Guide

GDPR and AI meeting transcription: who is actually responsible

No AI transcription tool is "GDPR compliant" by itself. The regulation puts the duties on the organisation that decides to record a meeting, and that organisation is you, not the app. Your job is to pick a lawful basis, tell people, keep only what you need, and check what the vendor really does with the audio. This page is general information, not legal advice, so speak to a lawyer who knows your country before you rely on it.

Updated September 2026

The short answer, and who carries the obligation

A vendor can help you comply. A vendor cannot be compliant on your behalf. GDPR hands out duties by role, not by product.

The organisation that decides why a meeting is recorded and how the recording is used is the controller (Article 4(7)). The company whose software turns that audio into text on your instructions is the processor (Article 4(8)). You are the controller when you record a client call, a stand-up, an interview or a lecture. Almost every enforceable duty on this page sits with you, not with the app.

So when a tool's homepage says "GDPR compliant", read it as shorthand for "we built features that let a controller comply". Article 42 does allow official certification schemes, but very few exist, and nobody can claim one they have not been granted.

Plain disclaimer, up front. This is general information for people choosing a tool for work. It is not legal advice. The law changes and national rules differ. If the recordings matter, ask a lawyer or your data protection officer.

One line worth knowing early: under Article 28(10), a processor that starts deciding purposes and means of its own becomes a controller for that processing. That is the line a vendor crosses when it trains its own models on your recordings.

Noter AI records, transcribes and summarizes your meetings on iPhone, iPad & Android, in 60+ languages.

Choosing a lawful basis for recording a meeting

Every recording needs one of the six lawful bases in Article 6(1). For meetings only two are realistic: consent under Article 6(1)(a), or legitimate interests under Article 6(1)(f). Pick one, write down which, and be able to explain it later.

Consent is stricter than people expect. Article 4(11) says it must be freely given, specific, informed and unambiguous, and Article 7(3) says a person can withdraw it at any time, as easily as they gave it. Most teams never answer the obvious follow-up: if one of eight people withdraws two days later, what happens to the file, the transcript, and the summary already emailed round?

Consent is weakest exactly where companies lean on it hardest, which is with their own staff. The Article 29 Working Party's Opinion 2/2017 on data processing at work concluded that consent cannot be a valid basis for most workplace processing, because the imbalance of power between employer and employee means it is rarely freely given.

Legitimate interests is not the easy option either. The EDPB's guidance on Article 6(1)(f) sets a three-step test: name the interest, show the processing is necessary for it, then balance it against the rights and reasonable expectations of the people recorded. Necessity is where most recordings fail. If written notes would do the job, recording everyone in the room is hard to call necessary.

QuestionConsent, Article 6(1)(a)Legitimate interests, Article 6(1)(f)
Works best forExternal people: clients, candidates, research participantsInternal meetings where recording is routine and expected
Biggest weaknessMust be freely given, so it is fragile with employeesYou must run and document a balancing test first
Can they pull out?Yes, any time under Article 7(3)Yes, under Article 21(1), and you stop unless you show overriding grounds
What you keep on fileProof of who consented and to what, under Article 7(1)A written legitimate interests assessment
What quietly breaks itMaking the recording a condition of attendingRecording more than the stated purpose needs

Transparency: what you tell people, and when

Article 13 applies when you collect personal data from the person it belongs to. Recording someone's voice is collecting from them directly, so the information is due at the time of collection. In plain terms: before you press record, not in a follow-up email.

Article 12(1) adds that it must be concise, transparent, intelligible, easily accessible and in clear, plain language. A link to a 4,000-word policy nobody opens does not really meet that.

Two channels work together. Put a short line in the calendar invite so people know before they join, then say it out loud at the start. The spoken version is useful evidence because it sits inside the file itself, timestamped, with everyone present. The wording and the awkward cases are in do you have to tell people you're recording a meeting.

  • Who you are. Controller identity and contact details, plus a DPO if you have one.
  • Why you are recording. The purpose, in one plain sentence.
  • Your lawful basis. Consent or legitimate interests, and what that interest is.
  • How long you keep it, and who else sees it, including the vendor and its cloud provider.
  • Whether it leaves the EEA, and which transfer safeguard covers that.
  • Their rights. Access, rectification, erasure, objection, withdrawal, and complaining to a supervisory authority.

Record less, keep it less

Article 5(1)(c) says personal data must be adequate, relevant and limited to what is necessary. Article 5(1)(e) says you keep it no longer than you need it. Both are easy to break with a tool that makes recording quick enough to become a reflex.

In practice: skip the small talk before the meeting starts, stop recording for the HR item someone raises, and do not record every one-to-one just in case. A recording you never needed is a risk you took for nothing.

