Modulate prepares platforms for regulatory compliance
120 million
500+ million
0
Experts in voice processing regulation for any platform
Modulate helps organizations meet these obligations confidently, providing expert guidance on consent and retention policies while delivering transparent, auditable insights into how our AI systems analyze and protect voice data.
Regulations
Data Privacy and Protection
There are a variety of data privacy and consumer protection laws worldwide, though the EU’s GDPR is arguably the most commonly cited. These laws cover a wide set of requirements focused on empowering end users with transparency and ownership over their data.
GDPR in particular requires that any data processing clearly distinguishes the controller who is ultimately responsible for the processing; outlines a series of rights of end users which must be respected; and requires a basis for all data processing activities. Data residency is also a frequent consideration.
Potential Financial Impact
4% of annual revenue (under GDPR; exact penalties may vary)
Requirements
- Lawful basis (such as user consent) for recording
- Adequate data residency controls to protect end user data
- Satisfy data subject rights such as the right to be forgotten
How Modulate Helps
Modulate acts as your data processor. We are capable of storing all data securely, fulfilling data subject requests, and supporting data residency risk assessments, as directed by your legal team. We’re also happy to collaborate on a DPA to ensure our housing and use of your data is exactly as you need.
.avif)
.avif)
Call Recording and Consent Laws
Call recording regulations tend to be focused on the subject of consent - specifically, whether explicit disclosure is required of automated analytics, and whether one or both parties are required to consent for the audio to be recorded. If you’ve ever heard “this call may be recorded for quality assurance” or similar notifications, these regulations are why.
Potential Financial Impact
$10,000 per violation (under the US Federal Wiretap Act; exact penalties may vary)
Requirements
- Obtain multi-party consent in regions which require it
- Disclose any data recording and analytics at call start
How Modulate Helps
As a back-end data processor, Modulate does not directly interact with your end users, so no need to worry about obtaining additional consents. In addition, all of Modulate’s solutions are highly configurable and can be activated or deactivated for individual calls on the fly as necessary, allowing you to adjust your use of our analytics depending on the consents obtained.
AI Transparency and Fairness
As AI technologies become more widely used, many new regulations have emerged to restrict the use of AI for high-risk decision-making or to enforce transparency and fairness requirements. The most notable of these is the EU AI Act, which focuses on risk-based classifications and proportional restrictions.
Potential Financial Impact
7% of annual revenue (under the EU AI Act; exact penalties may vary)
Requirements
- Assess the relative risk of each AI deployment
- Ensure human oversight over AI-enabled decisions
- Train AI systems only on ethically and legally sourced, and fair and unbiased, training datasets
How Modulate Helps
All of Modulate’s AI systems are trained with compliant data, which we’ve custom-sourced only with clear consent from participants, and hand-tuned to avoid bias. In addition, Modulate’s platform is designed with human intervention and oversight as a core principle - all AI-informed decisions can trivially be routed to humans for review, or human review can be prioritized for those calls the AI is least confident in. In most cases, deployments involving Modulate will be classified as “Limited Risk” under the EU AI Act (excepting any use in relation to a voice-based authentication system), but Modulate also supports customers directly as they conduct their own risk assessments.
.avif)
.avif)
Security and Access Control Standards
While not always required by regulation, most modern enterprises set minimum standards regarding the secure transmission, storage, and access of sensitive data. The common baselines for security include the ISO 27001 standard and SOC 2 assessments.
Potential Financial Impact
Not directly regulated, but substantially increases real risk of data breaches as well as regulatory exposure under data privacy regulation such as GDPR
Requirements
- Industry-standard encryption for all data at rest and in transit
- Access control restricting to only what’s required for each individual, with audit logs and individual accounts whose behavior can be monitored
- Incident response and breach notification plans in place with routine tests
How Modulate Helps
Modulate first got ISO 27001 certified many years ago, when our team consisted of only 12 employees. Security is built into everything we do and we’ve successfully managed the data of Fortune 500 companies and AAA game studios for years without any breaches. We also recognize that many organizations prefer to conduct their own security assessments for vendors and are experienced and ready to assist in completing such an assessment.
