Recording a meeting is legal almost everywhere, but the compliance work sits in four separate layers: consent rules that differ by state and country, data protection law that treats the recording and its transcript as personal data, sector rules such as HIPAA when health information comes up, and the practical question of where the file is stored and who can open it. The safe default is to treat every recorded meeting as regulated personal data from the moment it starts: disclose recording to everyone in the room, obtain consent to the strictest standard that could apply, host and process the recording in the jurisdiction the law requires, restrict access by role, and keep a retention schedule and an audit trail a regulator can inspect. This is general information for planning purposes, not legal advice, and a compliance or legal team should confirm the rules that apply to your specific jurisdictions and industry before you finalize policy.

United States federal wiretap law needs only one participant's consent, which can be the organization doing the recording. About a dozen states run "all-party" or "two-party" consent rules instead, including California, Florida, Illinois, Pennsylvania and Washington, where every participant must agree before a call is recorded. The rule that applies is usually the one where the participant is located, not where the host or the recording company sits, so a single internal call can cross both regimes at once.

The European Union does not have a single "recording consent" statute the way US wiretap law works; the relevant question is normally GDPR lawful basis (below), not a separate consent-to-record law. In practice, though, several member states criminalize secretly recording a private conversation regardless of the data protection analysis — Germany's Criminal Code is a well-known example — and GDPR's transparency principle expects participants to be told plainly, before the recording starts, that it is happening and why.

A workable global policy is simpler than tracking every state and country individually: announce recording at the start of every meeting, show a persistent on-screen or audible indicator for as long as it runs, and give participants a way to object or step out. That single standard satisfies the strictest US state and the EU's notice expectation at the same time, so there is little reason to run a lighter policy anywhere.

GDPR: a recording is personal data the moment it captures a voice

Under the GDPR, a recording or transcript that identifies a person, directly or by voice, is personal data, and processing it needs a lawful basis under Article 6. For ordinary internal business meetings, legitimate interest is the most common basis after a documented balancing test; consent is a weak fit for employees, because an employee who feels they cannot decline is not consenting freely under Article 4(11). Meetings that involve special-category data — health, union membership, political opinion — need an Article 9 condition on top, not just Article 6.

Data minimisation should shape the product, not just the policy: record only the meeting types that need it, decide deliberately between audio, video and transcript-only capture, and avoid indexing a recording into general search if it was never meant to be searchable by the whole company. A DPIA under Article 35 is typically required once recordings are scored, analyzed at scale, or used to evaluate employee performance.

Participants keep the normal data subject rights over a recording that contains their voice or image: access, rectification of an inaccurate transcript, and erasure where no other legal ground for keeping it exists. Erasure is harder for a raw audio file than for a text log, which is one reason many enterprises keep the structured summary and action items longer than the raw recording itself. Treat the recording as the primary personal data asset and the transcript, summary and search index as derivative copies that need to be deleted together.

KVKK: the same recording, a participant in Türkiye, a different rulebook

Law No. 6698 (KVKK) treats a voice or video recording of an identifiable person as personal data in the same way GDPR does, but its default lawful basis is different: explicit consent (açık rıza) is the norm, alongside narrower exceptions for contract performance, legal obligation and legitimate interest that track the GDPR list less closely than most global privacy programs assume. A privacy notice under KVKK Article 10 needs to exist in Turkish and describe what is recorded, why, and for how long, before the meeting starts.

If the recording, transcript or its backups leave Türkiye — which most cloud meeting tools do by default — that is a cross-border transfer under the amended Article 9, and it needs the Data Protection Board's standard contract or another approved mechanism, notified to the Authority within the required window. This is easy to miss precisely because it feels identical to the GDPR transfer question and is not: a Data Privacy Framework certification or EU standard contractual clauses say nothing about KVKK. Our EU AI Act, GDPR and KVKK compliance checklist covers the same transfer and residency questions for the AI systems that process this kind of recording. Any organization with regular Turkish participants should assume KVKK applies as its own regime, not as a GDPR variant.

HIPAA: only when the recording belongs to a covered entity or its vendor

HIPAA is the rule enterprise buyers most often apply too broadly. It governs "covered entities" — health plans, healthcare providers, and clearinghouses — and their "business associates," not every company whose employees happen to mention a health condition in a meeting. An HR conversation about an employee's medical leave is usually governed by employment and disability law, not HIPAA, unless the employer itself operates a self-insured health plan that is the covered entity.

