GDPR

The EU General Data Protection Regulation, which governs how the personal data of people in the EU/EEA is processed — including recordings of identifiable individuals — and requires a lawful basis, data minimisation and care with cross-border transfers.

Updated

A voice recording of an identifiable person is personal data under GDPR, so transcribing calls, meetings or interviews falls within scope. Controllers need a lawful basis, must minimise what they keep, and must be able to honour subject-access and deletion requests against the audio and its transcripts.

The harder constraint is transfer. Article 25 (“data protection by design and by default”) and the Schrems II ruling make sending EU personal data to US cloud services legally risky. On-prem transcription sidesteps the transfer question by processing audio locally, within the same jurisdiction, so nothing crosses a border. GDPR is separate from US frameworks such as HIPAA and SOC 2; meeting one does not satisfy the others.