Corporate Communications: Data Protection Guidelines

A misrouted call log, a publicly accessible call recording, or a former employee with active softphone access: In corporate communications, data protection risks usually arise not from spectacular hacker attacks, but from a lack of operational guidelines. This Corporate Communications Data Protection Guide outlines the specific areas Swiss companies should focus on when using VoIP, cloud PBX, Microsoft Teams, and mobile workstations.

Telephony has long been more than just a phone line at the workplace. Phone numbers, presence information, call data, voicemails, recordings, CRM notes, and chat histories together form a sensitive data environment. Those who integrate these components seamlessly—both technically and organizationally—not only protect personal data but also establish clear lines of responsibility, improve the ability to provide information, and ensure that communication functions reliably in everyday work.

Why Data Protection in Telecommunications Starts at the Operational Level

The Swiss Data Protection Act requires that personal data be processed in a lawful, proportionate, and secure manner. For companies with customers, employees, or locations in the EU, the GDPR may also apply. Which requirements apply in each specific case depends, among other things, on the company’s registered office, the individuals concerned, and the nature of the data processing.

However, the rules alone are not the decisive factor. Data protection must be evident in the day-to-day administration of the communication platform. Who is authorized to view call logs? Where are voicemails stored? How long are call recordings retained? What data flows from the phone system to CRM, ERP, or ticketing systems? Without reliable answers, even a modern cloud solution can quickly become a data source that’s difficult to control.

Metadata deserves special attention. Even information about who made a call, when, and to what number can reveal details about customer relationships, health issues, projects, or internal decisions. That is why call data is not merely a technical detail, but an integral part of the protection strategy.

Understanding Corporate Communications and Data Protection Properly

The first practical step is to take stock of actual communication channels. It’s not the list of products that matters, but rather the flow of data from the incoming call through to storage or deletion. This includes landline and mobile telephony, SIP trunks, cloud PBX, Microsoft Teams, IVR menus, contact center functions, softphones, IP phones, and interfaces to line-of-business applications.

For each relevant process, document which personal data is processed, for what purpose, who has access to it, and where the data is stored. In the case of a call recording, for example, this includes the voice, phone number, time, call duration, and, if applicable, the content of the conversation. In the case of a Teams integration, this also includes identities, presence data, chats, and calendar entries.

This transparency also highlights the difference between necessary and convenient data collection. A receptionist may need caller ID and the name of a contact person. However, they do not automatically need access to the complete call histories of all departments. Data minimization is therefore not an abstract principle, but a matter of clearly defined roles and access levels.

Records Only When There Is a Clear Basis

Call recordings are useful for quality assurance, training, contract documentation, or handling complex cases. At the same time, they constitute a significant intrusion into privacy. Before enabling this feature, companies should specify which calls will be recorded, how affected individuals will be notified, who is authorized to listen to the recordings, and when they will be deleted.

A general announcement before the call is not sufficient to serve as a free pass for any and all uses. Caution is particularly warranted in support cases involving sensitive information, HR matters, or health data. Often, targeted, time-limited recording makes more sense than continuously recording all calls in their entirety. Employees must also be able to easily use the pause and stop functions.

Technology: Encryption Is Just the Beginning

Secure corporate communication requires protection on multiple levels. The call connection should be protected against eavesdropping and tampering, for example, using TLS for signaling and SRTP for voice transmission. However, encrypted transmission alone is of little help if login credentials are shared, Unpatched devices remain, or administrator accounts are granted too broad of permissions.

A session border controller can monitor SIP connections, block attacks, and securely protect the connection between internal telephony systems, service providers, and collaboration platforms. However, its effectiveness depends on proper configuration: allowing only necessary connections, validating protocols, closing unnecessary ports, and monitoring for anomalies. With Microsoft Teams, it’s also important to clarify how calling integration, identities, and permissions interact with the existing communications architecture.

The network is also part of data protection. Phone systems, workstations, guest accounts, and management accounts should not operate unmonitored on the same network segment. Network segmentation, firewall rules, secure VPN access for remote work, and regular updates significantly reduce the attack surface. For small businesses, a Manageable Cloud PBX A system with centrally managed endpoints is more secure than a system that has evolved over time without clear lines of responsibility. For larger organizations, a local or hybrid architecture may be appropriate if it needs to meet specific integration or control requirements.

Control Access by Task

Most risks arise in connection with identities and permissions. A new phone can be set up quickly, but an employee who has left the company sometimes remains active for weeks. That is why the onboarding, transfer, and offboarding processes must also be strictly regulated for telephony, Teams, softphones, call groups, voicemail, and CTI interfaces.

