Guide

Is AI meeting transcription GDPR-compliant? It depends on where the audio goes.

Updated July 15, 2026·8 min read

Short version: transcription itself is not where GDPR gets difficult. Meeting audio contains personal data by definition (voices, names, opinions), so the real question is who processes it and where. That answer looks completely different for a cloud service than for a tool that runs on the phone. We built Fieldnoter on the on-device side of that line, so we have spent a long time with exactly these questions. What follows is plain-language background, not legal advice for your specific situation.

In this article

  1. How the GDPR roles work
  2. The cloud route: three things to arrange
  3. The on-device route: the questions mostly disappear
  4. Cloud vs on-device through a GDPR lens
  5. Do you need consent from participants?
  6. How to tell which kind of tool you have
  7. Frequently asked questions

How the GDPR roles work

GDPR thinks in roles. The party that decides why and how personal data is processed is the controller; for a recorded work meeting, that is normally your organization. Any external party that processes the data on the controller's behalf is a processor. The moment a transcription service receives your meeting audio on its servers, that service is a processor, and GDPR attaches concrete obligations to that relationship.

This role logic is why the location of the processing matters so much. The same recording, transcribed by the same class of speech model, triggers a completely different set of duties depending on whether the model runs on a vendor's server or on the phone in your pocket.

Diagram comparing a cloud notetaker, where audio is uploaded to a third-party server, with Fieldnoter, where audio never leaves the phone.
FIG. 01: the two architectures behind the same feature, and the GDPR questions that follow each.

The cloud route: three things to arrange

When a transcription service processes audio on its servers, that provider becomes a data processor for your organization. Under GDPR that means, at minimum:

None of this is impossible, but it is real work, and it explains why AI notetakers keep getting blocked at workplaces. Larger vendors offer EU data residency and signed DPAs precisely because they know these questions are coming. The assessment still has to be done, per tool, by someone qualified to do it.

The on-device route: the questions mostly disappear

When transcription runs on the phone itself and the audio never leaves the device, the picture changes structurally:

What remains, and this is important: recording a conversation is itself a processing activity. Your organization's policies on recording meetings, informing participants, and retention still apply, whatever tool you use. On-device processing removes the third-party problem; it does not remove your own responsibilities. For that reason we would not describe any tool, ours included, as "automatically GDPR-compliant". Compliance is something your organization does; a tool can only make it simpler or harder.

Cloud vs on-device through a GDPR lens

Cloud transcriptionOn-device transcription
Third party processes the audioYes, the providerNo
DPA needed for the transcriptionYes, Article 28Not for the transcription itself
Data locationProvider's servers, often USYour device
Transfer outside the EUOften, needs safeguardsNone
Your duties as recorderApply in fullApply in full

The last row is the one people skip. Both routes leave you with the same baseline duties around the recording itself; the difference is everything above it.

Assessing a tool for your organization? Our fact sheet for IT and security teams covers data flows, network behavior, and verification steps, on a single A4.

Read the IT fact sheet →

The most common question, and the least satisfying answer: it depends. Under GDPR, consent is one of several possible lawful bases for processing, so a recording is not automatically unlawful without it. Whether you need it in practice depends on your jurisdiction, the nature of the conversation, and above all your organization's own recording policy, which often goes further than the legal minimum.

The practical guidance is simpler than the legal analysis: tell people you are recording, before you start, every time. It costs one sentence, it is required by policy in many organizations, and it avoids the situation where a perfectly legal recording still damages trust. For anything sensitive, personnel matters, medical or legal conversations, check with your privacy officer first. This page is general background, not legal advice; for your specific situation, ask a qualified professional.

How to tell which kind of tool you have

Vendors describe their architecture in marketing language, so verify it yourself. Three checks, no expertise required:

The airplane mode test in three steps: turn on airplane mode, record and transcribe, and the full transcript appears while zero bytes were sent.
FIG. 02: the two-minute verification that settles the architecture question.

One honest footnote on the airplane-mode test: an on-device app still needs its speech model, and Fieldnoter downloads that model once at first setup. After that single download, everything runs offline on the phone's Neural Engine. A claim of "never touches the internet" would be false; "your audio never leaves the device" is the claim you can actually verify. For a security team that wants the full technical picture, we keep a fact sheet for IT and security teams with data flows and verification steps.

Frequently asked questions

Does GDPR prohibit AI meeting transcription?

No. GDPR does not ban any particular technology. It regulates the processing of personal data, and meeting audio contains personal data by definition: voices, names, opinions. The compliance work depends on who processes that data and where, which is why cloud and on-device tools raise very different questions.

Do I need a data processing agreement for an on-device transcription app?

A data processing agreement covers a party that processes personal data on your behalf. With Fieldnoter, transcription runs on your own device and the audio and transcripts never reach us, so there is no processing by us for such an agreement to cover. Your own obligations for the recording itself still apply. If your organization requires a formal assessment, involve your privacy officer.

Do I need consent from everyone in the meeting?

Not necessarily under GDPR, since consent is one of several possible lawful bases, but the honest answer is that it depends on your jurisdiction, the context, and your organization's policy. Telling participants you are recording is good practice in every case, and many organizations require it. Check your recording policy, and ask a privacy professional for your specific situation.

Does using an on-device app make me automatically GDPR-compliant?

No, and be wary of any tool that claims this. On-device processing can remove the third-party questions: no processor for the audio, no agreement to negotiate for it, no international transfer of the recording. Your own responsibilities remain: a lawful basis for recording, informing participants, retention, and secure storage.

How can I verify that audio never leaves the phone?

Put the phone in airplane mode and transcribe a recording. An on-device app completes the transcript with the radios off, because nothing in the pipeline depends on a server. Also check the App Store privacy label; Data Not Collected is audited by Apple. One honest footnote: Fieldnoter makes a one-time model download at first setup, and after that it runs offline.

We built Fieldnoter on the on-device model: transcription, speaker labels, and summaries on your iPhone, with nothing uploaded. We think that is the honest architecture for personal data, because it removes the third-party questions before they start. If that fits the work you do, it is on the App Store. Whatever you choose, the airplane-mode test above is the quickest way to see where a tool actually sends your audio.

See Fieldnoter

Read next