In the digital age, online meetings have become the new normal — not just in home offices, but also in international collaboration. At the same time, we're seeing a boom in AI technologies that automatically record, transcribe, and even summarize meetings.
The problem: while these tools keep getting smarter, many data protection questions remain unanswered. When is a recording legally permitted? What does this mean for the confidentiality of the spoken word? And how can companies build trust instead of fueling fears of surveillance?
AI-Powered Recordings in Everyday Life — A New Standard?
Digital assistants that "listen in" on meetings are no longer the exception. Tools like Otter.ai, Fireflies.ai, Zoom AI Companion, or Microsoft Copilot automatically generate:
- Verbatim records and transcripts
- Summaries with action points
- Emotional tone analyses
- Automatic follow-up e-mails
A real-world example:
A SaaS sales team uses an AI tool to automatically transcribe all customer calls and turn them into structured CRM notes. This saves time — but often the customer has no idea. And even internally, it's unclear where this data is stored and who can access it.
Bottom line: what looks productive can quickly become a breach of trust if communication isn't clear.
What Are the Legal Requirements for Recording Online Meetings?
Two principles apply in this legal context:
- Consent requirement: In Germany and across the EU, an online meeting may only be recorded if all participants clearly consent in advance.
- Information requirement: Participants must be clearly informed in advance about,
- why the recording is taking place,
- how the data will be processed,
- where it will be stored,
- and how long the data will be retained.
→ Important: An automatic notice like "This meeting is being recorded" is not enough if there's no active consent (e.g., via a click, written consent, or a verbal confirmation at the start of the call).
Common mistakes to avoid:
- Recording without a notice in the calendar invite
- Verbal notices without documented consent
Transcription tools running in the background — without other participants knowing
Section 201 of the German Criminal Code: Violating the Confidentiality of the Spoken Word — What Does This Mean in Practice?
Many forget: it's not just the GDPR that matters here. In Germany, the covert audio recording of a non-public conversation is a criminal offense — regulated under Section 201 of the German Criminal Code (StGB).
In practice, this means:
- Anyone who records a private or internal conversation without consent is committing a criminal offense — even in purely digital meetings.
- Non-public means: the conversation is only accessible to a closed group (e.g., a team meeting, a customer call, a job interview).
A case example:
An HR team records a candidate interview with an AI tool for later internal review — but forgets to obtain consent. Result: a clear violation of criminal law and the GDPR.
Challenges and Risks of Using AI in Online Meetings
Integrating AI systems brings efficiency gains, but also serious risks — especially when handling sensitive data:
- Data storage in insecure cloud environments, e.g., outside the EU (US, India, etc.)
- Lack of control over further processing by third parties, for example for AI training purposes
- Automatic extraction of personal characteristics such as voice pitch, mood, or reaction time (profiling)
Concrete risks:
- A faulty summary can distort statements and lead to misunderstandings.
If the transcript is sent to team members who weren't part of the call, this can constitute a breach of data confidentiality.
A Particular Risk: Automatic Transcription and Analysis by AI
Automatic transcription is convenient — but also tricky. Because:
- It creates a permanent written record of a spoken conversation.
- This can be forwarded, copied, or misused within seconds.
- The text often ends up in systems that many people can access — e.g., internal collaboration tools or CRM systems.
What companies should do:
- Only grant access to transcripts based on user roles
- Define automated deletion periods (e.g., 30 days)
- Ensure that no AI post-processing to "optimize" content takes place without consent
To put it in perspective:
A transcript is like a screenshot — but of the entire conversation. One wrong click, and it lands with the wrong person or an external stakeholder. That can be disastrous, not just from a data protection standpoint, but for the business too.
Best Practices for GDPR-Compliant Online Meetings
To make online meetings legally secure and trustworthy, the following measures are recommended:
Before the meeting:
- Clear notice in the calendar invite: "Recording planned — consent required"
- Choose GDPR-compliant tools (EU servers, clear policies, certified)
- Obtain consent in advance or document it verbally at the start
During the meeting:
- Create transparency: Who is recording? Why? Where does the data go?
- Add visual cues (e.g., keep the recording icon visible in the video call)
- Offer the option to decline or join anonymously
After the meeting:
- Access restricted to authorized persons
- Limit the storage period
- Implement deletion routines and audit logs
Optional: store summaries instead of full transcripts
Technology Solutions for Secure Online Meetings
Not every platform is the same. Look for tools with:
- End-to-end encryption
- Granular access controls
- GDPR-compliant storage (e.g., EU data centers)
- Configurable recording features (only activatable with consent)
Recommendation: use tools like BigBlueButton (open source, GDPR-compliant) or Zoom with enhanced privacy settings (when configured). With US providers, pay attention to Standard Contractual Clauses (SCCs) and supplementary data processing agreements.
Future Outlook: How AI Can Improve Security in Online Meetings
AI isn't just a risk — it can also be part of the solution when used correctly. Future systems could:
- Trigger real-time alerts for data protection violations (e.g., detecting unauthorized recording)
- Enable data-minimized processing (capturing only metadata, not content)
- Automatically provide transparency reports (who saw what, and when?)
Instead of tightening control, AI systems could help strengthen accountability and trust in digital collaboration — provided they're designed ethically and lawfully.
Conclusion: Building a Privacy-Safe Meeting Culture Through Clear Rules and Communication
AI-powered online meetings are here to stay. But only those who create transparency can build lasting trust with their employees, customers, and partners.
- Clear consent processes
- Deliberate tool selection
- Technical security measures
- Ethical handling of data
Companies that follow these principles can benefit from modern technology — without putting data protection or company culture at risk.
FAQ
Is recording online meetings with AI note-taking assistants legally permitted?
Is recording online meetings with AI note-taking assistants legally permitted?
A recording — whether audio, video, or transcription — is only legal if all participants have expressly consented in advance. A simple automatic notice or an AI bot silently running along in the background isn't legally sufficient. In addition, participants must be informed about how and where the data is stored.
What criminal consequences can secret AI recordings have?
What criminal consequences can secret AI recordings have?
In Germany, you risk not only fines under the GDPR but also criminal consequences. Under Section 201 of the German Criminal Code (StGB) (violation of the confidentiality of the spoken word), anyone who records another person's non-public spoken words without their consent is liable to prosecution. This also applies to digital meetings, job interviews, and internal team calls.
What specific data protection risks do AI transcription tools pose?
What specific data protection risks do AI transcription tools pose?
AI tools (such as Otter.ai, Fireflies, or Zoom AI Companion) turn spoken words into permanent text that can easily be copied or forwarded. The main risks include:
- Data storage on servers outside the EU (e.g., the US)
- Potential use of the audio data/transcripts by the software provider to train its own AI models
- Uncontrolled forwarding of sensitive meeting minutes to people who didn't attend the call
How can companies make AI recordings compliant with data protection law?
How can companies make AI recordings compliant with data protection law?
Companies should establish clear best practices:
- Inform in advance: Include notice of the planned recording in the calendar invitation.
- Obtain consent: Actively obtain and document the consent of all participants at the start of the call.
- Anonymization & deletion periods: Restrict access to transcripts on a role basis and set up automatic deletion periods (e.g., after 30 days).
- Choose secure tools: Use software with servers located in the EU and conclude Data Processing Agreements (DPAs) with the providers.