Where HIPAA genuinely applies — a health system's case conferences, a payer's utilization review calls, a telehealth visit — a recording containing protected health information triggers real obligations: a signed Business Associate Agreement with any vendor that records, transcribes or stores the call, the Security Rule's access controls, audit controls and encryption requirements, and breach notification if the recording is exposed. Recordings that touch substance-use treatment can fall under the stricter federal confidentiality rules for that category specifically, which is worth flagging to counsel separately. Ask whether your organization is a covered entity or business associate before assuming HIPAA governs a meeting; if it does, a BAA with the recording vendor is not optional.

Where the recording actually lives, and why that decides half the analysis

Data residency answers or removes several of the questions above in one move. A recording processed and stored inside the EEA avoids most GDPR transfer analysis; one processed inside Türkiye avoids the KVKK cross-border question; a regulated bank or insurer in a jurisdiction with in-country hosting rules avoids a separate sectoral breach. The reverse is also true: a recording that transits a US server for transcription, even briefly, is a transfer under both regimes regardless of where the meeting participants sat.

This is why the deployment model matters as much as the feature set when evaluating a meeting recording product. A cloud service with configurable regions covers most companies; regulated industries, government contractors and organizations with strict data-sovereignty requirements generally need a private, single-tenant environment or an on-premise deployment where recordings never leave the network at all. EasyMeeting supports all three models — cloud, private cloud and fully on-premise, including air-gapped networks — specifically because the right answer depends on the buyer's sector and jurisdiction, not on a single default. Decide data residency requirements before comparing vendors, because it eliminates options rather than adding a feature checkbox.

Access control: a board meeting and a sales call are not the same risk

A sales call recording is useful to a large group and low-risk if it leaks internally. A board meeting recording can contain material non-public information with insider-trading exposure; an HR meeting can contain special-category data under GDPR Article 9 or protected characteristics under employment law. Applying one access policy to both is how sensitive recordings end up searchable by people who never should have found them.

The baseline is role-based access tied to the identity system the organization already runs — the same single sign-on groups that gate every other system — with the ability to lock a specific meeting or an entire recurring series to a named list. Board, executive and HR series should default to restricted, not to "everyone in the workspace," and that restriction should survive even when a recording is later referenced in a summary or an action item. The people who can see a meeting's transcript should never be a wider group than the people who were actually invited to attend it.

Retention and deletion: a written policy, not a storage default

Storage limitation under GDPR Article 5(1)(e) and the equivalent principle under KVKK both require keeping personal data no longer than the purpose requires, which for most meetings is measured in weeks, not years — with clear exceptions for regulated records, litigation holds and statutory retention periods that some sectors carry. A retention policy that is just "whatever the vendor's default is" will not survive a data subject access request or an audit.

  1. Classify meeting types (sales, engineering, board, HR, clinical) and assign each a retention period based on business need and any statutory minimum that applies.
  2. Decide separately for audio, video, transcript and generated summary — the raw recording is usually the highest-risk, shortest-lived artifact, while a redacted summary may be kept longer.
  3. Automate deletion rather than relying on someone remembering; a manual process is the most common reason retention policies fail audits.
  4. Make deletion complete: the recording, transcript, search index entries, and backups all need to be purged, not just the reference a user sees.
  5. Log every deletion with a timestamp and the policy rule that triggered it, so the deletion itself becomes evidence of compliance.

A retention policy that only exists in a document and not in the product's configuration will not hold up to a regulator's first follow-up question.

The audit trail regulators and auditors actually ask for

When a regulator, auditor or opposing counsel asks about a recording program, the questions are consistently the same: who could access this recording, who actually did, when, and from where; what consent or notice was given and can you prove it; when was this scheduled for deletion and did that happen on time. A written policy without a corresponding log answers none of these credibly.

The minimum audit record for a single meeting should capture the recording's start and consent-notice event, every access with user identity, timestamp and IP or device context, any export or download, and the retention and deletion events tied to the applicable policy. That log needs to be immutable and exportable, because the moment it can be edited after the fact it stops functioning as evidence. HIPAA's Security Rule explicitly requires audit controls for this reason (45 CFR 164.312(b)), and GDPR's accountability principle expects the equivalent even where no single article names it. An audit trail that cannot be exported for a compliance team on request is not actually an audit trail.

