The moment you let an AI tool record a meeting, you start processing personal data about everyone in the room. Under the GDPR that comes with duties: a reason you are allowed to do it, transparency toward the people recorded, a contract with your vendor, and control over where the data ends up. None of this is exotic, but skipping it is how a helpful tool turns into a compliance problem.
This guide walks through what actually applies, in plain language, and ends with a checklist you can run against any tool. It is practical guidance, not legal advice; for a specific case, check with your data protection officer or a lawyer.
Recording, transcript and summary are all personal data
A person's voice identifies them, and so does what they said and when. That means it is not only the audio that counts as personal data. The transcript and the AI summary do too, because they still tie statements to identifiable people. Your meeting tool processes all three on your behalf, which is exactly why the vendor relationship matters.
You need a lawful basis before you hit record
The GDPR does not ban recording. It asks you to have a lawful basis for it. For meetings, two come up most often:
- Consent. Participants agree to be recorded. Consent must be freely given, specific and easy to withdraw. It fits external calls and situations where people can genuinely say no.
- Legitimate interest. You have a real business reason (accurate minutes, for example) that is not overridden by the participants' rights. This needs a short balancing assessment on file and is common for internal meetings.
Whichever you rely on, tell people clearly. A line in the invite, a spoken note at the start, and the visible recording indicator all help. Silent recording is the fastest way to lose trust and breach the transparency rule at the same time.
Sign a data processing agreement with the vendor
Because the tool processes personal data for you, it is a processor and you are the controller. That relationship requires a data processing agreement, or DPA. A workable DPA should cover the recordings, the transcripts and the summaries, and it should spell out:
- What the vendor may and may not do with the data.
- Any sub processors they use, and where those sit.
- Security measures, breach notification and deletion on termination.
- Whether your data is used to train the vendor's models. For many teams the answer needs to be no.
If a vendor cannot produce a DPA, that alone is usually enough to take them off the list.
Why EU data residency matters
Where recordings are stored and processed is central to compliance. EU data residency means the data stays on servers inside the European Union, which sidesteps the harder questions around international transfers and gives many European organizations the certainty their own policies demand. It is not strictly the only lawful option, but it is the simplest one to defend, and for public sector, healthcare and finance it is often mandatory. Our comparison table marks which tools offer EU hosting.
Bot or no bot
Tools capture meetings in two ways, and the difference is about visibility, not legality. Either way you still need a lawful basis and transparency.
A recording bot joins the call as a named participant, so everyone can see recording is happening. That visibility is helpful for transparency, though some guests find it intrusive. On-device capture records without a bot, which feels lighter but is less obvious to others, so the duty to announce it falls on you. Neither approach removes the need for consent or legitimate interest; they just change how plainly the recording announces itself.
Respect participant rights and retention
People recorded in your meetings keep their GDPR rights. They can ask what you hold, ask for a copy, and in many cases ask you to delete it. That is far easier to honour if you decide up front how long recordings live and delete them on schedule. Keeping every transcript forever "just in case" is both a compliance risk and a security one. Set a retention period, automate deletion where the tool allows, and make sure someone owns the process.
Your GDPR checklist for meeting tools
- Chosen a lawful basis (consent or legitimate interest) and documented it.
- Told participants clearly, before recording starts.
- Signed a DPA covering recordings, transcripts and summaries.
- Confirmed EU data residency, or a defensible alternative, for storage and processing.
- Checked whether your data trains the vendor's models, and turned that off if needed.
- Set a retention period and a way to delete data on request.
- Decided bot or no bot, and made recording visible either way.
Work through that list and an AI meeting tool becomes a straightforward, compliant part of your workflow rather than a liability. To see which tools tick the EU hosting and GDPR boxes, use our comparison table, and if you are still deciding, our guide on how to choose an AI meeting tool puts privacy in the wider picture.