GDPR Meeting Transcription: Why On-Device Is the Safest Default

7 min read

If you transcribe meetings with a cloud tool, every word spoken in that call lands on someone else’s server. Under GDPR, that’s not just a privacy question — it’s a compliance question with real consequences.

Most teams don’t think about this until it’s too late. They install Otter or Fireflies, start transcribing, and assume someone in legal already approved it. Usually, nobody did.

This post breaks down what GDPR actually requires when you transcribe meetings, where cloud tools fall short, and why on-device transcription is the simplest path to compliance. Whether you’re a Data Protection Officer auditing your tool stack or a team lead who just wants to transcribe standups without creating liability, here’s what you need to know.

What GDPR Says About Meeting Transcription

GDPR doesn’t mention “meeting transcription” by name. But it covers the data that transcription creates — and the processing that creates it.

Here’s what applies:

Audio is personal data

A recording of someone’s voice is personal data under GDPR (Article 4). It identifies a natural person. The moment you hit record, you’re processing personal data.

Transcripts are personal data

The text output — names, opinions, statements — is also personal data. If the transcript includes speaker labels (and it should), it’s directly tied to identifiable individuals.

You need a lawful basis

Under Article 6, you need a lawful basis to process that data. For most meeting transcription, this is either:

Consent is the cleaner path for external calls. For internal team meetings, legitimate interest may apply — but you still need to document it.

You need to tell people

Articles 13 and 14 require transparency. Participants must know:

This applies whether you use a cloud tool or a local one. The difference is what you have to disclose.

Why Cloud Transcription Tools Like Otter and Fireflies Create GDPR Risks

Cloud transcription doesn’t just process audio — it transfers it. And under GDPR, transfers matter.

Third-party processing

When you use Otter, Fireflies, Granola, or any cloud transcription service, your meeting audio is sent to their servers for processing. Under GDPR, that makes them a data processor — and you need a Data Processing Agreement (DPA) in place before the first byte leaves your machine.

Most teams don’t have one. Many don’t even know they need one.

International data transfers

If the transcription provider is US-based (Otter, Fireflies, Granola all are), you’re transferring personal data outside the EU/EEA. Post-Schrems II, this requires either:

The EU-U.S. Data Privacy Framework exists, but its long-term stability is uncertain — the two predecessors (Safe Harbor and Privacy Shield) were both invalidated by the Court of Justice. Relying solely on it is a gamble. Competitor policies described below are as of April 2026 and may change.

Data used for model training

Otter’s Privacy Policy states: “We also train our technology on transcriptions to provide more accurate services, which may contain Personal Information.” Under GDPR, using personal data to train AI models requires its own lawful basis and transparency obligations. If participants didn’t consent to their meeting audio training Otter’s speech models, that’s a problem.

Biometric data risks

Fireflies is facing a lawsuit under Illinois’ Biometric Information Privacy Act (BIPA) for collecting voiceprints. Voice data can qualify as biometric data under GDPR Article 9 — a special category that requires explicit consent. If your transcription tool creates voice profiles for speaker identification, you may need Article 9 compliance on top of everything else.

The bot problem

Otter’s bot auto-joins meetings. A federal class-action complaint (Brewer v. Otter.ai, Inc., August 2025) alleges this violates wiretapping and privacy statutes. Under GDPR, an uninvited bot recording participants who haven’t been informed — let alone consented — is a transparency failure at minimum.

What a GDPR-Compliant Transcription Setup Looks Like

You can transcribe meetings and stay GDPR-compliant. The requirements are:

  1. Inform participants before recording starts (transparency)
  2. Have a lawful basis documented (consent or legitimate interest)
  3. Minimize data processing — don’t send data to third parties unless necessary (data minimization, Article 5(1)(c))
  4. Control where data goes — know exactly which servers process your audio (accountability)
  5. Enable data subject rights — participants can request access to or deletion of their data
  6. Have a DPA with any processor that touches the data

Items 3 and 4 are where cloud tools make life hard. On-device transcription makes them trivial.

How On-Device Transcription Makes GDPR Compliance Simple

When transcription runs entirely on your machine, several GDPR headaches disappear:

No third-party processor

If audio never leaves your Mac, there’s no data processor to manage. No DPA needed for transcription. No processor’s privacy policy to audit. No subprocessor chain to trace.

