Alexa Now Sends All Recordings to Amazon — Is It GDPR Compliant?

Martin Bastius
22.07.2025
999
min.

Alexa Is Now Always in the Cloud — Your Voice Command, Your GDPR Risk

In a controversial move, Amazon has changed its privacy policy for Alexa-enabled devices — with major implications for GDPR compliance:
Since March 28, 2025, Amazon has disabled the "Don't send voice recordings" setting — on all Echo devices that would otherwise support local storage. This means that from now on, all Alexa interactions triggered by the wake word ("Alexa," "Echo," etc.) are always sent directly to Amazon's cloud. There is no longer any way to turn off this cloud processing.

This system change coincides with the rollout of Alexa+, Amazon's new generative AI assistant that promises more advanced, personalized, and context-aware conversations.

Amazon argues that this data transfer is necessary to deliver Alexa+ features such as memory, better contextual understanding, and intelligent dialogue. At the same time, this means that as a user, you lose control over whether your voice data is stored, analyzed, or even used to train future AI models. This raises significant questions about data protection, consent, and lawfulness — especially under the GDPR.

If your company develops AI tools, voice assistants, or smart home products, this is a clear signal: data protection and privacy by design are no longer optional — they're central to user protection and legal responsibility.

GDPR Concerns With Amazon's New Alexa Policy

Amazon's new Alexa policy raises many questions from a GDPR perspective.

While Alexa still waits for the wake word, removing the opt-out for sending recordings to the cloud changes the legal picture. Now, every interaction that's triggered is stored and processed off the device.

Here are the key GDPR principles that Amazon's new approach may violate:

1. Consent

According to Articles 6 and 7 of the GDPR, any data processing must be based on freely given, specific, informed, and unambiguous consent.

Amazon's decision to remove the ability to disable cloud processing significantly weakens user control. No one has to consent to data being collected and stored anymore — it's simply always on. Instead of "Don't send voice recordings," there's now the "Don't save recordings" setting. This means your voice recordings are always sent to the cloud and only deleted after processing — an approach that undermines the core GDPR principle of freely given, specific consent.

2. Right to Object

Under Article 21 GDPR, data subjects have the right to object to the processing of their personal data — especially when the processing is based on the company's legitimate interest (rather than consent).

Currently, there's no real mechanism for this. The only way to prevent recordings from being sent is to stop using Alexa altogether or disable the microphone. That's not a genuine opt-out in the GDPR sense — users are effectively forced to accept cloud processing.

3. Data Minimization

Article 5 GDPR requires that only data strictly necessary for the specific purpose may be collected.

With Alexa+, all voice data is now sent to the cloud by default. Amazon claims this practice enables new generative AI capabilities like memory and personalization. But under the GDPR, the key question is: is this comprehensive data collection actually proportionate?
Without a clear technical justification or more granular controls, sending every interaction is legally questionable.

4. Children's Data

Personal data belonging to children requires special protection under the GDPR. In many EU countries, children under 16 cannot consent to processing themselves — only their parents can.

Alexa is often used in family settings. When a child speaks after the wake word, Alexa now always sends that recording to Amazon — even if no adult has given permission. Amazon hasn't explained how it determines whether a speaker is a minor, or how it verifies parental consent.
This opens the door to unwanted data collection involving children without a legal basis — Amazon was previously fined $25 million in the US for retaining children's voice recordings indefinitely (COPPA).

Six steps describe what happens to data once it reaches Alexa+.
Sending voice data to Alexa involves GDPR weaknesses that need to be taken into account.

Best Practices for GDPR-Compliant Voice and AI Products

Amazon isn't the only company criticized for how it handles voice data. Google, Apple, and Meta have faced similar privacy scandals, from accidental recordings to missing consent and sending conversations to contractors. These cases make one thing clear: voice tech and data protection must go hand in hand.

Amazon's move is a textbook example of the conflict between AI development and data protection. It also shows that the trend toward "smarter" AI assistants often comes at the cost of less user control, with more focus placed on model performance instead.

For companies developing voice-controlled tools, the rule is clear: GDPR violations don't just result in fines — they also damage trust and reputation!

How do you design responsible voice systems?
Here are concrete tips to minimize risk and stay compliant:

  1. Obtain explicit, granular consent: Show users in detail what they're consenting to, whether it's recording, use for service improvements, product testing, or AI training.
  2. Practice data minimization: Only collect what you truly need — often a transcript is enough instead of the full audio.
  3. Make data protection the default: Don't make users dig through settings — strong privacy must be the default ("privacy by design and by default" under Art. 25 GDPR).
  4. Absolute transparency: Inform users (e.g., during onboarding or in privacy notices) clearly about which voice data is collected, when, why, for how long, and whether it's shared with third parties.
  5. Respect user rights: Build in tools that let users easily view, delete, or export their voice data without hurdles or delays.
  6. Account for context and third parties: Voice assistants are often placed in open spaces. Develop solutions (e.g., voice recognition or context-dependent activation) to avoid collecting unwanted data from children or bystanders.
  7. DPIA (Data Protection Impact Assessment) for all voice/AI projects:DPIA is mandatory if you process sensitive data, conduct profiling, or use automated decision-making.
The following is a list of various GDPR principles and an assessment of Alexa in this context.
When using Alexa+, it's important to take concrete steps to minimize GDPR risks.

Conclusion

Amazon's decision to have Alexa record everything by default is more than a technical upgrade — it brings the fundamental conflict between innovation and privacy to light.
Companies that take the GDPR seriously and handle user data responsibly during development are better positioned in the long run: they earn user trust and avoid the risk of fines or reputational damage.

Tip: heyData makes compliance simple, whether you're building the next big AI or laying the groundwork for data protection in the EU.

Published
22.07.2025
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories