Skip to main content

Compliance

Recording meetings in Europe: consent, GDPR and what to say

Recording a meeting where people can be identified is processing personal data under GDPR, so you need a lawful basis, and you have to tell people. Consent is one basis and often not the best one, because consent has to be freely given and an employee cannot freely refuse their manager. Most internal recording runs on legitimate interests with a documented assessment; external calls are usually consent. Either way, the practical obligation is the same: say it out loud, at the start, every time.

Recording meetings in Europe: consent, GDPR and what to say

A recording is personal data

A meeting recording contains identifiable speech, and often a face. That makes it personal data, and the transcript and the summary derived from it are personal data too. Everything GDPR says about personal data applies to all three: a lawful basis, a retention period, the right of access, the right to erasure.

Choosing a lawful basis

Consent is the obvious choice and frequently the wrong one. Consent must be freely given, specific and withdrawable, and a power imbalance undermines it. An employee asked by their manager whether the team meeting can be recorded is not in a position to freely say no, and a regulator will say so.

For internal meetings, legitimate interests is usually the more defensible basis, provided you have done and written down the balancing test: what the interest is, why recording is necessary for it, and why it does not override the participants’ rights. For external calls, meaning sales, interviews and client work, consent is normally the right answer, because the other party genuinely can decline.

What to actually say

One sentence at the top of the call, before anything substantive: what is being recorded, why, and how to opt out. Something like: "I’ve got a notetaker in this call that records and transcribes it so I don’t have to type. It goes to our workspace and nobody outside it sees it. Happy to turn it off if you’d rather."

Then honour it. If somebody says no, the recording stops, and there needs to be a way to stop it that does not require ending the meeting.

Why a visible bot is easier than a hidden one

A notetaker that appears in the participant list is doing part of your transparency obligation for you. Everyone who joins can see it, including the person who arrives ten minutes late and missed the announcement. A tool that records without any indication puts the entire burden on whoever remembered to say something.

This is also the direction the platforms are moving. Microsoft’s 2026 restrictions on third-party Teams bots exist because of unconsented capture, not because of transcription.

The three questions that catch people out

How long do you keep it?

Indefinitely is not an answer under data minimisation. A retention period has to exist, be written down, and actually run. This is the single most common gap between what a privacy policy says and what a system does, including, at the time of writing, ours: NeurTask deletes on request but has no automatic expiry yet, and our security page says so.

Where is it processed?

Application servers in Frankfurt do not mean much if the audio is sent to a speech-to-text provider in Virginia. Ask the vendor where the transcription and summarisation actually run, not where the database is. Transfers outside the EEA need a transfer mechanism and, increasingly, a customer who has read it.

Who else can see it?

Every sub-processor that touches meeting content should be listed publicly, with what they receive. If a vendor will not give you that list, that is the answer.

A workable default policy

  1. 1External calls: consent, asked at the start, recorded in the meeting notes.
  2. 2Internal calls: legitimate interests, with a written balancing test and an easy opt-out.
  3. 3Interviews and anything involving a candidate or a patient: consent, always, and ask before the call rather than during it.
  4. 4A retention period that exists in the product, not only in the policy.
  5. 5A named person who handles access and deletion requests, and a mailbox that reaches them.

Compliance

Questions

Do I need consent from everyone to record a meeting in the EU?

You need a lawful basis and you need to inform people. Consent is one lawful basis and is usually right for external calls; for internal meetings, legitimate interests with a documented balancing test is often more defensible, because consent given to an employer is rarely freely given.

Is a transcript personal data under GDPR?

Yes. A transcript of identifiable speech is personal data, and so is a summary derived from it. Access and erasure rights cover all three artefacts, not just the audio file.

Does an AI notetaker have to be visible in the meeting?

GDPR requires transparency rather than a specific mechanism, but a notetaker that appears in the participant list discharges part of that obligation automatically and covers latecomers who missed the verbal announcement. Some jurisdictions additionally require all-party consent to record.

Try it on your next call

Connect a calendar, let the notetaker join one meeting, and see what comes back. It takes about two minutes and costs nothing.

Free plan available. No card required.