Secure Video Conferencing Despite the Cloud Act

Jexity Meet TeamSeptember 28, 202612 min read
Woman in a video conference on her laptop, with an external drive next to it on the desk
On this page

Do you know where your meeting data is stored when you record a Zoom call or have meetings transcribed online? With US providers such as Zoom, Teams and Google Meet, US authorities can access this data under certain conditions. 85 percent of German companies now see their country as too dependent on US cloud services (bitkom.org). Whether video conferencing is secure depends less on the technology than on the processing model, meaning where and by whom the data is processed.

What matters for secure video conferencing?

In April 2026, Germany's BSI published the C3A criteria, the first assessment framework for cloud independence (bsi.bund.de). Besides attacks by criminals and state actors, the BSI names a third danger, so-called "Cyber Dominance". This refers to the possibility that a cloud provider permanently retains access to its customers' systems and data without them being able to effectively prevent it.

With cloud processing, your meeting data sits on a third-party provider's servers. The provider manages the technology, holds the keys and decides on updates and access rights. You give up control and gain scalability and low IT effort in return. What types of AI meeting assistants exist and where they process data is covered in the guide on choosing the right AI meeting assistant.

With local processing, recordings and minutes stay on your own computer, and a cloud provider has no access to them. According to the BSI, users can choose the processing location depending on criticality and their own risk analysis. So clarify in advance where recordings and minutes end up.

What should high-risk professions pay attention to?

Certain professional groups are under special protection. Doctors, lawyers and tax advisors are required under § 203 of the German Criminal Code (gesetze-im-internet.de) to protect the secrets of their clients and patients. A violation can be punished with up to one year in prison.

TRIESCHconsult (trieschconsult.de) warns of the risk of storing meeting data in insecure cloud services without a data processing agreement. Encryption and two-factor authentication are considered necessary minimum standards. The author classifies consumer messengers such as WhatsApp or Telegram as high-risk for professional use.

For these professional groups, secure video conferencing with simple transport encryption is not enough. The provider must have no technical access to the conversation content. And even encrypted transmission is of little use if the recording is then stored unencrypted in the cloud.

Why doesn't end-to-end encryption alone protect you?

Many providers advertise encryption, but not every encryption offers the same protection. There are two fundamentally different variants.

Transport encryption only protects the path between your device and the server. On the server itself, the data lies exposed, or the operator holds the keys. This is comparable to a letter transported in a sealed envelope that can be opened and copied by the courier.

End-to-end encryption (E2EE) encrypts the data at the sender and only decrypts it at the recipient. The platform operator cannot read along. A 2020 analysis by the DSN Group (dsn-group.de), citing the BSI, makes clear that when a so-called Multipoint Control Unit (MCU) is used, meaning the server that merges video and audio streams for most cloud providers, no real end-to-end encryption can be achieved.

But even genuine E2EE has an important limitation. It only protects the data during transmission. As soon as a meeting is recorded or transcribed online, a file is created that must be stored. If this recording or transcript ends up in the provider's cloud, the protection from E2EE is void, because the stored data is once again accessible there. Truly secure video conferencing must therefore secure both the transmission and the storage of the data.

A hand closing a laptop, with an external hard drive next to it on the desk

The Cloud Act and video conferencing

The Microsoft Transparency Report shows how real the access to data outside the US is (microsoft.com). In the second half of 2025, US law enforcement agencies used search warrants in 115 cases to demand content that Microsoft had stored on servers outside the US. A total of 5,587 requests for consumer accounts came in during this period. Microsoft lists requests for enterprise accounts separately, at 190 worldwide.

What is the Cloud Act?

The Cloud Act (Clarifying Lawful Overseas Use of Data Act) is a US law from 2018. It allows US authorities to compel providers under US law to hand over stored data, regardless of whether the data is located inside or outside the US. This is how the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) describe it in their joint assessment from 2019 (edpb.europa.eu). Whether the servers are in Frankfurt, Amsterdam or Singapore therefore does not matter.

32 percent of all US requests to Microsoft came with a non-disclosure order. In these cases, Microsoft is not allowed to inform those affected that their data was requested.

What effect does it have on video conferencing?

Every conversation on a US platform can become the subject of such an order, whether a client meeting, a job interview or a strategy session. Anyone who records meetings and has them transcribed stores the entire conversation content as searchable text with the provider. That makes transcripts a particularly revealing target for data requests. What rules already apply to the recording itself is explained in the article on recording meetings under GDPR.

