MiFID II does not care whether the message was sent on WhatsApp, Teams, Slack or an app that did not exist when the rule was written. The rule is technology neutral. What matters is whether the communication relates to an in-scope activity, and whether the firm can record it.
A rule written around a list of apps would be obsolete by the time it was published, and the drafters said so by not writing one. Article 76(3) goes further: recording arrangements have to stay technology neutral, be reviewed periodically for effectiveness, and be re-evaluated, with additional measures adopted where needed, at least whenever the firm accepts a new communication medium.
Article 16(7) of MiFID II requires investment firms to record relevant communications, retain them for five years, and take reasonable steps to prevent unrecordable private equipment from being used for regulated business. Articles 72 to 76 of Delegated Regulation 2017/565 provide the operating detail. The national law your member state has transposed applies alongside the directly applicable Delegated Regulation, and your home-state supervisor enforces it.
At a Glance
| MiFID II recording | Information |
|---|---|
| Issued by | European Parliament and Council, enforced by national competent authorities |
| Record | Relevant calls and electronic communications |
| Retain | Five years, extendable to seven |
| Prevent | Unrecordable private devices cannot be used for in-scope business |
| Produce | Records must be accessible to regulators and clients |
| Monitor | Firms must periodically test that recording is working |
A €4.6 Million Reminder That a Policy Is Not Enough
In February 2025, BaFin fined Deutsche Bank €23.05 million in total. €4.6 million of that related specifically to failures to record telephone conversations connected with investment services.
The interesting part is not that the firm had no recording policy. A COVID-19 exception for telephone investment advice expired, and BaFin found that Postbank “at times failed to take measures to ensure that the content of investment advice given by telephone was once again electronically recorded.” The order is final and binding.
The failure was a control that stopped working and went unnoticed, not the absence of a rule. The gap ran long enough to be worth €4.6 million. This is the failure Article 76(6) exists to catch.
What Article 16(7) Requires
The practical test is the activity, not the job title. If an employee receives, transmits or executes client orders, or deals on the firm’s own account, communications around that activity can fall within the recording requirement. It applies to investment firms, and to credit institutions providing investment services, including third-country firms operating through an EEA branch.
Article 16(6) sets the general duty: a firm keeps records of all services, activities and transactions sufficient for its competent authority to supervise it.
Article 16(7) then names communications specifically. Records “shall include the recording of telephone conversations or electronic communications relating to, at least, transactions concluded when dealing on own account and the provision of client order services that relate to the reception, transmission and execution of client orders.” The obligation attaches to equipment the firm provides, and to equipment the firm permits for business use.
The duty also covers communications intended to result in an in-scope activity, whether or not anything comes of them. A call that ends without an order is still a recordable call, and a chat thread that dies before anyone trades is still a record.
The Privately-Owned-Equipment Rule
Article 16(7) requires firms to “take all reasonable steps to prevent an employee or contractor from making, sending or receiving relevant telephone conversations and electronic communications on privately-owned equipment which the investment firm is unable to record or copy.”
The prohibition applies only to equipment the firm cannot record. A personal phone the firm can capture is not the problem the article describes.
Article 76(4) adds the administrative half. Firms keep and regularly update a record of the individuals who hold firm devices or approved privately-owned devices. That register is what turns “we have a policy” into something a supervisor can test.
Retention: Five Years, Seven on Request
Keeping a message for five years is storage. Being able to show a supervisor what the message said originally, and what changed since, is recordkeeping.
Article 72 requires records to stay accessible to the competent authority, to allow each key stage of processing to be reconstructed, to make corrections and prior content easy to identify, and to be protected against manipulation or alteration.
The window is five years, and up to seven where the competent authority asks. Article 76(11) starts that clock on the date the record is created, which settles whether it runs from the conversation, the trade or the ingestion.
What Clients Are Owed
Two duties sit inside the recording rule, and an archive does not discharge either on its own.
- Notice. Article 76(8): before providing order-related investment services, a firm tells clients that conversations and communications are recorded, and that a copy is available on request for five years, or seven where the competent authority requires it.
- Copies. Article 76(10): records go to the client involved on request, held in a durable medium, readily accessible, and complete enough to be usable.
Face-to-Face Meetings Count
Article 76(9) is the paragraph most often missed, because it is not about telephones or messaging at all.
Where a relevant conversation happens face to face, the firm records it in a durable medium: written minutes or notes are acceptable, and they have to capture the date and time, the location, the identity of the attendees, who initiated the meeting, and the relevant information about the client order, including price, volume, type of order and when it is to be transmitted or executed.
An in-person meeting that produces an order is a record with a required field list. The compliance question is whether those notes reach the same archive, under the same retention policy, as everything else.
The Monitoring Duty Is Separate
Article 76(6) requires firms to periodically monitor the records of transactions and orders subject to the recording requirements, including the relevant conversations. The monitoring is risk-based and proportionate to the firm.
Owning an archive does not perform this rule. The firm has to go back and check that recording was actually happening, that coverage matches the population of in-scope activity, and that gaps were found and dealt with. Article 76(2) makes management responsible for overseeing the policy, and Article 76(7) says the firm demonstrates both the policy and that oversight to the competent authority on request.
A firm that has never reconciled its order population against its communications records has not performed Article 76(6), however good the archive is.
Where Comma Fits
Comma is designed against SEC 17a-4, FINRA 4511, CFTC 1.31, and MiFID II electronic-recordkeeping requirements. That is a design statement, not regulatory approval, and several Article 76 obligations, including client notification, periodic monitoring and management oversight, belong to the firm and cannot be bought.
Capture breadth. The equipment rule creates a simple operational problem: if the firm cannot capture a channel, it has to take reasonable steps to prevent its use for in-scope business. Comma captures 40+ channels into one archive under one retention policy. The full list is on platform integrations.
Retention is configured, and the clock is stated. Retention is measured from capture under your configured policy, which is what lets a five-year window be set deliberately and extended where a competent authority asks for seven.
Client-copy export. Article 76(10) requires records to be readily accessible and available to clients on request. Archived communications are exportable in standard formats, scoped to a custodian and a date range, without a support ticket in the path.
Evidence for the monitoring duty. Detected capture interruptions and known exceptions are durable, reasoned records rather than silent holes, which is what a reconciliation under Article 76(6) reads.
Data location transparency. Comma discloses where communications data is processed and stored, and contract schedules identify the specific regions used for capture, storage and processing.
The Practical Requirement
MiFID II does not ask which apps your firm has banned. It asks whether the communications around your order flow are on the record, retained for the right period, retrievable for the client and the regulator, and checked periodically by someone at the firm.
An archive handles the capture, the retention and the production. The device register and the monitoring stay with you.
FAQ about MiFID II recording requirements
Does MiFID II ban WhatsApp for regulated business?
Can we provide investment services by telephone to a client we have not notified?
How does MiFID II differ from the UK's SYSC 10A?
Related regulations
FCA Recordkeeping (SYSC 10A)
The UK implementation of the same recording obligation. Firms operating on both sides of the Channel run against both at once.
Read the guide
DORA
EU operational resilience regulation applying since January 17, 2025, covering EU financial entities and the ICT third parties that serve them.
Read the guide
Off-Channel Communications Compliance
What off-channel compliance requires, where firms get cited, and what examiners check across jurisdictions.
Read the guide