You’re the data controller, and the processing happens on hardware you control. That’s the simplest possible compliance posture.

No international transfer

No server in Virginia. No cloud in Frankfurt. No transfer mechanism required. The data stays on the device in the jurisdiction where it was created.

No model training on your data

On-device speech recognition (like Apple’s Neural Engine) runs pre-trained models locally. Your audio doesn’t train anything. There’s no secondary processing purpose to disclose.

Data deletion is real

When you delete a transcript file from your Mac, it’s gone. You’re not hoping a cloud provider actually purges it from their backups, training pipelines, and analytics systems. You control the full data lifecycle.

Data minimization by default

GDPR’s data minimization principle (Article 5(1)(c)) says you should process only what’s necessary. On-device transcription processes audio locally and writes a text file. No audio is retained in a cloud dashboard. No metadata is logged on a third party’s servers. The processing is inherently minimal.

What You Still Need to Do

On-device transcription doesn’t make you automatically GDPR-compliant. You still need to:

The difference is that these are standard obligations you’d have anyway. Cloud transcription adds a layer of third-party risk, transfer mechanisms, DPAs, and processor audits on top.

Local Transcriber: GDPR-Compliant Meeting Transcription on Mac

Local Transcriber is a GDPR-compliant transcription tool that processes everything on your Mac. Audio capture, speech recognition, speaker diarization — all on-device using Apple’s Neural Engine. No audio is uploaded. No data leaves your machine. Local transcription privacy isn’t a feature we bolt on — it’s the architecture.

How to verify: Turn on Airplane Mode and transcribe a call. It works. Open Activity Monitor — zero outbound connections. That’s the test.

What this means for GDPR:

GDPR RequirementCloud ToolsLocal Transcriber
Data Processing AgreementRequired with each providerNot needed — no third-party processor
International transfer mechanismSCCs or DPF certification requiredNot needed — data stays on your Mac
Model training disclosureRequired (Otter trains on transcripts)Not applicable — no data leaves device
Data deletionDepends on provider’s retention policiesDelete the file. It’s gone.
Data minimizationAudio stored on cloud servers + dashboardsAudio processed locally, transcript saved as .md file
Subprocessor auditNeed to track provider’s subprocessorsNo subprocessors

Transcripts are saved as .md files on your filesystem. You control where they’re stored, how long they’re kept, and who has access. If someone exercises their right to erasure, you delete the file. For full details on how Local Transcriber handles your data, see our privacy policy.

Frequently Asked Questions

Yes. GDPR requires a lawful basis regardless of where processing happens. You still need to inform participants and have either consent or a legitimate interest assessment. On-device transcription simplifies the processing side — it doesn’t eliminate the transparency requirement.

Is voice data biometric data under GDPR?

It can be. Article 9 covers biometric data “for the purpose of uniquely identifying a natural person.” If your tool creates voiceprints or voice profiles for speaker identification, that may trigger Article 9’s stricter requirements (explicit consent). Local Transcriber uses Apple’s on-device diarization, which identifies speakers within a session but doesn’t create persistent voice profiles stored across recordings.

GDPR is separate from wiretapping and recording consent laws, which vary by country and sometimes by region. In Germany, recording without consent can be a criminal offense. In the UK, one-party consent generally applies. You need to comply with both GDPR and local recording laws. Always inform participants.

Does Local Transcriber work with Zoom, Teams, and Google Meet?

Yes. It captures system audio — any app that plays sound through your Mac. Zoom, Google Meet, Microsoft Teams, and everything else. No bot joins your call, no meeting link is shared with a third party.

Can my DPO verify that no data leaves the device?

Yes. Run Local Transcriber in Airplane Mode — it works fully offline. Monitor network activity with Activity Monitor or Little Snitch during a recording. Zero outbound connections. This is an auditable, verifiable claim, not a trust-us statement.

Try it yourself.

Download Local Transcriber, join a call, and see the transcript appear in real time. No account needed.

Download Now

14-day free trial · $20 one-time · macOS Sonoma 14.2+ · Apple Silicon native