GDPR-compliant meeting recording: consent, storage and retention

Last updated: July 2026

Recording a meeting in Europe — or with anyone in Europe on the call — is not just an etiquette question; under the GDPR a recording is personal data, and processing it needs a lawful basis, honest disclosure and a plan for how long you keep it. This is a practical walk through consent, storage and retention for meeting recordings, written for the person who actually presses record. It is general information, not legal advice — when the stakes are high, ask a qualified adviser.

Why a recording is personal data

The GDPR defines personal data as anything relating to an identifiable person, and a recording of someone speaking — their voice, their name, what they said — is squarely that. Making and keeping the recording is “processing”, which the regulation only permits with a lawful basis. For meetings the usual basis is consent; occasionally “legitimate interests” is argued, but consent is the cleanest and most defensible for a conversation. Be especially careful if the discussion touches special-category data — health, beliefs, trade-union membership — which carries stricter conditions.

Consent, done properly

Valid consent under the GDPR is specific, informed, freely given and given before the recording starts. In practice that means a few concrete habits:

  • Say clearly, out loud, that you are recording and why — before you begin, not after.
  • Note it in the calendar invite and, ideally, in a line of the meeting description, so nobody is surprised.
  • Make opting out real: someone who declines should be able to keep the recording off without friction or penalty.
  • Remember that many US states add their own all-party-consent rules, and a cross-border call is generally governed by the strictest one that applies.

Storage: where the recording lives, and who else can reach it

Once a recording exists, GDPR expects you to protect it and to minimise how far it spreads. The first question is where it is stored. If you use a cloud notetaker, the audio and transcript sit on that vendor’s infrastructure — which makes the vendor a processor acting on your behalf, usually pulling in sub-processors and sometimes transfers outside the EU, all of which need a data-processing agreement and appropriate safeguards. Data minimisation cuts the other way too: capture only what you need, and do not quietly enrich the record with everyone’s job titles and emails just because the calendar makes it easy.

The architecture that most naturally satisfies minimisation is the one where the recording never leaves your own machine. If the audio is transcribed on-device and stored locally, there is no processor, no sub-processor and no transfer to account for — the data simply never spread. That is not a loophole; it is data protection by design, which the GDPR explicitly favours.

Retention: keep it only as long as you need it

The GDPR’s storage-limitation principle says you should not keep personal data longer than necessary for the purpose you collected it for. For meetings that means deciding, deliberately, how long a recording or transcript should live and deleting it when that time is up — not letting an archive accumulate indefinitely because the tool never prompts you to clean up. People also have a right to erasure: if a participant asks you to delete a recording of them, you generally have to be able to do it. Practical steps: set a retention window, delete the raw audio once you have the transcript and summary you actually need, and know exactly where every copy is so “delete it” is a real option.

Where on-device recording fits

None of this requires the cloud. Recording and transcribing a meeting entirely on your own Mac addresses several GDPR obligations at once: minimisation (nothing is sent anywhere), security (no third-party store to be breached), and erasure (one machine, one copy, genuinely deletable). It does not replace consent — keeping data local protects it from third parties but says nothing about whether the people in the room agreed — and it is not a compliance certificate. But it removes a whole category of processor, transfer and retention questions simply by not creating them. See private meeting notes for what “on-device by default” means in practice.

A short checklist

  • Before: decide your lawful basis, put the recording in the invite, and plan to announce it.
  • During: state that you are recording and why; let anyone opt out.
  • Storage: know where audio and transcript live; minimise what you capture; have a DPA for any vendor.
  • Retention: set a deletion window; remove audio you no longer need; be able to honour an erasure request.

This is general guidance rather than legal advice, and the specifics depend on your jurisdiction and the nature of the meeting. When in doubt, keep less and ask someone qualified.

Questions, answered

Is recording a meeting GDPR-compliant?

It can be, if you have a lawful basis (usually consent), tell participants before recording, store the recording securely, and delete it when you no longer need it. A recording is personal data, so all the usual GDPR principles apply.

Do I need consent to record a meeting under GDPR?

In most meeting situations, yes — consent is the cleanest lawful basis, and it must be informed and given before recording starts. Announce it out loud and note it in the invite.

How long can I keep a meeting recording under GDPR?

Only as long as necessary for the purpose you recorded it for. Set a retention window, delete the raw audio once you have the transcript you need, and be able to honour erasure requests.

Does recording on-device make a meeting GDPR-compliant?

It helps but does not settle it. On-device recording satisfies data minimisation and makes deletion straightforward, but you still need consent from participants. Consent and private storage are separate obligations.

Continue