Privacy, consent and compliance

Writing a meeting recording policy for your team

A one-page meeting recording policy: when recording is allowed, how people are told, retention, access, voice recognition and AI notes, with a template.

By the Notey team at AInject · · 6 min read

In short

A meeting recording policy says, in one page, when your team may record meetings, how people are told, who can listen, how long things are kept, and which tools and features are allowed. It turns a set of individual judgement calls into one decision made once.

This guide goes through what each section should say and why, and ends with a template to adapt. It assumes you have read, or will read, is it legal to record a meeting? for the legal layers underneath.

Why write one

Without a policy, each person decides for themselves whether to record, what to tell people, and how long to keep the audio. Those decisions will differ, and the one that goes wrong is the one a client or a regulator asks about.

A policy also answers questions before they come up. A client asks whether their calls are recorded; a candidate asks what happens to the interview; a colleague asks why the notes mention an AI. The answer is the policy.

In the UK, the Information Commissioner's Office's guidance on monitoring workers (October 2023) expects employers to be transparent about monitoring and to be able to show it is necessary and proportionate. If recordings of internal meetings could be used to assess people, that guidance applies, and a policy is where you say whether they will be.

What each section should say

1. When recording is allowed

Be specific. For example: client calls with the client's agreement, internal project meetings, research interviews with a signed consent form. Then say when it is not allowed: one-to-ones unless both people ask, performance and disciplinary meetings, meetings with legal counsel, anything where someone has objected.

2. How people are told

Say what everyone must do: a spoken notice at the start, after the recorder has started; a line in calendar invitations; asking again when someone joins late; stopping if anyone objects. Put the exact wording in the policy. How to ask for consent to record has scripts you can copy.

3. The strictest rule wins

State that when participants are in different places, the team follows the strictest applicable rule, so a single participant in an all-party consent state or country means everyone is asked.

4. Retention

Set separate periods for audio, transcripts and notes. Audio is the most sensitive and usually the least needed once notes exist. A common pattern is to delete audio within a set number of days after the notes are checked, keep transcripts for the life of the project, and keep agreed notes as long as other project records. Data-protection law asks you to decide this in advance; see recording meetings under GDPR.

5. Access

Who may listen to a recording or read a transcript: the person who recorded it, the project team, nobody else without a reason. Say how recordings are shared, if at all. Sharing notes is usually enough; sharing raw audio rarely is.

6. Tools

List the tools people may use and where each keeps its data. Ask every vendor the same questions: where audio is transcribed, what is stored, who processes it, whether it trains on it, how deletion works. Where does your meeting audio go? is a checklist for that.

7. Voice recognition

Tools that recognise people across meetings store a voiceprint, which can be biometric data under GDPR and laws such as Illinois's Biometric Information Privacy Act. Decide whether it is allowed. If it is, say who must be told and how. Recognising voices across meetings covers the questions.

8. AI notes

Say whether AI summaries are allowed, whether people must be told, and that AI-written text is checked by a person before it is sent anywhere. Keep AI output labelled as such; the EU AI Act's transparency rules point the same way.

9. Who to ask

Name a person. Questions about recording come up in the middle of a working day and need an answer that day.

A template to adapt

Copy this and change the parts in square brackets. Keep it to one page.

Meeting recording policy — [Team], [date]

1. We record meetings only to take accurate notes. We do not use
   recordings to assess anyone's performance.
2. You may record: client calls when the client agrees; internal
   project meetings; research interviews with a signed consent form.
   You may not record: one-to-ones unless both people ask;
   performance, disciplinary or legal meetings; any meeting where
   someone objects.
3. Start the recorder, then say: "I'm recording this so I can take
   accurate notes. [What happens to it.] Is everyone all right with
   that?" Wait for an answer. Repeat it for anyone who joins late.
   Scheduled meetings also carry a line in the invitation.
4. If participants are in different places, follow the strictest
   rule that applies to any of them.
5. Audio is deleted within [N] days of the notes being checked.
   Transcripts are kept until [the project ends]. Notes are kept
   with other project records.
6. Only [the recorder and the project team] may access recordings
   and transcripts. Share notes, not audio.
7. Approved tools: [list]. No other tool may be used.
8. Voice recognition across meetings is [off / allowed only when].
9. AI notes are [allowed / not allowed]. AI-written text stays
   labelled and is checked by a person before it is sent.
10. Questions: [name, contact].

Rolling it out

Share the policy before the first recorded meeting, not after. Tell clients about it where it affects them, and put a sentence in your engagement letters or contracts if clients are likely to ask. Review it when you change tools. Rolling out a notetaker to a small team covers the rest of the rollout, including a security review.

How Notey fits into a policy

If your team uses Notey, these are the facts to write into the tools section:

  • Where audio goes. It is recorded to the Mac's disk and transcribed there with Apple's on-device speech recognition. It is not uploaded to be transcribed.
  • What is sent. Only transcript text, and only when someone asks for AI notes or has automatic write-ups turned on. It goes to Notey's service and on to OpenAI as a processor, is not used for training, and is not retained by Notey.
  • When it records. It asks when it notices a call, and nothing is saved until the person presses Allow, unless they have set a rule in advance (arming the next call, "always record" an app, or ticked calendars), which is shown on screen and can be withdrawn. A policy can say which of those rules are allowed.
  • Voice recognition is off by default; voices are stored on the Mac and can be forgotten individually.
  • AI output is labelled, and edits are marked as edited.
  • No shared workspace. Each person's meetings stay on their own Mac; the Team plan is one bill, not shared storage. Notes are shared by exporting Markdown.

Frequently asked questions

Does a small team need a meeting recording policy?

If more than one person records meetings, a short written policy saves each of them from making the same decisions differently. It also gives you something to show a client or a candidate who asks how recordings are handled.

What should a meeting recording policy include?

When recording is allowed and when it is not, how people are told, who can access recordings, how long audio, transcripts and notes are kept, whether voice recognition and AI notes are allowed, and who to ask.

How long should meeting recordings be kept?

No law sets one number. Data-protection law asks you to keep personal data no longer than the purpose needs and to decide that in advance. Many teams delete audio once the notes are checked and keep notes longer.

Can employees record meetings without the company's permission?

That depends on the law where they are and on their contract and your policy. A policy that says clearly when recording is allowed avoids the question.