All posts
6 min read

GDPR-compliant AI transcription: seven checks for law firms and medical practices before choosing a service

A recording of a client meeting, a therapy session or a research interview is not an ordinary file. It contains voices, names and often health data. Anyone who hands it to an AI service for transcription is passing personal data to a third party, and the GDPR sets conditions for that.

This article is a checklist of seven questions to ask a provider before the first recording is uploaded. The basics are covered in “GDPR and Transcription: What Companies Need to Know”, the general questions in “5 Questions You Should Ask Your Transcription Service”; here the focus is on law firms and medical practices, with the GDPR articles in hand.

1. Is there a data processing agreement under Article 28?

Anyone who uses a transcription service is the controller; the service is the processor. Article 28 GDPR requires a written contract covering the subject matter, duration, nature and purpose of the processing, the obligation to follow instructions, confidentiality, the technical and organisational measures under Article 32 and any sub-processors. Without that contract, the processing is not lawful, however secure the technology may be. Ask for the document, not for a promise.

2. Where is the recording processed and stored, and by whom?

A data centre in the EU is the simplest answer. If the server is outside the EU, the transfer needs a legal basis under Chapter V, such as the EU-US Data Privacy Framework or standard contractual clauses, plus an assessment of the destination country. Ask for the complete list of sub-processors with their registered office and place of processing: many services run on a cloud platform that is itself located outside the EU or managed from there. A provider that does not list them in its privacy policy has not done its homework.

3. Are the recordings used to train models?

Some providers reserve the right to use recordings or transcripts to improve their models. That is a separate processing purpose the controller has not authorised, and with health data it is unlawful without the explicit consent of the data subjects. The answer must be a clear no, and it must be in the contract.

4. How is the file encrypted, and who holds the key?

Encryption in transit (HTTPS) is standard today and says little. More important: is the file also encrypted in the provider’s storage, and is it already encrypted on the user’s device before it is uploaded? And the decisive question: who holds the key? If the provider holds it, the provider can read what it stores and must hand it over if ordered to. If only the user holds it, the stored content is unreadable for the provider. Have the key concept explained to you, not just the word “encrypted”.

5. Who at the provider has access, and is it logged?

Ask about staff access rights, about logging and whether support staff can view content. Article 32 requires measures appropriate to the risk; with client or patient conversations, the risk is high.

6. How long are the recording and transcript stored, and how are they deleted?

Under Article 28(3)(g), the processor must delete or return the data at the end of the service. Ask for specific time limits: what happens to the original recording after processing, after cancellation, when an account is deleted, and are there backups with their own retention period? An answer such as “your data remains accessible for 90 days after cancellation and is then deleted completely” can be verified; “we treat your data confidentially” cannot.

7. Are special categories involved, and is an impact assessment required?

Health data and information about sexual orientation, political opinions or religion fall under Article 9. A therapy session or a medical consultation almost always contains them. In that case, besides the legal basis, you need to check whether a data protection impact assessment under Article 35 is required. That is the controller’s job, but a good provider supplies the technical information needed for it.

What this means when choosing a service

The seven questions form a simple grid: contract, location and parties involved, purpose, encryption, access, deletion, risk. A provider with a concrete, written answer to every question can be verified. One that refers you to its privacy policy usually cannot.

For completeness, this is how scryp answers these questions: the data processing agreement under Article 28 is available online. Recordings, transcripts and file names are encrypted in the browser with AES-256-GCM; the master key (MEK) is derived from the password and never leaves the browser. The servers hold only encrypted content that scryp cannot read without this key, not even by order of an authority. The original recording is deleted after processing. No training on customer data, no tracking on the website. After cancellation, 90 days of access, then complete deletion; deleting an account takes effect immediately. scryp does not carry out anyone’s impact assessment for them, but it provides the information needed for it.