Glossary

GDPR

EU regulation governing personal-data processing. Recording a meeting requires a lawful basis and disclosure; local-only storage simplifies residency.

The General Data Protection Regulation (Regulation EU 2016/679) governs the processing of personal data of people in the EU. Recording a conversation that contains identifiable voices is personal-data processing under GDPR and requires a lawful basis (commonly legitimate interest or explicit consent), a documented purpose, and a record of where the data is stored.

A cloud notetaker handling EU data subjects with US-based processing typically forces a Transfer Impact Assessment and a careful look at subprocessor chains. A local-only flow collapses the data-residency question: the data is on the data subject's own device, which the controller (the user) physically controls. Disclosure to the other meeting participants is still required.

Related terms

  • HIPAAUS law governing protected health information. Cloud notetakers handling clinical audio require a Business Associate Agreement; local-only flows do not.
  • End-to-end encryption (E2EE)A property where only the communicating endpoints can read the content - the service operator cannot. Common in messaging, rarely true for meeting notetakers.
  • On-deviceProcessing that happens entirely on the user's hardware - no cloud, no network round-trip, no third-party data processor.
GDPR - what it means on a Mac · Mac Note Taker