Retention is the failure most teams only notice during an audit, because recordings pile up in a shared drive for years and nobody set a date. Decide a period per type of meeting, write it down, and check the tool can enforce it, including in backups and at the sub-processor. Sensible ranges are in how long you should keep meeting recordings.

Article 5(2) is what catches people out. Doing the right thing is not enough, you have to show you did it: a written basis, a written notice, a written retention rule, and a record of processing under Article 30. The Article 30(5) exemption for organisations under 250 employees helps less than it looks, because it falls away when processing is not occasional, and weekly meeting recording is not occasional.

Special category data, biometrics, and DPIAs

Article 9(1) treats some data as special category: health, beliefs, trade union membership, political opinions, racial or ethnic origin, sex life, plus biometric data used to identify someone. It needs a condition under Article 9(2) on top of your Article 6 basis, usually explicit consent.

You cannot control which of those turns up in a meeting. A supplier call becomes special category data the second a customer explains a health reason for a missed deadline. A human note taker writes "delay agreed" and moves on. A recorder keeps the sentence in full, in the audio and in a searchable transcript.

The biometric question comes up constantly, so here is the precise answer. Voice recordings are biometric in nature, but Article 9 only bites when biometric data is processed for the purpose of uniquely identifying a natural person. Speaker labels that split one file into Speaker 1 and Speaker 2 separate voices inside that recording, they do not match anyone against a stored voiceprint. Voice authentication, or a saved voice profile reused across recordings, crosses that line. Ask your vendor which it does.

On DPIAs: Article 35(1) requires one where processing is likely to result in a high risk to people's rights and freedoms, especially with new technology. Article 35(3) names three cases where one is always required, including large-scale processing of special category data. Regulators also publish their own lists under Article 35(4), so check yours.

Requests from the people in the recording

Anyone who spoke in a meeting you recorded is a data subject, and they exercise their rights against you, not the app.

Access, Article 15. They can ask for a copy of their personal data, and what they said is their personal data. The Article 12(3) deadline is one month from receipt, extendable by two further months for complex requests if you tell them within the first month and explain why.

The awkward part. A recording contains several people. Article 15(4) says the right to a copy must not adversely affect the rights and freedoms of others, so handing over raw audio of a six-person meeting because one person asked is usually wrong. Supply the relevant transcript sections instead, redacting others where you can.

Erasure, Article 17. If your basis was consent and it is withdrawn, Article 17(1)(b) applies. If it was legitimate interests and they object under Article 21(1) with nothing overriding on your side, Article 17(1)(c) applies. Either way you must find one person's data, which is impossible if you do not know which recordings exist.

Rectification, Article 16. An automatic transcript is not automatically accurate. If it puts a sentence in the wrong person's mouth or mangles a name, that is inaccurate personal data and the person can ask you to fix it. Pick a tool where the transcript can be edited and the summary regenerated, so the correction carries through.

Where the audio is processed: international transfers

Almost every AI transcription tool sends audio to a server rather than running the model on your phone. So Chapter V of GDPR, Articles 44 to 49, is in play the moment that server sits outside the EEA.

You have three routes. An adequacy decision under Article 45. Standard contractual clauses under Article 46(2)(c), plus a transfer impact assessment. Or a derogation under Article 49, which is written for occasional situations, not for a pipeline that runs every working day.

For the United States the relevant instrument is the EU-U.S. Data Privacy Framework adequacy decision, covering transfers to US organisations that have self-certified to it. Its status is settled for now, not permanently: the EU General Court rejected the action to annul it in Latombe v Commission on 3 September 2025, and, as of September 2026, an appeal against that judgment is still pending at the Court of Justice as Case C-703/25 P. Check the docket before you lean on this, because the day the Court rules the answer can move. Anyone selling you certainty about US transfers is overselling.

Check the vendor and its sub-processors yourself on the official Data Privacy Framework list rather than trusting a logo on a pricing page, and ask for a written sub-processor list with notice before it changes.

Do not confuse two questions. "Encrypted at rest" is a security measure under Article 32. "Stored in the EU" is a transfer question under Chapter V. A vendor can say yes to the first and still send your audio across an ocean. See where are my meeting recordings stored.

National rules that sit on top of GDPR

GDPR is not the only law that governs recording a conversation. The extra rules are sometimes stricter, and sometimes criminal.

Germany is the clearest example. Section 201 of the German Criminal Code, violation of the confidentiality of the spoken word, makes it a criminal offence to record the non-public spoken word of another person without authorisation, punishable by up to three years in prison or a fine. Passing that recording to a third party can be a separate offence. This is criminal law. It applies however tidy your GDPR paperwork is, and it means every participant has to agree before recording starts.

