AI Transcription and GDPR: The Most Common Mistakes

Jexity Meet TeamSeptember 28, 202614 min read
Laptop with a shield icon above an audio waveform during a video conference in the office
On this page

According to Deloitte Legal Germany, 48.6 percent of German companies have not seriously engaged with the EU AI Act (deloittelegal.de). At the same time, 36 percent already use AI, almost twice as many as the previous year (bitkom.org). When it comes to AI transcription of meetings, productivity and data protection collide particularly hard, because audio recordings contain voices, opinions and often confidential content. Anyone who wants to guarantee secure video conferencing must clarify the legal basics before the technical rollout. The most common mistakes when introducing it keep coming up, but they can be avoided.

Why does every second AI rollout fail on data protection?

73 percent of companies name data protection concerns as the most important obstacle to introducing AI transcription (sonix.ai). At the same time, according to the Cisco Data Privacy Benchmark Study 2025, around 46 percent of data protection and security experts admit to having entered personal employee data into generative AI tools (newsroom.cisco.com). The gap between awareness and action is the real risk factor.

Why meeting data deserves special protection

Anyone who has a meeting transcribed automatically generates personal data. Voices are biometric characteristics, and conversation content can contain trade secrets, health data or performance assessments. It gets especially sensitive when companies transcribe interviews, for example job interviews or staff appraisals. Unlike a written note, the speaking person can always be identified from the audio material, even if their name is never mentioned.

How high are the consequences of a violation? Across Europe, fines of 1.2 billion euros were imposed under the GDPR in 2024, with an average of 363 reported data breaches per day (dlapiper.com). In Germany alone, the DSGVO-Portal counted 266 fine notices and 8,623 data breaches (Article 33 GDPR) in the same year (dsgvo-portal.de). That such sums can hit individual companies hard is shown by the Vodafone case, with fines totalling 45 million euros in 2025, among other things for inadequate control of a data processor (sentiguard.eu).

A data protection shield symbolises safeguards during an ongoing video conference

The six most common mistakes can be sorted along the rollout process. They start with planning, continue with vendor selection, affect organisational involvement, and reach into future-proofing.

What happens if the impact assessment for AI transcription is missing?

A data protection impact assessment (DPIA, Article 35 GDPR) is mandatory for AI transcription in almost all cases. The Datenschutzkonferenz (DSK), the association of all German data protection supervisory authorities, states in its guidance on AI and data protection that AI systems in productive use regularly reach the threshold for high risk (datenschutzkonferenz-online.de). Many companies skip this step anyway, because they classify AI transcription as mere office software. That is the mistake.

How to create a DPIA in four steps

A DPIA is not a legal mega-project, but a structured document with four mandatory components (dsgvo-gesetz.de). First, you systematically describe which data is processed, that is audio data, voices, conversation content and the transcripts created from them. Second, you check necessity and proportionality, whether AI transcription is suitable for the intended purpose and the least intrusive means. Third, you assess the risks for the people affected, for example whether performance assessments would be possible or whether special categories of data such as health data are processed. Fourth, you document the safeguards that mitigate these risks.

For AI transcription, this specifically means where the audio data is transferred to, how long transcripts are stored, and who gets access. Whether you transcribe live, afterwards via a desktop app, or transcribe online via a browser-based tool, the DPIA must cover every processing path. A transcription tool with a transparent data architecture simplifies the DPIA, because the processing paths can be clearly documented. The effort for the impact assessment therefore directly reflects the architecture decision. File the finished DPIA with your data protection officer and keep it ready for the supervisory authority, because it can request it at any time. In practice, a dedicated compliance folder in the document management system works well, alongside the works agreement and the records of processing activities.

84 percent of employees change their behaviour when an AI note-taking tool is active in a meeting, and 47 percent have experienced such a tool recording or sharing something it was not meant to (fellow.ai). These numbers show that the legal basis is not a side issue. It shapes the entire way the tool is used.

