A cloud phone system holds some of the most sensitive material in your business: recorded conversations containing credit card details, medical information, legal instructions, and employee grievances. It’s also a payment system in disguise: a compromised extension can generate thousands of dollars of international calls overnight.
Most providers will happily sell you the platform without discussing any of this. Here’s what you need to have thought about.
1. Call Recording and Consent
Australia has no single national call recording law for business. Recording is governed by a combination of Commonwealth legislation, principally the Telecommunications (Interception and Access) Act 1979, which prohibits intercepting a communication passing over a telecommunications system and state and territory surveillance devices legislation, which varies meaningfully.
| Jurisdiction | Principal Legislation |
|---|---|
| New South Wales | Surveillance Devices Act 2007 (NSW) |
| Victoria | Surveillance Devices Act 1999 (Vic) |
| Queensland | Invasion of Privacy Act 1971 (Qld) |
| Western Australia | Surveillance Devices Act 1998 (WA) |
| South Australia | Surveillance Devices Act 2016 (SA) |
| Tasmania | Listening Devices Act 1991 (Tas) |
| ACT | Listening Devices Act 1992 (ACT) |
| Northern Territory | Surveillance Devices Act 2007 (NT) |
| Commonwealth | Telecommunications (Interception and Access) Act 1979 |
The rules differ on whether one party's knowledge is sufficient or all parties must be informed, and on what may be done with a recording afterwards. If you take calls from multiple states, which any business with a 1300 number does, the only workable approach is to design for the strictest interpretation.
The safe practical policy
- Announce recording at the start of every call, inbound and outbound, before any substantive conversation. A short, clear message: "This call may be recorded for quality and training purposes."
- Give callers a way to object and have a documented process for handling a call where the customer declines, usually pausing recording or transferring to a non-recorded line.
- Pause recording during payment card capture. Storing card numbers in an audio file creates PCI DSS obligations most SMEs aren’t equipped to meet. Use pause-and-resume, or better, send a payment link.
- Set a retention period and enforce it automatically. Keeping recordings indefinitely increases both risk and storage cost with no upside.
- Document who may access recordings and log every playback.
- Tell your staff. Employee monitoring has its own rules, including workplace surveillance legislation in NSW and the ACT. Recording your own staff without notice is a separate problem from recording customers.
2. Privacy Act Obligations
The Privacy Act 1988 and the Australian Privacy Principles apply to most organisations with turnover above AUD $3 million, and to certain smaller businesses including health service providers and those trading in personal information. Even where the Act doesn’t strictly apply, following the APPs is the sensible default.
Applied to a phone system, the key principles are:
- APP 1, Open and transparent management. Your privacy policy must describe that calls are recorded, why, and how long they’re kept.
- APP 3, Collection. Only collect what you need. Recording every call including internal ones is hard to justify.
- APP 5, Notification. The recording announcement is your notification event.
- APP 6, Use and disclosure. A recording collected for quality assurance should not be repurposed for marketing analysis without consideration.
- APP 8, Cross-border disclosure. If audio or transcripts are processed overseas, you generally remain accountable for how the overseas recipient handles them.
- APP 11, Security. Reasonable steps to protect the information, including access control and encryption.
- APP 12, Access. Individuals can request access to personal information you hold about them, which can include call recordings.
Also relevant: the Notifiable Data Breaches scheme. If call recordings are accessed by an unauthorised party and serious harm is likely, you may have an obligation to notify affected individuals and the OAIC. Make sure you know whether your provider's contract requires them to tell you promptly about a breach on their side. Many standard terms are vaguer than you would like.
3. Data Sovereignty and Offshore Processing
Ask every prospective provider these five questions, and get the answers in writing:
- Where is call media processed in real time? Not just where records are stored, where the audio path terminates.
- Where are recordings, transcripts and voicemail stored, including backups? Backups in another region are a very common gap.
- Which subprocessors are involved, particularly for AI transcription and text-to-speech, and where are they located?
- Is customer audio or text used to train models? The answer should be an unqualified no, in the contract.
- Can support staff access my recordings, and from which country? Offshore support with production access is an offshore data flow regardless of where the servers sit.
For government, health, legal, financial services, and education buyers, these answers may determine whether a provider is viable at all. For everyone else they still matter, because your customers' data is your responsibility, not your vendor's.
