GDPR and Transcription: What Companies Need to Know
Anyone who records meetings, transcribes interviews or processes dictation is processing personal data. Voices, names, opinions, sometimes health data or trade secrets - all of this falls under the General Data Protection Regulation (GDPR). Even so, many companies use transcription services without knowing the legal requirements.
This article explains which obligations apply, where the most common mistakes occur and how to use transcription in a GDPR-compliant way. At the end, we answer the questions most frequently asked about this topic: when the audio file may be deleted, which documentation is mandatory and what applies to meetings, doctor-patient conversations and US providers. Last updated: August 2026.
Why audio recordings are particularly sensitive
Audio recordings contain biometric features (the voice), often names and regularly sensitive information. In Germany, the non-publicly spoken word is additionally protected by § 201 of the Criminal Code, and in Austria by § 120 of the Criminal Code. A recording made without the knowledge of those involved can therefore be a criminal offense.
The GDPR classifies the processing of audio data as the processing of personal data under Art. 4(2). That means: every recording, storage and transcription needs a legal basis.
Legal bases for transcription
The safest legal basis for transcriptions is the explicit consent of all parties under Art. 6(1)(a) GDPR. Alternatives such as legitimate interest or contract performance are hard to enforce in practice, since courts regard manual minutes as the less intrusive option.
Art. 6(1) GDPR lists several possible legal bases. Three are relevant for transcriptions:
- Consent (Art. 6(1)(a)) - The safest basis. All parties must be informed before the recording and actively agree. Consent must be freely given, informed and revocable.
- Legitimate interest (Art. 6(1)(f)) - Theoretically possible, difficult in practice. Courts and data protection authorities argue that manual minutes are a less intrusive option.
- Contract performance (Art. 6(1)(b)) - Tenable only in exceptional cases, for example when the transcription is explicitly part of the contract.
Practical recommendation: Always obtain explicit consent. For meetings, this should be done in writing in the invitation and verbally at the start.
Special categories: health data and more
If recordings contain health data (medical dictation), trade union membership or religious beliefs, Art. 9 GDPR applies. These special categories require explicit consent - tacit agreement is not enough.
Transparency obligations: what you must disclose
Art. 13 and 14 GDPR require companies to inform data subjects comprehensively before the recording:
- That the recording and transcription take place, and for what purpose
- How long recordings and transcripts are stored
- Who gets access to the data (internally and externally)
- Whether a third-party provider (transcription service) is used
- What rights data subjects have (access, deletion, objection)
The problem with cloud transcription services
Many transcription tools process audio on servers outside the EU. This is problematic from a data-protection standpoint:
- Third-country transfer: Without an adequate level of protection (an adequacy decision, standard contractual clauses), the transfer is unlawful.
- Processing on behalf of a controller: The transcription service is a processor under Art. 28 GDPR - a data processing agreement (DPA) is mandatory.
- Access by the provider: With server-side processing, the provider has access to the plain text - a risk that many companies underestimate.
The safest solution: client-side encryption
Client-side encryption is the strongest technical safeguard under Art. 32 GDPR. Audio files are encrypted in the browser before they reach the server. Even in the event of a data breach at the provider, the data is worthless without the user’s key.
With client-side encryption, audio files are encrypted in the browser before they reach the server. The transcript is also stored encrypted - not even the provider can read the stored content.
For the GDPR this means: even in the event of a data breach at the provider, the data is worthless, because it cannot be decrypted without the user’s key. This is the strongest technical measure under Art. 32 GDPR.
Checklist for privacy-compliant transcription
- Obtain the consent of all parties before the recording
- Document the purpose and retention period
- Conclude a data processing agreement with the provider
- Check where the data is processed and stored (EU vs. third country)
- Ensure encryption - ideally client-side
- Define a deletion concept: when are recordings and transcripts deleted?
- Guarantee data-subject rights (access, deletion, objection)
- Maintain a record of processing activities under Art. 30 GDPR
Conclusion
Transcription without data protection is a legal risk. The GDPR sets clear requirements for consent, transparency and technical safeguards. Companies that process audio recordings should carefully vet their transcription service - in particular, whether the provider has access to the plain text and where the data is stored.
If you record meetings, you will find a practical solution - minutes, tasks and a transcript without a meeting bot, encrypted in Austria - on our page about AI meeting minutes. All plans start with a free 14-day trial; details are available on the pricing page.
Note: This article serves general information purposes and is no substitute for legal advice in individual cases.
Frequently asked questions
When can I delete the audio file after transcription?
You can delete the audio file as soon as the purpose of the recording has been fulfilled - usually once the transcript is available and has been approved. The GDPR requires storage limitation (Art. 5(1)(e)): personal data must not be kept for longer than the purpose requires. In practice, this means setting a fixed period in your deletion policy (e.g. 30 days after the transcript is approved) and deleting the recording automatically once that period expires. You may only keep it longer if there is a specific reason - for instance a statutory retention obligation or a documented legitimate interest such as preserving evidence. The transcript is usually the leaner document: it no longer contains the voice - a recording can be unambiguously attributed to an individual through voice recognition and can therefore become biometric data within the meaning of Art. 9 GDPR - and it is easier to anonymise.
What documentation obligations apply to transcription?
