A recorded meeting is personal data. Faces, voices, names, opinions, sometimes health details or HR matters, captured in one file and stored somewhere, which means every recorded meeting sits squarely inside the GDPR. Most organizations record first and think about this later, usually when a deletion request or a supervisory authority forces the question.
This guide covers what the regulation actually requires when you record meetings: the lawful basis for recording, how consent works in practice, what changes when AI joins the call, the retention rules that collide with Zoom's defaults, and the genuinely unsettled question in 2026 of where recordings are allowed to live. It is part of our broader guide to Zoom recording management, and it is written for the compliance officers and IT admins who own this problem.

What GDPR Requires, Briefly
The General Data Protection Regulation, in force since May 2018, governs how personal data of people in the EU is collected, processed, stored, and shared. It reaches organizations anywhere in the world that offer goods or services to people in the EU or monitor their behavior, which covers most companies that record meetings with European participants. Penalties reach €20 million or 4 percent of global revenue, whichever is higher, and enforcement stopped being theoretical years ago; the largest fine to date exceeded a billion euros.
Three of its articles do most of the work for recorded meetings, and each translates into something concrete.
Article 5: The Principles, Applied to Meetings
Article 5 sets the principles every processing activity must meet. For meeting recordings, the ones that bite are:
Data minimization. Record because a purpose requires it, not by default. An organization that records every meeting automatically, keeps everything, and can articulate no purpose for most of it is violating the first principle before anyone even asks about consent. A recording policy that names which meeting types get recorded and why is the fix, and it is also the document a regulator asks for first.
Storage limitation. Recordings may be kept only as long as their purpose requires. This is where Zoom's defaults collide with the regulation, and it deserves its own section below.
Integrity and confidentiality. Recordings must be protected against unauthorized access. A cloud recording shared through a forwardable link sits uneasily against this principle, a problem covered in detail in our guide to sharing Zoom recordings.
Article 6: The Lawful Basis, and Why Consent Is Not Always It
Article 6 requires a lawful basis before recording. Most articles on this subject say "get consent" and stop, but that advice is incomplete in a way that matters.
Consent under GDPR must be freely given, and regulators have repeatedly noted that the employment relationship makes free consent questionable: an employee asked by their manager to consent to recording is not meaningfully free to refuse. For internal meetings, many organizations instead rely on legitimate interest, documented through an assessment that weighs the business purpose against participants' privacy, paired with clear notice and a genuine way to object. Consent remains the cleaner basis for external participants, webinars, and customer calls.
This is not a technicality. Choosing the wrong basis means the recording program rests on nothing, and switching bases retroactively is not permitted.
How notice and consent work in practice today:
- State in the meeting invitation that the session will be recorded, with a link to the privacy notice
- Use the recording disclaimer built into modern meeting tools; Zoom, for instance, notifies joiners that recording is active and requires them to acknowledge it before continuing
- Announce recording verbally at the start for anyone who joined by phone
- Honor objections by pausing recording or, afterward, by removing the individual from the recording rather than losing the whole asset; automated GDPR redaction makes the surgical option practical
When AI Joins the Meeting
The question compliance teams now face did not exist when most recording policies were written: automatic transcription, AI summaries, and notetaker bots are processing activities in their own right, layered on top of the recording itself.
Two obligations follow. Participants must be told, specifically, that AI processing is happening; a generic "this meeting is recorded" does not cover a transcript being generated, summarized, and indexed. And where AI processing is systematic and large-scale, a data protection impact assessment is the safe assumption, particularly for transcription of sensitive discussions. Organizations deploying notetaker bots that join calls as silent participants should treat those bots exactly as they would an undisclosed human notetaker, which is to say: disclose them, every time.
None of this argues against AI processing of meetings. Transcripts and summaries are how recorded meetings become useful, as covered in turning meeting recordings into a knowledge base. The requirement is transparency about it, and a system that logs what processing happened to which recording.
