Meeting Recording: Store It Locally or in the Cloud?

On this page
- Where does your meeting recording end up after the call?
- How cloud providers process your recordings
- What local storage does differently
- Why does the Cloud Act threaten your GDPR compliance?
- US authorities and access to European data
- Microsoft's admission before the French Senate
- How safe is it to record on Zoom or Teams?
- Recording on Zoom and cloud recording
- Recording on Teams and the storage location fallacy
- Recording on Google Meet and automatic deletion
- Drawbacks of all three platforms when it comes to storage
- What encryption actually protects your meeting recording?
- Transport encryption vs. end-to-end
- Local encryption: full control over your data
- Which industries must store meeting recordings locally?
- Healthcare: patient data only into the cloud with a certificate
- Banks and insurers: strict retention obligations
- Lawyers, tax advisors and auditors: professional secrecy
- What does cloud storage cost compared to local storage?
- Ongoing costs with cloud providers
- A one-time investment for local storage
- Frequently asked questions
- Sources
Do you know which server your last meeting recording is sitting on right now? Most companies use Zoom or Microsoft Teams and store recordings in the cloud by default. Yet the US Cloud Act allows American authorities to access that data even when the servers are located in Europe. This conflict between the Cloud Act and the GDPR affects every company that stores recordings with a US provider.
According to the Bitkom Cloud Report 2025, 78% of German companies consider themselves too dependent on US cloud providers (Bitkom, 2025). At the same time, 90% use cloud services in their daily work. This contradiction particularly affects meeting recordings, which often contain sensitive conversation content.
Where does your meeting recording end up after the call?
90% of German companies with more than 20 employees now use cloud services (Bitkom, 2025). For meeting recordings, that means recordings from Zoom, Teams and Google Meet land on external servers by default. The video conferencing market is growing to nearly 10 billion dollars (Precedence Research, 2025), and with it the volume of sensitive conversation data in someone else's hands.
How cloud providers process your recordings
If you record a meeting on Zoom and choose the cloud option, Zoom stores the file on its own servers. With a 55% market share and more than 500,000 business customers (DemandSage, 2026), Zoom also processes these recordings for transcription and AI-generated summaries. Beyond storing the recording, Zoom actively analyzes it to offer conversation summaries, action items and search functions. Your conversation data therefore flows into further processing steps you have no control over.
With Microsoft Teams, recordings end up in OneDrive, SharePoint or the old Microsoft Stream, depending on configuration. Many IT departments assume that "EU data center" is synonymous with "safe". The Cloud Act shows why that can be a fallacy. On top of that, Microsoft also processes recordings for Copilot features and transcription, which raises additional questions about data processing.
What local storage does differently
With local recording, the file never leaves your own device. No third-party server, no third-country data transfer, no processing by external AI systems. Local AI tools like Jexity Meet store the recording on your hard drive by default until you actively decide to share it.
The decisive difference is control. You determine where the file is located, who can access it and whether it ever leaves the device at all. No provider can use your recording for its own purposes, no algorithm analyzes the content, and no authority can knock on the provider's door, because there isn't one. For companies with confidential conversation content, that is a fundamental advantage.
Why does the Cloud Act threaten your GDPR compliance?
The US Cloud Act, passed in 2018, requires American technology companies to hand over data to US authorities on request. That applies regardless of whether the servers are located in the US or in Europe (digitoren.de, 2026). For companies that store meeting recordings with Zoom or Teams, this creates a potential conflict between the Cloud Act and the GDPR. To learn how to protect the video calls themselves against this kind of access, read the article on secure video conferencing despite the Cloud Act.
US authorities and access to European data
Article 48 of the GDPR prohibits transferring personal data to third-country authorities without a legal basis under EU law. The Cloud Act creates exactly such a basis on the US side. Both laws claim to apply to the same data, and no treaty resolves this conflict.
Since September 2025, the EU Data Act has tightened the situation further. It actively obliges cloud providers to prevent unlawful access by non-EU authorities (digitoren.de, 2026). But how is a US company supposed to comply with the Cloud Act and the EU Data Act at the same time? A question that so far has no satisfying answer.
