Video Content Management, EnterpriseTube, Compliance, Security and Compliance, CIO and IT Leadership

GDPR and Recorded Meetings: Consent, Retention, and Where Recordings Live

GDPR compliant video conferencing & virtual meetings

A recorded meeting is personal data. Faces, voices, names, opinions, sometimes health details or HR matters, captured in one file and stored somewhere, which means every recorded meeting sits squarely inside the GDPR. Most organizations record first and think about this later, usually when a deletion request or a supervisory authority forces the question.

This guide covers what the regulation actually requires when you record meetings: the lawful basis for recording, how consent works in practice, what changes when AI joins the call, the retention rules that collide with Zoom's defaults, and the genuinely unsettled question in 2026 of where recordings are allowed to live. It is part of our broader guide to Zoom recording management, and it is written for the compliance officers and IT admins who own this problem.

Try All These Capabilities for Free Today!

What GDPR Requires, Briefly

The General Data Protection Regulation, in force since May 2018, governs how personal data of people in the EU is collected, processed, stored, and shared. It reaches organizations anywhere in the world that offer goods or services to people in the EU or monitor their behavior, which covers most companies that record meetings with European participants. Penalties reach €20 million or 4 percent of global revenue, whichever is higher, and enforcement stopped being theoretical years ago; the largest fine to date exceeded a billion euros.

Three of its articles do most of the work for recorded meetings, and each translates into something concrete.

Article 5: The Principles, Applied to Meetings

Article 5 sets the principles every processing activity must meet. For meeting recordings, the ones that bite are:

Data minimization. Record because a purpose requires it, not by default. An organization that records every meeting automatically, keeps everything, and can articulate no purpose for most of it is violating the first principle before anyone even asks about consent. A recording policy that names which meeting types get recorded and why is the fix, and it is also the document a regulator asks for first.

Storage limitation. Recordings may be kept only as long as their purpose requires. This is where Zoom's defaults collide with the regulation, and it deserves its own section below.

Integrity and confidentiality. Recordings must be protected against unauthorized access. A cloud recording shared through a forwardable link sits uneasily against this principle, a problem covered in detail in our guide to sharing Zoom recordings.

Article 6: The Lawful Basis, and Why Consent Is Not Always It

Article 6 requires a lawful basis before recording. Most articles on this subject say "get consent" and stop, but that advice is incomplete in a way that matters.

Consent under GDPR must be freely given, and regulators have repeatedly noted that the employment relationship makes free consent questionable: an employee asked by their manager to consent to recording is not meaningfully free to refuse. For internal meetings, many organizations instead rely on legitimate interest, documented through an assessment that weighs the business purpose against participants' privacy, paired with clear notice and a genuine way to object. Consent remains the cleaner basis for external participants, webinars, and customer calls.

This is not a technicality. Choosing the wrong basis means the recording program rests on nothing, and switching bases retroactively is not permitted.

How notice and consent work in practice today:

  • State in the meeting invitation that the session will be recorded, with a link to the privacy notice
  • Use the recording disclaimer built into modern meeting tools; Zoom, for instance, notifies joiners that recording is active and requires them to acknowledge it before continuing
  • Announce recording verbally at the start for anyone who joined by phone
  • Honor objections by pausing recording or, afterward, by removing the individual from the recording rather than losing the whole asset; automated GDPR redaction makes the surgical option practical

When AI Joins the Meeting

The question compliance teams now face did not exist when most recording policies were written: automatic transcription, AI summaries, and notetaker bots are processing activities in their own right, layered on top of the recording itself.

Two obligations follow. Participants must be told, specifically, that AI processing is happening; a generic "this meeting is recorded" does not cover a transcript being generated, summarized, and indexed. And where AI processing is systematic and large-scale, a data protection impact assessment is the safe assumption, particularly for transcription of sensitive discussions. Organizations deploying notetaker bots that join calls as silent participants should treat those bots exactly as they would an undisclosed human notetaker, which is to say: disclose them, every time.

None of this argues against AI processing of meetings. Transcripts and summaries are how recorded meetings become useful, as covered in turning meeting recordings into a knowledge base. The requirement is transparency about it, and a system that logs what processing happened to which recording.

Article 32: Security of the Systems That Hold Recordings

Article 32 requires technical and organizational measures matching the risk: confidentiality, integrity, availability, and resilience of the systems processing personal data. For a meeting archive, that translates to access restricted to those who need it, segregation of content by sensitivity and audience, encryption in transit and at rest, and the ability to show who accessed what. Article 30 adds the record-keeping duty: a maintained register of your processing activities. Per-recording audit logs are not that register, but they are the operational evidence that makes it credible when a supervisory authority asks how a specific recording was handled.

Meeting tools themselves cover parts of this for the live call. The gap opens after the meeting ends, when recordings accumulate in flat libraries with link-based sharing, no per-recording audit trail, and no segregation. That gap is organizational, and closing it is a storage-and-governance decision rather than a meeting-tool setting.