Article 32: Security of the Systems That Hold Recordings
Article 32 requires technical and organizational measures matching the risk: confidentiality, integrity, availability, and resilience of the systems processing personal data. For a meeting archive, that translates to access restricted to those who need it, segregation of content by sensitivity and audience, encryption in transit and at rest, and the ability to show who accessed what. Article 30 adds the record-keeping duty: a maintained register of your processing activities. Per-recording audit logs are not that register, but they are the operational evidence that makes it credible when a supervisory authority asks how a specific recording was handled.
Meeting tools themselves cover parts of this for the live call. The gap opens after the meeting ends, when recordings accumulate in flat libraries with link-based sharing, no per-recording audit trail, and no segregation. That gap is organizational, and closing it is a storage-and-governance decision rather than a meeting-tool setting.
Where Recordings May Live: The 2026 Transfer Question
For European organizations using US-based meeting platforms, the recording's storage location is a live legal issue, and 2026 has made it livelier.
The current mechanism, the EU-US Data Privacy Framework, received its adequacy decision in July 2023 and remains in force. Its footing, however, has visibly weakened: the review court underpinning it lost quorum in early 2025, a June 2026 US Supreme Court ruling undermined the independence of a key oversight body, and privacy groups have announced challenges aimed at having the framework struck down, as its two predecessors were.
Prudent organizations are not waiting for the outcome. The resilient posture is to keep European participants' recordings in Europe, or better, in infrastructure the organization controls, so that no invalidation ruling can strand years of accumulated recordings on the wrong legal footing overnight. When evaluating where your meeting archive lives, the ability to choose the region, or to run the platform in your own tenant or data center entirely, converts a legal dependency into a configuration setting.
Retention: Where Zoom's Defaults and Article 5 Collide
Zoom's retention behavior is built for storage management, not compliance. Deleted recordings sit in trash for 30 days and then purge permanently; plans include 10 GB of recording storage per license, and when it fills, teams delete ad hoc or download recordings to laptops and shared drives, scattering copies outside any policy.
Article 5's storage limitation demands the opposite: retention periods set by purpose, applied consistently, with defensible disposal at the end and the ability to place legal holds when litigation requires preservation. A recording of a routine standup and a recording of a disciplinary hearing should not share a retention fate, and neither should depend on whose storage quota filled up first.
In practice this means recordings need to move from the meeting tool into a system where retention is a policy attached to content, automatically at ingest rather than by someone remembering.
Data Subject Rights Against a Meeting Archive
Two rights generate most of the work:
Access (Article 15). A participant may request their personal data, including recordings they appear in. You have one month to respond, extendable in complex cases, and limited grounds to refuse. Fulfilling this requires being able to find every recording a person appears in, which an unsearchable archive cannot do.
Erasure (Article 17). A participant may request deletion. When the whole recording retains business value, redacting the individual, their face, voice, and identifying references, satisfies the request without destroying the asset. This is a case where the redaction route is both the compliant and the practical answer.
Building the Compliant Meeting Archive
The pattern across every section above is the same: the meeting tool handles the meeting, and compliance lives or dies in what happens to recordings afterward. A governed video platform is where those requirements become configuration rather than aspiration. VIDIZMO's EnterpriseTube is built for that role: recordings flow in automatically, retention policies and legal holds attach to content, role-based access and portal segregation implement Article 32, every action lands in an audit trail that satisfies Article 30, and deployment in your chosen region, your own cloud tenant, or your own data center answers the transfer question structurally. For erasure requests, integrated redaction removes individuals without destroying recordings.
A reasonable self-test: if a supervisory authority asked tomorrow for your recording policy, your retention schedule, and the access log of one sensitive recording, how many of the three could you produce? Organizations that can produce all three built their archive deliberately. Talk to us if you are working on becoming one of them.

Disclaimer: This article is for information purposes only and is not legal advice. Consult your counsel and the official GDPR text when building your compliance program.