← Blog

Is Fathom GDPR-Compliant? The Honest Answer for EU Teams

    Fathom can be used in a GDPR-compliant way, with a Data Processing Agreement and the right configuration. But it is a US company that hosts and processes meeting data in the United States, and it relies on the EU-US Data Privacy Framework and Standard Contractual Clauses to move European data there. For a European team that needs meeting data under EU jurisdiction end to end, that is the whole story.

    Here is what Fathom's own documentation says, what it gets genuinely right, and where the sovereignty question actually sits. All claims below are drawn from Fathom's own privacy policy, sub-processor list, and security pages, retrieved 2026-08-30.

    Where Fathom stores and processes your data

    Fathom Video, Inc. is a US company. By its own documentation it hosts its infrastructure in the United States and stores and processes recordings, transcripts, and AI summaries there. It does not advertise an EU-region data residency option for storage or processing, so a European customer's call data is transferred to and processed in the US.

    Fathom encrypts data in transit and at rest, holds SOC 2 Type II, and publishes a Data Processing Agreement. Those are real and worth crediting. But storage and processing location is where GDPR jurisdiction is decided, and by default that location is the United States.

    Give Fathom credit: a strong no-training posture

    It would be easy to attack Fathom on AI training. It would also be wrong. By Fathom's own documentation it does not train AI models on your meeting content, and it states that its AI sub-processors are contractually prohibited from training on your data and operate under zero-retention terms. That is a responsible posture, and a post that overstates it loses trust.

    So the argument against Fathom for a sovereignty-minded European buyer is not "they train on your calls." It is jurisdiction and consent.

    So why is it still a sovereignty problem?

    Fathom's AI features are generated through US-based AI sub-processors, and the company itself is US-headquartered, so transfers out of the EU rely on the Data Privacy Framework, which Fathom self-certifies, plus Standard Contractual Clauses. Those are valid mechanisms, but they do the same thing they do for every US vendor: they legitimise moving your data to the US, where it becomes reachable under US law such as the CLOUD Act.

    A self-certification is a company claim, and Data Privacy Framework adequacy remains politically contested after Schrems II. A provider that never moves the data out of the EU does not depend on any of that holding. This is exactly the distinction our GDPR-compliant AI meeting assistant comparison scores: residency for both storage and processing, Article 28 DPA terms, transfer basis, and no-training obligations. A tool can be excellent on retention and training and still leave your data under US jurisdiction.

    The consent problem travels with the bot

    Fathom joins Zoom, Google Meet, and Microsoft Teams as a bot participant, and it also offers a desktop recorder. If a notetaker records the non-public spoken word without the consent of all participants, that is a live legal issue in Germany and much of the EU, not a preference, and deploying a notetaker that records employees can trigger works-council co-determination. We cover exactly what that requires in AI notetaker consent in Germany. A tool that records first puts the consent burden entirely on you.

    Free check

    Running this test against your own notetaker? Our free 15-criteria AVV and GDPR check walks through sub-processors, transfer basis, and hosting jurisdiction. No signup, and the samples are templates, not legal advice.

    The EU alternative

    If the requirement is EU jurisdiction for storage and processing, the fix is a sovereign provider, not a US tool with good paperwork. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction: hosted in Frankfurt, with self-hosted EU transcription, no US AI provider in the analysis loop, and no training on your data. It publishes its Article 28 processor agreement (Auftragsverarbeitungsvertrag) and its sub-processor list. For the direct feature-by-feature and pricing view aimed at DACH teams, see the German Fathom-Alternative page.

    Fathom gets a lot right, especially on training and retention. For a European team that has to answer for where meeting data is processed and how consent is captured, "US company, US processing, transfer under the Data Privacy Framework" is the sentence that decides it.

    Frequently asked questions

    Is Fathom GDPR-compliant?

    Fathom offers a Data Processing Agreement, self-certifies under the EU-US Data Privacy Framework, and holds SOC 2 Type II. You can use it under GDPR with the right paperwork. But it is a US company that hosts and processes meeting data in the United States by default, so European call data is transferred to US jurisdiction and relies on the Data Privacy Framework and Standard Contractual Clauses.

    Where does Fathom store meeting data?

    By its own documentation, Fathom Video, Inc. is a US company that stores and processes meeting recordings and transcripts on US cloud infrastructure. It does not offer EU-region data residency for storage or processing, so European data is transferred to the United States.

    Does Fathom train AI on my meetings?

    By Fathom's own documentation, it does not train AI models on your meeting content and states that its AI sub-processors are contractually barred from training on your data, with zero-retention terms. Its no-training posture is genuinely strong. The GDPR question with Fathom is jurisdiction and consent, not model training.

    What is an EU-sovereign alternative to Fathom?

    A sovereign EU meeting assistant keeps recording, transcription, storage, and processing inside EU jurisdiction. Numi hosts in Frankfurt with self-hosted EU transcription, no US AI provider in the analysis loop, and no training on your data, and publishes its Article 28 processor agreement and sub-processor list.

    Numi keeps meeting data in the EU for both storage and transcription, with self-hosted transcription, no US AI provider in the analysis loop, and no training on your data, so residency and sovereignty finally line up.

    Start for free