Privacy, consent and compliance

Recording meetings under GDPR: what to settle before you press record

Meeting recordings and transcripts are personal data. What GDPR asks — lawful basis, notice, retention, vendors — and what on-device transcription changes.

By the Notey team at AInject · · · 9 min read

In short

Recording a work meeting is processing personal data. The recording holds people's voices and what they said; the transcript holds the same words in searchable form; an AI summary holds a condensed version, often with names attached to commitments.

Under the General Data Protection Regulation (GDPR), all three are personal data about everyone in the meeting — not just about you.

That does not make recording meetings difficult. It means a few decisions should be made once, deliberately, before recording becomes a habit. This guide goes through them in the order they come up.

1. Work out who is responsible

GDPR puts obligations on the controller — whoever decides why and how the data is processed.

  • If you record meetings as part of your job, the controller is usually your employer, and its policies apply to you. Check whether it already has a rule on recording meetings.
  • If you are self-employed — a consultant, a lawyer in your own practice, a therapist — you are probably the controller yourself.
  • The "household" exemption, which takes purely personal activity outside GDPR, does not cover professional meetings.

Every service that handles the recording or transcript on the controller's behalf is a processor. That includes a transcription service, an AI provider that writes summaries, and a cloud backup. Each one needs a data processing agreement (Article 28), and each one is a place the data has gone that you will need to account for.

2. Choose a lawful basis

Article 6 lists six lawful bases. For meeting recordings, three are realistic.

Lawful basisWhen it fitsWatch out for
Legitimate interests (Art. 6(1)(f))Keeping an accurate record of business meetings, where the recording is expected and not intrusiveYou must do and document a balancing test, and people can object
Consent (Art. 6(1)(a))Meetings with outside parties who can genuinely say no, such as a research interviewConsent must be freely given, specific and as easy to withdraw as to give
Legal obligation (Art. 6(1)(c))Where a regulation requires recording, as for some financial-services callsOnly covers what the regulation actually requires

Two points trip people up.

Consent from employees is rarely valid. The European Data Protection Board's guidelines on consent say that, because of the imbalance of power, employees can seldom give consent freely to their employer. For internal meetings, legitimate interests with a clear notice is usually the sounder basis.

GDPR consent and "consent to record" are different things. Many countries have criminal or telecoms laws that make recording a private conversation without the participants' agreement an offence, whatever your GDPR basis. Germany's criminal code, for example, protects the confidentiality of the spoken word. So you may rely on legitimate interests for GDPR and still need everyone's agreement to record under national law. Asking at the start of the meeting covers both. See is it legal to record a meeting? for how consent rules differ.

3. Tell people, at the time

Article 13 requires you to tell people, when you collect their data, who you are, why you are recording, the lawful basis, who receives it, how long you keep it, and what rights they have.

In practice that means two things:

  1. Say it at the start of the meeting. "I'm recording this so I can write up accurate notes. The recording stays with me and I delete it after a month." A tool whose recording indicator only you can see — which is the case for any recorder that does not join the call — makes this sentence your job.
  2. Point to the full details in writing. A line in the calendar invite linking to your privacy notice is enough for most business meetings.

How to ask for consent to record has wording you can use.

4. Record only what you need, and keep it only as long as you need it

Two principles in Article 5 matter most for recordings.

Data minimisation. If you need notes, you may not need to keep the audio. If you need a transcript of what the client said, you may not need to record the internal chat after they leave. Stopping the recording when the part you need is over is a minimisation measure.

Storage limitation. Decide how long each thing is kept before you start, and write it down:

  • Audio: often the shortest period — long enough to check the transcript and notes.
  • Transcript: as long as you need to refer back to what was said.
  • Notes and action items: as long as the project or client relationship needs them.

Then actually delete. A retention period that nobody applies is a finding waiting for an audit.

5. Map where the data goes

This is where tools differ most, and where the choice of notetaker changes your paperwork.

For each meeting, list every place the audio, the transcript and the notes go:

  • Transcription. Many notetakers send audio to a cloud speech-to-text provider. That provider is a processor; if it is outside the EU or UK, the transfer needs a legal mechanism under Chapter V, such as the EU–US Data Privacy Framework or standard contractual clauses.
  • AI summaries. Sending the transcript to a language model is another processing operation, usually by another processor.
  • Storage and backup. Where the files rest, and who else can read them.
  • Bots. A bot that joins the call is operated by the vendor, which receives the full meeting stream.

