Skip to content
Legal·8 min read

AI meeting assistants: the GDPR checklist

You switch on the AI meeting assistant. It listens, transcribes, and has the summary written before you have hung up. What happens in the background is processing of personal data about everyone in the meeting, the customer's people included, by a vendor that is often based in the United States, and the responsibility for that processing sits with you, not the vendor. Here is the checklist of what GDPR requires before the tool goes live: roles, contract, information, impact assessment and transfers, along with what Sweden's regulator has actually said about AI transcription in 2026.

SP

Salesprep editorial team

Sales and sales training editorial team

Definition

AI meeting assistant : An AI meeting assistant is a tool that records, transcribes and summarises meetings. Because it processes personal data about every participant, the company using it is the controller and needs a legal basis, information before recording starts, a processor agreement with the vendor, an impact assessment if it evaluates staff, and a valid basis for transfers outside the EU.

This is an overview, not legal advice. It draws on the text of GDPR, on the guidance from IMY, the Swedish Authority for Privacy Protection, on processor agreements, impact assessments and transfers to the United States, and on what IMY said about AI transcription in spring 2026. The basic question of whether you may record at all, the Criminal Code and the rule for someone who takes part in the call themselves, is covered in our article on recording sales calls. This one is about what changes when a vendor's AI does the work.

You are the controller, the vendor is your processor

IMY's definitions are plain. The controller is the organisation that decides why the data is processed and how. The processor handles data on the controller's behalf and may only do so on instruction. A rep who switches on the assistant is doing it on the company's behalf, so the company is the controller and the vendor is the processor. Responsibility for doing this properly does not shift to the vendor just because the vendor is big or American.

Article 28 requires you to use only processors that provide sufficient guarantees, and it requires a written contract setting out the subject matter, duration, nature and purpose of the processing, the types of personal data, the categories of data subjects and your rights and obligations. IMY's list of mandatory contents adds instructions, confidentiality, security measures under Article 32, rules for sub-processors, help with data subjects' rights, deletion or return when the contract ends, and a right of audit. Read with particular care what the vendor does with your transcripts. A vendor that trains its own models on them is no longer acting solely on your instruction, and a processor agreement does not cover that.

Information has to come before the recording

Under Article 13, whoever collects data directly from a person must inform them at the time the data is obtained, meaning before or as the recording starts, not in an email afterwards. For the customer's participants, whose data arrives through the meeting, Article 14 applies and lands in the same place. The information must say who you are, why you are recording, which legal basis you rely on (normally legitimate interest), how long the material is kept and that anyone can object. What differs from an ordinary recording is that you should also name the vendor that is in the room. Since 19 June 2026 there is, in addition, an explicit rule for telephone sales of financial services to consumers: the consumer must be told at the start of the call whether it may be recorded (Distance Contracts Act, Chapter 3 Section 9). No equivalent statutory rule exists for B2B meetings, but the practical advice is the same.

The simplest routine is one sentence in the invitation and one when the meeting opens: 'We have an AI assistant from X transcribing, the summary is kept for 90 days, say the word if you would like it switched off.' Anyone who says the word gets their way. A meeting recorded against the participants' express wishes is rarely worth the transcript.

When is an impact assessment required?

Article 35 requires a data protection impact assessment before any processing likely to result in a high risk, especially where new technology is involved. IMY lists nine criteria, among them systematic monitoring of people, large-scale processing, data about people in a dependent position such as employees, and the use of new technology. IMY's rule of thumb is that an assessment is required when at least two criteria are met. An assistant that only transcribes your own customer meetings often meets one. An assistant that also scores your reps' talk ratio, tone or 'engagement' probably meets two: new technology and systematic monitoring of employees. At that point the assessment is not optional, and IMY's guidance on monitoring employees requires the employer to settle the question before processing starts.

Add one question from a different rulebook. Since 2 February 2025 the AI Act prohibits AI systems used to infer the emotions of people in the workplace, except for medical or safety reasons (Article 5(1)(f)). If the tool offers 'sentiment analysis' of your own reps, let a lawyer decide where the line runs before you switch that feature on.

The US question in autumn 2026

Most AI meeting assistants process data in the United States. The transfer is permitted if the vendor is certified under the EU-US Data Privacy Framework, which the European Commission approved by an adequacy decision on 10 July 2023, or if you have standard contractual clauses under Article 46. On 3 September 2025 the General Court dismissed the action to annul the framework, in Latombe v Commission, and the judgment has reportedly been appealed to the Court of Justice; the appeal had not been decided as of September 2026. On 3 July 2026, after a US ruling on the independence of oversight bodies, IMY wrote that the adequacy decision still stands but that organisations should stay informed and be prepared for what to do if it were overturned. In practice: find out whether the vendor is on the DPF list, keep the clauses as a fallback, and know how you would export and delete your transcripts if you had to switch.

What IMY has actually said about AI transcription

There is no IMY decision on AI meeting assistants in sales, and none appeared on IMY's enforcement pages in September 2026. The closest thing is IMY's regulatory sandbox assessment of 13 April 2026, on AI transcription in social services. The authority found that a legal basis exists, but stressed human control, strong security measures and clear routines for deletion, encryption and access control, and noted that staff need training, time and support to review the transcripts. Social services handle more sensitive data than a sales meeting, but the routines are the same at a smaller scale: who may read, how long it is kept, who corrects errors.

The checklist

  • Roles: you are the controller, the vendor is the processor. Check that the vendor does not train its own models on your meetings unless you have expressly chosen that.
  • Contract: a processor agreement under Article 28 with IMY's mandatory contents, including sub-processors and deletion at the end of the contract.
  • Basis and information: a documented legitimate interest assessment, information in the invitation and at the start of the meeting, the vendor named, a way to say no.
  • Impact assessment: done if the tool evaluates staff or meets two of IMY's criteria.
  • Transfers: DPF certification or standard contractual clauses, and a plan for changing vendor.
  • Retention: a fixed storage period for recordings and transcripts, and a routine for sensitive data that happens to be said in the meeting.

Part of what teams want from AI assistants is to learn from the conversations: what the customer said, how the rep answered, what should have been said. You can get that without recording a single customer. In Salesprep's Follow-up module the rep practises the follow-up call against an AI buyer, and every call is scored on seven metrics with a written comment per score. No customer, no transcript to protect. Follow-up is available on Pro and up, and three free calls in the Cold call module come with the account, no card required.

Common questions about this topic

What does GDPR require before you connect an AI notetaker to your sales calls?

Five things: a legal basis, normally a documented legitimate interest assessment, and information to every participant before recording starts under Articles 13 and 14, including which vendor is present. Then a processor agreement with the vendor under Article 28 and, if the tool systematically monitors or evaluates staff, a data protection impact assessment under Article 35 as well. Finally a valid transfer mechanism if the vendor processes data in the United States, either certification under the EU-US Data Privacy Framework or standard contractual clauses. Add a fixed retention period on top, since Article 5(1)(e) prohibits keeping data longer than the purpose requires.

Do the customer's participants have to consent to an AI assistant joining the meeting?

No, consent is not the usual basis, legitimate interest is, and the Swedish Criminal Code's rule on unlawful interception does not apply to someone who takes part in the conversation. But participants must be informed before recording starts, they have the right to object, and anyone who asks you to switch the assistant off should get their way. One exception to note: a bot that keeps recording after your own people have left the meeting is no longer a participant, and that puts you back in the Criminal Code's risk zone.

Try it yourself.

Three free calls are included when you create an account. No credit card needed and the first call fits in before your coffee cools.

Create a free account