Employees need only the permissions required to perform their tasks. The receptionist role differs from that of IT administration, and IT administration differs from auditing. Multifactor authentication for administrative access, individual accounts instead of shared ones, and regular authorization reviews are effective foundational measures. Especially when working with external IT partners, time-limited access, traceable approvals, and logging should be standard practice.

The same applies to shared devices. An IP phone in a conference room must not disclose personal voicemails or complete contact lists. Mobile devices require a screen lock, up-to-date software, and a plan in case of loss or theft. Whether mobile device management is necessary depends on the company’s size, risk profile, and the data being used. For mobile teams that interact with customers, it’s usually a worthwhile investment.

Review the cloud, provider, and order processing

With hosted telephony, it is not only your own company that processes data. Providers, hosting partners, support teams, and, in some cases, software vendors may also be involved. Before implementation, it should be clear which party assumes which role, in which countries data is processed, and what technical and organizational measures are contractually guaranteed.

It is important to have clear policies regarding order processing, subcontractors, support access, data exports, and retention periods. Having a Swiss contact person does not replace this review, but it does make operational coordination much easier. Winet, for example, supports communication environments such as SIP trunks and Ayrix-PBX including Microsoft Teams integration with direct technical support. The key factor is that the chosen solution aligns with your organization’s data protection framework and isn’t just something that looks good on paper.

Also ask about procedures in the event of incidents: Who notifies whom in the event of a security incident? Which logs are available for analysis? How quickly can accounts be locked, phone numbers redirected, or compromised devices replaced? Data protection and availability go hand in hand. A poorly managed incident can lead to data loss or unauthorized access just as easily as an attempted attack.

Establish Mandatory Rules for Data Retention Periods, Logs, and Emergencies

Communication data should not be stored for longer than is necessary for the documented purpose. Different retention periods often apply to call logs, voicemails, recordings, chat exports, and system logs. Blanket settings based on the idea that “more history is better” lead to unnecessary data holdings and complicate requests for information or deletion.

A deletion policy that is technically feasible makes sense: automatic retention periods, clearly labeled archives, regulated exceptions for ongoing cases, and regular reviews. Backups deserve special attention in this context. They ensure data availability, but must not result in deleted data persisting permanently without being noticed. Therefore, define retention periods and access rights for backups.

You don’t need a voluminous folder for security incidents that no one can find when it really matters. A brief, tested procedure is enough to get started: identify the incident, restrict access, document the impact, involve the appropriate people, and review any required reports in a timely manner. Employees need to know who to contact in the event of suspicious calls, phishing attempts, lost devices, or misdirected voicemails.

Data Protection as Part of Well-Managed Communication

The most effective corporate communications data protection guide doesn't end with a one-time review. New call groups, additional locations, changes to Teams licenses, CRM projects, and new employees are constantly altering the flow of data. Therefore, be sure to schedule data protection audits whenever there is a major change to your telephony or collaboration environment.

Start with a specific area, such as call recordings or admin accounts. If responsibilities, technology, and deletion policies function transparently in that area, the same standard can be applied step by step to all corporate communications. This way, data protection doesn’t become an obstacle to modern collaboration, but rather a reliable component of professional accessibility.

Current

How secure are cloud PBX systems for Swiss small and medium-sized businesses?
Current

How secure are cloud PBX systems for Swiss small and medium-sized businesses?

A noticeably high volume of calls over the weekend, a compromised user account, or an Internet outage at the main location: Security issues in telecommunications can manifest themselves…
Should I choose Direct Routing or Operator Connect?
Current

Should I choose Direct Routing or Operator Connect?

Microsoft Teams has long been the central hub for chats, meetings, and files in many companies. However, as soon as employees also start using…
The Best VoIP Security Features in Action
Current

The Best VoIP Security Features in Action

An unusually high international call, a compromised softphone, or tampered call forwarding: With VoIP, damage is often not caused by…
Which phone services work during a power outage?
Current

Which phone services work during a power outage?

A power outage at the office rarely affects only the phone system. Routers, switches, Wi-Fi, IP phones, and local servers all shut down at the same time. Which…
Centrally Manage Corporate Communications
Current

Centrally Manage Corporate Communications

When employees handle calls through the phone system, chats via Microsoft Teams, call forwarding to cell phones, and customer interactions on the side using their personal numbers,…
Guide to Emergency Planning for Telephone Services in the Workplace
Current

Guide to Emergency Planning for Telephone Services in the Workplace

If the phone system goes down, it’s not just one device that stops working. Customers can’t reach support, suppliers don’t receive any feedback, and…