Stay Compliant! Sensitive Data, Found and Removed Automatically
September 29, 2026
CyRecord spots sensitive details as they’re spoken and removes them before they’re ever stored.
How sure are you that your call archive right now contains zero private information? Dates of birth, home addresses, bank details and more that were captured during perfectly ordinary conversations.
Once a call is recorded and transcribed, every one of those details becomes stored, searchable data, and under Australian privacy law, that makes it your responsibility.
The regulator is already acting on it.
- Australian Clinical Labs was ordered to pay $5.8 million over a health data breach
- Meta settled for $50 million
- Medibank and Optus are both facing civil penalty action.
With maximum penalties now reaching $50 million or 30% of turnover, sensitive data sitting in your recordings is a risk worth removing.
How CyRecord protects every call
CyRecord identifies personal and sensitive information automatically as calls are recorded and transcribed, then handles it according to the rules you set.
It works in three layers.
- Conversation-level detection scans transcripts in real time for names, phone numbers, addresses, email addresses, card numbers, dates of birth and ID references. It’s tuned for the way people actually speak, including reading numbers aloud and spelling out details.
- Australian identifier detection recognises Medicare numbers, Tax File Numbers, driver’s licence and passport numbers, bank accounts, ABNs and ACNs for what they are, rather than treating them as a random string of digits.
- Custom definitions allow you to create your own identifiers and data structures for redaction.
- Checksum validation for high-risk identifiers such as Tax File Numbers adds a rules-based confirmation on top of the AI models, reducing the chance that a genuine identifier slips through.
Your data, your rules
Once something sensitive is detected, you decide what happens to it in the recording, the transcript and any reporting output.
- Redact: the value is replaced with a category tag such as [DATE_OF_BIRTH], so reviewers know sensitive data was present without seeing it.
- Mask: the content is silenced or beeped in the audio and blanked in the transcript.
- Pseudonym: the value is swapped for a realistic but fake equivalent, so QA and training transcripts still read naturally.
Treatments can differ by category, so you might mask bank details outright while pseudonymising names. Detection profiles can be applied per site, per queue or per campaign, and you can add your own terms too, from internal case formats to specific product names.
Role-based permissions control access to configuration, and detection processing doesn’t retain your data beyond each individual request.
Protected before, not after
With CyRecord, your detection profile, logs and treatment policy are already in place, so you can demonstrate compliance at any time rather than scrambling after an incident.
Our team will work with you to build a detection profile that matches your obligations and call types, starting with the standard Australian categories and adding any terms specific to your organisation.
This is general information only and is not legal advice. Organisations should seek advice from their own legal or privacy counsel on their specific obligations.