Where Recordings May Live: The 2026 Transfer Question

For European organizations using US-based meeting platforms, the recording's storage location is a live legal issue, and 2026 has made it livelier.

The current mechanism, the EU-US Data Privacy Framework, received its adequacy decision in July 2023 and remains in force. Its footing, however, has visibly weakened: the review court underpinning it lost quorum in early 2025, a June 2026 US Supreme Court ruling undermined the independence of a key oversight body, and privacy groups have announced challenges aimed at having the framework struck down, as its two predecessors were.

Prudent organizations are not waiting for the outcome. The resilient posture is to keep European participants' recordings in Europe, or better, in infrastructure the organization controls, so that no invalidation ruling can strand years of accumulated recordings on the wrong legal footing overnight. When evaluating where your meeting archive lives, the ability to choose the region, or to run the platform in your own tenant or data center entirely, converts a legal dependency into a configuration setting.

Retention: Where Zoom's Defaults and Article 5 Collide

Zoom's retention behavior is built for storage management, not compliance. Deleted recordings sit in trash for 30 days and then purge permanently; plans include 10 GB of recording storage per license, and when it fills, teams delete ad hoc or download recordings to laptops and shared drives, scattering copies outside any policy.

Article 5's storage limitation demands the opposite: retention periods set by purpose, applied consistently, with defensible disposal at the end and the ability to place legal holds when litigation requires preservation. A recording of a routine standup and a recording of a disciplinary hearing should not share a retention fate, and neither should depend on whose storage quota filled up first.

In practice this means recordings need to move from the meeting tool into a system where retention is a policy attached to content, automatically at ingest rather than by someone remembering.

Data Subject Rights Against a Meeting Archive

Two rights generate most of the work:

Access (Article 15). A participant may request their personal data, including recordings they appear in. You have one month to respond, extendable in complex cases, and limited grounds to refuse. Fulfilling this requires being able to find every recording a person appears in, which an unsearchable archive cannot do.

Erasure (Article 17). A participant may request deletion. When the whole recording retains business value, redacting the individual, their face, voice, and identifying references, satisfies the request without destroying the asset. This is a case where the redaction route is both the compliant and the practical answer.

Building the Compliant Meeting Archive

The pattern across every section above is the same: the meeting tool handles the meeting, and compliance lives or dies in what happens to recordings afterward. A governed video platform is where those requirements become configuration rather than aspiration. VIDIZMO's EnterpriseTube is built for that role: recordings flow in automatically, retention policies and legal holds attach to content, role-based access and portal segregation implement Article 32, every action lands in an audit trail that satisfies Article 30, and deployment in your chosen region, your own cloud tenant, or your own data center answers the transfer question structurally. For erasure requests, integrated redaction removes individuals without destroying recordings.

A reasonable self-test: if a supervisory authority asked tomorrow for your recording policy, your retention schedule, and the access log of one sensitive recording, how many of the three could you produce? Organizations that can produce all three built their archive deliberately. Talk to us if you are working on becoming one of them.

EnterpriseTube - Free Trial

Disclaimer: This article is for information purposes only and is not legal advice. Consult your counsel and the official GDPR text when building your compliance program.

FAQ

Frequently Asked Questions

Is it legal to record meetings under GDPR?

Yes, with a lawful basis under Article 6 and proper notice to participants. Consent is one basis; documented legitimate interest is often more appropriate for internal meetings, since consent inside an employment relationship may not count as freely given. Recording without any basis or notice is where organizations get in trouble.

Do we need consent from every meeting participant?

Not always. For internal meetings many organizations rely on a documented legitimate-interest assessment with clear notice and a genuine way to object. Consent is the cleaner basis for external participants, webinars, and customer calls. Whichever basis you choose must be decided before recording, not retrofitted.

How long can we keep meeting recordings under GDPR?

As long as the recording's purpose requires and no longer, per Article 5's storage-limitation principle. In practice that means retention periods set by meeting type, applied automatically, with defensible disposal at the end and legal holds when litigation requires preservation. Default platform behavior, such as trash purges and storage-quota deletions, is not a retention policy.

Do AI notetakers and auto-transcription need separate disclosure?

Yes. AI transcription, summaries, and notetaker bots are processing activities on top of the recording itself, and participants must be told about them specifically. Large-scale or sensitive AI processing of meetings is also the safe trigger for a data protection impact assessment.

TopicsVideo Content ManagementEnterpriseTubeComplianceSecurity and ComplianceCIO and IT Leadership

You may also like

Document Review Training: Proving One Standard

Document Review Training: Proving One Standard

The challenge, when it comes, is almost never that a reviewer was unqualified.

Compliance Training Tracking: What You Have to Prove

Compliance Training Tracking: What You Have to Prove

The question a regulator asks is narrower than the one most training programs are built to answer.

CLE Video: Delivering the Session, Proving the Credit

CLE Video: Delivering the Session, Proving the Credit

Recording the session is the easy half, and the hard half does not announce itself until roughly a year in.

See all posts

See it on your own content

Tell us what you are trying to solve and we will show you how it works on your infrastructure.