A recording is personal data
A meeting recording contains identifiable speech, and often a face. That makes it personal data, and the transcript and the summary derived from it are personal data too. Everything GDPR says about personal data applies to all three: a lawful basis, a retention period, the right of access, the right to erasure.
Choosing a lawful basis
Consent is the obvious choice and frequently the wrong one. Consent must be freely given, specific and withdrawable, and a power imbalance undermines it. An employee asked by their manager whether the team meeting can be recorded is not in a position to freely say no, and a regulator will say so.
For internal meetings, legitimate interests is usually the more defensible basis, provided you have done and written down the balancing test: what the interest is, why recording is necessary for it, and why it does not override the participants’ rights. For external calls, meaning sales, interviews and client work, consent is normally the right answer, because the other party genuinely can decline.
What to actually say
One sentence at the top of the call, before anything substantive: what is being recorded, why, and how to opt out. Something like: "I’ve got a notetaker in this call that records and transcribes it so I don’t have to type. It goes to our workspace and nobody outside it sees it. Happy to turn it off if you’d rather."
Then honour it. If somebody says no, the recording stops, and there needs to be a way to stop it that does not require ending the meeting.
Why a visible bot is easier than a hidden one
A notetaker that appears in the participant list is doing part of your transparency obligation for you. Everyone who joins can see it, including the person who arrives ten minutes late and missed the announcement. A tool that records without any indication puts the entire burden on whoever remembered to say something.
This is also the direction the platforms are moving. Microsoft’s 2026 restrictions on third-party Teams bots exist because of unconsented capture, not because of transcription.
The three questions that catch people out
How long do you keep it?
Indefinitely is not an answer under data minimisation. A retention period has to exist, be written down, and actually run. This is the single most common gap between what a privacy policy says and what a system does, including, at the time of writing, ours: NeurTask deletes on request but has no automatic expiry yet, and our security page says so.
Where is it processed?
Application servers in Frankfurt do not mean much if the audio is sent to a speech-to-text provider in Virginia. Ask the vendor where the transcription and summarisation actually run, not where the database is. Transfers outside the EEA need a transfer mechanism and, increasingly, a customer who has read it.
Who else can see it?
Every sub-processor that touches meeting content should be listed publicly, with what they receive. If a vendor will not give you that list, that is the answer.
A workable default policy
- 1External calls: consent, asked at the start, recorded in the meeting notes.
- 2Internal calls: legitimate interests, with a written balancing test and an easy opt-out.
- 3Interviews and anything involving a candidate or a patient: consent, always, and ask before the call rather than during it.
- 4A retention period that exists in the product, not only in the policy.
- 5A named person who handles access and deletion requests, and a mailbox that reaches them.