Three legal bases come into question for processing audio data in a meeting. Consent (Article 6(1)(a) GDPR) requires that all participants give free, informed and explicit consent (exkulpa.de). In an employment relationship, this voluntariness is regularly doubtful, because employees are in a position of dependency towards their employer. Anyone who relies on the fact that nobody objects does not have valid consent.

The second option is legitimate interest (Article 6(1)(f) GDPR). The company must demonstrate that its interest in transcription outweighs the interests of the people affected (datenschutz-agentur.de). Concretely, that means you document the purpose, for example more efficient minutes, and check whether a less intrusive means exists. For recordings, the balancing test is generally strict (datenschutzkanzlei.de).

The third and most robust option is a works agreement. It relies on an opening clause (Article 88 GDPR) and allows the processing of employee data to be regulated collectively. The works council represents the interests of the workforce and helps shape the conditions (sally.io). Which legal basis you choose also affects whether you may record job interviews or staff appraisals, because stricter requirements for voluntariness apply there. Anyone who regularly wants to transcribe interviews needs a robust legal basis before the first conversation is recorded.

What Section 201 of the German Criminal Code has to do with meeting recordings

Besides the GDPR, criminal law also applies to meeting recordings. Section 201 of the German Criminal Code (StGB) makes violating the confidentiality of the spoken word a criminal offence (gesetze-im-internet.de). Anyone who records the non-publicly spoken word without authorisation, meaning without the consent of those involved, risks a prison sentence of up to three years or a fine. Whether this also covers live transcription that does not permanently store audio but processes the spoken word has not been conclusively settled. The solution is simple: inform all participants at the start of the meeting that an AI is taking notes, and obtain their agreement. This transparency duty applies regardless of whether you transcribe a secure video conference, transcribe online, or record an in-person meeting.

Many companies rely on consent but make mistakes in the implementation that render it invalid. Flawed consent is legally just as risky as having no legal basis at all. The following five steps follow the requirements that data protection law places on valid consent (exkulpa.de).

Step 1, inform before the start. Consent must be obtained before the recording begins. Inform all participants at the start of the meeting that an AI is taking notes, which data is processed, and for what purpose. Only after this information may transcription start.

Step 2, ensure voluntariness. In an employment relationship, genuine voluntariness is particularly difficult. Employees must not fear disadvantages if they refuse consent. That means there must always be an equivalent alternative, for example a manual record.

Step 3, document consent. Verbal agreement is formally sufficient but hard to prove. Use a short digital form or a documented query at the start of the meeting. The burden of proof lies with the company.

Step 4, enable withdrawal. Anyone can withdraw their consent at any time, without giving reasons. The company must ensure that withdrawal is just as easy as giving consent, and that the processed data is deleted afterwards.

Step 5, involve external guests. The same requirements apply to external meeting participants. Add a note about AI transcription to the invitation already, and obtain consent separately, so that internal and external agreements are documented cleanly. This applies especially to secure video conferences with customers or partners where confidential information is discussed.

If consent becomes too cumbersome in everyday work, that is often a sign that a works agreement would be the better legal basis. It regulates processing collectively and makes individual consent for recurring meetings unnecessary.

Why must the works council be involved before the rollout?

Every AI tool that can process performance or behavioural data of employees is subject to co-determination (Section 87(1) no. 6 of the German Works Constitution Act). AI transcription falls under this because it is objectively capable of capturing individual speaking shares, talk time and conversation content, regardless of whether the company intends this kind of monitoring (haufe.de). Anyone who informs the works council only after the tool is already in use risks a preliminary injunction.

How to involve the works council successfully

The works council has more than a right to information here, namely a genuine co-determination right. Introducing the tool without its consent is unlawful and can be prohibited retroactively. That sounds like an obstacle, but in practice it is an advantage, because a jointly negotiated works agreement is at the same time the most robust legal basis for AI transcription.

