Transcription and GDPR: recordings containing personal data
A voice recording of an identifiable person is personal data within the meaning of Art. 4(1) GDPR. Transcribing such a recording is data processing: it needs a lawful basis under Art. 6, the information duties of Art. 13–14 fulfilled, and handing the file to a transcription provider requires a processing agreement under Art. 28.
This article is general information, not legal advice. It describes typical situations; if you process sensitive recordings or operate in a regulated industry, discuss your specific case with a lawyer or a data protection officer.
The guide is useful whichever transcription tool you use — the checklist at the end applies to any provider.
When a recording is personal data
A voice can identify a person on its own, and what is said usually adds further identifiers: a name, a job title, an employer, a described situation. If the speaker can be recognized — directly or by combining the recording with other information — the recording falls under the GDPR. Special caution applies to Art. 9 data: information about health, political opinions, religion or sexual orientation, whose processing is prohibited by default and requires a separate ground such as explicit consent.
- An interview with a patient about their treatment — health data (Art. 9), the strictest regime.
- An HR clarification meeting — employee data, and often data of third parties mentioned in the conversation.
- A focus group — data of every participant; collect consents at recruitment.
- A podcast guest conversation — the guest's personal data; publication is a separate processing operation needing its own basis.
Lawful basis for recording and the information duty
The GDPR does not ban recording — it requires a basis under Art. 6(1). In practice the usual candidates are: the speaker's consent (point a), necessity for the performance of a contract (point b), and the controller's legitimate interest (point f) — the last one requires a balancing test: whether your interest is overridden by the recorded person's rights. On top of that sit the information duties of Art. 13–14: participants should know the conversation is recorded, for what purpose, and how long the record will be kept.
Recording your own conversations without notice is a separate question. Under Polish law, recording a conversation you take part in is, as a rule, not a criminal offence under Art. 267 of the Criminal Code — but that does not switch off GDPR duties when the recording contains other people's personal data, nor civil-law risks around personality rights. Secretly recording third parties is a far riskier situation legally. When in doubt: tell the participants and note it at the start of the recording.
Entrusting processing to a transcription provider
When you send a recording to a transcription service — an agency, a freelancer or an AI tool — the provider processes personal data on your behalf and becomes a processor. Art. 28 GDPR then requires a data processing agreement (it can be concluded electronically, e.g. by accepting terms and a processing policy) defining the subject matter, duration, nature and purpose of processing and the parties' obligations.
- Documented instructions: the provider processes the recording solely to deliver the transcription, not for its own purposes.
- Confidentiality: people with access to the data are bound to secrecy.
- Security (Art. 32): encrypted transmission, access control, storage in a private bucket.
- Sub-processors: you know who else takes part in the processing (e.g. the infrastructure or ASR model provider).
- Transfers outside the EEA (Chapter V): check where the files physically go and on what legal basis.
- Termination: deletion or return of the data once the service is done, at your request.
Retention: how long to keep recordings and transcripts
The storage-limitation principle (Art. 5(1)(e) GDPR) is blunt: keep data no longer than the purpose requires. In practice that means a written retention rule, e.g. “delete the audio once the transcript is done, delete the transcript once the piece is published”. The raw recording usually stops being needed sooner than the text.
This is how skryba.ai does it: files go to a private Cloudflare R2 bucket, anonymous uploads expire automatically, and on an account you can enable automatic audio deletion after 1, 7 or 30 days — the transcript stays until you delete it yourself. You can delete a recording or the whole account at any time and download a copy of your data from settings. The details, including the list of entities data is entrusted to, are in the privacy policy.
Checklist: what to require from a transcription provider
| Requirement | Why | Where to check |
|---|---|---|
| Data processing agreement (DPA) | An Art. 28 GDPR requirement for any entrusted processing | Terms of service / a separate DPA document |
| Data location and transfers outside the EEA | GDPR Chapter V; a transfer needs a legal basis | Privacy policy, sub-processor list |
| Retention controls | Art. 5(1)(e) — storage limitation | Account settings: automatic audio deletion |
| Deletion and export on request | Art. 15–17 data-subject rights must be actionable | Recording/account deletion and data-export features |
| Encryption and access control | Technical measures under Art. 32 | Privacy policy, security section |
| No use of recordings for the provider's own purposes | Processing only on documented instructions | Terms of service and privacy policy |
Scroll the table sideways to see the remaining columns.
Frequent questions about GDPR and recordings
Can I record a conversation without the other person's consent?
Recording a conversation you take part in is, as a rule, not a criminal offence in Poland — but the GDPR still requires a lawful basis and the information duty when the recording contains other people's personal data. Secretly recording third parties' conversations is a far more serious legal risk. Safe practice: give notice and capture the consent on the recording; take unusual cases to a lawyer.
Is AI transcription GDPR-compliant?
The tool can be used in a GDPR-compliant way — compliance is decided by how you use it: your lawful basis for the recording, an Art. 28 processing agreement with the provider, knowing where the data lives, and configured retention. The checklist above verifies this for any transcription service.
How long may recordings be kept?
As briefly as the purpose allows — the GDPR sets no fixed periods. Write the rule into a retention policy (e.g. audio until the transcript is finalized) and enforce it automatically, so deletion never depends on someone remembering.