GDPR Data Subject Rights Applied to Meeting Transcripts
Meeting transcripts trigger GDPR's full framework the moment identifiable people speak.

A meeting transcript becomes personal data the instant someone who can be identified says something into the recording, and that single fact pulls the entire GDPR framework into force. There is no softer category to file it under. Calling the file "notes" or "a summary" changes nothing about the obligations attached to it, because the law looks at what the data is, not what the organization calls it.
Meeting transcripts as personal data from the first word spoken
Article 4 of GDPR defines personal data broadly: any information that can identify a living individual, directly or indirectly, and a transcript is a document built almost entirely out of this kind of material, so a transcript counts as personal data as soon as someone identifiable starts talking.
Three categories of meeting data draw the most regulatory attention: voice recordings, treated as biometric-adjacent; verbatim transcripts; and the behavioral inferences an organization might draw from patterns across many meetings, such as who speaks the most or who gets interrupted. Article 9's stricter biometric rules apply only when a recording is processed to uniquely identify a person through voiceprint analysis, not simply because a voice was recorded. Ordinary speech-to-text transcription is content transcription. It captures words, not a biometric identifier, and does not by itself trigger Article 9's special-category threshold.
What does trigger Article 9 is the content of what gets said. The stricter rules depend on the substance of the conversation, not on the mechanics of capturing it. An organization can run entirely ordinary speech-to-text and still find itself holding special-category data, because the trigger sits in what was said.
None of this would matter much if transcription stayed a niche practice. Otter.ai, Fireflies, and Microsoft Copilot have moved AI note-taking from a specialist function into a default feature of everyday collaboration software, and that shift has multiplied the number of organizations now processing this kind of data at scale, often without recognizing the legal weight it carries. A sales team that turns on an AI note-taker for every client call is, whether it thinks of it this way or not, running a personal data processing operation subject to the full GDPR framework, including the obligations owed to everyone in the meeting whose data is captured.
A valid lawful basis as the prerequisite for exercising any data subject right
None of the eight data subject rights under GDPR exist in a vacuum. They attach to processing that is already happening, and that processing has to rest on one of the lawful bases set out in Article 6 before any of it begins. Get the lawful basis wrong, and no amount of careful rights-handling afterward will fix the underlying problem.
Three bases cover most enterprise meeting recording. Legitimate interest under Article 6(1)(f) is the typical default for internal business meetings, but it is not a box to check after the fact. It requires a documented balancing test, done in advance, showing that the business need for recording outweighs the privacy interests of the people in the room, and that documentation needs to exist before anyone joins the call. Contractual necessity under Article 6(1)(b) applies only when recording is actually required to perform a participant's contract, not merely convenient for managing the relationship. Consent under Article 6(1)(a) is appropriate only where recording is genuinely optional and a participant can decline without facing any professional consequence for doing so.
The employer-employee relationship is where this goes wrong most often. Employee consent to recording is frequently invalid, because the power imbalance between employer and employee makes it hard for an employee to refuse freely, a point the EDPB's Guidelines 05/2020 on consent confirms directly, and one that European data protection authorities have already acted on in enforcement decisions. Where transcript content includes special-category data, the problem compounds further. Legitimate interest cannot stand alone in that situation; one of the Article 9(2) conditions has to be satisfied on top of it.
This choice is not an abstract compliance exercise filed away for an audit. It determines, directly, how the rest of this article plays out. Erasure requests are harder to refuse under consent than under legitimate interest. The right to object under Article 21 attaches specifically where legitimate interest is the stated basis. Portability under Article 20 is available only where consent or contract is the basis, and not otherwise. Every right examined from here forward bends according to which basis the organization picked before the meeting ever started.
Right to be informed: what participants must be told before the recording starts
The right to be informed is a legal condition set out in Articles 13 and 14, requiring considerably more than a line at the top of the call saying the meeting may be recorded.
Participants need to be told what data is being captured, the specific purpose it will be used for, the lawful basis relied on, who will have access to it (including any AI sub-processors involved and any infrastructure based in the United States), and how long the data will be kept. A workable verbal disclosure names the recording tool in use, states the purpose, gives separate retention periods for the audio and the transcript, and tells participants how to request deletion. Capturing that spoken acknowledgment inside the recording itself creates a useful evidentiary record, embedded in the very data it concerns.
Where an AI meeting tool joins as a visible bot in the call, rather than capturing audio covertly through some other channel, its presence in the waiting room functions as a natural consent checkpoint before recording even starts.
Getting this step wrong carries a cost sharper than most organizations assume. Recording or transcribing a meeting without participants' knowledge can itself constitute a personal data breach under Articles 33 and 34, which brings supervisory authority notification obligations into play and, in some cases, a requirement to notify the individuals affected directly. Disclosure handled upfront is far cheaper than disclosure forced by discovery after the fact. That asymmetry sets up the next problem directly: once participants know a transcript exists, some of them will ask to see it.
Right of access: how to respond when a participant requests their transcript data
Access requests are where theory meets an inbox. Under Article 15, anyone in the EU can ask for a copy of audio recordings and transcripts that refer to them, and the organization has one calendar month to respond. What makes transcript-based access requests harder than a standard subject access request is structural: a transcript is a multi-speaker record, and the requesting individual's data sits woven in with everyone else's.
Spain's AEPD has addressed this directly, finding that access cannot be refused just because other people appear in the same recording. Where necessary, the organization should mask or anonymize the other participants rather than deny the request outright, protecting their privacy while still honoring the rights of the person who asked. That is a real operational task: someone has to go into the transcript, identify every other speaker, and produce a version that discloses only what the requester is entitled to see.
