Data Protection Impact Assessment: AI meeting transcription
Template under Article 35 GDPR for the use of an AI system for meeting transcription and summarization
Updated 30 July 2026 · Template, not legal advice
This template shows the most common case: AI meeting transcription with speaker attribution in an employment context. Placeholders are marked in color. For a version tailored to your inputs and the preceding do-you-need-one check, use the DPIA quick-check.
Header
Subject: Use of an AI system for meeting transcription and summarization
Controller: [Controller / organization]
Data protection officer / contact: [DPO contact]
Processor (tool and provider): [Tool and provider]
Assessment date: [Date] · Version 1.0
1. Systematic description of the processing (Art. 35(7)(a))
Purpose: Automatic transcription and summarization of meetings and calls to produce notes and, where enabled, to evaluate talk-time for coaching.
Data subjects: the controller's employees and external meeting participants.
Data categories: audio or transcript text with speaker attribution, metadata (time, participants), derived analytics. Conversation content may contain special categories under Art. 9.
Recipients: authorized internal users; processor [Tool and provider].
Processing arrangement: contract under Art. 28 GDPR; processing in the EU; sub-processors documented.
Retention period: [Retention], then automatic deletion.
2. Necessity and proportionality (Art. 35(7)(b))
Legal basis: consent under Art. 6(1)(a) for external participants; in the employment context, a works agreement together with Section 26 BDSG (Germany). For audio recording, Section 201 of the German Criminal Code must also be observed.
Data minimization: transcribe only the meetings relevant to the purpose; no permanent audio storage unless necessary.
Purpose limitation: notes only and, if agreed, coaching. No use for performance control without a separate legal basis and works-council involvement.
Transparency: announcement in the meeting and in the invitation; data-subject rights are upheld.
3. Assessment of the risks (Art. 35(7)(c))
Assessment per risk: likelihood x severity.
R1 Profiling of speech contributions: likelihood medium, severity high. Transcripts allow profiles of individuals to be built.
R2 Purpose creep to performance monitoring: likelihood medium, severity high. A notes tool can gradually become performance control.
R3 Unauthorized access to transcripts: likelihood medium, severity high. Transcripts contain sensitive content; risk from over-broad sharing, sub-processors, or processing outside the EU.
4. Mitigating measures (Art. 35(7)(d))
For R1: limit analytics to the agreed purpose; no hidden scores; a ban on analysis for non-agreed purposes in the works agreement.
For R2: strict purpose limitation; separation of coaching and performance rating; works-council co-determination under Section 87(1) no. 6 (Germany); technical blocks against person-level reporting.
For R3: role-based access (need-to-know); encryption; processing in the EU; review of sub-processors (AVV check); short retention and automatic deletion; access logging.
5. Outcome and next steps
Residual risk after measures: acceptable, provided the measures are implemented and secured in a works agreement.
Prior consultation of the supervisory authority under Art. 36 GDPR: only required if a high residual risk remains after the measures.
Involvement: advice of the data protection officer sought under Art. 35(2); works council involved.
Review: on material changes to the processing, at least annually.
Template, not legal advice. This template follows Article 35 GDPR, the threshold analysis used by EU supervisory authorities, and the criteria of the European Data Protection Board guidelines WP248. It does not replace an individual review or the involvement of the data protection officer under Art. 35(2) GDPR. In Germany, where a works council exists, the introduction is subject to co-determination under Section 87(1) no. 6 of the Works Constitution Act. Confirm the result with your data protection officer and, where in doubt, with legal counsel.
Created with numigtm.com · Compliant Rollout Kit · Updated 30 July 2026