When transcription runs on the device, the transcription provider drops out of the list for the audio entirely. That is a real simplification. It is not an exemption: the notes still have to be accounted for, and so do your laptop's own security and backups.

Where does meeting audio go? turns this into questions to put to any vendor.

6. Handle special categories with care

Some meetings contain special category data under Article 9 — health, religious or political beliefs, trade union membership, sex life or sexual orientation. A therapy session, an occupational health review or a grievance hearing may be full of it. Processing it needs an Article 9 condition as well as an Article 6 basis, and it raises the bar on every step above.

Voice recognition deserves a mention of its own. A voiceprint used to recognise who is speaking is biometric data processed to identify a person, which Article 9 treats as a special category. A notetaker that recognises people across meetings is doing exactly that, so it should be off unless you have deliberately decided to use it and told the people concerned.

7. Check whether you need a DPIA

A data protection impact assessment (Article 35) is required where processing is likely to result in a high risk to people. Routinely recording every internal meeting, recording employees' calls for monitoring, or processing special category data at scale are the kinds of cases that can trigger one. A single consultant recording client calls for their own notes usually is not — but if your organisation is rolling out a notetaker to everyone, assess it.

8. Be ready for access and erasure requests

Anyone recorded can ask for a copy of their personal data (Article 15) and, in many cases, for it to be erased (Article 17). That includes recordings, transcripts and notes that mention them.

You can only answer if you can find it. Keep meetings somewhere searchable, know which ones a person appears in, and know how to delete a meeting completely — audio, transcript, notes and any backups.

How Notey fits into this

Notey will not make you compliant; nothing you install will. What it does is keep the data map short, so the decisions above have fewer moving parts.

  • Audio stays on your Mac. It is recorded to your disk and transcribed there by the speech recognition built into macOS. No transcription service receives it.
  • Nothing leaves without an account. Recording, transcription and search work with no account and no network.
  • AI notes send text only, and only when you ask — or when a meeting ends, if you have turned automatic write-ups on. The transcript text goes to Notey's service and on to OpenAI, which acts as a processor and does not train on it; Notey does not keep it after the response. The privacy policy sets this out.
  • AI output is labelled wherever it appears, which also matters for the EU AI Act's transparency rules.
  • Voice recognition is off by default. When it is on, voices are stored on your Mac, listed on the People screen, and can be forgotten individually.
  • Deletion is complete. Deleting a meeting removes its recording, transcript and notes, and with sync on, from every one of your Macs.
  • Sync between your own Macs is optional and encrypted on the Mac with a key only your Macs hold. Recordings stay on the Mac that made them and are never uploaded, not even encrypted.
  • The recording indicator — a red dot and elapsed time — is on screen whenever audio is being kept. It is visible to you, not to the call, which is why step 3 matters.

A checklist to keep

  1. Know who the controller is, and whether a policy already exists.
  2. Pick a lawful basis and write down why.
  3. Check whether national law needs everyone's agreement to record.
  4. Tell people at the start, and point to a written notice.
  5. Set retention periods for audio, transcripts and notes — and apply them.
  6. List every processor the data passes through, and the transfer mechanism for each.
  7. Treat health, grievance and similar meetings, and voice recognition, as special category processing.
  8. Assess whether a DPIA is needed before rolling recording out to a team.
  9. Make sure you can find and fully delete any meeting on request.

Frequently asked questions

Not necessarily. Consent is one of six lawful bases, and for work meetings legitimate interests is often more appropriate, because consent from employees is rarely freely given. But GDPR is not the only law involved — national laws on recording conversations may require consent regardless of your GDPR basis.

Is a meeting transcript personal data?

Yes, if the people in it can be identified — by name, by voice, or by what they say. The audio, the transcript and an AI summary of it are all personal data about the participants.

Does on-device transcription make me GDPR compliant?

No. It removes one processor — the transcription service — from the chain, which simplifies your records and any transfer questions. You still need a lawful basis, a notice, a retention period and a way to answer access and erasure requests.

How long can I keep a meeting recording?

GDPR sets no fixed period. It requires you to keep personal data no longer than the purpose needs, and to decide that period in advance. Many teams keep the notes and delete the audio once the notes are checked.

Does this apply in the UK?

The UK GDPR and the Data Protection Act 2018 follow the same structure, and the Information Commissioner's Office is the regulator. The points in this guide apply in the same way.