TL;DR(要約)
GDPR compliant AI meeting assistants handle more personal data than they sometimes get credit for.
A single customer call can produce an audio recording, video, transcript, speaker names, AI summary, action items, and CRM updates. If people in the EU are involved, GDPR may apply to the personal data inside those records.
So when you’re comparing GDPR compliance software for meetings, a GDPR badge on the homepage isn’t enough.
You need to know where meeting data is stored, whether it is used to train AI models, what happens if somebody does not want to be recorded, how long the data stays around, and whether the vendor gives you the documents your legal or security team will eventually ask for.
I reviewed nine highly rated AI meeting tools against those questions.
This guide is for GDPR compliance software evaluation (in the AI meeting tools category), not legal advice. Your GDPR obligations depend on how and why your organization processes personal data.
The Best GDPR-Compliant AI Meeting Tools: Quick Comparison
| 順位 | ツール | Privacy score | G2 rating | データの保管場所 | Meeting data used for AI training? | 最適 |
|---|---|---|---|---|---|---|
| 1 | tl;dv Our pick | 9.7/10 | 4.7/5, 537 reviews | EEA; EU AI processing available | いいえ | Strong all-round privacy controls |
| 2 | ミートギーク | 9.3/10 | 4.6/5, 490 reviews | EU or US; EU AI processing available | いいえ | Teams prioritizing EU residency |
| 3 | ジェイミー | 9.2/10 | 4.7/5, 50 reviews | European-region storage and processing | いいえ | EU-first bot-free recording |
| 4 | Avoma | 9.1/10 | 4.6/5, 1,365 reviews | US by default; EU options can be discussed | いいえ | Configurable recording consent |
| 5 | Fireflies.ai | 8.7/10 | 4.7/5, 753 reviews | US by default; EU private storage available | いいえ | Enterprise administration |
| 6 | Sembly AI | 8.1/10 | 4.6/5, 46 reviews | US or EU deployment options | Opt-out; Enterprise excluded | Flexible enterprise deployment |
| 7 | Grain | 8.0/10 | 4.7/5, 313 reviews | 米国 | いいえ | Sales and customer-facing teams |
| 8 | Fathom | 7.8/10 | 5.0/5, 7,017 reviews | 米国 | De-identified customer data may be used for Fathom model training unless opted out | Ease of use and strong user reviews |
| 9 | Otter.ai | 6.8/10 | 4.4/5, 505 reviews | 米国 | De-identified recordings and transcripts may be used to train Otter models | General transcription |
How I Ranked the Tools
I ranked these tools on the privacy and compliance factors that matter when meetings contain personal, confidential, or commercially sensitive information. Each tool received a score from 0 to 10 for six criteria. I then applied the weights below to calculate the final Privacy Score.| What I checked | 重量 |
|---|---|
| GDPR documentation, DPA, and subprocessor transparency | 20% |
| Data residency and international-transfer transparency | 20% |
| AI model-training policy | 20% |
| Recording notice and consent controls | 15% |
| Security, access, retention, and deletion controls | 15% |
| Independent G2 rating and review volume | 10% |
A high AI-training score requires a clear default no-training policy. Opt-outs score lower. For residency, I scored where data is stored and where AI processing takes place separately.
The G2 component considers both rating and review volume, so a small review set does not automatically outrank a much larger one.
For transparency, tl;dv’s 9.7 comes from 10/10 for GDPR documentation, residency, model-training policy, and consent controls; 9/10 for security and data controls; and 8/10 for review strength. Weighted, that is 9.65, rounded to 9.7.
The Privacy Score is my editorial assessment based on current public documentation. It is not a GDPR certification.
The criteria also reflect GDPR principles such as transparency, purpose limitation, data minimisation, storage limitation, security, and accountability. The European Commission explains those principles here: GDPR principles for businesses and organisations
If you want to understand the wider privacy issues before comparing individual products, tl;dv has a separate guide to AI and privacy in 2026.
1. tl;dv: Best Overall for GDPR-Conscious Teams
Privacy Score: 9.7/10 | G2: 4.7/5
Personal data collected through tl;dv is primarily processed and stored in the EEA. Our core services are hosted in Europe, and users can choose whether AI processing takes place in Europe or the US. We do not use customer data to train our AI, and we maintain SOC 2 Type II compliance.
Our consent collection is one of the strongest parts of the privacy setup. When enabled for eligible scheduled meetings, external participants see a consent screen before joining. They can accept or decline. If anyone declines, they can still attend the meeting, but the recording is blocked for that session with no override.
Consent collection is not enabled automatically. It requires a synced calendar and auto-recording, and manually starting early can bypass that flow.
Pros: European hosting, EU AI-processing option, no customer-data model training, SOC 2 Type II, detailed privacy documentation, and a genuine decline-and-block recording flow.
Limitations: Consent collection is not enabled by default, requires a synced calendar and auto-recording, and can be bypassed if recording is started manually before the scheduled meeting time.
