Transcription and on-device AI

Recognising voices across meetings: the privacy questions

A notetaker that recognises voices across meetings stores voiceprints, which GDPR and Illinois BIPA treat as biometric data. What to ask before switching it on.

By the Notey team at AInject · · 7 min read

In short

A notetaker that recognises the same person across meetings has to store something about their voice to compare against — a voiceprint.

Under the GDPR and under Illinois' Biometric Information Privacy Act (BIPA), that is biometric data, which carries stricter rules than an ordinary recording: in many cases explicit or written consent, a published retention policy, and deletion on schedule.

The people whose voices are learned are usually not the person who installed the tool. They are the colleagues, clients and candidates on the other side of the call. That is the privacy question in one sentence, and this guide goes through what follows from it: the difference between telling voices apart and recognising them, what the law says, and what to check before turning the feature on.

Telling voices apart is not recognising them

Two different things get called "speaker identification".

  • Diarization splits one recording into speakers: Speaker 1 said this, Speaker 2 said that. It works within a single meeting and knows nothing about who anyone is. Speaker diarization explained covers how it works.
  • Recognition compares a voice against stored voiceprints and says "this is probably Priya". It works across meetings because it keeps something about Priya's voice from last time.

There is a third, simpler source of who-said-what: recording your microphone and the computer's sound as separate tracks. Your side and their side are known from which track the audio arrived on, and no voice has to be learned at all.

Only recognition stores a voiceprint, so only recognition raises the biometric questions below.

What the law says

GDPR: special category data

The GDPR defines biometric data in Article 4(14) as personal data resulting from specific technical processing of a person's physical, physiological or behavioural characteristics which allows or confirms their unique identification. A voiceprint used to recognise someone fits that description.

Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a person, unless one of the conditions in Article 9(2) applies. For recognising people in meetings, the realistic one is usually explicit consent under Article 9(2)(a). Explicit consent must be freely given, which is hard to show for employees recognised by their employer's tools.

The UK GDPR follows the same structure. Using special category data at scale can also trigger a data protection impact assessment. Recording meetings under GDPR covers the surrounding steps: lawful basis, notice, retention, processors.

Illinois: BIPA

The Biometric Information Privacy Act (740 ILCS 14) lists "voiceprint" by name as a biometric identifier. For private entities — a term the Act defines broadly, excluding government bodies — it requires, among other things:

  • a public written policy with a retention schedule, and destruction when the purpose is met or within 3 years of the person's last interaction with the entity, whichever comes first (section 15(a));
  • informed written consent before collecting a biometric identifier, after telling the person in writing what is collected, why and for how long (section 15(b));
  • no disclosure to others without consent, with limited exceptions (section 15(d)).

People can sue under BIPA themselves. The Act sets liquidated damages of $1,000 for each negligent violation and $5,000 for each intentional or reckless one, or actual damages if greater (section 20). An amendment signed in August 2024 (Public Act 103-0769) limits repeated collection from the same person by the same method to a single violation, and confirms that a written release can be given with an electronic signature.

Elsewhere

Other US states have biometric laws of their own — Texas, for example, lists voiceprint among biometric identifiers in its Business and Commerce Code — and several state consumer privacy laws treat biometric data as sensitive. The pattern is consistent enough to plan around: tell people, get their agreement, keep voiceprints only as long as needed, and delete them on request.

Questions to ask before turning it on

For any notetaker with speaker recognition, these questions decide how much of the above you take on:

  1. Is it on by default? A feature that learns voices the moment you install it has collected biometric data before anyone decided to.
  2. What triggers a voiceprint? Every speaker in every meeting, or only people you deliberately name?
  3. Where are voiceprints stored? On your device, or on the vendor's servers? If on servers, who can access them and in which country?
  4. Can you see the list? You cannot answer an access or deletion request for data you cannot find.
  5. Can you delete one person completely? Including from backups.
  6. Does it act on its own? A system that silently relabels a transcript can put the wrong name on a commitment. Suggestions you accept are easier to defend.
  7. Who are the people? Recognising your own team members, who can be told in advance, is different from recognising clients or job candidates.

Whatever the answers, the people being recognised need to know. How to ask for consent to record has wording that can be extended to cover recognition.

How Notey handles voice recognition

Notey tells your side from theirs by the two tracks, so knowing who is "You" and who is "Them" needs no voiceprint. When several people are on the other side, their voices are told apart after the recording within that meeting, and you name them. Recognising people across meetings is a separate feature, built around the questions above:

  • Off by default. It does nothing until you switch it on.
  • Created only when you name someone. Recording and transcribing do not create a voiceprint. Naming a speaker on the other side, with the feature on, saves their voice from that meeting.
  • Stored on your Mac. Voices are not sent anywhere in the clear. If you sync between your Macs, they travel sealed with everything else, and each Mac uses them only with voice recognition switched on there. Forgetting a voice on one Mac forgets it on all of them.
  • Listed. The People screen shows everyone remembered and which meetings contributed.
  • Suggested, never applied. In a later meeting a similar voice is offered as a suggestion, labelled as one, and you accept or reject it.
  • Forgettable. "Forget this voice" deletes a person's voiceprints. Deleting a meeting removes its contribution.

Notey's privacy policy notes that a voiceprint may be biometric data under laws including the GDPR and BIPA, and that if you turn the feature on in meetings with other people, having whatever notice or consent your jurisdiction requires is your responsibility. For how the transcription itself runs on the Mac, see on-device transcription explained.

Frequently asked questions

Is a voiceprint biometric data?

Under the GDPR, voice data processed with specific technical processing to uniquely identify a person is biometric data, and processing it for that purpose is a special category under Article 9. Illinois' Biometric Information Privacy Act lists "voiceprint" by name as a biometric identifier.

Is telling speakers apart in a transcript the same as voice recognition?

No. Diarization groups the voices within one recording into Speaker 1, Speaker 2 and so on, without knowing who anyone is. Recognition compares a voice with stored voiceprints to say who it is, across meetings, which is where biometric rules come in.

It depends on where you and the people recorded are. Illinois' BIPA requires informed written consent before a private entity collects a biometric identifier, and under the GDPR explicit consent is one of the few conditions that can apply. Check with your data protection officer or a lawyer before switching it on for meetings with other people.

Does Notey recognise voices by default?

No. It is off until you switch it on. When it is on, a voice is saved only when you name someone, stays on your Mac, and a name is only ever suggested, never applied by itself.