Germany adds a second layer for employers. Where a works council exists, Section 87(1)(6) of the Works Constitution Act gives it co-determination over technical equipment designed to monitor employee behaviour or performance, and German courts read that broadly. No agreement, no rollout.

Article 88 is why this varies so much: each member state can write its own rules for the employment context, so a French, German, Dutch and Polish workforce do not get the same answer.

The UK kept UK GDPR, then amended it with the Data (Use and Access) Act 2025. Its data protection provisions came into force on 5 February 2026, and from 19 June 2026 controllers need a complaints process, acknowledging complaints within 30 days.

France shows the same idea in a softer form. There is no Section 201 equivalent, but Article L2312-38 of the Labour Code makes the employer inform and consult the works council before bringing in any technique that allows employee activity to be monitored. A tool rolled out quietly is already defective on that point before anyone opens the GDPR question, which is exactly what Article 88 is there to allow.

Outside Europe the test stops being GDPR and becomes local consent law, decided state by state in the US. That is a different question with different answers, and it is set out country by country in meeting recording laws by country.

The GDPR contract questions to put to a vendor

The wider security review — encryption, who inside the vendor can play a recording, backups, share links, certifications — is a separate job, and it is laid out in the AI note taker security checklist. The questions below are the narrower set: the ones that come straight out of the Article 28 contract and Chapter V, and that a processor has to answer in writing rather than in a sales call.

Send them before you buy, not after, and ask for the answers in the data processing agreement rather than in an email. Article 28(9) says the contract has to be in writing anyway, so anything a salesperson promises that is not in the DPA is not a processor obligation you can enforce.

Question to askWhich article it comes fromA good answer sounds like
Will you sign a data processing agreement?Article 28(3) requires a written contract before any processing startsYes, here is our DPA, and it carries every Article 28(3) term
Which sub-processors do you use, and how do we hear about changes?Article 28(2) needs your authorisation, general or specific, before a processor hands work onA dated public list, advance notice of changes, and a right to object
Which transfer tool covers audio that leaves the EEA?Chapter V, Articles 44 to 49, needs a named instrument, not a reassuranceAdequacy or standard contractual clauses, named, with a transfer impact assessment you can read
Do you train your own models on our recordings?That is the vendor's purpose, not yours, so Article 28(10) turns it into a controller for that processingNo, written into the contract, not into an FAQ page
Will you assist with access, erasure and objection requests?Article 28(3)(e) puts that duty on the processor, and your one-month Article 12(3) clock depends on itA documented route, a named contact, and a response time that fits inside your deadline
Will you help us run a DPIA?Article 28(3)(f) covers assistance with Articles 32 to 36, including prior consultationYes, with the technical detail the assessment actually needs
What happens to our data when the contract ends?Article 28(3)(g) makes it your choice to have it deleted or returnedDeleted or returned on your instruction, with a stated window that covers backups
Can we audit you, or see the evidence instead?Article 28(3)(h) gives the controller an audit and inspection rightAudit rights written into the contract, plus current evidence you can review under NDA

Where Noter AI stands, plainly

This site sells an AI meeting recorder, so here is where most pages would add a GDPR badge. We are not going to. Here is what is documented and what is not, so you can hold it against the checklist above.

Documented. Transcription happens in the cloud, not on your device, so the audio does leave your phone. Data is encrypted in transit and at rest. The privacy notice names the third-party services it relies on, Google Vertex AI for transcription and Google Firestore for storage, and says data may be processed in other countries. Treat that as the notice's own list rather than as a full sub-processor register with advance notice of changes, which is the Article 28(2) artefact a procurement team will ask for. You can delete a note at any time, and deleting your account deletes your data. On free accounts, recordings and transcriptions are removed automatically after 90 days.

Not documented. No SOC 2 report, no ISO 27001 certificate, no HIPAA compliance and no BAA. No published EU-only data residency, and no standard data processing agreement offered today. If your organisation needs any of those on paper before a tool is approved, Noter AI is not the right pick, and it is better to hear that now than three weeks into a procurement review.

Where it helps. Retention and deletion sit in your hands. The transcript is editable and the summary can be re-run after a fix, which is what Article 16 rectification asks for. For in-person meetings, recording runs from your own phone, so no bot with a company name joins the room. On Zoom, Meet, Teams and Webex a bot does join the call, and its visible presence is a useful prompt to give the notice, not a substitute for giving it. Either way the Article 13 duty is yours and not the app's, which is where GDPR puts it.