Four things should be documented: (1) An entry in your record of processing activities under Art. 30 GDPR - purpose, categories of data subjects and data, recipients (e.g. the transcription provider), time limits for erasure and technical and organisational measures; the legal basis is not a mandatory element, but supervisory authorities recommend including it. (2) A data processing agreement under Art. 28 GDPR with the provider, if the provider has or could have access to the data. (3) Evidence that data subjects were informed (Art. 13 GDPR) and - where processing is based on consent - the consent itself (Art. 7(1) GDPR). (4) For large-scale processing of sensitive data, such as health data in medical practices or studies, additionally a data protection impact assessment under Art. 35 GDPR. The exemption from the record of processing activities for organisations with fewer than 250 employees (Art. 30(5)) practically never applies to regular transcription: it ceases to apply as soon as processing is more than occasional or health data is involved.
Recording and transcribing meetings: what are the rules on consent and data protection?
For the recording itself: as a rule, you need the agreement of everyone involved. The non-public spoken word is protected under criminal law: in Germany, even secretly recording a conversation is a criminal offence (§ 201 StGB, German Criminal Code) - including when the person recording is a participant. In Austria (§ 120 StGB, Austrian Criminal Code), recording a conversation you take part in yourself is not a criminal offence, but passing it on or publishing it without the speakers' agreement is - and simply uploading it to a transcription service can already count as passing it on. Everyone involved must therefore know in advance that a recording is being made and must be able to agree to it. Under data protection law, the processing additionally needs a legal basis under Art. 6 GDPR: with external participants, this is usually consent (Art. 6(1)(a)); for internal work meetings, legitimate interest (Art. 6(1)(f)) may be an option, but it is open to challenge - supervisory authorities point to written minutes as a less intrusive means; consent remains the safe route. Be careful with consent from employees: it is only valid if it is genuinely freely given; in Germany and Austria, such questions are frequently regulated by works agreements (§ 87(1) no. 6 BetrVG and § 96 ArbVG respectively). Established good practice: announce the recording in the invitation and at the start of the meeting, state the purpose, retention period and the provider used, allow people to object - and delete the recording once it has been transcribed.
How do I recognise GDPR-compliant transcription software?
By five verifiable characteristics: processing and storage in the EU; a data processing agreement under Art. 28 GDPR; no use of your recordings to train AI models; encryption in transit and at rest - strongest when it is client-side, so the provider never sees the plaintext (zero-knowledge); and a deletion function that genuinely removes recordings and transcripts. In addition: access control, logging and support with your data protection impact assessment (Art. 28(3)(f) GDPR). There is no legally mandated GDPR seal of approval for software - it is the processing that is compliant, not the product; voluntary certifications under Art. 42 GDPR can be an indication. A provider that can demonstrate the points above will generally meet the requirements for technical and organisational measures under Art. 32 GDPR - but the specific risk of your processing always remains the deciding factor.
Can US cloud transcription services be used in a GDPR-compliant way?
Legally possible, but subject to conditions and with residual risk. Since July 2023, data transfers to the USA have been permitted on the basis of the EU-US Data Privacy Framework, provided the provider is certified under it. The Framework was upheld by the General Court of the EU in September 2025; however, an appeal to the Court of Justice (CJEU) is pending, and a US Supreme Court ruling of June 2026 on the independence of the FTC has raised fresh doubts (as of August 2026). Without certification, standard contractual clauses plus a transfer impact assessment are required. In any case: conclude a data processing agreement, check whether recordings are used for training purposes, and bear in mind that the provider processes the plaintext of your conversations. For sensitive content - health data, client information, trade secrets - processing in the EU without the provider having access to the plaintext is the considerably lower-risk choice.
Is it permitted to transcribe medical consultations or therapy sessions?
Yes, but under stricter conditions. Health data is a special category of personal data under Art. 9 GDPR; processing it requires one of the exceptions in Art. 9(2) - typically explicit consent (point (a)) or treatment by persons bound by professional secrecy (point (h) in conjunction with Art. 9(3)). On top of that comes the professional duty of confidentiality (in Germany § 203 StGB, German Criminal Code; in Austria § 54 Ärztegesetz, the Medical Practitioners Act, or, for psychotherapists, the Psychotherapiegesetz, the Psychotherapy Act): an external transcription provider may only be involved if it is contractually bound to confidentiality and its access is limited to what is necessary. On the technical side, client-side encryption minimises the risk most effectively, because the provider cannot read the content at all. For larger practices, hospitals and research institutions, a data protection impact assessment under Art. 35 GDPR is also often called for; for a single-practitioner practice it is not mandatory, but it is advisable when using AI tools.
Is AI transcription GDPR-compliant?
Yes, provided the processing complies with the rules of the GDPR - the technology itself is neither permitted nor prohibited. Specifically, you need a legal basis for the audio recording and the transcription (Art. 6, and Art. 9 GDPR for health data), informing those involved (Art. 13), a data processing agreement with the provider (Art. 28), technical safeguards such as encryption (Art. 32) and a deletion policy (Art. 5(1)(e)). It is also crucial whether the AI runs in the EU or in a third country, and whether the provider uses your recordings to train its models - the provider must disclose both. Responsibility always remains with the organisation that initiates the recording and decides on its purpose, not with the provider of the conferencing or transcription tool.
How long may I keep transcripts?
For as long as the purpose requires - and no longer than necessary (Art. 5(1)(e) GDPR). Statutory retention periods only apply if the transcript itself is a document subject to a retention obligation, for instance as business correspondence or an accounting record: in Germany, six years for business letters, eight years for accounting records (since 2025) and ten years for books and annual financial statements (§ 257 HGB, § 147 AO); in Austria, seven years (§ 132 BAO). Ordinary meeting minutes usually do not fall into this category; here, your deletion policy determines the period. Our recommendation: keep the transcript for as long as it serves as a working document; anonymise passages containing personal data as soon as they are no longer needed; and delete the underlying recording before the transcript.