← Compare

Is Otter.ai GDPR Compliant? Where Your Call Data Goes, and the Transfer Gaps

    Short answer

    Otter.ai can be run inside a GDPR-compliant setup, but your call data leaves the EU. Otter.ai, Inc. is a Delaware company whose own Privacy Policy places compute and storage on AWS “based in the United States,” and every sub-processor it lists sits in the US, including OpenAI and Anthropic for AI. It offers a proper Article 28 DPA with Standard Contractual Clauses and self-certifies to the EU-US Data Privacy Framework, so an EU controller can use it lawfully with a transfer assessment. But there is no EU data-residency option, and the recordings, transcripts, and AI analysis fall under US jurisdiction. This piece quotes Otter's own current documents, retrieved 2026-07-26.

    Is Otter.ai GDPR compliant?

    Otter.ai can be run inside a GDPR-compliant setup, but your call data leaves the EU. Otter.ai, Inc. is a US company, and its own Privacy Policy states that compute and data storage run on Amazon Web Services "based in the United States." It offers a proper Article 28 processor agreement with Standard Contractual Clauses, and it self-certifies to the EU-US Data Privacy Framework, which are the tools that legitimize an EU-to-US transfer on paper. What they do not change is that recordings, transcripts, and the AI layer sit on US infrastructure under US jurisdiction.

    So an EU controller who signs the DPA, runs a transfer impact assessment, and accepts the residual risk can use Otter lawfully. Otter is not non-compliant by default. But there is no EU data-residency option in its documents, and every sub-processor it lists sits in the United States. For a recording tool, where identifiable personal data physically lives and which jurisdiction can compel it matters as much as the contract.

    Who Otter.ai is and where it processes data

    Otter's Privacy Policy names the operating entity and its home jurisdiction: "Otter.ai, Inc., a company registered in Delaware with its registered address located at 800 W El Camino Real, Suite 170, Mountain View, CA 94040." That places the controller of the service, and its legal exposure, squarely in the United States.

    On location, the same policy is explicit that storage and compute are US-based: "Cloud service providers who we rely on for compute and data storage, including Amazon Web Services, based in the United States." Data is encrypted at rest with AES-256, but the documents disclose no EU region for any part of the pipeline. Otter does not break out where audio capture and transcription physically run beyond this US cloud footprint.

    Sources, retrieved 2026-07-26: otter.ai/privacy-policy.

    Otter's DPA and the transfer mechanism

    Otter's data processing terms are not a standalone PDF. They are incorporated into the contract as Appendix 1 of the Terms of Service and pulled in by reference from the Software Services Agreement. The Article 28 roles are stated directly.

    What the DPA says

    Otter's Terms of Service, Appendix 1, state: "Customer is a Controller and appoints Company as a Processor on behalf of Customer." On international transfer it provides: "Customer and Company hereby agree to conclude the provisions of module two (controller to processor) of the Standard Contractual Clauses," and adds a UK Addendum for UK transfers. The safeguard offered for EU data leaving the EEA is the SCCs, not EU-only storage.

    The Privacy Policy layers the Data Privacy Framework on top: Otter states it complies with "the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework." The DPF is the third attempt at a durable EU-US transfer basis after Safe Harbor and Privacy Shield were each struck down, and it is under active legal challenge, so a posture that relies on it carries standing risk. Note that DPF self-certification is a claim by the provider; verify its current active status on the US Department of Commerce list before relying on it.

    Sources, retrieved 2026-07-26: otter.ai/terms-of-service, otter.ai/privacy-policy.

    Otter's sub-processors are all US-based

    Otter publishes a sub-processor list at otter.ai/subprocessors (effective 31 March 2026). On that list, every named sub-processor is located in the United States, including the storage and AI layers that touch call content.

    • Amazon Web Services, Inc. (United States), described as the "Cloud service provider and customer data storage platform." Google Cloud Platform and Crusoe, both United States, are also listed as cloud providers.
    • Anthropic (United States), listed for "Backend support for AI functionality," with the note "no customer data used for training."
    • OpenAI (United States), listed to evaluate "LLM effectiveness for harmful content detection," with the note "no data storage."
    • Research Transcriptions (United States), listed for "Annotating training and evaluation data."

