← Blog

GDPR-Compliant Call and Meeting Recording in Europe: The 2026 Buyer's Guide

    This article is a buyer's guide, not legal advice. Consult a qualified lawyer for guidance specific to your situation.

    GDPR-compliant call and meeting recording in Europe rests on four things you control: a lawful basis for the recording, the per-country consent rules that apply to the people on the call, where the data is processed (data residency versus data sovereignty), and how long you keep it (retention). Get those four right and the recording is defensible. Get any one of them wrong and the compliant-looking tool in your stack becomes a liability. This guide walks through each of the four in the order a buyer should evaluate them in 2026, and points you to the deeper legal breakdowns where you need them.

    Is call recording legal under GDPR?

    Yes, call recording is legal under GDPR when you have a lawful basis and you meet local consent rules. GDPR does not ban recording. It regulates it. A recording that captures the voice of an identifiable person is personal data, which means the whole framework applies: you need a legal ground to process it, you must be transparent about it, and you must protect it and delete it when it is no longer needed.

    Two points raise the stakes. First, recordings often capture more than a voice. A sales or support call can reveal health, financial hardship, or political views, which are special-category data under Article 9 and carry a higher bar. Second, the recording is only the start. Transcription, AI summaries, and coaching scores are all separate processing that inherits the same obligations. For the full legal breakdown of what EU law requires before you press record, see what is actually legal under GDPR when recording sales calls in Europe.

    Choosing a lawful basis: consent vs legitimate interest

    Every recording needs a lawful basis under Article 6, and for business calls the practical choice is between consent and legitimate interest. They lead to very different operational workflows, so decide before you buy a tool, not after.

    Definition

    A lawful basis is one of the six legal grounds in Article 6 GDPR that makes processing personal data permissible. For call and meeting recording, the two that apply in practice are the participant's consent, or the recorder's legitimate interest weighed against the participant's privacy rights. You must pick and document a lawful basis before recording begins. You cannot switch bases later to justify data you already collected.

    Consent is the cleaner basis in principle. It must be freely given, specific, informed, and unambiguous, and the person must be able to withdraw it as easily as they gave it. The catch is operational: you have to capture and log an affirmative opt-in from every participant before recording starts, and honour withdrawals afterward. For inbound and cooperative meetings that is workable. For cold outbound it adds friction at the worst moment.

    Legitimate interest under Article 6(1)(f) is usually the more practical basis for B2B recording, but it is not a free pass. You must complete a Legitimate Interest Assessment (LIA), a documented balancing test that shows your purpose (coaching, quality, dispute resolution) does not override the participant's reasonable privacy expectations. The balance tips in your favour when the person is acting professionally, the retention is short, the use is narrow, and there is a genuine opt-out. If a participant objects, you stop, regardless of your LIA.

    Consent rules vary by country

    GDPR sets a floor, but individual European countries add their own recording rules on top, and the biggest variable is one-party versus all-party consent. In a one-party regime, one participant knowing about the recording can be enough. In an all-party (two-party) regime, everyone on the call must be informed or must agree before recording begins. Buyers selling across borders have to plan for the strictest country their participants sit in, not the most lenient.

    A short country read for 2026:

    • Germany. The strictest of the major markets. Secret recording of the spoken word is a criminal offence under Section 201 StGB, separate from and on top of GDPR. Every participant must be informed before recording starts, a verbal notice at the top of the call is the reliable safeguard, and a works council can add co-determination requirements for employee-facing tools. For the deep Germany rules, see the Germany call recording and Section 201 StGB compliance guide.
    • France. The CNIL expects clear prior information to all participants and treats AI analysis of voice, such as emotion or tone profiling, as a distinct processing activity that must be disclosed on its own, not folded into a generic "calls may be recorded" line.
    • Netherlands. The Autoriteit Persoonsgegevens applies GDPR strictly and treats AI analysis of call content as potential employee monitoring, which brings works council consultation into scope even when the stated purpose is customer quality.
    • United Kingdom. UK GDPR mirrors the EU rules for recording, but note that call recording also engages PECR, and cross-border data flows between the UK and EU depend on an adequacy decision that should be monitored rather than assumed.