A data processing agreement under Art. 28 GDPR cannot prevent this access. According to the EDPB and EDPS, providers under US law that process data under the GDPR face a conflict between US law and the GDPR. A contract between you and the provider does not resolve this contradiction. Anyone looking for secure video conferencing must therefore pay attention to the provider's country of origin. Not every European provider is automatically protected. Subsidiaries of US companies can still be subject to US disclosure obligations through their parent company. German video conferencing providers without a US parent company and without business in the US are generally not subject to this.

Why the Data Privacy Framework doesn't fully protect you

What is the Data Privacy Framework?

The Data Privacy Framework (DPF) is an agreement between the EU and the US. It is meant to ensure that personal data of European citizens is adequately protected even at US companies. Over 5,300 US companies have certified under the DPF (activemind.legal). This certification allows them to transfer data from the EU to the US without violating the GDPR.

However, this is already the third such agreement. Safe Harbor fell in 2015 through a ruling by the European Court of Justice (CJEU), Privacy Shield in 2020 through another. In both cases, a single ruling was enough, and companies had to switch their data transfers on short notice.

Why the DPF is shaky

The DPF only works if an independent authority in the US watches over US companies keeping their promised data protection rules. This task falls to the Federal Trade Commission (FTC), comparable to a consumer protection agency. On June 29, 2026, the US Supreme Court ruled that the US government may dismiss FTC members at any time. Previously, they were protected from political influence. Without this independence, the FTC can no longer credibly guarantee compliance with the DPF, and the entire agreement loses its foundation.

Among companies that use or are considering cloud services, the provider's country of origin plays a role for 98 percent. When making a concrete choice, 61 percent name the country of origin as a decision criterion. In fact, 71 percent source cloud offerings from the US, even though 91 percent would prefer German providers. 37 percent would even accept trade-offs against existing offerings for digital independence (bitkom.org). A provider without US dependency lowers both risks at once, the possible loss of the DPF and US data access. Anyone who switches to a European or local provider now does not need to change contracts or run new legal reviews if the DPF falls.

Three processing models compared

Depending on protection needs and IT capacity, three processing models are worth considering.

US cloud

Platforms such as Zoom, Teams and Google Meet store and process data on servers owned by US companies. It does not matter whether the servers are physically located in the EU or the US, because the US disclosure law applies to the company, not the server location. DPF certification allows the data transfer to the US but offers no technical protection against government access. Recordings and transcripts sit on US-controlled servers and are viewable by the provider. These platforms offer a large feature set and a short learning curve, but the company remains dependent on the DPF and has no protection against government access to stored data. Where recordings are best kept is compared in the article on meeting recording in the cloud and locally.

EU cloud

European video conferencing providers run their servers in Europe, for example in Germany or Switzerland (heise.de). Without a US parent company, they are generally not subject to the Cloud Act. Switching to such a provider reduces the access risk and removes the DPF dependency. However, the operator still has technical access to the data on its servers. Even if the video transmission is encrypted, recordings and transcripts sit on the provider's servers, and end-to-end encryption does not protect these stored files. When choosing a provider, make sure it has no US parent company that would indirectly subject it to US disclosure obligations. Transcription is more limited in feature scope at some European providers than at US platforms.

Local processing

In the third model, processing happens on your own device. Jexity Meet works on this principle by default. With the default settings, the AI on your device creates a complete transcript from the recording, summarizes the key results, lists open action items and produces finished minutes that you can export and share as PDF or Markdown. Past meetings stay by default in a local library, which you can ask questions about decisions, topics or participants from earlier meetings. By default, the meeting content does not leave the device, and neither the provider nor third parties have access to it. That removes the question of server location and cloud provider entirely. The weakness of end-to-end encryption for stored files also does not matter, because recordings and transcripts are then not stored on someone else's server. Processing does, however, require computing power on your own device, and the finished minutes must be shared manually with colleagues when needed.

US cloudEU cloudLocal
Cloud Act riskYesLowNo
Provider can view dataYesYesNo
Recordings protectedNoPartiallyYes
IT effortLowLowMedium (device computing power)
DPF dependencyYesNoNo

How to switch to secure video conferencing

The study "State of Digital Sovereignty 2026", reported by the provider Tuta, surveyed 1,818 IT decision-makers in Germany, France and the Nordic countries (tuta.com). In Germany, 39.7 percent are already actively introducing European software alternatives, almost twice as many as the year before. 32.4 percent are planning to switch away from foreign providers, 16.4 percent have already switched.