Proceed like this. Present the planned tool to the works council, disclose the DPIA, and negotiate a works agreement together (sally.io). This regulates which meetings are transcribed, how long transcripts are stored, and who gets access. Whether you transcribe the weekly team meeting live or only selected customer meetings, the works agreement must cover every use case. A tool like Jexity Meet makes this negotiation easier, because the works council can trace the data paths. This also creates a framework for the case that managers want to transcribe interviews or document performance reviews in the future.

What does unapproved AI do to the meeting room?

Unauthorised AI tools, known as shadow AI, cause around 20 percent of all data breaches according to the IBM Cost of a Data Breach Report 2025, and cost an average of 4.63 million US dollars per incident, about 670,000 US dollars more than regular incidents (kiteworks.com). At the same time, the Verizon Data Breach Investigations Report 2025 shows that around 60 percent of all confirmed data breaches involve human action (mimecast.com). Together, both figures explain why the biggest risk often does not come from the technology, but from the employees who help themselves.

How shadow AI arises in meetings

When a company does not offer an approved solution for AI transcription, employees find their own tools. They install free browser extensions, use live transcription via their private accounts, or transcribe meetings online via services whose data protection terms nobody has checked. According to the same Fellow.ai study, 50 percent of non-users of AI note-taking tools cite data protection as the main reason for their rejection (fellow.ai). The flip side is uncomfortable, because the other half may already be using tools without informing the employer.

Why an approved alternative helps

Bans alone do not solve the problem. If employees have a genuine need to document their meetings more efficiently, they will find ways. The more effective strategy is a vetted and approved tool that meets the need without sending data outside the company. Jexity Meet is one such alternative: it works without a bot joining the call, and keeps the processing with the company by default. That removes the incentive for shadow AI, and the IT department keeps control. Giving employees a simple way to transcribe meetings also reduces the risk of uncontrolled data leaving the company. Anyone who has conversations transcribed online by unvetted services loses control over the data.

Cost per data breach: shadow AI vs. regular incidents Cost per data breach: shadow AI vs. regular incidents. Bar chart: Shadow AI incidents (USD million) 4.63; Regular incidents (USD million) 3.96. Source: IBM Cost of a Data Breach Report 2025, via kiteworks.com 2025. Cost per data breach: shadow AI vs. regular incidents Shadow AI incidents cost about 670,000 USD more than regular incidents Shadow AI incidents(USD million) 4.63 Regular incidents(USD million) 3.96 Source: IBM Cost of a Data Breach Report 2025, via kiteworks.com (2025)
Source: IBM Cost of a Data Breach Report 2025, via kiteworks.com, 2025.

What does the AI Act change from August 2026?

From 2 August 2026, the core transparency obligations of the EU AI Act (Article 50) apply (consulting.tuv.com). AI systems must be recognisable as such, and AI-generated content must be labelled. Violations of these transparency obligations can incur fines of up to 15 million euros or 3 percent of annual turnover; for prohibited AI practices (Article 5), fines can reach up to 35 million euros or 7 percent (consulting.tuv.com). Reduced caps apply for small and medium-sized companies. Even so, according to Deloitte Legal Germany, 48.6 percent of German companies have not seriously engaged with the implementation (deloittelegal.de).

Two obligations and one recommendation for meeting AI

For AI transcription in meetings, two concrete obligations arise (Article 50 AI Act), which can be implemented with little effort (consulting.tuv.com). First, the disclosure obligation: all participants must learn at the start of the meeting that an AI is taking notes. Second, the labelling obligation: the finished transcript and the minutes created from it must be recognisable as AI-generated, for example through a note in the document header. Third, it is advisable to document which system created the AI transcription. Article 50 itself does not require this, but it makes it easier to demonstrate compliance to participants and supervisory authorities.

Anyone who already documents meetings via live transcription today without informing participants is violating the GDPR, and from August 2026 will additionally violate the AI Act. This applies to every form of AI-supported documentation, whether you transcribe a secure video conference or have an interview transcribed. Anyone planning the rollout now can cover all three points with a short checklist.

