English · Deutsche Version

Free tool · Compliant Rollout Kit 4 of 4

Does your AI notetaker need a DPIA? Quick-check and template

Two steps in one tool. First, answer eight questions and the quick-check tells you, with reasons, whether a Data Protection Impact Assessment under Article 35 GDPR is required. Then the tool assembles a pre-filled DPIA for AI meeting transcription that you can adopt directly, copy, or download as a Word file. Everything runs in the browser; nothing is uploaded or stored.

Updated 30 July 2026 · Template, not legal advice

Step 1: Do-you-need-one check

1. Are contributions or behavior systematically evaluated or analyzed (e.g. talk-time, sentiment, coaching scores)? Systematic evaluation · Art. 35(3)(a), WP248
2. Are automated decisions made with legal or similarly significant effect (e.g. automated performance rating, ranking)? Automated decision-making · WP248
3. Are employees or participants systematically or continuously monitored (e.g. an assistant joins every meeting)? Systematic monitoring · WP248
4. Are special categories of data under Article 9 processed (e.g. voiceprints, health, trade-union or religious statements spoken in meetings)? Special categories · WP248
5. Is data processed at large scale (many meetings, many people, on an ongoing basis)? Large scale · WP248
6. Are datasets matched or combined with other systems (e.g. CRM, HR, calendar)? Matching or combining · WP248
7. Are vulnerable data subjects involved (e.g. employees in a subordinate relationship, job applicants)? Vulnerable data subjects · WP248
8. Is innovative technology used (e.g. AI transcription, speaker diarization, LLM analysis)? Innovative technology · WP248

Step 2: Details for the template

Name of the AI meeting system in use and the provider (processor).
The advice of the DPO is sought under Art. 35(2) GDPR.
Quick-check result

Your pre-filled DPIA

Copied

Template, not legal advice. The check and the template follow Article 35 GDPR, the threshold analysis used by EU supervisory authorities, and the criteria of the European Data Protection Board guidelines WP248. They do not replace an individual review or the involvement of the data protection officer. Confirm the result with your data protection officer and, where in doubt, with legal counsel. Created with numigtm.com.

When is a DPIA required? The threshold analysis

Under Article 35(1) GDPR a Data Protection Impact Assessment must be carried out where processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of individuals. Whether that is the case is decided in a threshold analysis. EU supervisory authorities and the European Data Protection Board guidelines WP248 list nine criteria for this. The quick-check above covers the eight that are relevant to meeting transcription.

CriterionWhat it means for AI meeting transcription
Systematic evaluationTalk-time, sentiment, coaching or conversation scores evaluate people. Under Art. 35(3)(a) a systematic and extensive evaluation can trigger a DPIA on its own.
Automated decision-makingWhere scores feed automatically into performance rating or ranking, the risk rises sharply.
Systematic monitoringAn assistant that joins every meeting monitors employees continuously.
Special categoriesConversations unavoidably contain Article 9 data (health, trade union, religion). Voiceprints may add biometric data.
Large scaleMany meetings, many people, on an ongoing basis: that is large-scale processing.
Matching or combiningLinking with CRM, HR or calendar broadens the personal data.
Vulnerable data subjectsEmployees are in a subordinate relationship and count as vulnerable.
Innovative technologyAI transcription, speaker diarization and LLM analysis are new technologies within the meaning of Article 35.

The supervisory authorities' rule of thumb. Where two or more of these criteria are met, a DPIA is generally required. With AI meeting transcription and speaker attribution, several criteria are almost always met at once. So for most buyers the answer is: yes, a DPIA is needed.

Why meeting transcription is treated as high risk

A transcript with speaker attribution links every sentence to a specific person. That turns a conversation into a durable, analyzable record of individuals' behavior, word choice, and contributions, often in an employment context and across many sessions. Supervisory authorities cite exactly these features as indicators of high risk.

Two publicly documented cases underline this:

The practical consequence: anyone introducing AI meeting transcription should document the threshold analysis and, as a rule, produce a DPIA before the first recording runs.

The three typical risks of meeting transcription

The pre-filled template assesses three risks that arise with almost every AI meeting transcription. For each it names concrete mitigating measures.

1. Profiling of speech contributions

From many transcripts a profile of individuals can be built: how much someone speaks, which terms they use, how behavior looks over time. This is an evaluation within the meaning of Article 35 and touches informational self-determination.

2. Purpose creep to performance monitoring

A tool introduced for notes can gradually become performance monitoring, for example when talk-time or scores feed into appraisals. This change of purpose conflicts with the purpose-limitation principle of Article 5 and, in Germany, is a core concern of the works council under Section 87(1) no. 6 of the Works Constitution Act.

3. Unauthorized access to transcripts

Transcripts contain sensitive conversation content. If they are shared too widely, insufficiently access-restricted, or processed outside the EU, the risk of unauthorized access rises, including by sub-processors or foreign authorities.

Worked example: a sales team introduces an AI notetaker

A 40-person sales team introduces an AI assistant that transcribes customer calls and internal meetings, produces summaries, and evaluates talk-time for coaching. Here is how the check turns out:

Six criteria are met, well above the threshold of two. The check reports DPIA required: yes. The team adopts the pre-filled template, adds its organizational details, seeks the advice of the data protection officer, and, in Germany, presents the DPIA to the works council as the basis for a works agreement.

