How Expert Networks Handle Recording Consent Across Jurisdictions: A Field Guide to One-Party, All-Party, and GDPR Regimes
A working reference for the consent regimes that govern expert-call recording in the jurisdictions where buy-side research actually happens.

A single expert call routinely crosses two or three legal regimes before the moderator even joins. The analyst dials in from New York, the expert sits in Munich, the compliance officer approving the transcript is in London, and the recording lands on infrastructure in Virginia. Each of those seats carries its own rule for what consent means, who has to give it, and what the recording becomes once it exists. Buy-side firms want the recording anyway , for AI ingestion, transcript search, and audit trails , which is why the consent layer has moved from a footnote in the terms of service to a first-class operational problem for every expert network.
This is a working reference for the regimes analysts and compliance teams encounter most often, and how the operational layer at expert networks actually handles the differences.
The US Federal Baseline: One-Party Consent
The federal wiretap statute, 18 U.S.C. § 2511, permits recording of a wire, oral, or electronic communication where one party to the communication has consented. For a US-domiciled expert network running a call between a US-based analyst and a US-based expert, the analyst's own consent is sufficient at the federal layer. That is the baseline most networks reference when they describe their default posture.
The baseline is thin, though, because federal law is a floor and not a ceiling. Any state can impose a stricter standard, and several have.
The All-Party States: Why Networks Default to Two-Party
A short list of states require the consent of every party to a communication before it can lawfully be recorded. California is the most-cited example, with California Penal Code § 632 prohibiting the recording of a confidential communication without the consent of all parties. Florida, Illinois, Massachusetts, Pennsylvania, and Washington operate under broadly comparable regimes, with meaningful variations in what counts as a confidential communication, what the notice requirement looks like, and what remedies are available.
From an operational standpoint, expert networks rarely try to route calls dynamically based on the state of each participant. The routing logic is fragile, the geolocation signal is unreliable when experts dial in from mobile phones, and the downside of getting it wrong is a plaintiff-friendly statute in a plaintiff-friendly state. The common posture is to default to all-party consent for every call, US or otherwise, and to bake the consent capture into the pre-call script the moderator reads. That policy simplification is the reason a US expert on a US call still hears a recording-consent notice before the substantive discussion begins.

