Fathom can be used in a GDPR-compliant way, with a Data Processing Agreement and the right configuration. But it is a US company that hosts and processes meeting data in the United States, and it relies on the EU-US Data Privacy Framework and Standard Contractual Clauses to move European data there. For a European team that needs meeting data under EU jurisdiction end to end, that is the whole story.
Here is what Fathom's own documentation says, what it gets genuinely right, and where the sovereignty question actually sits. All claims below are drawn from Fathom's own privacy policy, sub-processor list, and security pages, retrieved 2026-08-30.
Where Fathom stores and processes your data
Fathom Video, Inc. is a US company. By its own documentation it hosts its infrastructure in the United States and stores and processes recordings, transcripts, and AI summaries there. It does not advertise an EU-region data residency option for storage or processing, so a European customer's call data is transferred to and processed in the US.
Fathom encrypts data in transit and at rest, holds SOC 2 Type II, and publishes a Data Processing Agreement. Those are real and worth crediting. But storage and processing location is where GDPR jurisdiction is decided, and by default that location is the United States.
Give Fathom credit: a strong no-training posture
It would be easy to attack Fathom on AI training. It would also be wrong. By Fathom's own documentation it does not train AI models on your meeting content, and it states that its AI sub-processors are contractually prohibited from training on your data and operate under zero-retention terms. That is a responsible posture, and a post that overstates it loses trust.
So the argument against Fathom for a sovereignty-minded European buyer is not "they train on your calls." It is jurisdiction and consent.
So why is it still a sovereignty problem?
Fathom's AI features are generated through US-based AI sub-processors, and the company itself is US-headquartered, so transfers out of the EU rely on the Data Privacy Framework, which Fathom self-certifies, plus Standard Contractual Clauses. Those are valid mechanisms, but they do the same thing they do for every US vendor: they legitimise moving your data to the US, where it becomes reachable under US law such as the CLOUD Act.
A self-certification is a company claim, and Data Privacy Framework adequacy remains politically contested after Schrems II. A provider that never moves the data out of the EU does not depend on any of that holding. This is exactly the distinction our GDPR-compliant AI meeting assistant comparison scores: residency for both storage and processing, Article 28 DPA terms, transfer basis, and no-training obligations. A tool can be excellent on retention and training and still leave your data under US jurisdiction.
The consent problem travels with the bot
Fathom joins Zoom, Google Meet, and Microsoft Teams as a bot participant, and it also offers a desktop recorder. If a notetaker records the non-public spoken word without the consent of all participants, that is a live legal issue in Germany and much of the EU, not a preference, and deploying a notetaker that records employees can trigger works-council co-determination. We cover exactly what that requires in AI notetaker consent in Germany. A tool that records first puts the consent burden entirely on you.
Running this test against your own notetaker? Our free 15-criteria AVV and GDPR check walks through sub-processors, transfer basis, and hosting jurisdiction. No signup, and the samples are templates, not legal advice.
The EU alternative
If the requirement is EU jurisdiction for storage and processing, the fix is a sovereign provider, not a US tool with good paperwork. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction: hosted in Frankfurt, with self-hosted EU transcription, no US AI provider in the analysis loop, and no training on your data. It publishes its Article 28 processor agreement (Auftragsverarbeitungsvertrag) and its sub-processor list. For the direct feature-by-feature and pricing view aimed at DACH teams, see the German Fathom-Alternative page.
Fathom gets a lot right, especially on training and retention. For a European team that has to answer for where meeting data is processed and how consent is captured, "US company, US processing, transfer under the Data Privacy Framework" is the sentence that decides it.