A full response has to go further than handing over the transcript text. If employees have been running their own ungoverned AI transcription tools outside any approved system, the organization simply cannot locate every record that needs to go into the response, and an incomplete answer counts as a compliance failure no matter how well-intentioned the gap was.
Sweden's supervisory authority, IMY, gave a concrete signal of how seriously regulators now take this area. Its sandbox report from April 2026 examined whether AI-based transcription and summarization could be used lawfully in a healthcare-adjacent social services context, and concluded that a lawful basis does exist, but only alongside human verification of the transcripts and clear technical and organizational procedures around them. That finding reads less like an abstract caution and more like regulators actively testing how transcription tools hold up in practice.
Right to rectification: why AI transcription errors are a distinct legal problem
AI transcription errors are not the same kind of problem as a typo in a CRM field. The mistake sits embedded inside a document that may already have been shared, stored, and relied on by people who read it as an accurate record of what was said, and the speaker has standing under Article 16 to demand it be corrected.
Article 16 gives a misquoted speaker the right to request that the transcript be corrected to reflect what was actually said. The stakes here are not merely cosmetic. A faulty AI summary can distort a statement in a way that misleads anyone who reads it later, and if that flawed transcript has already gone out to people who were never on the call, confidentiality is breached on top of the inaccuracy.
Correcting the record is harder than it sounds, because a transcript rarely lives in one place. The organization has to track down every copy, inside the meeting platform itself, inside summary emails sent out afterward, inside CRM notes generated automatically from the AI output, and correct each one individually rather than fixing only the source file and calling the job done. An organization that configures per-record deletion and keeps tight control over how far a transcript is allowed to travel before anyone reviews it for accuracy narrows this problem considerably, simply because there are fewer copies to chase down once an error surfaces.
Right to erasure: the most operationally demanding right
Erasure is the right that exposes the real gap between a privacy policy on paper and what an organization can actually do with its own systems. Deleting a transcript is not a single action: it means finding every copy, handling backups correctly, reckoning with whatever a vendor's AI model may have learned from the data, and telling the subject honestly what can and cannot technically be done, and regulators are now checking specifically for this.
Article 17 gives participants the right to request deletion of recordings and transcripts, though the right has limits. Processing required by law, or needed to establish or defend a legal claim, can override an erasure request, but routine business meeting recordings rarely clear that bar.
Regulators have moved past treating this as a theoretical risk. The EDPB ran a coordinated erasure enforcement action through 2025, with results published in February 2026, drawing on responses from 764 controllers across 32 participating supervisory authorities, and the resulting report identified backup handling and weak anonymization as systemic failures across the sample. That finding tells organizations that regulators now treat incomplete erasure as a compliance gap to be closed, not an administrative lapse to be noted and forgiven.
The EDPB's enforcement sample revealed two specific technical failure modes. The first is anonymization substitution: controllers replaced actual deletion with anonymization techniques that did not guarantee irreversibility. The second is that deleting personal data memorized inside a trained model's weights is far harder than deleting a record from a database. The practical response regulators seem to accept is to document the limitation in the DPIA and tell the subject, as part of the erasure response, that this specific piece cannot be removed, rather than claiming full erasure has happened when it has not.
Backup handling calls for the same honesty. GDPR does not demand the impossible, but it does require a documented, reasoned, and proportionate approach to purging backup copies on a defined schedule, along with a clear account of what has been erased and what has not. And the shadow IT gap returns here in its sharpest form: an organization cannot erase data it does not know exists, which makes a current vendor tool inventory and an approved-tool policy a prerequisite for erasure compliance, not a nice-to-have governance exercise set aside for a slow quarter. An adequate erasure response, even where perfect erasure is impossible, tells the subject what was deleted, what could not be, and why, in writing.
Right to restriction: a temporary hold that organizations rarely build a workflow for
Restriction under Article 18 gets confused with erasure often, but it is a distinct instruction: stop using this data while a dispute is being sorted out or a verification is pending, rather than delete it outright.
A subject can invoke restriction while disputing the accuracy of a transcript, tying directly back to the rectification right, while objecting to the lawful basis the organization relied on, or while waiting on verification of a separate erasure request already filed. During that restriction period, the organization can keep the data in storage but cannot otherwise touch it. It cannot be searched, analyzed, shared, or fed into training an AI model, unless the subject consents to further processing or a specific exception applies, such as a legal claim or an important public interest.
Building that workflow is the controller's own responsibility.
Right to data portability: what "structured, machine-readable format" means for transcript data
Portability under Article 20 applies, and this right comes into play, only where the processing rests on consent or contract as its lawful basis, a choice made before the meeting ever started.
Where portability does apply, a participant can ask for their data in a structured, commonly used, machine-readable format, an exportable text file or structured document for a transcript, an exportable audio file for the recording, rather than a copy locked inside a proprietary viewer. Someone who spoke across twenty separate meetings needs the segments attributable specifically to them, rather than a complete dump of every meeting file those conversations happened to touch.
This right also applies earlier than most organizations expect, before a contract even ends. Vendor data processing agreements need to cover data return at contract end, with written confirmation that destruction has taken place, and portability intersects with that obligation whenever a subject wants their data moved before the contract itself ends, not only once it terminates.
Sources
- GDPR Meeting Tools: European Enterprise Guide
- GDPR-Compliant Transcription: A Practical Checklist (2026)
- decision974 en
- Spain’s Supervisory Authority Issues New Guidance on AI‑Based Voice Transcription
- AI Voice Transcription (II): accountability, rights and transparency
- EDPB report on the right to erasure: Key takeaways from the 2025 Coordinated Enforcement Action and what controllers must do now
- What the EDPB's Right-to-Erasure Report Reveals About Where Organizations Still Struggle - Jetico


