klangzeile
Menu

Blog

Transcribing sensitive recordings under the GDPR: what EU-only really means

A recording of a meeting, an interview or a patient conversation is personal data: voices, names, opinions, sometimes health or HR details. Sending it to a transcription service makes that service your processor under the GDPR. Phrases like "hosted in the EU", "zero data retention" and "deleted after download" help only if you know what each one covers. This article is a practical guide, not legal advice.

Your role and the vendor's role

When you upload a recording, you are the controller: you decide why and how the data is processed. The transcription vendor is a processor acting on your instructions. Article 28 GDPR requires a written contract between you, the data processing agreement (DPA; in German Auftragsverarbeitungsvertrag, AVV). Any provider the vendor itself uses to process your content, such as the hosting company or a speech model provider, is a sub-processor and must be bound by the same obligations.

Two things stay with you regardless of the vendor:

  • A legal basis for recording and transcribing, and informing the people who were recorded. In some countries recording a private conversation without consent is itself an offence; in Germany, for example, section 201 of the Criminal Code makes it an offence to record another person's non-public spoken words without authorisation.
  • Special categories under Article 9 (health, religion, trade union membership, biometric data and others). If recordings contain them, you need a specific justification and possibly a data protection impact assessment (Article 35).

What "processing in the EU" means in practice

"Our servers are in the EU" can mean very different things. Ask about each stage the data passes through:

  • Upload and storage: where the file lands, where the result is kept until you fetch it.
  • The speech model: many vendors pass audio on to a model provider. Where does that run, and under which company?
  • Side channels: e-mail intake, content delivery networks, error tracking, support tools. These are often outside the EU even when the core service is not.
  • The company behind it: a provider with a parent company outside the EU may be subject to foreign authorities' access requests even for data stored in the EU. How much weight to give that is debated; your data protection officer should decide.
  • Transfers: where data does leave the EU, the DPA should name the mechanism, typically the EU standard contractual clauses or, for US companies, the EU-US Data Privacy Framework.

What "zero data retention" means

Zero data retention (ZDR) usually describes an agreement with a model provider: inputs and outputs are used to answer the request and are not stored afterwards, and they are not used for training. Questions that separate a real commitment from a slogan:

  • Is it contractual, or a default setting that can change?
  • Does it cover every feature that touches your content (transcription, speaker labels, summaries, translation), or only some?
  • Are there exceptions, for example abuse monitoring logs kept for a period? Some model providers keep such logs by default and waive them only under a separate agreement.
  • Does it apply to the vendor's own systems as well, or only to the model provider?

What "deleted after one fetch" means

Asynchronous transcription needs somewhere to keep the result between the end of processing and your download. "Deleted after one fetch" means that storage is short-lived: the first successful download removes the result, and an unread result expires after a fixed time. Check:

  • How long an unread result survives, and whether that is enforced automatically.
  • How it is stored in the meantime (encrypted, with keys where?).
  • What remains afterwards. Almost every service keeps some metadata: job id, duration, timestamps, billing records. That is normal, but it should contain no content and have its own retention period.
  • Backups and logs: are results or file names ever written to backups or logs?

The trade-off: if you lose the downloaded file, the vendor cannot give it to you again. Plan your own storage first.

What a DPA covers

Article 28(3) GDPR lists what the contract must contain. In plain terms:

  • subject matter, duration, nature and purpose of processing, types of personal data and categories of people affected;
  • processing only on your documented instructions, and no use for the vendor's own purposes;
  • confidentiality of everyone involved;
  • security measures under Article 32, usually as an annex of technical and organisational measures (TOMs);
  • rules for sub-processors: a list, your right to object to changes, the same obligations passed down;
  • help with data subject requests, breach notification and impact assessments;
  • deletion or return of data at the end of the service;
  • information and audit rights so you can check compliance.

A DPA that is only one page, or that has no sub-processor list, is a warning sign.

How klangzeile handles it

For comparison, here is how one service answers these questions, according to its DPA and quickstart. Servers run at Hetzner in Nuremberg, Germany. Transcription, speaker labels, summaries and translation are done by Mistral AI in the EU under zero data retention. Uploaded audio is held in volatile memory until it is handed to the speech model; the result is stored encrypted (AES-256-GCM) until the first fetch, at most 24 hours. Job metadata without content (status, duration, a hash) is kept for 30 days. A glossary of names and terms, if you save one, is stored encrypted until you change it. One exception to "EU only" is documented openly: the optional e-mail inbox receives mail via Cloudflare, a US company, so processing outside the EU is possible on that channel under standard contractual clauses. Use the API if you want to avoid it.

What to ask any vendor

  1. Which sub-processors touch the audio or the transcript, and where does each one process it?
  2. Is zero data retention contractual, and which features does it cover?
  3. How long are unread results kept, and what remains after deletion?
  4. Is content ever used for training, analytics or product improvement?
  5. Are file names, transcripts or audio ever written to logs or backups?
  6. Which side channels (e-mail, CDN, support tools) are outside the EU?
  7. Where can I read the DPA and TOMs before signing up?
  8. How will I be told about a new sub-processor, and how far in advance?

Checklist before you upload sensitive recordings

  • [ ] Legal basis for recording and transcribing documented; participants informed.
  • [ ] Special categories identified; impact assessment done if needed.
  • [ ] DPA concluded and filed; sub-processor list read.
  • [ ] Every processing location known, including optional channels you plan to use.
  • [ ] Zero data retention confirmed for all features you enable.
  • [ ] Result retention on the vendor side understood; your own storage and deletion planned.
  • [ ] Access to API keys limited to the people and systems that need them.
  • [ ] Record of processing activities updated (Article 30).

A worked example

Muster GmbH wants to transcribe HR exit interviews. The data protection officer notes that the recordings may contain health details (Article 9), so the team documents consent from each interviewee, runs a short impact assessment, and concludes the vendor's DPA. They use the API rather than the e-mail inbox to keep every step in the EU and store the downloaded protocols in their HR system with a 12-month retention rule. The vendor holds nothing after the download except job metadata.

FAQ

Is EU hosting enough to be GDPR-compliant? No. Location is one factor. You also need a legal basis, a DPA, appropriate security and a clear retention plan.

Can the vendor delete a person's data on request? If content is not stored after delivery, there is nothing left to delete on their side; the request then concerns your own copy. Anything the vendor does keep, such as a saved glossary with names, is a different matter and should be deletable by you.

Do speaker labels count as biometric data? Anonymous labels such as S1 and S2 are not meant to identify anyone. Whether a specific setup counts as biometric processing is a question for your data protection officer; see speaker diarization explained.

Related: SRT vs WebVTT · Speaker diarization explained · Meeting transcription with a summary API · Custom vocabulary for speech recognition

← All articles