On accuracy, which is a duty and not just a quality question. Article 5(1)(d) says personal data must be accurate and, where necessary, kept up to date, and a transcript that puts a sentence in the wrong person's mouth is inaccurate personal data about a named individual. Transcription here covers 60+ languages with automatic detection, and language is tagged word by word, so a meeting that runs half in German and half in English comes back readable in both instead of the second language being transliterated phonetically. That matters less as a feature and more as the difference between a record you can stand behind and one you end up correcting under Article 16.

On price, $9.99 a month or $49.99 a year, flat rather than per seat. That has a compliance edge as well as a budget one. Seat licences push small teams toward sharing one login, and a shared login wrecks your accountability record under Article 5(2), because you can no longer say who made a recording, who agreed the lawful basis for it, or whose erasure request it belongs to. One subscription per person keeps that chain intact. There is a free trial. It is on the App Store and Google Play.

Whichever tool you pick: write down your lawful basis, put the notice in the invite and say it out loud, set a retention period the tool can enforce, then send the eight contract questions above to your vendor and keep the answers in writing.

Frequently asked questions

Is Noter AI GDPR compliant?

That question has no clean yes. Under GDPR your organisation is the controller and carries the duties, so compliance describes how you use a tool, not the tool itself. What is documented: transcription runs in the cloud, data is encrypted in transit and at rest, the privacy notice names the third-party services it uses, Google Vertex AI for transcription and Google Firestore for storage, and you can delete your notes or your whole account at any time. What is not documented: no SOC 2, no ISO 27001, no HIPAA or BAA, no EU-only data residency, no standard DPA today, and no formal sub-processor register with advance notice of changes. Check that against what your organisation requires.

Do I need consent from everyone in a meeting?

Under GDPR, not necessarily, because consent is only one of six lawful bases and legitimate interests under Article 6(1)(f) often fits internal meetings better. But national law can override that. In Germany, Section 201 of the Criminal Code makes recording someone's non-public spoken word without authorisation a criminal offence, so every participant has to agree regardless of your GDPR basis. Even where consent is not legally required, telling people is, under Article 13.

Can I rely on employee consent to record work meetings?

Usually not, and this is a common mistake. The Article 29 Working Party's Opinion 2/2017 on data processing at work concluded that consent cannot be a valid basis for most workplace processing, because the imbalance of power between employer and employee means it is rarely freely given. For internal meetings, legitimate interests under Article 6(1)(f) is normally more defensible, supported by a written balancing test done before you start recording.

Is a meeting recording biometric data under GDPR?

A voice recording is biometric in nature, but Article 9 only treats biometric data as special category when it is processed for the purpose of uniquely identifying a person. Speaker labels that split one file into Speaker 1 and Speaker 2 separate voices inside that recording, they do not match anyone against a stored voiceprint, so on their own they generally do not trigger Article 9. Voice authentication, or a saved voice profile reused across recordings, does. Ask your vendor in writing which of the two it performs.

Do I need a DPIA before rolling out an AI note taker?

Possibly, and you should check rather than assume. Article 35(1) requires a data protection impact assessment where processing is likely to result in a high risk to people's rights and freedoms, especially with new technology. Article 35(3) lists three cases where one is always required, including large-scale processing of special category data. Supervisory authorities also publish their own lists under Article 35(4) of processing that always needs a DPIA, so look at your national regulator's list before deciding.

How long can I keep a meeting recording under GDPR?

GDPR does not give a number. Article 5(1)(e) says you keep personal data no longer than necessary for the purpose you collected it for, so you set the period yourself and justify it. In practice a short window for routine internal meetings and a longer one for recordings tied to a contract or a legal obligation works well. Write the periods down, and confirm the tool can delete on schedule, including from backups and from any sub-processor.

What happens if someone in the recording asks for a copy of it?

You have to answer, and the clock in Article 12(3) is one month from receipt, extendable by two more months for complex requests if you tell them within the first month. You do not automatically hand over the raw audio, because Article 15(4) says the right to a copy must not adversely affect the rights and freedoms of others, and a meeting recording contains other people. The usual approach is to supply the transcript sections relating to that person, with other participants redacted where practical.

Does it matter that transcription happens in the cloud rather than on my phone?

Yes, in two ways. Cloud processing means the audio leaves your device, so your privacy notice must say so and name the categories of recipient. It also puts Chapter V in play if the servers sit outside the EEA, which needs an adequacy decision, standard contractual clauses, or a derogation. For US transfers the current instrument is the EU-U.S. Data Privacy Framework, which survived an annulment challenge at the EU General Court in September 2025, with an appeal still pending at the Court of Justice as of September 2026 (Case C-703/25 P). Check the current status before you rely on it.

Let Noter AI take your meeting notes

Record, transcribe, and summarize meetings on iPhone, iPad & Android, or send a bot to Zoom, Teams, Meet, or Webex. In 60+ languages.

Related reading