2. MeetGeek
Privacy Score: 9.3/10 | G2: 4.6/5
European customers can use its EU instance, where production data stays within the EEA at both the storage and AI-processing layers. Speech-to-text also runs in EU regions where available. MeetGeek states that meeting content and AI outputs are not used to train its own or external models unless the customer explicitly opts in in writing.
It is SOC 2 Type II audited, publishes a DPA and subprocessors, and supports workspace-level retention. Enterprise customers can arrange custom or zero-retention policies.
MeetGeek tells participants when recording is happening and does not support covert recording. Its published standard flow focuses more heavily on clear notice than on a universal pre-meeting accept-or-decline mechanism, which is why its consent score sits below ours.
Pros: EU storage and AI processing, no meeting-content model training, SOC 2 Type II, published DPA, and configurable retention.
Limitations: MeetGeek’s standard flow focuses on recording notice rather than a universal pre-meeting accept-or-decline step.
3. ジェイミー
Privacy Score: 9.2/10 | G2: 4.7/5
Jamie says meeting data storage and processing remain within the EEA, Switzerland, and the UK. Audio is deleted after transcription, customer data is not used for model training, and Jamie is ISO 27001 certified. Its DPA also lists subprocessors and prohibits AI-model training on personal data.
Jamie is bot-free, so nothing joins the participant list. That also works for in-person meetings and teams that dislike meeting bots.
Bot-free capture makes participant notification more important, not less. Jamie includes consent-email functionality, but recording is less visually obvious than a bot in the call.
Pros: European-region processing, no model training, audio deleted after transcription, public DPA and subprocessors, ISO 27001, and bot-free capture.
Limitations: Because Jamie records without a visible meeting bot, participant disclosure depends more heavily on the consent and notification process you use.
For more on that, see whether bot-free recording is legal.
4. Avoma: Best for Configurable Recording Consent
Privacy Score: 9.1/10 | G2: 4.6/5
Admins can choose between four organization-wide levels: no automated notification, notification only, acknowledgment required, or explicit permission required. At the strictest level, participants can accept or decline before recording begins. If somebody declines, Avoma automatically disables recording for that session.
Avoma says customer data is not used to train its models and maintains SOC 2 Type II compliance.
Its main trade-off is residency. Avoma says customer data is hosted on US AWS infrastructure by default, while organizations requiring EU residency can discuss options with its enterprise team.
Pros: Excellent consent controls, centralized enforcement, no customer-data model training, public DPA, and strong security documentation.
Limitations: Customer data is hosted in the US by default. Organizations that require EU residency need to discuss available options with Avoma’s enterprise team.
5. Fireflies.ai: Best for Enterprise Administration
Privacy Score: 8.7/10 | G2: 4.7/5
Fireflies states that meeting audio, video, transcripts, and summaries are never used to train its own or external AI models. It also says its AI vendors operate under zero-data-retention agreements.
Teams can send advance compliance emails with a decline link, and several conferencing integrations support opt-in recording. The exact flow varies by platform, so test your normal setup before deployment.
Fireflies stores and processes data in the US by default. Enterprise Private Storage can keep meeting data in the EU, but processing still occurs in the US.
Pros: No meeting-data AI training, SOC 2 Type II, advance participant notifications, enterprise governance tools, and private-storage options.
Limitations: Enterprise Private Storage can keep stored meeting data in the EU, but Fireflies states that processing still takes place in the US.
6. Sembly AI: Best for Flexible Enterprise Deployment
Privacy Score: 8.1/10 | G2: 4.6/5
Sembly offers dedicated cloud deployment in US or EU regions, custom retention policies, SSO, and workspace-level compliance controls. Enterprise workspaces are automatically excluded from model training.
The model-training policy differs on other plans. Sembly’s current privacy information says Enterprise audio, video, and text are not used for training, while customers on other plans can manage this through an opt-out setting.
That is why it scores below tools with a default no-training policy across all plans.
Pros: EU deployment option, SOC 2 Type II, custom retention, Trust Center documentation, and strong Enterprise controls.
Limitations: Enterprise workspaces are excluded from model training automatically, while customers on other plans need to use the available opt-out setting.
7. Grain: Best for Sales and Customer-Facing Teams
Privacy Score: 8.0/10 | G2: 4.7/5
Grain states that it does not use meeting data to train AI models. It is SOC 2 Type II certified, encrypts customer data in transit and at rest, and uses role and permission controls for meeting access.
Grain hosts its application on AWS in the US, and its subprocessor list includes US-based providers such as AWS, Anthropic, OpenAI, Recall.ai, and AssemblyAI.
Grain’s bot recording flow also includes recording disclosures and host approval. Its desktop capture works without a bot, which again makes your own participant-notification process important.
Pros: No meeting-data model training, SOC 2 Type II, clear access controls, published subprocessors, and strong customer-conversation functionality.
Limitations: Grain hosts its application in the US and lists several US-based subprocessors that can handle meeting content.
If meeting transcripts are also being sent to other AI systems, our guide to GPT security risks in meeting summaries covers the extra questions worth asking.
8. Fathom: Best User Rating, With Some Privacy Trade-Offs
Privacy Score: 7.8/10 | G2: 5.0/5
Fathom has the strongest independent user rating here: 5.0/5 from more than 7,000 G2 reviews.
