Recording Your Meetings: The Data Protection Implications You Might Be Missing

15th June 2026

Recording a meeting used to mean setting up a dictaphone and manually transcribing it to minutes. Today it is a single click in Teams, Zoom, Google or any one of the plethora of new transcription services, that auto-generates a transcript, and an AI summary in your inbox before you have logged off. Some employees are doing it themselves on their phones.

Each click creates personal data. And in many of the cases we see, organisations have not thought through what that means until a Subject Access Request lands and they realise they have hours of recordings they should not still be holding.

Every recording is personal data

Audio or video of identifiable people is personal data. The moment you press record, your organisation is processing it, and the full UK GDPR framework applies: a lawful basis, transparency, minimisation, storage limitation, security, and the full range of data subject’s rights. The ICO’s own guidance is clear that you can record video conferencing sessions only where you have a valid purpose that can’t be achieved using less intrusive methods, such as taking minutes. If minutes do the job and you cannot obtain consent, recording is probably not justified.

The consent and lawful basis problem

The instinct for many organisations is to put a tick-box at the start of the meeting and call it consent. In an employment context, this rarely works. Consent must be freely given, and the power imbalance between employer and employee makes that hard to demonstrate. The ICO’s workplace monitoring guidance acknowledges that legitimate interests is usually the most flexible lawful basis, but it still requires a documented proportionality assessment.

In a 2023 case before the Austrian Federal Administrative Court found that a bank that recorded every incoming client call could not rely on legitimate interests because the recording was indiscriminate, not targeted to a defined need. Blanket recording of every meeting, in any organisation, sits squarely in that danger zone. And if one person in the meeting objects, you may need to stop or take written minutes instead. ‘They were outvoted’ is not a valid response.

Sensitive meetings amplify the risk

The category that concerns us most is the routine recording of disciplinaries, grievances, occupational health calls and welfare meetings. These almost always involve special category data: health, religion or other beliefs, sexuality, political or trade union membership. Article 9 of the UK GDPR requires a specific condition to be identified for processing of this data, this is in addition to your standard lawful basis, and the ICO expects stronger safeguards: greater security, tighter access, shorter retention, and a clear demonstration of necessity.

If your disciplinary policy says ‘meetings will be recorded’ as a default, that is worth a second look.

The AI summary trap

Modern tools make this easier than ever, and create a problem of their own. A meeting is recorded; a transcript is generated; an AI summary is produced and shared with the participants. The summary is genuinely useful, an agreed record of what was said. We’ve explored the wider privacy implications of AI in business in our earlier blog on the privacy risks of AI.

The problem is what happens next. In our experience, organisations almost never delete the recording or transcript once the summary is signed off. They get filed ‘just in case’. Six months later, a Subject Access Request asks for everything the organisation holds about an individual, and the entire recording plus a verbatim transcript has to be reviewed, redacted and disclosed. That is hours of staff time and real legal risk.

The storage limitation principle in Article 5(1)(e) is unambiguous: personal data must be kept no longer than necessary. If the agreed summary serves the operational purpose, the recording and transcript should be deleted on a documented schedule.

When employees record their own conversations

We are increasingly asked whether an employee can record a meeting on their personal phone. The starting point is Article 2(2)(c) of the UK GDPR, the so-called ‘household exemption’ or historically ‘domestic purposes’. An individual recording a conversation they are part of, for their own personal use, falls outside of the scope of UK GDPR. Lawful basis, transparency and consent are not required.

However, the exemption is narrower than it looks. The moment the recording is shared publicly, posted to social media or used to build an online presence, the individual becomes a controller in their own right. At that point all the usual obligations kick in: and so to disclose or share the data they must have identified a lawful basis, which is either consent or legitimate interests, but regardless they should have informed everyone in the meeting, and respected the rights of every other person on the call. Employment tribunals will sometimes admit covert recordings as evidence, but they almost always disapprove of them, and the cost to the individual rarely matches the perceived gain.

What good looks like!

A few practical steps reduce most of the risk:

  • Announce recording at the start of every meeting, and offer a non-recorded alternative where realistic.
  • Undertake a DPIA (data protection impact assessment) for any routine or systematic recording, especially for sensitive meeting types. An LIA (legitimate interest assessment) may also be required.
  • Document your lawful basis carefully, and where possible avoid relying on consent in the employment context.
  • Default to short retention, and automate deletion of recordings and transcripts once the agreed summary is approved.
  • Restrict access to recordings to a tight, named group, particularly for HR and welfare matters.
  • Update your privacy notice and staff handbook to set expectations clearly.

How Griffin House Consultancy Can Help

Recording meetings is one of the fastest-changing areas of workplace data protection, and the answers are rarely one-size-fits-all. We help organisations draft recording and retention policies, run DPIAs on AI transcript and meeting tools, train HR and managers on lawful recording practice, and review existing recordings to bring storage practices back into line. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533, and one of our team will be happy to talk it through.

 

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

 

Sources

ICO, Data sharing advice for small organisations: video conferencing

Legislation.gov.uk, UK GDPR Article 2 (material scope)

Legislation.gov.uk, UK GDPR Article 5 (principles)

Legislation.gov.uk, UK GDPR Article 9 (special category data)

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details