The DPIA template in full

The tool assembles exactly this template from your inputs. The full text below shows it for the most common case (AI meeting transcription with speaker attribution in an employment context) and can be adopted directly. Placeholders are marked in color. You can also open the template as a standalone document, print it, and save it as PDF. It follows the structure of Article 35(7) GDPR.

Header

DATA PROTECTION IMPACT ASSESSMENT (DPIA) under Art. 35 GDPR Subject: Use of an AI system for meeting transcription and summarization Controller: [Controller / organization] Data protection officer / contact: [DPO contact] Processor (tool and provider): [Tool and provider] Assessment date: [Date] · Version 1.0

1. Systematic description of the processing (Art. 35(7)(a))

Purpose: Automatic transcription and summarization of meetings and calls to produce notes and, where enabled, to evaluate talk-time for coaching. Data subjects: the controller's employees and external meeting participants. Data categories: audio or transcript text with speaker attribution, metadata (time, participants), derived analytics (e.g. talk-time). Conversation content may contain special categories under Art. 9. Recipients: authorized internal users; processor [Tool and provider]. Processing arrangement: contract under Art. 28 GDPR; processing in the EU; sub-processors documented. Retention period: [Retention], then automatic deletion.

2. Necessity and proportionality (Art. 35(7)(b))

Legal basis: consent under Art. 6(1)(a) for external participants; in the employment context, a works agreement together with Section 26 BDSG (Germany). For audio recording, Section 201 of the German Criminal Code must also be observed. Data minimization: transcribe only the meetings relevant to the purpose; no permanent audio storage unless necessary. Purpose limitation: notes only and, if agreed, coaching. No use for performance control without a separate legal basis and works-council involvement. Transparency: announcement in the meeting and in the invitation; data-subject rights are upheld.

3. Assessment of the risks (Art. 35(7)(c))

Assessment per risk: likelihood x severity.

R1 Profiling of speech contributions: likelihood medium, severity high. Transcripts allow profiles of individuals to be built. R2 Purpose creep to performance monitoring: likelihood medium, severity high. A notes tool can gradually become performance control. R3 Unauthorized access to transcripts: likelihood medium, severity high. Transcripts contain sensitive content; risk from over-broad sharing, sub-processors, or processing outside the EU.

4. Mitigating measures (Art. 35(7)(d))

For R1: limit analytics to the agreed purpose; no hidden scores; a ban on analysis for non-agreed purposes in the works agreement. For R2: strict purpose limitation; separation of coaching and performance rating; works-council co-determination under Section 87(1) no. 6 (Germany); technical blocks against person-level reporting. For R3: role-based access (need-to-know); encryption; processing in the EU; review of sub-processors (AVV check); short retention and automatic deletion; access logging.

5. Outcome and next steps

Residual risk after measures: acceptable, provided the measures are implemented and secured in a works agreement. Prior consultation of the supervisory authority under Art. 36 GDPR: only required if a high residual risk remains after the measures. Involvement: advice of the data protection officer sought under Art. 35(2); works council involved. Review: on material changes to the processing, at least annually. Created with numigtm.com. Template, not legal advice. Updated 30 July 2026.

Frequently asked questions

In most cases yes. Under Article 35 GDPR a DPIA is required where processing is likely to result in a high risk to the rights and freedoms of individuals. AI meeting transcription with speaker attribution usually meets several of the criteria that the WP248 guidelines list: systematic evaluation, innovative technology, employment context, and large scale. When two or more criteria are met, a DPIA is generally mandatory. The quick-check above returns a reasoned assessment.

The check follows the threshold analysis used by EU supervisory authorities and the nine criteria of the WP248 guidelines. You answer eight yes-no questions on evaluation, automated decisions, systematic monitoring, special categories, scale, combining data sources, vulnerable data subjects, and innovative technology. Rule of thumb: two or more criteria met generally trigger a DPIA. A systematic and extensive evaluation of employees under Article 35(3)(a) can trigger the obligation on its own. The result is an assessment, not a binding determination.

Article 35(7) requires four components: a systematic description of the processing operations and purposes; an assessment of necessity and proportionality; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address the risks, including safeguards and security measures. The template on this page covers all four and names the three typical risks of meeting transcription: profiling of speech contributions, purpose creep to performance monitoring, and unauthorized access to transcripts.

A transcript with speaker attribution links every sentence to a person and makes talk-time, word choice, and behavior analyzable across many meetings, often in an employment context and at large scale. Supervisory authorities cite these features as indicators of high risk. A DPIA commissioned by the Dutch government on Microsoft 365 Copilot, which also summarizes Teams conversations, found several high risks and advised against use until resolved. It was also reported that in 2025 a German company was fined for rolling out Copilot with transcription without a DPIA and without works-council involvement.

No. Under Article 35(2) GDPR the controller seeks the advice of the data protection officer when carrying out a DPIA. In Germany, where a works council exists, the introduction is also subject to co-determination under Section 87(1) no. 6 of the Works Constitution Act. The template is a Muster and an educational aid that structures and speeds up the process; it does not replace involving the data protection officer or, where in doubt, legal counsel.

Yes. The quick-check and the template are free and usable without registration. The full template text is on the page, and the Muster can be downloaded as a Word file or printed to PDF without providing an email address. Everything runs in the browser; nothing is uploaded or stored.

Part of the Compliant Rollout Kit

Four legally required artifacts belong to every German AI-notetaker rollout. This is the fourth. The others are reachable from the Rollout Kit overview.