Guide
Is AI meeting transcription GDPR-compliant? It depends on where the audio goes.
Short version: transcription itself is not where GDPR gets difficult. Meeting audio contains personal data by definition (voices, names, opinions), so the real question is who processes it and where. That answer looks completely different for a cloud service than for a tool that runs on the phone. We built Fieldnoter on the on-device side of that line, so we have spent a long time with exactly these questions. What follows is plain-language background, not legal advice for your specific situation.
In this article
How the GDPR roles work
GDPR thinks in roles. The party that decides why and how personal data is processed is the controller; for a recorded work meeting, that is normally your organization. Any external party that processes the data on the controller's behalf is a processor. The moment a transcription service receives your meeting audio on its servers, that service is a processor, and GDPR attaches concrete obligations to that relationship.
This role logic is why the location of the processing matters so much. The same recording, transcribed by the same class of speech model, triggers a completely different set of duties depending on whether the model runs on a vendor's server or on the phone in your pocket.
The cloud route: three things to arrange
When a transcription service processes audio on its servers, that provider becomes a data processor for your organization. Under GDPR that means, at minimum:
- A data processing agreement (DPA) with the provider, covering what they may do with the audio, retention, and sub-processors. Article 28 makes this mandatory, and the sub-processor list deserves real attention: your audio may pass through hosting providers and AI vendors you have never heard of.
- A lawful basis and transparency. Meeting participants should know their words are being processed by a third party, and depending on the situation you may need their consent.
- An international transfer assessment if the provider or its infrastructure is outside the EU. Transfers need a valid mechanism under Chapter V, such as an adequacy decision or standard contractual clauses. For US providers this is the hard part: legislation like the CLOUD Act can compel access to data they hold, wherever the servers stand, which is why many EU compliance teams simply say no, whatever the privacy policy promises.
None of this is impossible, but it is real work, and it explains why AI notetakers keep getting blocked at workplaces. Larger vendors offer EU data residency and signed DPAs precisely because they know these questions are coming. The assessment still has to be done, per tool, by someone qualified to do it.
The on-device route: the questions mostly disappear
When transcription runs on the phone itself and the audio never leaves the device, the picture changes structurally:
- No processor for the content. No third party touches the audio, so there is no DPA to negotiate for it and no sub-processor chain to audit. To be precise about the legal logic: the DPA obligation attaches to processing carried out by an external party on your behalf, and with on-device transcription that processing does not exist.
- No international transfer. The recording is not transferred anywhere, so there is nothing for transfer rules to apply to. The CLOUD Act question dissolves for the same reason: there is no US provider holding your audio.
- Data minimization by architecture. The strongest privacy measure is data that never leaves your control in the first place.
What remains, and this is important: recording a conversation is itself a processing activity. Your organization's policies on recording meetings, informing participants, and retention still apply, whatever tool you use. On-device processing removes the third-party problem; it does not remove your own responsibilities. For that reason we would not describe any tool, ours included, as "automatically GDPR-compliant". Compliance is something your organization does; a tool can only make it simpler or harder.
Cloud vs on-device through a GDPR lens
| Cloud transcription | On-device transcription | |
|---|---|---|
| Third party processes the audio | Yes, the provider | No |
| DPA needed for the transcription | Yes, Article 28 | Not for the transcription itself |
| Data location | Provider's servers, often US | Your device |
| Transfer outside the EU | Often, needs safeguards | None |
| Your duties as recorder | Apply in full | Apply in full |
The last row is the one people skip. Both routes leave you with the same baseline duties around the recording itself; the difference is everything above it.
Assessing a tool for your organization? Our fact sheet for IT and security teams covers data flows, network behavior, and verification steps, on a single A4.
Read the IT fact sheet →Do you need consent from participants?
The most common question, and the least satisfying answer: it depends. Under GDPR, consent is one of several possible lawful bases for processing, so a recording is not automatically unlawful without it. Whether you need it in practice depends on your jurisdiction, the nature of the conversation, and above all your organization's own recording policy, which often goes further than the legal minimum.
The practical guidance is simpler than the legal analysis: tell people you are recording, before you start, every time. It costs one sentence, it is required by policy in many organizations, and it avoids the situation where a perfectly legal recording still damages trust. For anything sensitive, personnel matters, medical or legal conversations, check with your privacy officer first. This page is general background, not legal advice; for your specific situation, ask a qualified professional.
How to tell which kind of tool you have
Vendors describe their architecture in marketing language, so verify it yourself. Three checks, no expertise required:
- Put the device in airplane mode and try to transcribe. Cloud tools stop working; on-device tools do not notice.
- Check whether the app requires an account. A server-side product almost always does.
- Check the App Store privacy label. "Data Not Collected" is audited by Apple and hard to fake.
One honest footnote on the airplane-mode test: an on-device app still needs its speech model, and Fieldnoter downloads that model once at first setup. After that single download, everything runs offline on the phone's Neural Engine. A claim of "never touches the internet" would be false; "your audio never leaves the device" is the claim you can actually verify. For a security team that wants the full technical picture, we keep a fact sheet for IT and security teams with data flows and verification steps.
Frequently asked questions
Does GDPR prohibit AI meeting transcription?
No. GDPR does not ban any particular technology. It regulates the processing of personal data, and meeting audio contains personal data by definition: voices, names, opinions. The compliance work depends on who processes that data and where, which is why cloud and on-device tools raise very different questions.
Do I need a data processing agreement for an on-device transcription app?
A data processing agreement covers a party that processes personal data on your behalf. With Fieldnoter, transcription runs on your own device and the audio and transcripts never reach us, so there is no processing by us for such an agreement to cover. Your own obligations for the recording itself still apply. If your organization requires a formal assessment, involve your privacy officer.
Do I need consent from everyone in the meeting?
Not necessarily under GDPR, since consent is one of several possible lawful bases, but the honest answer is that it depends on your jurisdiction, the context, and your organization's policy. Telling participants you are recording is good practice in every case, and many organizations require it. Check your recording policy, and ask a privacy professional for your specific situation.
Does using an on-device app make me automatically GDPR-compliant?
No, and be wary of any tool that claims this. On-device processing can remove the third-party questions: no processor for the audio, no agreement to negotiate for it, no international transfer of the recording. Your own responsibilities remain: a lawful basis for recording, informing participants, retention, and secure storage.
How can I verify that audio never leaves the phone?
Put the phone in airplane mode and transcribe a recording. An on-device app completes the transcript with the radios off, because nothing in the pipeline depends on a server. Also check the App Store privacy label; Data Not Collected is audited by Apple. One honest footnote: Fieldnoter makes a one-time model download at first setup, and after that it runs offline.
We built Fieldnoter on the on-device model: transcription, speaker labels, and summaries on your iPhone, with nothing uploaded. We think that is the honest architecture for personal data, because it removes the third-party questions before they start. If that fits the work you do, it is on the App Store. Whatever you choose, the airplane-mode test above is the quickest way to see where a tool actually sends your audio.
See Fieldnoter