A laptop and a calendar on a conference table symbolise preparing for the AI Act

Frequently asked questions

Is AI transcription in meetings generally GDPR compliant?

Yes, if the requirements are met. These include a valid legal basis, a data protection impact assessment, informing all participants, and appropriate technical safeguards. A secure video conference with AI transcription requires all four building blocks at the same time. 73 percent of companies name data protection concerns as the most important obstacle to adoption (sonix.ai), but with the right preparation, every one of them can be addressed.

Do I need new consent for every meeting?

Not necessarily. If processing is based on a legitimate interest or a works agreement, a single comprehensive arrangement is enough. With consent as the legal basis, all participants, including external guests, must give informed consent every time. For recurring meetings with changing participants, that quickly becomes impractical.

Does the works council have to agree to AI transcription?

Yes. AI transcription falls under co-determination (Section 87(1) no. 6 of the German Works Constitution Act) because it processes performance and behavioural data. Without co-determination, the rollout is unlawful and can be stopped by a preliminary injunction. A jointly negotiated works agreement is at the same time the most robust legal basis.

Is verbal consent enough?

Verbal consent is possible in principle, but hard to prove. The GDPR requires that the company can demonstrate consent at any time. In practice, a short digital form or a documented query at the start of the meeting is recommended (exkulpa.de).

What changes with the AI Act from August 2026?

AI systems must be recognisable as such, and generated content must be labelled. Violations of the transparency obligations (Article 50) can result in significant fines. Implementation is manageable: inform participants, label transcripts, document the system used.

Sources(21)
  1. deloittelegal.deDeloitte Legal: EU AI Act Survey
  2. bitkom.orgBitkom: Durchbruch Künstliche Intelligenz
  3. sonix.aiSonix: Meeting Transcription Adoption Statistics
  4. newsroom.cisco.comCisco: Data Privacy Benchmark Study (2025)
  5. dlapiper.comDLA Piper: GDPR Fines and Data Breach Survey
  6. dsgvo-portal.deDSGVO-Portal: Review of GDPR Fines and Data Breaches 2024 (2024)
  7. sentiguard.euSentiguard: GDPR Fines 2025, Below the Billion Mark but Still Significant (2025)
  8. fellow.aiFellow.ai: AI Notetaker Statistics
  9. kiteworks.comKiteworks: IBM Cost of a Data Breach Report 2025 (2025)
  10. mimecast.comMimecast: Verizon Data Breach Investigations Report 2025 (2025)
  11. consulting.tuv.comTÜV Consulting: EU AI Act from 2 August 2026 for Companies
  12. consulting.tuv.comTÜV Consulting: Transparency Obligations under the EU AI Act Article 50
  13. datenschutzkonferenz-online.deDatenschutzkonferenz (DSK): Guidance on AI and Data Protection (2024)
  14. dsgvo-gesetz.deDSGVO-Gesetz.de: Article 35 GDPR (statutory text)
  15. datenschutz-agentur.deDatenschutz-Agentur: Legal Basis for Transcription
  16. exkulpa.deExkulpa: Data Protection for Recording Video Conferences
  17. datenschutzkanzlei.deDatenschutzkanzlei: Recording Video Conferences
  18. sally.ioSally.io: Recording Meetings in Germany - Data Protection
  19. gesetze-im-internet.deSection 201 StGB: Violation of the Confidentiality of the Spoken Word (statutory text)
  20. haufe.deHaufe: AI-Automated Transcription of Interviews and Meetings - Co-Determination
  21. eur-lex.europa.euEUR-Lex: Regulation (EU) 2024/1689 (AI Act) (2024)
ai transcriptionsecure video conferencinglive transcriptiontranscribe onlineinterview transcription
Share:LinkedInXE-Mail

This article was created with AI assistance and editorially reviewed. Images are AI-generated.

Try it on your next meeting

Record or import one meeting and see the minutes it produces. No account and no credit card.