. The OPC updated its guidance on recording customer calls for two reasons: to align with best practices on handling biometric data, and to clarify “other considerations” for businesses.
The headline change: voiceprints collected from customers are uniquely identifying voice characteristics, and they count as sensitive biometric information, with clarified rules on when meaningful consent is required. Two scope points came with the announcement: PIPEDA applies to recorded calls regardless of who initiated them, and businesses that outsource to call centres or telemarketers must ensure those third parties follow the rules. Your vendor’s IVR is your compliance problem.
The Rogers precedent sitting behind this
None of this arrived out of nowhere. The OPC’s biometrics guidance, published in August 2025, already held that even short-term biometric processing must be treated with care, and it named the Rogers Voice ID program as the worked example. Rogers used voice identification to authenticate callers to its support lines. The OPC found the purpose appropriate under PIPEDA’s section 5(3): a legitimate need to fight telecom fraud, an effective method, no less intrusive alternative with comparable results, and privacy loss proportionate to the benefit.
But consent was where Rogers lost. The OPC required express consent before both “tuning” and enrolment, because voiceprints are sensitive biometric information and no caller reasonably expects their voice to be captured to build a biometric representation. The key line: a generic statement like “this call may be recorded for identification purposes” is generally not sufficient. The organization must specify separately and explicitly that biometric information will be collected, used, or disclosed.
The October update takes that logic and generalizes it from one telecom’s authentication program to every recorded customer call in Canada.
Where the consent bar sits now
This is the part to print and hand to the team that owns your IVR scripts:
| Plain call recording | Voiceprint collection | |
|---|---|---|
| What the caller hears | ”This call may be recorded” covers quality and training purposes | You must state separately and explicitly that biometric information will be collected, used, or disclosed |
| Consent standard | Implied consent may suffice for ordinary recording | Meaningful, express consent: the sensitivity of voiceprints and the caller’s lack of reasonable expectation both push it to express |
| Retention | Kept for the stated recording purpose, then disposed of | Templates and training data need their own retention and disposal rules, documented and enforced |
| Vendor handling | Your call centre follows your instructions | You must verify the vendor’s consent flows, enrolment logic, and template storage meet the same standard |
The retention row deserves emphasis. The OPC treats biometric templates as data that cannot be changed once compromised, so “kept as long as the recordings” is not a retention policy for voiceprints. If your vendor keeps tuning data indefinitely, that is now your finding.
What practitioners are actually saying
I checked the practitioner conversation on Reddit for a reality check. The sentiment around voiceprint authentication in call centres runs strongly skeptical. The irreversibility argument dominates: unlike a password, a voice cannot be rotated after a database leak. Practitioners on r/sysadmin and r/Cybersecurity101 go further, arguing voiceprints are weaker security than marketed, since AI-generated voice clones can fool automated checks and failed verifications typically fall back to a human agent asking weaker security questions. In that reading, voice authentication is a convenience feature more than a security control.
Callers report the practical side: rigid enrolment phrasing that locks out elderly relatives, and people who proactively call to opt out of voice recognition only to be pitched re-enrolment. The recurring objection is that “this call may be recorded” notices are understood to cover agent quality control, not biometric harvesting, which lines up exactly with the OPC’s position that a generic notice cannot substitute for explicit, separate disclosure. One more wrinkle: AI voice agents whose callers speak over the consent line, so the consent never actually lands. If your consent mechanics can be interrupted by a fast talker, you do not have consent mechanics.
Treat that as community signal, not law. But when the regulator and the people picking up the phone agree that your notice does not cover what you are doing, the direction of travel is not ambiguous.
Actionable takeaway: Pull your call scripts this week and run three checks. First, does anything in the caller journey collect a voiceprint, train a voice model, or enrol the caller in voice authentication? If yes, your generic recording notice is now officially insufficient: you need a separate, explicit biometric disclosure with real opt-in mechanics. Second, audit the consent mechanics. Confirm the disclosure plays before any collection begins and cannot be skipped or talked over, and document the opt-out path. Third, send your call-centre and telemarketing vendors a written questionnaire: where are voice templates stored, what is the retention and disposal rule, who can access them, and what evidence backs the consent each template rests on? The OPC has now told you, twice, what it expects. The next step in this sequence is an investigation, and the first exhibit will be your script.