Skip to content

Regulation Guide

MiFID II Has No List of Approved Apps. It Has a Recording Test.

Article 16(7) asks two questions about any message: does it relate to an in-scope activity, and can the firm record it. The app it was sent on is not one of them.

Record the conversations and electronic communications that relate to client orders and own-account dealing, keep them for five years, hand a copy to the client on request, and stop staff using equipment you cannot record.

MiFID II does not care whether the message was sent on WhatsApp, Teams, Slack or an app that did not exist when the rule was written. The rule is technology neutral. What matters is whether the communication relates to an in-scope activity, and whether the firm can record it.

A rule written around a list of apps would be obsolete by the time it was published, and the drafters said so by not writing one. Article 76(3) goes further: recording arrangements have to stay technology neutral, be reviewed periodically for effectiveness, and be re-evaluated, with additional measures adopted where needed, at least whenever the firm accepts a new communication medium.

Article 16(7) of MiFID II requires investment firms to record relevant communications, retain them for five years, and take reasonable steps to prevent unrecordable private equipment from being used for regulated business. Articles 72 to 76 of Delegated Regulation 2017/565 provide the operating detail. The national law your member state has transposed applies alongside the directly applicable Delegated Regulation, and your home-state supervisor enforces it.

At a Glance

MiFID II recordingInformation
Issued byEuropean Parliament and Council, enforced by national competent authorities
RecordRelevant calls and electronic communications
RetainFive years, extendable to seven
PreventUnrecordable private devices cannot be used for in-scope business
ProduceRecords must be accessible to regulators and clients
MonitorFirms must periodically test that recording is working

A €4.6 Million Reminder That a Policy Is Not Enough

In February 2025, BaFin fined Deutsche Bank €23.05 million in total. €4.6 million of that related specifically to failures to record telephone conversations connected with investment services.

The interesting part is not that the firm had no recording policy. A COVID-19 exception for telephone investment advice expired, and BaFin found that Postbank “at times failed to take measures to ensure that the content of investment advice given by telephone was once again electronically recorded.” The order is final and binding.

The failure was a control that stopped working and went unnoticed, not the absence of a rule. The gap ran long enough to be worth €4.6 million. This is the failure Article 76(6) exists to catch.

What Article 16(7) Requires

The practical test is the activity, not the job title. If an employee receives, transmits or executes client orders, or deals on the firm’s own account, communications around that activity can fall within the recording requirement. It applies to investment firms, and to credit institutions providing investment services, including third-country firms operating through an EEA branch.

Article 16(6) sets the general duty: a firm keeps records of all services, activities and transactions sufficient for its competent authority to supervise it.

Article 16(7) then names communications specifically. Records “shall include the recording of telephone conversations or electronic communications relating to, at least, transactions concluded when dealing on own account and the provision of client order services that relate to the reception, transmission and execution of client orders.” The obligation attaches to equipment the firm provides, and to equipment the firm permits for business use.

The duty also covers communications intended to result in an in-scope activity, whether or not anything comes of them. A call that ends without an order is still a recordable call, and a chat thread that dies before anyone trades is still a record.

The Privately-Owned-Equipment Rule

Article 16(7) requires firms to “take all reasonable steps to prevent an employee or contractor from making, sending or receiving relevant telephone conversations and electronic communications on privately-owned equipment which the investment firm is unable to record or copy.”

The prohibition applies only to equipment the firm cannot record. A personal phone the firm can capture is not the problem the article describes.

Article 76(4) adds the administrative half. Firms keep and regularly update a record of the individuals who hold firm devices or approved privately-owned devices. That register is what turns “we have a policy” into something a supervisor can test.

Retention: Five Years, Seven on Request

Keeping a message for five years is storage. Being able to show a supervisor what the message said originally, and what changed since, is recordkeeping.

Article 72 requires records to stay accessible to the competent authority, to allow each key stage of processing to be reconstructed, to make corrections and prior content easy to identify, and to be protected against manipulation or alteration.

The window is five years, and up to seven where the competent authority asks. Article 76(11) starts that clock on the date the record is created, which settles whether it runs from the conversation, the trade or the ingestion.

