meetergo
A laptop on a video call with an AI note-taking panel open, and a shield icon marking the transcript as processed locally

AI Meeting Notes and GDPR: A 5-Step Compliance Checklist

|14 min read
Dominik Rapacki
Dominik Rapacki
Dominik Rapacki is the CEO and founder of meetergo.com, driving GDPR-compliant scheduling innovation. Featured in leading podcasts, he’s a recognized expert in SaaS, sales, and digital transformation

The person who switches on the AI notetaker is the one carrying the GDPR risk, and almost nobody frames it that way. Vendors sell compliance as a property of their software: certifications, encryption, a data processing agreement you sign once and forget. Under GDPR, none of that makes you the processor. You booked the call, you invited the participants, you decided to record them. That makes your company the controller, and the obligations that follow attach to you, not to the tool.

The awkward part is that the people with the strongest claim against you are usually not your colleagues. They're the client, the candidate, the supplier's project manager: everyone on the call who never installed anything, never saw a terms page, and often never got told a machine was listening.

Key Takeaways

  • You are the controller, the notetaker vendor is the processor. Signing a data processing agreement under Article 28 does not transfer responsibility for lawful basis, disclosure or deletion. Those stay with you.
  • Consent from the meeting host is not consent from the meeting. Every other participant is a separate data subject with separate rights, which is exactly the fault line running through the current US litigation over AI recorders.
  • Where the model runs matters as much as where the file is stored. A vendor can host transcripts in Frankfurt and still send the audio to a US inference endpoint for summarisation.
  • Retention is where most teams quietly fail. Transcripts default to forever in most tools, and forever is not a retention period a regulator will accept.
  • Some meetings should never be transcribed at all. Health, union membership, disciplinary matters and legally privileged conversations raise the bar so high that skipping the recording is the cheaper answer.

Why this got urgent in 2026

For two years the answer to "is our AI notetaker compliant?" was a shrug and a link to a SOC 2 report. That stopped working when the recording question moved into court.

In re Otter.AI Privacy Litigation is a consolidated case in the Northern District of California, brought by people who say they were recorded and transcribed on calls they joined without being asked. The claims run under the Federal Wiretap Act and the California Invasion of Privacy Act, and per UC Today's coverage of the case the plaintiffs are largely not customers of the product. A motion to dismiss was heard in May 2026. No ruling has issued, so no court has found anything unlawful yet.

That's US wiretap law, not GDPR, and it would be sloppy to pretend otherwise. What it does is expose the fact pattern that GDPR handles differently and, in some respects, more strictly. In the EU there's no two-party-consent doctrine to argue about, because consent is only one of six lawful bases and rarely the right one at work. Instead you owe every participant a clear explanation of what you're collecting, why, on what basis, for how long, and who else sees it, before the processing starts.

The friction is real and people notice it. In an r/legaltech thread on the case, one commenter described notetakers turning up on calls without their owner, because calendar-linked bots auto-join whether or not the person who invited them shows up. A practising lawyer in the same thread warned against putting confidential conversations through any third-party AI service unless you control the data or have a zero-retention arrangement.

Here's the workflow that holds up.

Step 1: Pick your lawful basis before you switch anything on

Most teams skip straight to a consent checkbox. That's usually the wrong basis and it creates a problem you can't undo later.

Article 6 gives you six options. For internal meetings with employees, consent is weak, because an employee can rarely refuse their manager freely, and a consent that isn't freely given isn't valid. Legitimate interests works better for ordinary business meetings: you document the purpose, you weigh it against the participants' expectations, you write down the outcome. For external calls with clients or candidates, legitimate interests also tends to fit, provided you're transparent and you offer a genuine way to opt out.

Write the assessment down and store it with your records of processing. If your DPO can't name the basis you're relying on, you don't have one.

The one place consent is the right answer is when the meeting content falls under Article 9: health data, trade union membership, religious or philosophical beliefs, sexual orientation, biometric identifiers. There you need explicit consent or a specific legal authorisation, and a checkbox at the bottom of a calendar invite won't get you there.

Step 2: Tell everyone before the recording starts, not after

Article 13 requires the information to reach the data subject at the point of collection. In practice that means three touchpoints, not one.

Put a line in the calendar invite body stating that the meeting may be transcribed by an AI assistant, name the tool, and link your privacy notice. Say it out loud in the first thirty seconds of the call and pause long enough for someone to object. Then make the objection route real: someone who says no should get a meeting without transcription, not a meeting where you keep recording and promise to delete the file later.

