Important disclaimer: this article provides general information, not legal advice. For specific compliance questions, consult a qualified data protection professional or legal counsel.
Meeting transcription creates personal data. Audio recordings contain voices — a category of biometric data under GDPR. Transcripts contain names, opinions, and potentially sensitive professional information. If you're operating in Europe or handling data about EU residents, this has compliance implications worth understanding.
The good news: meeting transcription is entirely compatible with GDPR when done correctly. Here's what the regulation actually requires.
Is recording and transcribing meetings legal under GDPR?
Yes — with conditions. GDPR doesn't prohibit recording meetings. It requires that personal data processing has a valid legal basis. For meeting recordings in a professional context, the most commonly applicable bases are:
- Consent: all participants explicitly agree to being recorded
- Legitimate interests: the organization has a genuine business need and participants' interests don't override it
- Contract: recording is necessary for the performance of a contract
For most internal team meetings, legitimate interests is the applicable basis — as long as participants are informed. For external meetings with clients or candidates, consent is typically cleaner and more defensible.
The consent question in practice
You don't need a signed form for every meeting. A clear, upfront verbal statement works: "I'll be recording and transcribing this meeting for my notes. Is that okay with everyone?"
What you can't do is record covertly. In most EU member states, secretly recording a conversation is not only a GDPR violation but potentially a criminal offense under local law. Transparency is non-negotiable.
For remote meetings, many platforms (Zoom, Teams, Google Meet) show an on-screen notification when recording starts — this satisfies the transparency requirement for participants who acknowledge it.
Data minimization: only transcribe what you need
GDPR's data minimization principle means you should only collect and process personal data that's necessary for your purpose. In practice, this means:
- Don't record the entire meeting if you only need the last 20 minutes
- Don't keep raw audio once you have an accurate transcript
- Delete transcripts when they're no longer needed for the original purpose
A good practice: set a retention policy. Keep meeting transcripts for 90 days by default, then delete them unless there's a specific reason to retain.
The cross-border transfer problem
This is where many teams inadvertently create compliance risk. When you use a US-based transcription service (Otter.ai, Fireflies.ai, etc.), your meeting data — which includes personal data of EU residents — is transferred to the United States.
Such transfers are permitted under GDPR when appropriate safeguards are in place. Most major US services use Standard Contractual Clauses (SCCs) for this purpose. However:
- You need to have a Data Processing Agreement (DPA) with the service
- You should record this transfer in your Records of Processing Activities (ROPA)
- If your organization has strict data residency requirements, SCCs may not be sufficient
On-device transcription avoids this issue entirely. If the audio never leaves your device, there's no cross-border transfer to manage.
Special category data
GDPR imposes stricter requirements on "special category" data: health information, political opinions, religious beliefs, sexual orientation, trade union membership, and others. If your meetings routinely touch on these topics — HR discussions, medical consultations, union negotiations — you need explicit consent and additional safeguards.
This is particularly relevant for HR teams conducting performance reviews, disciplinary hearings, or health-related conversations.
Participants' rights
People whose personal data appears in a transcript have GDPR rights: access, rectification, erasure, and objection. In practice, this means:
- If someone asks to see their data in your transcripts, you must be able to provide it
- If someone asks for their data to be deleted, you need to be able to comply
- This is much simpler when transcripts are stored locally and organized clearly
Practical compliance checklist
- ✓ Inform participants before recording starts
- ✓ Obtain consent (explicit or through clear notice) — document it where possible
- ✓ Establish a legal basis for processing and document it
- ✓ Have a DPA with any third-party transcription service you use
- ✓ Apply a data retention policy to your transcripts
- ✓ Know how to respond to access or deletion requests
- ✓ If using cloud services, record the transfer in your ROPA
The simplest compliance path: transcribe on-device, store locally, delete when no longer needed. On-device transcription eliminates the cross-border transfer issue, simplifies your data map, and gives you full control over retention.
Ecla: GDPR-friendly by design
On-device transcription, no cloud storage, no cross-border transfers. Privacy compliance without the complexity.
Join the waitlist →