English · Deutsche Version
Free tool · Compliant Rollout Kit 4 of 4
Two steps in one tool. First, answer eight questions and the quick-check tells you, with reasons, whether a Data Protection Impact Assessment under Article 35 GDPR is required. Then the tool assembles a pre-filled DPIA for AI meeting transcription that you can adopt directly, copy, or download as a Word file. Everything runs in the browser; nothing is uploaded or stored.
Updated 30 July 2026 · Template, not legal advice
Template, not legal advice. The check and the template follow Article 35 GDPR, the threshold analysis used by EU supervisory authorities, and the criteria of the European Data Protection Board guidelines WP248. They do not replace an individual review or the involvement of the data protection officer. Confirm the result with your data protection officer and, where in doubt, with legal counsel. Created with numigtm.com.
Under Article 35(1) GDPR a Data Protection Impact Assessment must be carried out where processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of individuals. Whether that is the case is decided in a threshold analysis. EU supervisory authorities and the European Data Protection Board guidelines WP248 list nine criteria for this. The quick-check above covers the eight that are relevant to meeting transcription.
| Criterion | What it means for AI meeting transcription |
|---|---|
| Systematic evaluation | Talk-time, sentiment, coaching or conversation scores evaluate people. Under Art. 35(3)(a) a systematic and extensive evaluation can trigger a DPIA on its own. |
| Automated decision-making | Where scores feed automatically into performance rating or ranking, the risk rises sharply. |
| Systematic monitoring | An assistant that joins every meeting monitors employees continuously. |
| Special categories | Conversations unavoidably contain Article 9 data (health, trade union, religion). Voiceprints may add biometric data. |
| Large scale | Many meetings, many people, on an ongoing basis: that is large-scale processing. |
| Matching or combining | Linking with CRM, HR or calendar broadens the personal data. |
| Vulnerable data subjects | Employees are in a subordinate relationship and count as vulnerable. |
| Innovative technology | AI transcription, speaker diarization and LLM analysis are new technologies within the meaning of Article 35. |
The supervisory authorities' rule of thumb. Where two or more of these criteria are met, a DPIA is generally required. With AI meeting transcription and speaker attribution, several criteria are almost always met at once. So for most buyers the answer is: yes, a DPIA is needed.
A transcript with speaker attribution links every sentence to a specific person. That turns a conversation into a durable, analyzable record of individuals' behavior, word choice, and contributions, often in an employment context and across many sessions. Supervisory authorities cite exactly these features as indicators of high risk.
Two publicly documented cases underline this:
The practical consequence: anyone introducing AI meeting transcription should document the threshold analysis and, as a rule, produce a DPIA before the first recording runs.
The pre-filled template assesses three risks that arise with almost every AI meeting transcription. For each it names concrete mitigating measures.
From many transcripts a profile of individuals can be built: how much someone speaks, which terms they use, how behavior looks over time. This is an evaluation within the meaning of Article 35 and touches informational self-determination.
A tool introduced for notes can gradually become performance monitoring, for example when talk-time or scores feed into appraisals. This change of purpose conflicts with the purpose-limitation principle of Article 5 and, in Germany, is a core concern of the works council under Section 87(1) no. 6 of the Works Constitution Act.
Transcripts contain sensitive conversation content. If they are shared too widely, insufficiently access-restricted, or processed outside the EU, the risk of unauthorized access rises, including by sub-processors or foreign authorities.
A 40-person sales team introduces an AI assistant that transcribes customer calls and internal meetings, produces summaries, and evaluates talk-time for coaching. Here is how the check turns out:
Six criteria are met, well above the threshold of two. The check reports DPIA required: yes. The team adopts the pre-filled template, adds its organizational details, seeks the advice of the data protection officer, and, in Germany, presents the DPIA to the works council as the basis for a works agreement.
The tool assembles exactly this template from your inputs. The full text below shows it for the most common case (AI meeting transcription with speaker attribution in an employment context) and can be adopted directly. Placeholders are marked in color. You can also open the template as a standalone document, print it, and save it as PDF. It follows the structure of Article 35(7) GDPR.
In most cases yes. Under Article 35 GDPR a DPIA is required where processing is likely to result in a high risk to the rights and freedoms of individuals. AI meeting transcription with speaker attribution usually meets several of the criteria that the WP248 guidelines list: systematic evaluation, innovative technology, employment context, and large scale. When two or more criteria are met, a DPIA is generally mandatory. The quick-check above returns a reasoned assessment.
The check follows the threshold analysis used by EU supervisory authorities and the nine criteria of the WP248 guidelines. You answer eight yes-no questions on evaluation, automated decisions, systematic monitoring, special categories, scale, combining data sources, vulnerable data subjects, and innovative technology. Rule of thumb: two or more criteria met generally trigger a DPIA. A systematic and extensive evaluation of employees under Article 35(3)(a) can trigger the obligation on its own. The result is an assessment, not a binding determination.
Article 35(7) requires four components: a systematic description of the processing operations and purposes; an assessment of necessity and proportionality; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address the risks, including safeguards and security measures. The template on this page covers all four and names the three typical risks of meeting transcription: profiling of speech contributions, purpose creep to performance monitoring, and unauthorized access to transcripts.
A transcript with speaker attribution links every sentence to a person and makes talk-time, word choice, and behavior analyzable across many meetings, often in an employment context and at large scale. Supervisory authorities cite these features as indicators of high risk. A DPIA commissioned by the Dutch government on Microsoft 365 Copilot, which also summarizes Teams conversations, found several high risks and advised against use until resolved. It was also reported that in 2025 a German company was fined for rolling out Copilot with transcription without a DPIA and without works-council involvement.
No. Under Article 35(2) GDPR the controller seeks the advice of the data protection officer when carrying out a DPIA. In Germany, where a works council exists, the introduction is also subject to co-determination under Section 87(1) no. 6 of the Works Constitution Act. The template is a Muster and an educational aid that structures and speeds up the process; it does not replace involving the data protection officer or, where in doubt, legal counsel.
Yes. The quick-check and the template are free and usable without registration. The full template text is on the page, and the Muster can be downloaded as a Word file or printed to PDF without providing an email address. Everything runs in the browser; nothing is uploaded or stored.
Four legally required artifacts belong to every German AI-notetaker rollout. This is the fourth. The others are reachable from the Rollout Kit overview.