    When participants sit in different countries, obtaining clear consent from everyone is the safest single policy, because it satisfies both GDPR and the stricter national regimes at once. For the broader legal breakdown across Europe, including the consent-versus-disclosure trap and the four disclosures you owe every participant, see the full GDPR recording breakdown.

    Data residency is not data sovereignty

    This is the distinction that separates a real GDPR-compliant recording solution from one that only looks compliant on the spec sheet. Data residency tells you where your recordings are stored. Data sovereignty tells you which legal system controls them. They are not the same thing, and conflating them is the most common mistake buyers make in 2026.

    Here is why it matters. A US-owned provider can store your recordings in a Frankfurt data centre and still be compelled by US law to hand them over. The US CLOUD Act lets US authorities require a US-controlled company to produce data it holds, regardless of where in the world that data physically sits. So EU storage on its own does not stop US legal reach. It moves the servers, not the jurisdiction. For the mechanics of how the CLOUD Act reaches EU-stored data, see the CLOUD Act and EU data sovereignty explainer.

    Sovereignty closes that gap. It means the storage location and the controlling entity both sit under EU jurisdiction, so no foreign government can compel access. When you evaluate a recording tool, the question to ask is not only "where are the servers?" but "who controls the processor, and which laws can reach it?" For the fuller picture of what sovereignty means and how to judge a vendor's claim, see the guide to what sovereign AI actually means in the EU.

    Retention and data minimization

    GDPR's storage limitation principle in Article 5(1)(e) is simple to state and easy to violate: keep recordings only as long as you genuinely need them, then delete them. The default setting on many tools is the opposite, storing everything indefinitely, and that indefinite hoard is a live liability with no legal basis behind it.

    Definition

    Retention is the defined period for which you keep a recording before deleting it, justified by the purpose you collected it for. Under GDPR you must set the period in advance, document why it is proportionate, and enforce deletion when it expires. Retention applies not just to the audio but to every derived artifact: the transcript, the AI summary, the coaching score, and any copy held by a sub-processor.

    For coaching and quality assurance, a retention window of 30 to 90 days is a common and defensible standard. Once the coaching signal is extracted, the raw recording rarely serves a further legitimate purpose. Recordings that document a contract are the exception and may justify longer retention tied to commercial record-keeping law, but that should be a deliberate flag on specific recordings, not a blanket default.

    Two practical points for buyers. First, transcript and audio are separate assets. You may delete the audio and keep an anonymised transcript, or apply different windows to each, but you must decide and document it. Second, automated deletion beats manual deletion, because a scheduled purge removes the risk that a forgotten recording lingers for years. Make sure the deletion cascade reaches every derived artifact and every sub-processor, and confirm you can honour an erasure request within one month.

    The 2026 buyer's checklist

    Work through this in order when you evaluate a GDPR-compliant call recording solution in Europe. Each item is a question the vendor should be able to answer without hedging.

    1. Lawful basis documented. You have chosen consent or legitimate interest and written it down, with an LIA on file if you rely on legitimate interest.
    2. Consent capture flow. The tool captures an affirmative opt-in or delivers a genuine pre-recording notice, and logs that it happened.
    3. Per-country rules mapped. You know which countries your participants sit in and have planned for the strictest, including Germany's Section 201 StGB.
    4. Where processing runs. You know where recording, transcription, storage, and AI analysis each physically happen, not just where the account is billed.
    5. Sub-processors listed. The vendor publishes its sub-processors and gives you change notification rights.
    6. Transfer mechanism. Any data leaving the EEA is covered by a valid transfer mechanism plus a transfer impact assessment, or does not leave at all.
    7. Retention schedule. A defined retention period with automated deletion across audio, transcript, and derived artifacts.
    8. Deletion and subject access. You can locate, export, and delete a specific recording in response to a data subject request within one month.
    9. DPA in place. A signed Data Processing Agreement under Article 28 that prohibits the vendor from using your data for its own purposes, including AI training.
    10. Audit and logging. The tool records who accessed each recording and when, so you can demonstrate accountability.