Two details people get wrong. First, a bot named "Notetaker" sitting silently in the participant list is not disclosure, because nobody is obliged to interpret your tooling. Second, if the notetaker is scheduled to auto-join meetings from your calendar, it will eventually join one you're not in. Turn auto-join off unless you have a process for the calls you don't attend.

If the meeting is an interview, the bar is higher again, because candidates are in an unequal position and the recording may feed into a hiring decision. Our interview and hiring scheduling setup for talent teams covers the coordination side; the disclosure script is on you.

Step 3: Find out where the audio goes and where the model runs

This is the step that separates a real assessment from a checkbox exercise, and it's the one enterprise reviewers keep flagging.

A security team that ran a formal review of AI notetakers across a 500-person company posted their findings on r/sysadmin: vague data-flow documentation, admin controls too thin for their headcount, audit logging that existed but wasn't granular enough, and no data residency options. One reply pushed it further and asked where inference actually runs, pointing out that plenty of certified vendors still route transcripts through cloud models even when storage sits in the right region.

That distinction is the whole game. Storage location is a marketing claim. Processing location is a Chapter V question. Ask the vendor four things in writing:

  • Which region stores the audio file, the transcript, and the derived summary, and are they the same region?
  • Which model provider generates the summary, and in which country does that inference happen?
  • Is your content used to train or improve any model, by the vendor or by a downstream provider?
  • What's the sub-processor list, and how are you notified when it changes?

If any answer routes to a US-controlled provider, you're into transfer territory: the Schrems II judgment invalidated Privacy Shield and set the standard for assessing whether the destination country's surveillance law undercuts your safeguards. We've written up how the CLOUD Act reaches data held by US companies regardless of where the servers physically sit, and what EU data sovereignty means in practice once you get past the marketing.

The cleanest way out of the transfer question is not to make a transfer. If the audio never leaves the laptop, there's no Chapter V analysis to run and no sub-processor list to police.

Step 4: Set a retention clock and actually honour deletions

Article 5 requires storage limitation: you keep personal data no longer than you need it for the purpose. Most notetakers default to indefinite retention, and most teams never change it.

Pick a number per meeting category and enforce it in the tool, not in a policy document. Sales discovery calls might justify 90 days. Interview recordings should usually go once the vacancy closes, unless local employment law says otherwise.

Then test the deletion path before you need it. A participant can ask for erasure, and your answer has to cover the audio file, the transcript, the AI summary, the copy that got pushed into your CRM, and any Slack or email thread the summary was auto-sent to. Tools that fan summaries out to every attendee by default make this materially harder, because you've now created copies you don't control.

Step 5: Run a DPIA when the content is sensitive

Article 35 triggers a data protection impact assessment when processing is likely to result in high risk. Systematic AI transcription of conversations involving health information, employee monitoring, or large-scale profiling lands in that zone.

You don't need one for every meeting type, only for the categories where the answer is genuinely uncertain: therapy and patient calls, disciplinary hearings, works council discussions, anything where the transcript could later be read as evidence. For regulated verticals, our notes on scheduling and data handling for law firms and privacy constraints in healthcare booking cover adjacent ground.

There's also a newer layer. The EU AI Act's Article 50 transparency obligations require that people are informed when they're interacting with an AI system, which lands directly on notetakers that speak, join, or send output on your behalf. Treat it as a second disclosure duty sitting on top of Article 13, not a replacement for it.

Tools that help

The category splits into two architectures, and the compliance work is completely different for each.

Cloud notetakers with a joining bot send audio to the vendor's infrastructure, transcribe and summarise there, then sync results back. They're easy to deploy across a team and give admins central controls, which is genuinely useful at scale. They also put you into the full Article 28, Chapter V and sub-processor workflow above, every time. If you're evaluating this tier, we compare the main options in our roundups of Otter.ai alternatives and Fireflies alternatives, and there's a broader field review in our guide to meeting transcription software.

