Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018
Law. Placed at UK locations. Read 30 Sep 2026; 3 provisions cited by the planner.
UK interception regulations reg 3(1)(a)Interception effected by, or with the express consent of, the system controller The interception must be of a communication while it is being transmitted over a telecommunication system, and it must be carried out by the system controller (the person entitled to control the system's operation or use) or with that person's express consent. A vendor, outsourced call centre or IT provider that monitors on the business's behalf needs the controller's explicit authority; implied acquiescence is not enough for this route. Regulation 3(1)(b) and (c) add that the conduct must also fit a purpose in paragraphs (2) to (4) and satisfy regulation 4.
UK interception regulations reg 3(2)(c)Purpose: to ascertain or demonstrate standards achieved or to be achieved by users in the course of their duties Monitoring or recording is authorised to find out or show the standards that people reach, or should reach, when they use the system for their work, which covers quality assurance and training on business calls, emails and messages. It does not extend to communications that are not made in the course of duties.
UK interception regulations reg 4(1)(c)All reasonable efforts to inform every user that communications may be intercepted The system controller must have made all reasonable efforts to tell each person who might use the system that communications carried on it can be intercepted. This covers workers and anyone else who may use the system (contractors, visitors on guest networks); the Regulations do not require the consent of the other party to a call or message, but the users of the controller's own system must be told. Informing external callers is a separate data protection transparency duty.