GDPR Meeting Recording: What UK Teams Need to Know

If your team records meetings to generate AI notes, GDPR meeting recording rules apply the moment audio is captured — a recording of an identifiable person is personal data, and everything that follows sits under UK GDPR and the Data Protection Act 2018. The good news: for most finance and professional-services teams, compliant recording is entirely achievable and does not usually hinge on getting explicit consent from everyone in the room. What it hinges on is having a clear lawful basis, telling people what you're doing, holding the audio no longer than you need, and knowing exactly who touches the data along the way.
Here's the honest headline before the detail: the tool you choose does not make you compliant. Your lawful basis, your notice, and your retention practices do. A bot that joins your call and a device-first recorder can both be run compliantly — or badly. This piece explains how to run it well.
Lawful basis: usually legitimate interests
You need a lawful basis under Article 6 to record and process meeting audio. In practice, two apply to most business meetings.
- Legitimate interests (Article 6(1)(f)) is the workhorse. Producing an accurate record of a meeting for minutes, actions and follow-up is a genuine business interest, and it's typically proportionate. You should document a short Legitimate Interests Assessment (LIA) — the purpose, why it's necessary, and a balancing test against attendees' rights. Keep it on file; you don't need to publish it.
- Consent (Article 6(1)(a)) is sometimes the better fit — for example, recording a webinar, a coaching session, or any setting where people would reasonably expect a choice. Consent must be freely given, specific and withdrawable, which is awkward for routine internal meetings but sensible for one-off or sensitive ones.
A practical note often misunderstood: "consent" in GDPR terms is not the same as telling people you're recording. You can rely on legitimate interests and still owe everyone clear notice. Notice is a transparency duty; consent is a lawful basis. Don't conflate them.
Transparency: tell people, every time
Under Articles 13 and 14 people must know their data is being processed. For recorded meetings that means:
- A visible notice at the start of the meeting ("This meeting is being recorded to produce notes").
- A line in the calendar invite so attendees know before they join.
- A reference in your privacy notice covering meeting recordings — purpose, lawful basis, retention, and their rights.
The ICO's consistent expectation is that processing should not be a surprise. If an attendee only discovers afterwards that they were recorded, you have a transparency problem regardless of your lawful basis.

Data minimisation, retention and special categories
Record only what you need, and keep it only as long as you need it.
- Minimise. If the AI note is the deliverable, you rarely need to retain raw audio once the summary is produced and checked. Deleting the recording after transcription is often the cleanest posture.
- Retention. Set a defined period and enforce it. A common approach: audio deleted within days of transcription; the text note retained per your normal business-records policy.
- Special-category data (Article 9). Meetings drift into health, trade-union, or other sensitive topics without warning — HR, welfare and some client conversations especially. Article 9 sets a higher bar. Be cautious about recording those at all, and where you do, make sure you have an Article 9 condition (usually explicit consent or employment-law grounds) on top of your Article 6 basis.
Quick compliance checklist
| Requirement | What "good" looks like | Typical retention |
|---|---|---|
| Lawful basis | Documented LIA (or recorded consent) | Kept while recording is in use |
| Notice | Invite line + in-meeting announcement + privacy notice | Standing |
| Raw audio | Deleted once note is produced and checked | Days, not months |
| AI note/transcript | Retained per business-records policy | Months to years, defined |
| Special-category topics | Article 9 condition or don't record | Minimise aggressively |
| DSAR readiness | Know where audio and notes live | N/A |

Processors, sub-processors and where the audio lives
This is where tool choice genuinely matters for your compliance story — not because one is "GDPR-compliant" and another isn't, but because of how many parties touch the data and where it sits.
Any third party processing meeting audio on your behalf is a processor, and you need a written contract (an Article 28 Data Processing Agreement) with each one. Cloud transcription vendors, AI providers and hosting platforms are often sub-processors beneath them. Two practical questions decide most of your risk:
- Where is the audio stored and processed? UK/EU is straightforward. US or other transfers need appropriate safeguards (typically the IDTA or an equivalent mechanism).
- How many hands is it passing through? Every additional sub-processor is another contract to hold, another location to map, and another entry in your record of processing.
Where device-first, bot-free capture helps (honestly)
A device-first, bot-free recorder captures audio locally and sends only what's needed for transcription. There's no third-party bot joining as a silent attendee, and fewer parties sit in the processing chain. That makes the compliance story simpler to describe and easier to defend — a shorter data map, fewer DPAs, a clearer answer to "where did the audio go?".
But be straight about it: this is a simplification, not a licence. A platform-native recorder (Teams, Zoom, Google Meet) or a well-run meeting bot can be perfectly compliant. Many are backed by mature DPAs and UK/EU hosting. The bot-versus-device question affects how tidy your data map is; it does not, by itself, determine whether you're lawful. If you want a broader view of the market, see our rundown of the best AI meeting notetakers for 2026, which covers where different tools store audio.
DSARs: recordings are in scope
A meeting recording or transcript containing an individual's personal data is disclosable under a Data Subject Access Request. You must be able to find it, and to redact third parties' data before releasing it. Two things make this survivable: knowing where recordings and notes live (another reason to keep the chain short), and having a retention policy that deletes audio promptly — you can't be asked to produce what you've properly deleted.
Do's and don'ts
- Do announce recording at the start and in the invite.
- Do document a Legitimate Interests Assessment.
- Do delete raw audio once the note is produced.
- Do hold a DPA with every processor and map your sub-processors.
- Don't assume "everyone knows" — transparency is an active duty.
- Don't record HR or welfare conversations without an Article 9 condition.
- Don't treat any tool as compliance in a box.
Frequently asked questions
Is it legal to record meetings in the UK?
Yes, for legitimate business purposes, provided you have a lawful basis (usually legitimate interests), give clear notice, and handle the data responsibly. Recording covertly is where organisations get into trouble.
Do I need consent from everyone?
Usually no — most internal business meetings run on legitimate interests, which requires notice but not consent. Consent is the right basis for webinars, coaching, or sensitive sessions where people should have a genuine choice.
How long can we keep recordings?
As long as you have a documented reason, and no longer. A common posture is to delete raw audio within days of producing the note, then retain the text note under your normal records policy. Set the period and enforce it.
What about external attendees?
They have the same rights. Flag recording in the invite and at the start so they can object or decline, and make sure your privacy notice is reachable. External participants are exactly who a "surprise recording" complaint tends to come from.
None of this is legal advice — for high-risk or special-category processing, take proper counsel. But for everyday finance and professional-services meetings, a clear basis, honest notice and disciplined retention are what keep you right.
Ready to talk it through?
Talk to our team and we'll help you map a compliant, bot-free recording setup for your firm.