What Clients Are Owed

Two duties sit inside the recording rule, and an archive does not discharge either on its own.

  • Notice. Article 76(8): before providing order-related investment services, a firm tells clients that conversations and communications are recorded, and that a copy is available on request for five years, or seven where the competent authority requires it.
  • Copies. Article 76(10): records go to the client involved on request, held in a durable medium, readily accessible, and complete enough to be usable.

Face-to-Face Meetings Count

Article 76(9) is the paragraph most often missed, because it is not about telephones or messaging at all.

Where a relevant conversation happens face to face, the firm records it in a durable medium: written minutes or notes are acceptable, and they have to capture the date and time, the location, the identity of the attendees, who initiated the meeting, and the relevant information about the client order, including price, volume, type of order and when it is to be transmitted or executed.

An in-person meeting that produces an order is a record with a required field list. The compliance question is whether those notes reach the same archive, under the same retention policy, as everything else.

The Monitoring Duty Is Separate

Article 76(6) requires firms to periodically monitor the records of transactions and orders subject to the recording requirements, including the relevant conversations. The monitoring is risk-based and proportionate to the firm.

Owning an archive does not perform this rule. The firm has to go back and check that recording was actually happening, that coverage matches the population of in-scope activity, and that gaps were found and dealt with. Article 76(2) makes management responsible for overseeing the policy, and Article 76(7) says the firm demonstrates both the policy and that oversight to the competent authority on request.

A firm that has never reconciled its order population against its communications records has not performed Article 76(6), however good the archive is.

Where Comma Fits

Comma is designed against SEC 17a-4, FINRA 4511, CFTC 1.31, and MiFID II electronic-recordkeeping requirements. That is a design statement, not regulatory approval, and several Article 76 obligations, including client notification, periodic monitoring and management oversight, belong to the firm and cannot be bought.

Capture breadth. The equipment rule creates a simple operational problem: if the firm cannot capture a channel, it has to take reasonable steps to prevent its use for in-scope business. Comma captures 40+ channels into one archive under one retention policy. The full list is on platform integrations.

Retention is configured, and the clock is stated. Retention is measured from capture under your configured policy, which is what lets a five-year window be set deliberately and extended where a competent authority asks for seven.

Client-copy export. Article 76(10) requires records to be readily accessible and available to clients on request. Archived communications are exportable in standard formats, scoped to a custodian and a date range, without a support ticket in the path.

Evidence for the monitoring duty. Detected capture interruptions and known exceptions are durable, reasoned records rather than silent holes, which is what a reconciliation under Article 76(6) reads.

Data location transparency. Comma discloses where communications data is processed and stored, and contract schedules identify the specific regions used for capture, storage and processing.

The Practical Requirement

MiFID II does not ask which apps your firm has banned. It asks whether the communications around your order flow are on the record, retained for the right period, retrievable for the client and the regulator, and checked periodically by someone at the firm.

An archive handles the capture, the retention and the production. The device register and the monitoring stay with you.

FAQ about MiFID II recording requirements

Does MiFID II ban WhatsApp for regulated business?
No. Article 16(7) requires all reasonable steps to prevent staff using privately owned equipment the firm is unable to record or copy. The prohibition is conditional on the firm's inability to capture. A firm that can archive WhatsApp on a permitted device is meeting the rule; a firm that cannot capture it has to prevent its use for in-scope business.
Can we provide investment services by telephone to a client we have not notified?
No. Article 16(7) prohibits providing investment services by telephone to clients who have not been notified in advance that the conversation will be recorded. The notification has to reach new and existing clients before the service is provided.
How does MiFID II differ from the UK's SYSC 10A?
The substance is close, because SYSC 10A is the UK implementation of the same MiFID II obligation and survived Brexit largely intact. Both run a five-year retention window extendable to seven, both use a reasonable-steps test for unrecordable equipment, and both impose a separate monitoring duty. The difference is the instrument and the supervisor: EU firms answer to their national competent authority under national law transposing the Directive, UK firms answer to the FCA under the Handbook. See the FCA recordkeeping guide.

Related regulations

See how Comma supports your recordkeeping obligations

Last updated:

Share this page

More