Compliance checklist

ControlGoverned byWhat "done" looks like
Recording notice and consentUS state wiretap laws, GDPR transparency, KVKK Art. 10Visible/audible notice at start of every meeting, logged, with an opt-out path
Lawful basis on fileGDPR Art. 6, 9Documented basis per meeting type; balancing test for legitimate interest
Explicit consent and Turkish noticeKVKK Art. 4, 10Açık rıza captured or an applicable exception documented, notice in Turkish
Cross-border transfer mechanismGDPR Ch. V; KVKK Art. 9Adequacy, SCCs or Board-approved contract in place before data leaves the region
BAA with recording vendorHIPAA (covered entities and business associates only)Signed BAA, encryption and audit controls confirmed before use for clinical calls
Data residencyGDPR, KVKK, sector rules (banking, insurance, public sector)Region or on-premise deployment matched to the strictest applicable requirement
Role-based accessGDPR Art. 5, 32; internal policySSO-integrated groups; named-list restriction available for board and HR series
Retention scheduleGDPR Art. 5(1)(e); KVKK destruction rules; sector retention lawPer-meeting-type schedule, automated deletion, exceptions for legal holds
Audit trailHIPAA Security Rule 45 CFR 164.312(b); GDPR accountabilityImmutable log of access, consent and deletion, exportable on request
Vendor and sub-processor reviewGDPR Art. 28; KVKK Art. 9DPA on file, sub-processors listed, no-training/zero-retention settings verified

Frequently asked questions

In roughly a dozen US states and in most jurisdictions with a data-protection or wiretap regime, no — every participant must be told, and in "all-party consent" states each must agree. Even where the law only requires one party's consent, GDPR's transparency principle and most companies' own policies expect clear notice regardless. The safest and simplest global rule is to announce recording every time.

One-party consent means only one participant in a conversation needs to agree to it being recorded, which can be the person or company doing the recording. All-party (also called two-party) consent requires every participant to agree. US federal law is one-party; about a dozen states, including California and Illinois, require all-party consent, and the applicable rule generally follows the participant's location.

Not necessarily "consent" in the strict GDPR sense — legitimate interest is the more common lawful basis for ordinary business meetings, since consent from an employee is rarely considered freely given. What GDPR does require regardless of basis is transparency: participants must be told the recording is happening, why, and what happens to it afterward.

Is a company meeting recording covered by HIPAA?

Only if the organization is a HIPAA covered entity (a health plan, healthcare provider or clearinghouse) or a business associate handling protected health information on one's behalf. A typical business discussing an employee's health situation in an HR meeting is not automatically subject to HIPAA; a health system's clinical case review almost certainly is. Confirm covered-entity status before assuming HIPAA applies.

Does KVKK apply if the meeting is hosted outside Türkiye but a participant is there?

Yes. KVKK applies based on whose personal data is processed, not where the recording server sits, so a Turkish participant's voice or image being recorded triggers KVKK regardless of where the meeting was hosted. If the recording is then stored or processed abroad, that is also a cross-border transfer requiring its own legal mechanism.

How long should a company keep meeting recordings?

There is no single answer; it depends on meeting type, applicable sector retention rules, and litigation holds, but the general data-protection principle is to keep the minimum needed and delete on a schedule rather than by default. Many enterprises keep raw recordings for a short, fixed period and retain the written summary and action items longer, since the summary carries less identifiable audio data.

Who should be able to access a board meeting or HR recording?

Only the people who were actually part of that meeting or have a defined, documented need to review it later, such as compliance or legal counsel under a specific process. Board and HR recordings should be restricted to a named list rather than a broad workspace-wide group, and every access to them should be logged, since both carry outsized legal and reputational risk if they leak.

Can meeting recordings be stored in the cloud and still be compliant?

Yes, for most companies, provided the vendor supports region-specific storage, a signed data processing agreement, and the access and retention controls described above. Regulated industries, public-sector organizations and companies under strict data-sovereignty rules more often need a private or on-premise deployment instead, since some sector rules go beyond what regional cloud storage alone satisfies.

How Nanobase AI can help

Nanobase AI builds and deploys EasyMeeting, an AI meeting assistant that can run in the cloud, in a dedicated private cloud, or entirely on your own infrastructure, including air-gapped networks. Deployments are configured against the rules you answer to: consent and notice flows, data residency in the region you require, SSO-based access control with named-list restriction for board and HR series, automated retention and deletion, and an exportable audit trail covering every access and deletion. As a Silicon Valley enterprise AI engineering company and a member of the NVIDIA Inception Program, we work with your legal and compliance teams rather than around them, and recommend a pilot on your own meetings first. Explore our solutions or book a live demo. Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.