Local notetakers run the speech model on the device itself. Nothing is uploaded, so there's no processor, no transfer and no training question, and the retention clock is whatever your own disk policy says.

meetergo Log is our take on the second approach. Whisper runs on the machine, transcripts stay on the machine, and Ghost Mode means no bot appears in the participant list and no "recording started" banner fires, because there's nothing joining the call. It handles 40+ languages with automatic detection, separates speakers, works offline, and imports existing recordings in eight-plus formats. It's free forever on every plan including the free tier, with no account required to transcribe.

meetergo Log transcribing a meeting locally on the desktop, with the transcript and AI summary side by side

Two honest limits. Ghost Mode removes the platform's recording banner, which means the disclosure duty in Step 2 falls entirely on you, and you should take that more seriously, not less. And a device-local tool gives you no central admin console or org-wide audit log, so if your security team's checklist looks like the r/sysadmin one above, a local app answers the data-residency question and leaves the governance question open. For teams that want the whole call inside EU infrastructure rather than on a laptop, meetergo connect handles the video side, and our security documentation sets out where platform data sits.

Common mistakes

Treating the vendor's DPA as the end of the work. A signed Article 28 agreement is the floor. It says nothing about whether your lawful basis holds or whether your disclosure reached the client on the call.

Confusing certification with jurisdiction. ISO 27001 and SOC 2 describe how well a company runs its security programme. Neither answers whether a US parent company can be compelled to hand over your transcripts, which is a separate analysis we walk through in our overview of data privacy laws by region.

Letting summaries auto-distribute. The moment a transcript lands in five inboxes and a CRM record, your deletion obligation has five more places to reach and your access controls have quietly stopped meaning anything.

Recording the meetings you shouldn't. A checklist that a commenter on the same r/sysadmin thread offered as a vendor-neutral baseline covers storage, role-based access, retention guarantees and audit logs. It's a good checklist. It still won't make a transcribed occupational health conversation a good idea.

Assuming the bot's presence counts as notice. It doesn't, and after the Otter litigation it's the assumption most likely to be tested.

Skip the transcript entirely if any of this is true

Not every meeting benefits from a compliance workflow. Some just shouldn't be recorded, and recognising them early saves more time than any tooling decision.

Skip it when the conversation is legally privileged, when it involves an employee's health or a disciplinary process, when a participant has objected once already, or when you're on a call with someone whose employer's policy you can't check. Take manual notes. The five minutes you lose are cheaper than a supervisory authority asking why a candidate's medical disclosure ended up in a searchable archive.

Get meeting notes that never leave your device

meetergo Log transcribes and summarises your meetings locally, so the audio never reaches a server and the transfer question never comes up. Free forever, no account needed, macOS and Windows.

Frankfurt-hosted

Transcribe meetings without a transfer problem.

Runs on your deviceNo audio leaves your machineFree forever
Get meetergo Log

FAQs

Is it legal to use an AI notetaker in the EU?

Yes, when you have a lawful basis under Article 6, you've informed participants before processing starts, and you can meet access and deletion requests. Nothing in GDPR bans automated transcription. What it bans is doing it quietly.

Do I need consent from every participant?

Not necessarily consent, but you do owe every participant the Article 13 information. For internal meetings, legitimate interests is usually the sounder basis, because employee consent is hard to treat as freely given. For special-category content under Article 9, explicit consent or a specific legal authorisation is required.

Does an EU data centre make a notetaker GDPR-compliant?

No. Regional storage is one input. You still need a lawful basis, disclosure, a retention schedule, and clarity on where inference runs and whether any US-controlled entity can be compelled to produce the data. Our write-up on GDPR compliance strategies goes through the wider picture.

What about the built-in transcription in Teams, Zoom and Google Meet?

Same analysis, different vendor. The platform is your processor, the disclosure duty is still yours, and you should check the tenant-level settings for retention and for whether transcripts feed any model improvement. We looked at one platform's settings in detail in our piece on Google Meet privacy.

Can we transcribe job interviews?

Technically yes, with disclosure and a documented basis. Practically, treat it as higher risk: candidates are in an unequal position, the transcript may influence a decision, and any health or disability disclosure during the call pulls you straight into Article 9.

How long can we keep meeting transcripts?

As long as the documented purpose requires, and no longer. Set a per-category schedule and enforce it in the tool. If nobody in your organisation can name the number, the retention period is effectively indefinite and that's the position you'd have to defend.

What's the lowest-effort compliant setup?

Local processing plus a disclosure line in every invite. It removes the processor, transfer, training and sub-processor questions in one move and leaves you with two obligations you can discharge: tell people, and delete on request. If you'd rather compare full tool options first, start with our roundup of AI note taker apps.

GDPR-compliant. Hosted on EU servers.

Replace five tools with one. Add only the apps you need.

Start with scheduling. Turn on forms, video, CRM and AI notes only when they fit your workflow.

No credit card required. Cancel anytime.