Best for GDPR & EU Teams

Best GDPR-Compliant AI Meeting Assistants for European Teams

Data residency is where most buyers start and it is rarely where the risk actually is. Subprocessors, training defaults, and the EU AI Act's workplace prohibitions matter at least as much. Here is who holds up under all four.

Reviewed by Marcus Webb | Last updated August 2026

The best GDPR-compliant AI meeting assistant in 2026 is Hedy, because it can run transcription and analysis on-device on supported hardware — data that never leaves the device raises no transfer question at all — backed by EU data residency, AES-256 encryption, and a contractual no-training policy. Jamie is the strongest EU-hosted cloud option, with processing in Germany, ISO 27001 certification, and meeting audio deleted after transcription. MacWhisper is fully local but transcription-only.

GDPR compliance for a meeting tool is not one question, it is four. Where is the data processed — and if outside the EEA, under what transfer mechanism? Who are the subprocessors, because a vendor hosting in Frankfurt while routing inference through a US model provider has not solved your transfer problem. Is your data used for training, which is a purpose-limitation question and, after the August 2026 Otter.ai ruling, increasingly a litigation question too. And what does the tool infer about people, because the EU AI Act now prohibits some inferences outright regardless of consent. Most vendor comparison tables cover only the first. The picks below are ordered by how well they answer all four.

EU Data Handling: How the Tools Compare

ToolWhere processing happensTrains on your data?Emotion inference risk
Hedy On-device on supported hardware; EU residency option for cloud features No (contractual) None — no sentiment or engagement scoring
Jamie Germany; states data stays in EEA/CH/UK, limited subprocessor exceptions No; audio deleted after transcription None — post-meeting notes only
MacWhisper Entirely on your Mac; no server involved No — no data is transmitted None
Circleback Cloud; EU-U.S. Data Privacy Framework participant, SOC 2 Type II No (stated) None advertised
Krisp Audio layer on-device; notes and transcription in cloud States no training; privacy policy also lists model improvement — ask None advertised
Read.ai US cloud Confirm per tier Ships sentiment and engagement scoring — ask whether it infers from audio or text
Granola US cloud Yes by default (anonymized); opt out in Settings None advertised
Otter.ai US cloud Yes by default unless you opt out None advertised
Notta Cloud Trains on some conversations by default None advertised

The Four Questions That Actually Decide GDPR Fit

Residency is necessary and not sufficient. A vendor telling you data is hosted in Frankfurt has answered one question. The one that follows is who else touches it. If transcription or summarisation calls a model API hosted in the United States, personal data has left the EEA regardless of where the database sits, and you need a transfer mechanism for that leg. Ask for the subprocessor list, in writing, and read it. Jamie is unusually clear here, stating that data stays within the EEA, Switzerland, and the UK with limited subprocessor exceptions under standard safeguards. Most vendors are considerably vaguer, and vagueness at this stage of a procurement is itself information.

The training default is a purpose-limitation problem. Under GDPR you must specify why you are processing personal data and not quietly repurpose it. A vendor that transcribes your meeting to give you notes, and also uses that recording to improve its models, is processing for a second purpose that your participants almost certainly never agreed to. Otter.ai, Granola, and Notta all train on customer data by default, and in each case the opt-out is a setting the user has to go and find. Only Granola's Enterprise tier has it off from the start and enforceable by an administrator. In August 2026 a US federal court held that plaintiffs had plausibly alleged Otter was a third-party eavesdropper because it independently collects, retains, and uses recordings for its own commercial purposes — a pleading-stage holding in another jurisdiction, but the same underlying intuition about what repurposing does to a vendor's position.

Consent from one participant does not cover the room. This is the most common mistake we see in European deployments. The person who starts the recording can consent for themselves. They cannot consent on behalf of the client, the candidate, or the counterparty. Worse, for employee recordings consent is generally not a defensible lawful basis at all, because the power imbalance in an employment relationship means staff cannot refuse freely — so organisations relying on an employee consent form are usually relying on nothing. Bot-free tools sharpen this, because nothing announces itself and the disclosure duty falls entirely on your user. That is manageable with a stated practice. It is not manageable by accident.

The EU AI Act adds a prohibition that consent cannot cure. Article 5(1)(f) bans AI systems that infer employees' emotions from biometric data in the workplace. It has applied since February 2025, and the administrative fines behind it under Article 99 have been available since 2 August 2025, up to the higher of €35 million or 7% of worldwide turnover. 2 August 2026 brought general applicability of the Act's remaining obligations, not the penalty regime. The Commission's guidelines put emotion inferred from written text outside the prohibition, so most transcript-based sentiment scoring is likely fine; inference from vocal tone or prosody is much closer to the line. Tools that ship sentiment or engagement analytics — Read.ai, Avoma, Fireflies.ai — are the ones to ask, and the question is specifically whether the inference runs on audio or on text. Tools that simply do not score people, which includes every pick on this page, avoid the question entirely.

Frequently Asked Questions

Which AI meeting assistant is most GDPR-compliant? +
Hedy, because the strongest answer to a data protection question is not processing the data on someone else's infrastructure at all. On supported hardware it runs transcription and analysis on-device, so there is no international transfer to justify and no vendor-side copy to govern, backed by EU data residency for cloud features, AES-256 encryption, and a contractual no-training commitment. For teams that need a cloud tool, Jamie is the strongest EU-hosted option: processing in Germany, ISO 27001 and DORA compliance, and meeting audio deleted after transcription. MacWhisper is fully local but does transcription only, with no calendar integration or team features.
Is EU data residency enough for GDPR compliance? +
No. Residency addresses where data is stored, but a vendor can host in the EU and still send personal data outside the EEA through subprocessors — most commonly a US-hosted model API used for transcription or summarisation. Ask every vendor for its current subprocessor list and check whether any inference step leaves the EEA. Then check the training default, the retention period, and whether the tool infers anything about people that the EU AI Act prohibits. Residency is the first question, not the last one.
Can I rely on employee consent to record internal meetings in the EU? +
Usually not. Under GDPR, consent must be freely given, and regulators take the view that the power imbalance in an employment relationship means employees cannot freely refuse an employer's request. That makes consent a weak lawful basis for recording staff; legitimate interests, properly assessed and documented, is normally the more defensible route. Separately, consent cannot cure an EU AI Act Article 5 prohibition at all — if a tool infers employees' emotions from biometric data in the workplace, no amount of agreement makes that lawful.
Does the EU AI Act ban AI notetakers? +
No. A tool that only transcribes and summarises a meeting is generally not high-risk under the Act, and its main obligation is transparency under Article 50. Be careful before extending that to products used to monitor or evaluate employees — coaching scorecards, performance analytics, engagement scoring — because Annex III 4(b) can bring employment-related monitoring into the high-risk regime. What is prohibited under Article 5(1)(f) is inferring a person's emotions from biometric data in a workplace or education setting. That reaches sentiment and engagement analytics if the inference is drawn from voice characteristics; the Commission's guidelines place inference from written text outside the prohibition. Ordinary transcription and summarisation are unaffected.