It is SOC 2 Type II and GDPR compliant, provides a DPA, and offers several recording-notification options. Its advance consent feature can disable auto-recording when an attendee declines. However, the host can later manually start recording if consent is obtained separately.
Fathom stores all data in the US. External AI providers cannot train on customer data, but Fathom may use de-identified customer data to improve its own models. Users and organizations can opt out.
Pros: Exceptional G2 rating, SOC 2 Type II, clear recording notices, advance consent functionality, and documented deletion controls.
Limitations: Fathom stores data in the US and may use de-identified customer data to improve its own models unless the user or organization opts out.
9. Otter.ai: Established Product, but a Different Training Policy
Privacy Score: 6.8/10 | G2: 4.4/5
Otter is one of the most established AI transcription tools. It has SOC 2 Type II, publishes security and subprocessor information, encrypts data at rest, and requires users to indicate when recording takes place.
Its infrastructure is US-based. AWS is listed as its customer-data storage platform in the United States.
The biggest difference is model training. Otter states that it uses a proprietary process to de-identify recordings and transcripts before using that data to train its own models. Its external AI providers are not permitted to train on customer data.
That differs from tools that exclude customer meeting content from model training altogether, which explains its lower Privacy Score.
Pros: Mature product, SOC 2 Type II, published subprocessors, encryption, and established sharing and deletion controls.
Limitations: Otter uses de-identified recordings and transcripts to train its own models.
For more context on the current recording and consent questions around AI notetakers, we track them in our AI meeting recorder lawsuits guide.
What to Check Before Choosing GDPR Compliance Software for Meetings
Before you shortlist a tool, ask these eight questions:
- Where are recordings, transcripts, backups, and AI outputs stored?
- Where does AI processing happen? Storage and processing can happen in different countries.
- Does meeting content train the vendor’s own models or any third-party models?
- What happens when somebody declines recording? Check whether recording actually stops.
- Can admins set retention periods and permanently delete meeting data?
- Can you read the DPA and current subprocessor list before signing?
- Who can access a recording by default?
- Can privacy and recording settings be enforced across the whole organization?
A DPA is worth reading. Article 28 contracts cover processing instructions, confidentiality, security, subprocessors, data-subject rights, deletion or return, and audits. The ICO provides a practical summary.
For teams doing a wider security review, our meeting-recording guide for IT leaders goes further into permissions, governance, storage, and rollout.
Does Using GDPR-Compliant Software Make Your Meetings GDPR Compliant?
いいえ。
The software vendor controls how its service processes data. Your organization still decides why a meeting is being recorded, what should be captured, who can access it, how long it should be kept, and what lawful basis applies.
So “Is this tool GDPR compliant?” should not be your only procurement question.
“Can we configure this tool so the way our team actually records and handles meetings meets our privacy requirements?”
A product can offer European hosting, encryption, and a DPA while your own settings still retain meetings longer than necessary or give too many people access.
If recording consent itself is the concern, we have separate guides to recording someone without their permission and call recording laws in 2026.
Which GDPR-Compliant AI Meeting Tool Should You Choose?
There is no single right choice for every team, but tl;dv ranked first in this comparison based on the privacy criteria used throughout the article.
If your priorities are European data handling, clear consent controls, no customer meeting data used for AI training, and strong security documentation, it is a strong place to start. If you want to test how it fits your own workflow, you can try tl;dv for free.
Before choosing any tool, check the DPA, subprocessors, retention settings, and recording controls against your own requirements.
FAQs About GDPR Compliance Software
What is the best GDPR-compliant AI meeting tool?
Based on the methodology used here, I ranked tl;dv first with a Privacy Score of 9.7/10. That score reflects European data hosting, an EU AI-processing option, no customer-data model training, SOC 2 Type II, public privacy documentation, and a consent flow that can block recording when somebody declines.
MeetGeek and Jamie are also strong choices when European data residency is a priority.
Is an AI meeting recording personal data under GDPR?
It can be. Recordings and transcripts regularly contain names, voices, job information, opinions, and other information linked to identifiable people. When that information falls within GDPR’s scope, GDPR requirements apply to its processing. European Commission GDPR principles
Does GDPR require consent before every meeting is recorded?
Not necessarily. Consent is one lawful basis under GDPR, but it is not the only one. The appropriate lawful basis depends on the circumstances and purpose of the processing.
Separate call-recording laws may also apply, so GDPR should not be treated as the only rule to check.
Should an AI meeting assistant use my recordings to train its models?
There is no single rule for every organization, but the vendor should make its policy clear before you give it access to business conversations.
tl;dv, MeetGeek, Jamie, Avoma, Fireflies, and Grain state that customer meeting content is not used to train their models by default. Sembly uses opt-out controls outside Enterprise. Fathom can use de-identified customer data unless you opt out. Otter uses de-identified recordings and transcripts to train its own models.
For a shorter privacy-specific comparison, we also have a guide to GDPR-compliant meeting assistants.