    If a vendor cannot answer items 4, 5, and 8 cleanly, the residency-versus-sovereignty gap from the previous section is probably hiding in your stack. For a factual breakdown of where the most widely used tools fail these criteria, see our guide on comparing GDPR-compliant AI meeting assistants for EU sales teams.

    Sovereign recording: where residency and sovereignty finally line up

    The reason the four pillars are hard to satisfy at once is that most tools solve residency and ignore sovereignty. A sovereign meeting assistant is built the other way around. It keeps the recording, the transcription, the storage, and the AI analysis all under EU jurisdiction, so the place the data lives and the law that governs it are the same. That is what makes the four pillars line up rather than fight each other: with a sovereign design, EU residency is not a marketing line bolted onto a US-controlled backend, it is the actual jurisdiction of every step in the pipeline.

    For a buyer, that collapses a lot of the checklist into one architectural decision. When processing never leaves EU jurisdiction, the transfer mechanism question, the CLOUD Act exposure, and the "who really controls the processor" question stop being open risks. You still have to do the work on lawful basis, consent, and retention, but you remove the structural problem that no amount of paperwork can fix.

    Frequently asked questions

    Is call recording legal under GDPR?

    Yes. Call recording is legal under GDPR when you have a valid lawful basis under Article 6, you meet the consent rules of each country the participants are in, and you handle the recording with transparency, defined retention, and appropriate safeguards. A recording of an identifiable person is personal data, so recording without a lawful basis or without meeting local consent rules is unlawful. Content that reveals health, politics, or other special categories requires extra care under Article 9.

    Do you need consent to record a call in Europe?

    Not always for GDPR, but often for local law. GDPR lets you record on consent or on legitimate interest with a documented balancing test. Some countries add all-party consent rules on top. Germany, for example, makes secret recording of the spoken word a criminal offence under Section 201 StGB, so every participant must be informed before recording starts. When participants are in different countries, obtaining clear consent from everyone is the safest path because it satisfies both GDPR and stricter national rules at once.

    Does EU data storage make recording GDPR compliant?

    No. EU data storage is one factor, not the whole answer. Storing recordings in an EU data centre is data residency. It does not stop US legal reach if the provider is US-controlled, because the US CLOUD Act can compel a US company to hand over data regardless of where it sits. Sovereignty means the recording, transcription, storage, and AI analysis all sit under EU jurisdiction and control. GDPR compliance also still requires a lawful basis, consent handling, retention limits, a DPA, and a valid transfer mechanism for any data that leaves the EEA.

    How long can you keep call recordings under GDPR?

    Only as long as necessary for the purpose you collected them for, under the storage limitation principle in Article 5(1)(e). For coaching and quality assurance, a retention window of 30 to 90 days is a common defensible standard. Recordings that document a contract may justify longer retention tied to commercial record-keeping law. You must define the retention period, document the justification, delete recordings automatically when it expires, and be able to honour an erasure request within one month.

    What is the difference between data residency and data sovereignty?

    Data residency is where the data is physically stored. Data sovereignty is which legal system controls it. A US-owned provider can store your recordings in Frankfurt and still be forced by US law to disclose them, so residency alone does not remove US legal reach. Sovereignty means both the storage location and the controlling entity sit under EU jurisdiction, so no foreign government can compel access. For call recording, buyers should ask who controls the processor, not just where the servers are.

    Numi keeps call and meeting recording, transcription, storage, and coaching under EU jurisdiction, so residency and sovereignty finally line up.

    Get Early Access