gremlin.group / blog/ ai-meeting-notes-and-gdpr

PhonicAISmall BusinessSecurity

AI Meeting Notes and GDPR: What to Check Before You Hit Record

AI note-takers save hours of minute-taking, but every recording is personal data. Here is a practical UK GDPR checklist for small businesses and charities before switching one on.

Someone on the team finds an AI note-taker. It joins the Monday call, produces a tidy summary with action items, and everyone agrees it is a big improvement on handwritten minutes. Within a month it is recording supplier calls, trustee meetings and a one-to-one about a staff member’s sick leave.

Nobody checked anything first. That is common, and understandable. The tools are easy to switch on and the benefit is obvious. But a recording of a meeting, and the transcript made from it, is personal data. Under UK GDPR the organisation that decides to record is responsible for how that data is handled, whichever tool does the work.

None of this means AI meeting notes are off limits. It means a few questions need answering before the first recording, not after a complaint. This is general information, not legal advice.

Tell people they are being recorded

Everyone in the meeting should know it is being recorded and transcribed before it starts. That means internal staff, external guests, volunteers and anyone dialling in.

This is about transparency, and it is separate from consent. UK GDPR requires you to tell people how their information is used whatever lawful basis you rely on. A line in the meeting invite, a mention at the start of the call, and a reference in your privacy notice cover most of it. If a participant objects, have an answer ready, such as switching recording off for that meeting.

Have a lawful basis

UK GDPR requires a lawful basis for processing personal data, and the ICO’s guidance sets out the options. For meeting recordings the realistic candidates are usually legitimate interests or consent.

Consent is harder to rely on than it sounds. The ICO says consent will not usually be appropriate where there is a clear imbalance of power, and names employers as a particular example. Staff may feel they cannot say no to their manager. For internal meetings, legitimate interests is often the more realistic route, but it means weighing your reasons for recording against the impact on the people being recorded, and writing that assessment down.

Whichever basis you choose, decide it before you start recording and document why.

Know where recordings and transcripts go

This is the question most people skip. When an AI tool records a meeting, where does the audio go, where is the transcription done, and where are the results stored?

Some tools send audio to the vendor’s servers for processing. Some store recordings in the vendor’s cloud indefinitely. Some process data outside the UK, which brings additional rules about international transfers. Some vendors’ terms allow them to use customer content to improve their models.

Check the vendor’s privacy policy and terms for:

  • Where audio is processed and where recordings and transcripts are stored
  • Whether data leaves the UK, and what safeguards apply if it does
  • Whether your content is used to train or improve their models, and whether you can opt out
  • Who at the vendor can access recordings

If the answers are not clear from the documentation, ask the vendor in writing before you roll the tool out.

Check the contract with any third party

If a vendor processes recordings on your behalf, they are likely acting as your processor and you remain the controller. UK GDPR requires a contract between the two that covers specific points, including processing only on your documented instructions, security, confidentiality, the use of sub-processors and what happens to the data when the contract ends. The ICO’s guidance lists what that contract needs to include.

Most established vendors publish a data processing agreement. Find it, read it, and keep a copy. Check the list of sub-processors too, since your recordings may pass through other companies’ systems as well.

Decide how long to keep things, then delete them

UK GDPR says personal data should not be kept for longer than you need it. A recording made to produce minutes probably does not need to exist once the minutes are agreed. The transcript may need to be kept for longer, or it may not.

Set a retention period for each type of recording and stick to it. Default settings in many tools keep everything forever. Remember that deleting a recording in one place does not delete the downloaded copy, the transcript pasted into an email or the summary saved to a shared drive.

The less you keep, the less you have to secure, search and hand over later.

Expect subject access requests to include transcripts

Anyone can ask for a copy of the personal data you hold about them. That includes recordings and transcripts of meetings they were in, and transcripts where they are discussed by name.

The ICO’s guidance says you must respond without undue delay and at the latest within one month of receiving the request. That can be extended by a further two months if the request is complex or you have received a number of requests from the same person.

Transcripts make these requests harder. They are searchable, which helps, but they also contain other people’s personal data, which may need to be redacted before you hand anything over. If recordings are scattered across personal accounts and laptops, finding them all within a month is difficult. Another reason to keep less, and to know where it is.

Be careful with sensitive conversations

Some meetings involve special category data: health, ethnic origin, religious beliefs, trade union membership, sexual orientation and similar. HR conversations about sickness absence, occupational health or grievances often do. For charities, support and safeguarding conversations frequently do.

The ICO’s guidance says that using special category data needs an additional condition on top of your lawful basis, and that both should be documented. Where processing is likely to be high risk, a data protection impact assessment is required, and the ICO’s advice is to carry one out if in any doubt.

The simpler option for many organisations is a rule that these meetings are not recorded by AI tools at all, or only with a specific, documented decision each time.

Write it down as a policy

None of the above works if each person decides for themselves. A short internal policy covers it:

  • Which tools are approved, and which are not
  • Which meetings can be recorded, and which never are
  • How participants are told
  • Where recordings and transcripts are stored
  • How long they are kept and who deletes them
  • Who handles subject access requests

It does not need to be long. One page that people actually read beats a ten-page document nobody opens. It fits naturally alongside the basics in our small business security guide.

One option: keep processing on the device

Part of the risk above comes from audio leaving your control. One way to reduce that is a tool that transcribes on the device instead of sending audio to a vendor’s servers.

Phonic, our first app, works this way. It transcribes recordings on the device, and recordings are stored in the user’s own iCloud Drive, or on the device if iCloud is not used. That means no separate transcription vendor is processing the audio. The details are in the Phonic privacy policy.

That does not make anyone GDPR compliant on its own. iCloud is still provided by Apple under the user’s Apple Account and Apple’s terms, and you are still responsible for telling people, having a lawful basis, deleting recordings on time and answering access requests. On-device processing changes the answer to the “where does it go” question. It does not remove the others.

The practical takeaway

AI meeting notes are useful, and most small organisations can use them sensibly. The work is in the questions you answer first: who knows they are being recorded, why you are allowed to record, where the data goes, who else handles it, how long you keep it, and what you do when someone asks for it.

Answer those once, write them down, and review them when you change tools.

This is general information, not legal advice. If you are unsure about a specific situation, the ICO’s guidance and helpline are a good starting point, and a data protection specialist can advise on the details.

If you want help reviewing the tools you use or putting a practical policy in place, get in touch.

M Written by Michael, Co-Founder Cloud architect and co-founder of Gremlin Group. Spends most of his time designing AWS infrastructure and writing about cloud architecture, cost optimisation, and DevOps.

Got a process that eats your week?

Tell us about it. If AI is the right fix we will build it, and if a spreadsheet would do, we will say so.