EU and UK: Recording as Personal-Data Processing
Inside the EU and the UK, the analysis shifts. A recording of a natural person's voice is personal data, and its capture, storage, and downstream use is processing under the GDPR and the UK Data Protection Act 2018. Processing requires a lawful basis under Article 6 of the GDPR , most commonly consent or legitimate interest for expert-call recording , plus a defined retention period, a record of processing activities, and the data-subject rights that attach to any personal-data set.
This is why expert consent forms drafted for EU experts are materially longer than their US equivalents. They specify the controller and any processors in the chain, the purposes for which the recording will be used, the retention window, and the mechanism the expert can use to exercise access, rectification, and erasure rights. When a buy-side firm asks the network to hand the recording to an internal AI ingestion pipeline, the processor chain grows, and the consent artifact has to grow with it. A recording that was lawfully captured under one purpose is not automatically lawful for a new one.
The UK regime post-Brexit tracks the EU framework closely under the UK GDPR and the DPA 2018, with the ICO as the supervisory authority. The practical implication for networks is that a UK-seated expert is treated on the EU pattern rather than the US one.
Canada: PIPEDA and the Knowledge-and-Consent Standard
Canada's Personal Information Protection and Electronic Documents Act requires the knowledge and consent of an individual for the collection, use, or disclosure of their personal information in the course of commercial activity. A voice recording of a Canadian expert is personal information, and the consent standard applies whether the recorded party is the expert or the analyst.
Provincial regimes in Alberta, British Columbia, and Quebec add their own overlay, and Quebec's Law 25 in particular has tightened the requirements around cross-border transfer and processor disclosure. Networks handling Canadian experts typically apply a consent flow that resembles the EU pattern more than the US one, with a written record of the expert's acknowledgment retained alongside the recording.
Australia: Effectively All-Party in Most States
Australia layers the federal Telecommunications (Interception and Access) Act 1979 over state Surveillance Devices Acts in New South Wales, Victoria, Queensland, and the other states and territories. The federal act governs interception in transit; the state acts govern the use of a listening or recording device to capture a private conversation. Read together across the major states, the effect is close to all-party consent for the recording of a private conversation, with narrow exceptions.
An expert network scheduling a call with an Australian expert cannot reliably rely on a single-party consent posture. The operational default is the same as for California: capture all-party consent in the pre-call script, log it against the call record, and store the artifact with the recording.
Mainland China: PIPL, Data Security Law, and the Cross-Border Problem
Mainland China is the regime where the compliance layer changes the shape of the product itself. The Personal Information Protection Law treats a recorded call containing a PRC national's voice as personal information, and Articles 38 through 40 of the PIPL impose specific conditions on the cross-border transfer of that information, including , above defined thresholds , a security assessment by the Cyberspace Administration of China. The Data Security Law adds a separate overlay for data classified as important or as involving national security.
A recording of a PRC-based expert speaking to a US buy-side analyst, stored on infrastructure outside the PRC, is a cross-border transfer of personal information. The compliance cost of doing this at scale is why several networks have restructured their PRC operations: onshore-only recording infrastructure, no recording at all for certain call types, and expanded pre-call disclosures on both sides. The pause on China-related expert calls following the 2023 enforcement actions against Capvision and other research firms operating in the mainland is the backdrop against which every current PRC consent flow is designed.
Japan and South Korea: One-Party Consent, but Confidentiality Drives the Practice
Japan and South Korea both permit recording with one-party consent as a general matter of criminal law. The operational constraint is not the recording statute; it is the professional-secrecy and confidentiality obligations that attach to the expert. Japanese labor practice in particular carries strong expectations of ongoing confidentiality toward a former employer, and an ex-employee who discusses a former employer's operations on a recorded call without prior written acknowledgment of the recording carries a meaningful personal risk.
Networks handling Japanese and Korean experts commonly require a written pre-consent that goes beyond the recording notice and covers the scope of the expert's participation, the topics considered off-limits, and the expert's acknowledgment that the discussion will not touch on their former employer's non-public information. The consent artifact is thicker than the statute requires because the exposure sits in the expert's employment relationship, not the network's recording posture.
The Operational Layer at the Networks
The consent regime is the input. The output is what an expert network's operations team actually builds. Across the major networks , GLG, AlphaSights, Guidepoint, Third Bridge, Dialectica, and the smaller specialist firms , a recognizable pattern has emerged.
Jurisdiction is detected before the call from the expert profile and the analyst's seat, and the recording default is set accordingly. Cross-border calls that combine a strict-regime expert with a permissive-regime analyst are commonly defaulted to recording-off unless the buy-side firm has completed a specific opt-in flow. The pre-call script the moderator reads is templated by jurisdiction pair, with the consent capture logged against the call record. Consent forms for EU, UK, Canadian, and PRC experts are longer, name the processor chain, and specify the retention window.
The newer artifact, and the one buy-side AI teams increasingly ask for, is a machine-readable consent record attached to each transcript. When a transcript is ingested into an internal research corpus and a language model is asked to summarize or search it, the AI agent needs to know which recordings it is permitted to use, for which purposes, and for how long. A PDF consent form does not answer that question at query time. A structured consent artifact , jurisdiction, lawful basis, retention window, permitted downstream uses , does. The networks that have built this layer are quietly winning the AI-readiness conversation with the largest buy-side clients.
What This Means for the Compliance Stack
The practical read for a buy-side compliance team evaluating an expert-network relationship is that the recording-consent posture is now a first-order question and not a schedule at the back of the MSA. The questions worth asking are concrete: what is the network's default posture for a cross-border call, how is jurisdiction detected, where is the recording stored, what is the retention window, what does the consent artifact look like when it reaches the internal AI pipeline, and how is PRC exposure handled.
The questions that were adequate two years ago , is the call recorded, and can we have the file , no longer describe the surface area of the problem.
Are your experts using AI to cheat?
Try our free demo to find out today.
Powering institutional-grade transcription for expert networks.
INFLXD provides AI-powered, human-edited transcription with sub-1% error rates for the world's leading expert networks and financial research firms.
Visit inflxd.com →Keep reading.

How Expert Networks Handle Recusal When a Consultant Becomes Conflicted Mid-Engagement
The operational playbook for what happens between initial screening and the post-call score, when an expert's conflict profile changes after the project has already started.

How Expert Networks Screen for Non-Competes and Garden Leave: A Field Guide for Buy-Side Compliance
The screening layers that stand between a former-employer call and a legal problem, and how buy-side teams should read them.

How Buy-Side Firms Handle Expert-Network Call Translation for Cross-Border Research
Seven structural models buy-side teams use when the expert and the analyst do not share a working language, and the cost, compliance, and transcript tradeoffs behind each.