Why "Australian data centre" is a starting point, not an answer
Plenty of international platforms host their media servers in Sydney while running transcription through an overseas AI service, storing backups in another region, and providing support from a third country. A Australian-built and Australian-operated platform removes several of these questions entirely, which is precisely why it’s worth paying attention to who built the system, not just where it runs.
4. Encryption and Transport Security
Two layers matter:
- Signalling encryption (SIP over TLS) protects the call setup information: who called whom, when, and from where. Without it, that metadata is visible on the network path.
- Media encryption (SRTP) protects the audio itself. Without it, anyone with access to a network segment can reconstruct the conversation.
Ask whether TLS and SRTP are enabled by default or optional, and whether they apply to desk phones as well as apps. Some deployments encrypt the softphone but leave provisioned handsets on plain SIP. Also ask about the provisioning process: handsets that download their configuration over unencrypted HTTP expose SIP credentials, which is a direct path to the fraud scenario below.
At rest, recordings should be encrypted with keys the provider manages properly, and access should be logged. For sensitive sectors, ask whether customer-managed keys are available.
5. Toll Fraud: The Cost Nobody Budgets For
Toll fraud is the most common financial loss associated with VoIP systems. An attacker obtains SIP credentials: usually through a weak password, an exposed provisioning file, or an unpatched on-premise system and places a large volume of calls to expensive international or premium destinations, often over a weekend. The traffic is real, the calls are billed, and recovery is difficult.
Controls that actually work:
- Spend caps and velocity alerts at the provider level. A hard daily limit is the single most effective control. Ask whether it’s on by default.
- International calling disabled by default, enabled only for the users who need it, and restricted to the countries they actually call.
- Premium and satellite destinations barred unless there’s a business reason.
- Strong, unique SIP credentials, never the extension number as the password, which remains distressingly common.
- IP restriction or device registration limits so credentials only work from your networks.
- MFA on the administration portal. The portal is where an attacker changes the call forwarding to a premium number.
- Out-of-hours alerting for unusual call volumes. Most fraud runs Friday night to Monday morning.
Also settle the commercial question before you sign: who pays if fraud occurs? Provider terms vary widely, and the default position in many contracts is that the customer wears the cost. A provider that offers caps, alerting, and a reasonable fraud policy is worth more than a two-dollar-per-user discount.
6. Access Control and Offboarding
- Role-based access. A team leader who needs call statistics should not automatically be able to listen to every recording in the business.
- Single sign-on where available, so departures are handled once in your identity provider rather than in every SaaS platform separately.
- An offboarding checklist that includes the phone system: deactivate the account, revoke mobile app sessions, reassign the extension and voicemail, and forward the direct number.
- Audit logs for configuration changes. Call forwarding changed at 2am is a signal worth catching.
- Recording playback logging, so you can answer "who listened to this call?" if it’s ever asked.
7. Emergency Calling and Continuity Obligations
VoIP services must support calls to Triple Zero, and the routing of those calls depends on the address information registered against the service. This creates two obligations in practice:
- Keep registered service addresses accurate for every site, and update them when you move.
- Brief remote and mobile staff that a call from a softphone may present the office address. Anyone calling Triple Zero should state their actual location immediately.
Also consider power and internet dependency. Unlike a legacy copper line, an IP handset stops working in a blackout. Mitigate with mobile app failover, a UPS on the network equipment, and a documented plan for what staff do when the site is offline. Consumer protections including the Telecommunications Consumer Protections (TCP) Code also apply to how providers must handle complaints and service information, worth knowing if a dispute arises.
8. Vendor Due Diligence Checklist
- Where is media processed, stored, and backed up? (Get it in writing.)
- Are TLS and SRTP enabled by default, on apps and handsets?
- Is customer audio used for AI model training?
- Which subprocessors handle transcription and speech synthesis?
- Can support staff access recordings, and from where?
- What are the default toll fraud caps and alerts, and who bears the loss?
- Does the platform support MFA and role-based access?
- What are the configurable retention periods for recordings and transcripts?
- How quickly must the provider notify you of a data breach?
- Can you export all your data, including recordings, if you leave?
Providers that are Australian-built, Australian-hosted, and Australian-supported answer the majority of these questions with a single sentence, which is a practical reason to prefer them beyond patriotism. Uniden Voice over Cloud is our top-rated Australian option on exactly this basis: local infrastructure, local support, and AI features that run within the same Australian platform rather than being handed off to an offshore service.