Why switching is easier than expected

59 percent of cloud users name lock-in effects as the biggest obstacle to switching providers (bitkom.org). This problem is smaller for video conferencing software. Unlike CRM or ERP systems, no customer data, histories or configurations need to be transferred. Mainly, you need to sort out recordings and transcripts stored with the previous provider, which you should export or delete. The learning curve is usually short, because video conferencing tools generally work in similar ways. And you don't have to switch everything at once. Start with the most sensitive areas, such as client meetings, HR conversations or strategy sessions, and let general meeting operations continue temporarily on the previous platform. What the tools themselves cost is covered in the article what AI meeting tools really cost.

What happens if you don't switch?

The migration costs, which 33.5 percent of German respondents in the Tuta study name as an obstacle (tuta.com), are usually low for video conferencing tools. Waiting, on the other hand, risks significantly higher costs. If the DPF falls a third time, affected companies would have to switch on short notice. That means time pressure when choosing a provider, unplanned license costs and productivity losses from running two systems in parallel without preparation. Anyone who already has a secure video conferencing alternative in place stays capable of acting, no matter what happens to the DPF.

Make the processing location the first criterion in your selection. Many providers offer free trial periods. Use them for a test run with a real meeting.

Frequently asked questions

Can Zoom be used in a GDPR-compliant way?

Zoom is certified under the DPF and therefore currently approved for data transfers to the US. GDPR compliance depends on correct configuration, a data processing agreement and a data protection impact assessment. The access risk from US authorities remains regardless, because Zoom as a US company is subject to the Cloud Act. Anyone using Zoom's AI features, such as summaries or automatic transcription, must meet further data protection requirements. Which GDPR mistakes commonly happen there is covered in detail in our article AI transcription and GDPR.

Which secure video conferencing solution is suitable for lawyers and doctors?

Professionals bound by confidentiality obligations under § 203 of the German Criminal Code need a solution where no third party can access the conversation content. End-to-end encryption alone is not enough. E2EE only protects the transmission, not the stored recording or transcript. If this data then sits in the provider's cloud, the protection is voided. German video conferencing providers that operate under German law and without US disclosure obligations offer additional legal certainty. The safest option is a local solution where neither the recording nor the transcript leaves your own computer.

What happens if the Data Privacy Framework is struck down?

Then data transfers to US providers without additional safeguards would be unlawful. Twice already, in 2015 and 2020, the CJEU has struck down such agreements. The Supreme Court ruling from June 2026 has raised this risk again. Companies that have already switched to a European provider without a US parent company or to local processing would not be affected.

Which server location offers the best protection?

The server location alone is not enough. A US provider with a data center in Frankfurt is still subject to US disclosure obligations, because the Cloud Act ties to the company, not the server location. What matters is therefore whether the provider is subject to US jurisdiction and whether it can technically view the stored data. Local processing is the safest, because the data never leaves your own computer.

Can I record meetings and transcribe them online securely?

That depends on the processing location. Cloud-based transcription at US providers is subject to US disclosure obligations. European providers process the data in Europe, but the transcripts sit on the provider's servers. The safest option is local processing. Jexity Meet, for example, performs recording and transcription directly on your own computer by default, without a cloud upload.

Sources(10)
  1. bsi.bund.deBSI: C3A criteria against "Cyber Dominance" (2026)
  2. dsn-group.deDSN Group: End-to-end encryption of video conferences (2020)
  3. bitkom.orgBitkom: German cloud, 4 in 10 companies would accept trade-offs (2026)
  4. microsoft.comMicrosoft: Transparency report on government requests (2025)
  5. activemind.legalactiveMind.legal: Data Privacy Framework after the Supreme Court ruling (2026)
  6. tuta.comTuta: State of Digital Sovereignty (2026)
  7. trieschconsult.deTRIESCHconsult: Digitalization and confidentiality under § 203 of the German Criminal Code (2025)
  8. heise.deheise.de: Video conferencing tools, European alternatives compared (2025)
  9. gesetze-im-internet.de§ 203 German Criminal Code: Violation of private secrets (statute text)
  10. edpb.europa.euEDPB/EDPS: Joint assessment on the Cloud Act (2019)
secure video conferencingGerman video conferencing providerCloud Actonline transcription
Share:LinkedInXE-Mail

This article was created with AI assistance and editorially reviewed. Images are AI-generated.

Try it on your next meeting

Record or import one meeting and see the minutes it produces. No account and no credit card.