Microsoft's admission before the French Senate
A hearing before the French Senate in June 2025 showed just how concrete this risk is. Microsoft openly admitted there that the company cannot prevent US authorities from accessing European customer data. Even when the data sits on servers in France, Microsoft has no legal way to refuse such access (The Register, 2025).
That statement has consequences. In a survey of 518 decision-makers, 65% said sovereignty and compliance mattered more to them than speed of innovation and cost (otris, 2026). For meeting recordings, which regularly contain confidential business content, that trade-off deserves particular care.
You can find out more about the legal framework for recording meetings in Germany in the article Can I record a meeting? GDPR and criminal law explained.
How safe is it to record on Zoom or Teams?
The average cost of a data breach stands at 4.88 million dollars. For data in the public cloud, that figure rises to over 5 million (IBM, 2024). For meeting recordings with sensitive conversation content, cloud platforms therefore represent a concrete financial risk. The two largest providers each show their own weaknesses.
Recording on Zoom and cloud recording
In April 2020, more than 500,000 Zoom accounts were compromised through credential stuffing and sold on the dark web for a few cents. Zoom subsequently paid 85 million dollars in a settlement (Huntress, 2022). The incident happened some years ago, but it illustrates the underlying problem. Anyone who records on Zoom and chooses cloud recording is trusting a third party with the custody of sensitive data.
Zoom does offer an EU data center, but as a US company it remains subject to the Cloud Act. The local recording option saves the file on your own machine, but it is not available on every plan.
Recording on Teams and the storage location fallacy
When you record a meeting in Teams, the file ends up in SharePoint or OneDrive for Business. Microsoft advertises its EU Data Boundary, under which European customer data is processed in EU data centers. The EU Data Boundary does not, however, protect against the Cloud Act.
There is also a practical problem. Global corporations often host their Microsoft 365 tenants in the US. In those cases, meeting recordings physically sit on US servers without users being aware of it.
Recording on Google Meet and automatic deletion
To record on Google Meet, you need at least the Business Standard plan for 13.60 EUR per user per month (workspace.google.com). Recordings land exclusively in the organizer's Google Drive. Google Meet offers no way to record locally without the cloud. That sets it apart from Zoom, which at least offers a local option.
Google deletes recordings after 3 months by default (support.google.com). For companies with retention obligations, for example in the financial sector with 5 to 7 years under §83 WpHG, that is a significant risk. Anyone who does not actively adjust the deletion periods loses meeting recordings automatically. Like Zoom and Microsoft, Google as a US company is also subject to the Cloud Act. Gemini AI features additionally process recordings for summaries and transcripts (Google Workspace Blog), which raises further questions about data processing.
Drawbacks of all three platforms when it comes to storage
Whether you record on Zoom, on Teams or on Google Meet, the three major platforms share a fundamental problem. All recordings end up on servers of US companies subject to the Cloud Act. Google Meet and Teams have no local storage option at all. Zoom does offer local recordings, but then disables transcription and all AI functions. Storage is limited everywhere. Zoom offers 10 GB per license, Google Meet deletes after 3 months, Teams counts against the 1 TB OneDrive quota. Anyone using Zoom, Teams and Google Meet in parallel ends up managing recordings across three separate systems with no central search. For companies that want to keep control over their data, storage that is local by default with tools like Jexity Meet is one option that addresses Cloud Act exposure, automatic deletion and platform lock-in at the same time.
To see which recording method works best in which scenario, check the comparison in Meeting recording software compared.
What encryption actually protects your meeting recording?
52% of companies introduced end-to-end encryption for sensitive workflows in 2026, up from 38% the year before (CompareCheapSSL, 2026). That sounds like progress. But it also means that almost half of all companies still don't encrypt meeting recordings end to end. Three levels determine how well your recordings are protected.
Transport encryption vs. end-to-end
Most video conferencing and transcription tools encrypt data in transit. That applies to Zoom, Microsoft Teams, Google Meet and Webex, just as it does to most cloud-based AI recording and transcription tools. The encryption protects against interception in transit. On the server itself, however, the data sits unencrypted. The provider, its employees and potential attackers with server access can view the recording.
End-to-end encryption goes a step further. Only the participants hold the keys, and the provider cannot read the data. But Zoom disables cloud recording, live transcription and all AI functions when end-to-end encryption is turned on (Zoom Support, 2026). Microsoft Teams restricts things even further. End-to-end encryption there only works in one-to-one calls, not in group meetings, and recordings are blocked entirely (Microsoft, 2026). If you want maximum encryption, you cannot record in the cloud at the same time.