    No EU or EEA region is given for any entry, including AWS, which the page marks only as "United States." An EU controller reading this list is looking at a supply chain that begins and ends in the US.

    Sources, retrieved 2026-07-26: otter.ai/subprocessors.

    Residency, sovereignty, and the CLOUD Act

    Residency is where data physically sits. Sovereignty is which jurisdiction can compel it. Otter's documents describe US residency across the board: US hosting, US sub-processors, and a transfer mechanism whose purpose is to move EU data to the US.

    Because Otter.ai, Inc. is a US company on US infrastructure, it falls under the US CLOUD Act, which can compel a US provider to produce data in its possession or control regardless of where servers sit. A DPA and the SCCs bind two private parties; they cannot override a valid US order, and orders can carry non-disclosure obligations. For the wider mechanics, see our explainer on the CLOUD Act and EU data sovereignty for AI.

    Where Otter.ai is genuinely solid

    Otter's security program is credible, and it is worth stating plainly what it does well.

    • SOC 2 Type 2. Otter's security page states it "has achieved SOC 2 Type 2 report," and that its security policies are "created based on the ISO 27001/2 framework." Read the second as framework alignment rather than a stated ISO 27001 certificate.
    • A real Article 28 DPA with SCCs Module 2 and a UK Addendum, auto-incorporated into the contract.
    • Encryption at rest using AES-256, plus HIPAA-aligned handling for health-related information and a clear "We do not sell your data" CCPA stance.
    • No-training posture on the AI vendors, with Anthropic marked "no customer data used for training" and OpenAI marked "no data storage."

    None of that is in doubt. The gap is not the quality of Otter's paperwork or security. It is the jurisdiction the whole stack runs under, which no certificate closes.

    The EU-native alternative

    If the requirement is that call recordings and their analysis stay under EU jurisdiction rather than being transferred out under a framework, Otter does not meet it. The structural answer is a provider with no US hosting and no US AI provider in the analysis loop. Numi is a sovereign meeting assistant built on that principle: EU data residency, self-hosted open-source transcription, no US AI provider in the loop, and a GDPR Article 28 processor agreement (Auftragsverarbeitungsvertrag) behind it. For the full field of EU-native options, see our guide to Gong alternatives for the DACH region in 2026, and compare the data practices of the major tools on our compliance comparison hub.

    Frequently asked questions

    Is Otter.ai GDPR compliant?

    Otter.ai can be used within a GDPR-compliant setup: it offers an Article 28 DPA (Appendix 1 of its Terms of Service) with Standard Contractual Clauses and a UK Addendum, and it self-certifies to the EU-US Data Privacy Framework. But Otter.ai, Inc. is a US company, and its Privacy Policy states compute and storage run on AWS based in the United States, with every listed sub-processor in the US. EU personal data is transferred to the United States, so compliance requires a DPA, SCCs, and your own transfer risk assessment, and the data does not stay in the EU.

    Where does Otter.ai store and process data?

    Otter's Privacy Policy states it relies on cloud service providers for compute and data storage, including Amazon Web Services, based in the United States. Its sub-processor list marks every provider, including AWS, Google Cloud, OpenAI, and Anthropic, as United States. Data is encrypted at rest with AES-256, but no EU data region is disclosed.

    Does Otter.ai have a DPA?

    Yes. Otter's data processing terms are incorporated as Appendix 1 of its Terms of Service and pulled in by reference from the Software Services Agreement. They name the customer as controller and Otter as processor under Article 28, and conclude Module 2 of the Standard Contractual Clauses plus a UK Addendum for restricted transfers.

    Does Otter.ai use my calls to train AI?

    Otter's sub-processor list marks its AI vendors with no-training and no-storage notes: Anthropic is listed with no customer data used for training, and OpenAI is listed with no data storage. Those vendors are both located in the United States. The no-training posture is a genuine plus, but it is separate from the question of where the data physically sits, which is the US.

    Can the CLOUD Act reach data held by Otter.ai?

    Yes. Otter.ai, Inc. is a US company hosting on US infrastructure, so it falls under the US CLOUD Act, which can compel a US provider to produce data in its control regardless of where servers sit. A DPA and SCCs govern the contract between two private parties and cannot override a valid US legal order.

    Numi keeps call audio, transcription, storage, and coaching under EU jurisdiction, so your DPA is backed by control, not just a contract.

    Get Early Access