Transcription and data protection: what to settle before you upload
August 19, 2026 · 9 min read
Transcribing interviews, lectures, or meetings almost always means processing personal data. Which rules apply, when consent is required, and how to recognise a service that handles it properly.
An audio file with voices in it is rarely harmless. As soon as it is clear who is speaking, you are processing personal data — and often more than that: a research interview contains life stories, a team meeting contains personnel matters, a medical consultation contains health data. Transcription changes none of that; it only makes the content searchable. This article sorts out what should be settled before the upload. It is not legal advice; when in doubt, your data protection officer or a lawyer decides.
First: was the recording allowed in the first place?
Choosing a transcription service comes too late if the recording itself was unlawful. In Germany, section 201 of the Criminal Code makes recording the spoken word of a non-public conversation a criminal offence when done without authorisation — that covers secretly captured calls and meetings as much as a dictaphone quietly left running. Many jurisdictions have comparable rules, and some require the consent of every participant. A talk in front of a large audience is a different matter from a one-to-one conversation, and asking “may I record this?” at the start is the cheapest safeguard there is.
- Announce the recording before it starts — and capture the agreement on tape
- In groups, ask everyone present, not only the host
- For lectures, check the institution's rules; many allow recordings for personal use only
- On a call, the other side has the same rights as someone in the room
- Missing permission cannot be repaired after the fact
Which legal basis carries the processing?
Article 6 GDPR requires a legal basis for every processing of personal data. Three of them matter in everyday transcription: consent, performance of a contract, and legitimate interest. Which one applies depends on context — a research interview rests on a different basis than the minutes of an internal meeting.
| Situation | Typical basis | What else to consider |
|---|---|---|
| Research interview | Consent (Art. 6(1)(a)) | Withdrawal must be possible at any time and practically workable |
| Your own lecture notes | Legitimate interest for private study | Do not share, do not publish |
| Internal meeting | Legitimate interest or works agreement | Employee data protection and co-determination apply |
| Journalistic interview | Media privilege, varies by jurisdiction | Honour promises about anonymisation and approval |
| Medical or therapeutic session | Art. 9 GDPR, strict requirements | Health data does not belong in an arbitrary online service |
Special categories: where convenience ends
Article 9 GDPR gives special protection to particular categories: health, ethnic origin, political opinions, religious beliefs, trade union membership, sex life, biometric data. Such content appears in transcripts more often than people expect at upload time — in a subordinate clause of an interview, in a sick note mentioned during a team meeting. Processing these categories is prohibited in principle, with narrow exceptions. If you work with them, you need a solid exception, a risk assessment, and as a rule a provider with contractually guaranteed safeguards — not the first free tool at hand.
Transcribing at work: processor agreements
As soon as you transcribe on behalf of an organisation — a university, newsroom, law firm, company — the transcription service processes data on your instructions. Article 28 GDPR requires a data processing agreement covering purpose, duration, instructions, sub-processors, security measures, and deletion. Without that contract the processing is formally impermissible, no matter how carefully the provider works technically. This does not apply to private notes; it does apply to everything professional.
How to recognise a clean transcription service
Providers differ less in accuracy than in what happens to your audio afterwards. A serious service answers these six questions publicly, without you having to ask:
- How long are audio and transcript stored — and what does “deleted” mean in practice?
- Who are the sub-processors, and in which countries are their servers?
- Are my recordings used to train models? (The answer should be a clear no.)
- Is there a data processing agreement, and can I get it without a sales call?
- What data accrues on the side — account, IP address, analytics cookies?
- What happens in a data breach, and how quickly am I told?
At Sprechverlauf, recognition runs through the Replicate API in the United States. Under Replicate's retention policy, prediction inputs, outputs, files, and logs are removed automatically after about one hour by default; on our own server, audio, transcript text, file names, and prompts are not stored permanently. There is no account, so no name or address data either. That is enough for many use cases — for health data and privileged client information it explicitly is not.
Data minimisation is the most effective measure
The safest processing is the one that never happens. Before uploading a two-hour recording, it is worth asking whether the whole file is really needed or only the twenty minutes that matter. Names can be replaced with initials in the transcript once it is shared, and audio files rarely belong permanently in a cloud folder that the entire team can read.
- Transcribe only the section you need instead of the whole recording
- Pseudonymise transcripts before sharing or quoting them
- Actually delete audio when the work is done, including from the recycle bin
- Decide the retention period in advance rather than looking for one later
- Restrict access to the people who genuinely need the text
The rights of the people recorded
Whoever was recorded keeps their rights over the transcript: access, rectification, erasure, restriction, objection. In practice that means you need to know where a given recording is and how to find it when someone calls six months later. A plain list with recording date, purpose, participants, and storage location serves that purpose better than any later search through the file system — and is part of good practice in research projects anyway.