Local encryption: full control over your data
The strongest level is local encryption. The recording is encrypted directly on your device, and only you hold the key to decrypt it. No cloud provider, no authority and no attacker can open the file without physically gaining access to your device.
The advantages over cloud encryption are considerable. First, the recording works even without an internet connection, which is critical for on-site meetings or unstable networks. Second, there are no restrictions on meeting functions, because the encryption works independently of the conferencing platform. Third, every third-country transfer is eliminated, because the data never leaves the device. And fourth, you keep full control over when and with whom you share the recording.
For industries with strict data protection requirements, this complete control over your own data is often the simplest way to meet legal obligations. But even companies without regulatory duties benefit clearly from local encryption, because sensitive business conversations, strategy discussions or HR topics never leave their own sphere of control.
Which industries must store meeting recordings locally?
In healthcare, data breaches cost an average of 9.77 million dollars, more than in any other industry (IBM, 2024). Three sectors are particularly affected because they must comply with stricter rules for storing sensitive data than other companies.

Healthcare: patient data only into the cloud with a certificate
Since July 2024, cloud providers in healthcare have had to present a security certificate from Germany's Federal Office for Information Security. Since July 2025, this requirement has been tightened further: providers must now also demonstrate that their security measures are actually effective (solidaris.de, 2025). This also applies to meeting recordings from doctor-patient conversations or case discussions between physicians. If a company uses a cloud provider without this certificate for patient data, it violates applicable law and faces fines and liability risks. Anyone who stores locally needs no certificate, because no external provider processes the data.
Banks and insurers: strict retention obligations
Since January 2025, the Digital Operational Resilience Act, or DORA, has applied. It requires banks, insurers and securities firms in the EU to demonstrably manage their IT risks, even when they use cloud services (BaFin, 2025). In addition, §83 of the German Securities Trading Act requires that all conversations which could lead to a business transaction be retained for 5 to 7 years (§83 WpHG). Anyone recording such conversations in Teams must archive them in a legally defensible way for the entire period. How seriously this is taken is shown by a case from the US. There, the securities regulator imposed fines totaling 63.1 million dollars on 12 financial firms in January 2025 for failing to properly retain their communications (SEC, 2025).
Lawyers, tax advisors and auditors: professional secrecy
These professions are bound by §203 of the German Criminal Code. In simple terms, that means they must protect their clients' secrets under threat of criminal punishment. Before client data goes into a cloud, the provider must be contractually bound to confidentiality, through a dedicated supplementary agreement, not just general terms and conditions (innFactory, 2026). With a US cloud provider, the conflict between the Cloud Act and the GDPR adds to the risk. If US authorities demand access, that can trigger the criminal offense of breaching private secrets. Local storage without a cloud provider avoids this risk.
What does cloud storage cost compared to local storage?
European spending on sovereign cloud infrastructure is rising from 6.9 billion dollars in 2025 to 12.6 billion in 2026, an increase of 83% (Gartner via Computerworld, 2026). This trend shows that companies are willing to invest more for data sovereignty. But does local storage also pay off for individual meeting recordings?
Ongoing costs with cloud providers
Cloud recording is included in many video conferencing subscriptions, but it causes hidden costs. Storage space is limited. Zoom Pro, for example, offers 10 GB of cloud storage per license. A one-hour meeting in HD takes up 0.5 to 1 GB depending on quality. Anyone who wants to record on Google Meet instead needs the paid Business Standard plan and shares that storage with all other Drive files. Anyone recording several meetings a day quickly hits the limit with every provider and has to buy additional storage.
On top of that come compliance audits, data protection impact assessments and reviews of data processing agreements. These hidden costs rarely show up in the calculation. The article Recording meetings in person, online and hybrid shows the differences by meeting format.
A one-time investment for local storage
Local recording relies on hardware you already have. An external 2 TB SSD costs under 100 euros and stores hundreds of hours of meetings. No monthly storage fees, no compliance reviews for third-party providers, no third-country transfer assessments.
Frequently asked questions
Is a local meeting recording safer than the cloud?
