GDPR
EU regulation governing personal-data processing. Recording a meeting requires a lawful basis and disclosure; local-only storage simplifies residency.
The General Data Protection Regulation (Regulation EU 2016/679) governs the processing of personal data of people in the EU. Recording a conversation that contains identifiable voices is personal-data processing under GDPR and requires a lawful basis (commonly legitimate interest or explicit consent), a documented purpose, and a record of where the data is stored.
A cloud notetaker handling EU data subjects with US-based processing typically forces a Transfer Impact Assessment and a careful look at subprocessor chains. A local-only flow collapses the data-residency question: the data is on the data subject's own device, which the controller (the user) physically controls. Disclosure to the other meeting participants is still required.
Related terms
- HIPAA ↗US law governing protected health information. Cloud notetakers handling clinical audio require a Business Associate Agreement; local-only flows do not.
- End-to-end encryption (E2EE) ↗A property where only the communicating endpoints can read the content - the service operator cannot. Common in messaging, rarely true for meeting notetakers.
- On-device ↗Processing that happens entirely on the user's hardware - no cloud, no network round-trip, no third-party data processor.