3CX GDPR Statement

Introduction

GDPR as such does not apply to products directly, but to how customers’ and employees’ data are being protected and to the procedures and organisational measures in place at a company level, as well as good practices implemented internally.

This GDPR Statement is provided for general informational purposes and does not constitute a contract, warranty, or legally binding commitment. For legally binding terms governing the processing of personal data by 3CX, customers should refer exclusively to the 3CX Data Processing Addendum (DPA) and Privacy & Cookies Policy.

3CX acts as a data controller for account, licensing and customer-portal data, and may act as a processor for certain cloud-based or hosted PBX services, where applicable. Customers remain responsible for configuring and operating their 3CX systems in compliance with GDPR and other applicable laws. For clarity purposes it is noted that self-hosted PBX deployments place full “controller” responsibilities on the customer, and 3CX has no access to PBX content/data unless (a) customer enables hosting services or (b) customer requests support access.

Data Protection in 3CX Phone System

In regards to data protection the 3CX Phone System includes multiple security features designed to support compliance and safeguard data, for example:

  • Your 3CX Phone System database is designed so that it is not exposed to the WAN or LAN when deployed following recommended security practices, and can be accessed only by the local system.
  • The Management Console will blacklist any offender who inputs incorrect credentials 10 times
  • The Management Console access can be done only through HTTPS
  • The 3CX SSL certificate included when using a 3CX FQDN is signed by a trusted authority and transport has strong encryption ciphers
  • 3CX Call Reports or voicemails or recordings can be accessed only by authenticated users

3CX does not monitor, access or analyse the content of communications, in compliance with the EU ePrivacy framework, except where explicitly required for security incident response or where the customer requests diagnostic support.

Fraud Prevention & Misuse

3CX implements measures designed to assist customers in identifying, preventing and mitigating fraudulent or abusive calling activity. These include rate-limit mechanisms, IP-based access restrictions, blacklist/whitelist functionality, and event-based notifications where configured.

Customers remain responsible for configuring their system appropriately and applying recommended anti-fraud safeguards.

3CX may process certain technical and traffic-related metadata for the purposes of detecting, preventing and responding to fraud, service abuse, or security incidents, on the basis of 3CX’s legitimate interests (Art. 6(1)(f) GDPR), and only to the extent strictly necessary for fraud detection and security purposes.

3CX cooperates with law enforcement agencies when presented with valid and lawful requests.

Configuration & Access Controls

The configuration can be adjusted to strengthen access or clear periodically old data:

  • Access rights segregation exists to delegate management console partial access
  • Passwords can be renewed at any time
  • 3CX log files have low verbosity by default
  • Logging can be turned off completely
  • Call history can be purged manually by the administrator for a given period
  • 3CX Phone System voicemails and recordings quota can be set to delete automatically everything older than a configurable number of days
  • 3CX Phone System voicemails can be sent by email and immediately deleted, such that they are not stored locally at all

Security depends on proper customer configuration. Administrators are responsible for implementing adequate access controls, password policies, IP restrictions, and data-retention settings appropriate to their environment.

Customers are solely responsible for ensuring that disabling logs does not compromise their own compliance, auditability, or security obligations.

International Data Transfers

Where personal data is transferred outside the EU/EEA, 3CX relies on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or other approved transfer mechanisms, as reflected in the DPA. Any subprocessors outside the EEA are listed in the DPA and are subject to SCCs and transfer impact assessments (TIAs).

Data Subject Rights

Individuals are entitled to exercise their rights under GDPR (access, rectification, erasure, restriction, objection, portability). These rights can be exercised by contacting 3CX through the contact details provided in the Privacy Policy. Where 3CX acts as a processor, data subject requests relating to PBX content must be directed to the customer (data controller).

Contact Information

For GDPR-related enquiries, data subject rights requests, or security concerns, customers may contact the 3CX Privacy Team or Data Protection Officer using the contact details provided in the main 3CX Privacy Policy.

Data Processing Addendum (DPA)

Customers in EU/EEA can refer to the Data Processing Addendum (DPA) found in their Customer Portal/Subscriptions/key page, which details further our data processing and subprocessors.

In case of any inconsistency between this GDPR Statement and the DPA, the DPA shall prevail and constitute the sole legally binding document governing 3CX’s role as a processor.

See Also

Last Updated

This document was last updated 26 June 2026

https://www.3cx.com/company/gdpr-statement/