In most cases, yes. Local recordings are not exposed to the Cloud Act and eliminate third-country transfer risks. According to IBM, data breaches involving cloud-stored data cost over 5 million dollars (IBM, 2024). Local encryption with your own key management offers the strongest protection.
Am I allowed to record a Zoom meeting without asking all participants?
No. Under German law, §201 of the Criminal Code prohibits recording non-public spoken words without the consent of all participants. That applies regardless of whether you record locally or in the cloud. Obtain the explicit consent of everyone involved before every recording.
Where does Microsoft Teams store the meeting recording?
Teams recordings land in SharePoint (for channel meetings) or OneDrive for Business (for one-to-one calls). The physical location depends on the tenant setup. Despite the EU Data Boundary, Microsoft as a US company remains subject to the Cloud Act, which limits the protection of European data.
What does the Cloud Act mean for German companies?
The US Cloud Act (2018) allows US authorities to request data from US technology companies regardless of where it is stored. For German companies recording with Zoom or Teams, this creates a potential conflict between the Cloud Act and the GDPR. The EU Data Act has required cloud providers since September 2025 to prevent unlawful access by non-EU authorities (digitoren.de, 2026).
What encryption does a meeting recording need?
For maximum protection, AES-256 encryption with local key management is recommended. Transport encryption (TLS) only protects the transmission path. End-to-end encryption prevents access by the provider. 52% of companies already use E2EE for sensitive workflows (CompareCheapSSL, 2026). Local encryption goes furthest, since the key never leaves the device.
Sources(20)
- bitkom.orgBitkom: Wirtschaft ruft nach deutscher Cloud (2025)
- otris.deotris: Studie Cloud-Governance (2026)
- digitoren.dedigitoren.de: Cloud Act, EU Data Act, was deutsche Unternehmen jetzt beachten müssen (2026)
- theregister.comThe Register: Microsoft admits it cannot guarantee data sovereignty (2025)
- newsroom.ibm.comIBM: Cost of a Data Breach Report (2024)
- huntress.comHuntress: Zoom Data Breach (2022)
- comparecheapssl.comCompareCheapSSL: Data Privacy & Encryption Statistics (2026)
- solidaris.desolidaris.de: Einsatz von Cloud-Diensten im Gesundheitswesen, endlich eine klare Regelung (2025)
- bafin.deBaFin: IT- und Cybersicherheit (2025)
- gesetze-im-internet.de§83 WpHG: German Securities Trading Act, recordkeeping duties (statute)
- sec.govSEC: 12 financial firms sanctioned over recordkeeping failures (2025)
- precedenceresearch.comPrecedence Research: Video Conferencing Market (2025)
- demandsage.comDemandSage: Zoom Statistics (2026)
- computerworld.comComputerworld: Gartner, European Spending on Sovereign Cloud IaaS to Nearly Double in 2026 (2026)
- innfactory.deinnFactory: Berufsgeheimnis §203 StGB und Public Cloud (2026)
- support.zoom.comZoom Support: End-to-end encryption, restrictions (2026)
- learn.microsoft.comMicrosoft: Teams End-to-End Encryption (2026)
- workspace.google.comGoogle Workspace: Pricing (2026)
- workspace.google.comGoogle Workspace Blog: Google Workspace enables the future of AI-powered work for every business (2025)
- support.google.comGoogle Support: Retention periods for Meet recordings (2026)
This article was created with AI assistance and editorially reviewed. Images are AI-generated.
Keep reading

Recording Conversations at Work: A Complete Guide
31 hours a month lost in unproductive meetings, and without documentation, 70% of decisions are forgotten within 24 hours. Learn how to record conversations legally, transcribe them and turn them into minutes.
14 min read
Recording Hybrid Meetings: How to Get Every Recording Right
Three people in the room, two working from home, and nobody hits record. Here is how to capture every meeting format without losing audio, video, or privacy along the way.
10 min read
Can I Record a Meeting? GDPR and Criminal Law Explained
Anyone recording a meeting must follow GDPR and criminal law at the same time. This article explains the rules both laws set for recordings, shows the most common mistakes, and how to make recordings legally sound.
12 min readTry it on your next meeting
Record or import one meeting and see the minutes it produces. No account and no credit card.