AI Meeting Notetakers Need A Data Processing Agreement Before UK Teams Use Them

AI Trust & Governance

12 August 2026 | By Ashley Marshall

Quick Answer: AI Meeting Notetakers Need A Data Processing Agreement Before UK Teams Use Them

If an AI meeting tool records, transcribes or summarises a call involving personal data, UK GDPR treats that as processing personal data. You need an existing or newly identified lawful basis under Article 6, a written Data Processing Agreement with the vendor under Article 28, and an entry in your Records of Processing Activities. If the conversation touches health, immigration status or other special category information, you also need an Article 9 condition.

Most UK teams turned on an AI notetaker for a Tuesday call and never asked who owns the transcript afterwards.

Why this quietly became a 2026 problem

A year ago, most sales and account management teams at UK firms had one person, at most, running an AI notetaker on client calls. A tracking report published in May 2026, covering 21 tools across a broad UK and US survey base, found adoption of AI notetakers jumped from roughly one tool per team in 2025 to fourteen tools per team in 2026, with generative AI usage inside meetings up eleven percentage points year on year. Fireflies now claims 75% Fortune 500 adoption on its own marketing pages. Whether or not that figure is exact, the direction is not in doubt: bots that record, transcribe and summarise are now the default in most client-facing meetings, not the exception.

That speed is the problem. Procurement teams that would never sign a new CRM without a security review have let Otter, Fireflies, Fathom or Granola into board calls, client onboarding sessions and HR one-to-ones on the strength of a free trial and a Slack recommendation. Someone clicked "allow" in a calendar integration and a third-party bot has been quietly joining every meeting on that calendar since.

The Information Commissioner's Office has been explicit that this does not sit in a regulatory grey area just because the tool is described as AI. The ICO's own guidance states plainly that AI does not get special treatment under data protection law - the same Article 6 lawful basis and Article 28 processor obligations that applied to a human PA taking minutes apply to a bot doing the same job. What has changed is scale, retention and where the recording actually goes once the call ends.

For UK firms, that means the compliance question is no longer "is this allowed" but "can we currently evidence that it is allowed." For most organisations using AI notetakers today, the honest answer is no.

What counts as processing, and why your existing lawful basis might already cover it

Every AI notetaker performs the same core sequence: it joins or records the call, generates a transcript, produces a summary or action list, and typically stores all three somewhere outside your own systems. Each of those steps is processing personal data under UK GDPR the moment a named individual, their voice, or identifiable information about them is captured. That includes internal meetings between colleagues, not just external client calls.

The reassuring part, confirmed by legal commentary reviewing ICO positioning through early 2026, is that using an AI tool to do a task you were already doing lawfully does not automatically require a brand new lawful basis. If your organisation already had a legitimate interests basis, contractual necessity, or consent framework for keeping meeting notes and sharing them with attendees, that basis generally still applies when an AI tool performs the note-taking instead of a human. The purpose has not changed - only the method has.

Where firms come unstuck is assuming this means no further action is needed. It does not. Article 5 accountability obligations mean you must be able to demonstrate the basis applies to the new method, not just assert that it probably does. That means documenting, in writing, why the existing basis extends to automated transcription, recording and third-party storage - and doing a proportionate assessment of whether the new method changes the risk to individuals enough to require a Data Protection Impact Assessment.

In practice, three things usually change the risk profile enough to warrant a fresh look: the transcript now leaves your infrastructure and sits on a US vendor's servers, it is retained for longer than a human note-taker's memory, and it becomes searchable and shareable in ways a paper notepad never was. Those are exactly the features vendors sell as benefits. They are also exactly what regulators expect you to have assessed.

When special category data pushes you into Article 9 territory

Most meetings are mundane. Some are not, and AI notetakers do not know the difference. A recruitment call that touches a candidate's disability or a return from parental leave, a client meeting where someone mentions a health condition affecting delivery timelines, an HR one-to-one about a grievance involving a protected characteristic - all of these generate special category data the moment they are transcribed and stored.

Special category data under UK GDPR (health, racial or ethnic origin, religious belief, sexual orientation, trade union membership and similar) requires both a lawful basis under Article 6 and a separate condition under Article 9. The ICO's guidance on special category data is unambiguous that these are two distinct hurdles, and clearing one does not clear the other. A legitimate interests basis that comfortably covers ordinary meeting minutes does not automatically extend to a transcript that captures someone's health disclosure in passing.

This is where blanket AI notetaker rollouts create real exposure. A human minute-taker exercises judgement about what to record and what to leave out of a formal note. An AI transcription bot does not - it captures everything verbatim, including the aside about a diagnosis or a disclosure that was never meant to be a permanent, searchable record. That transcript then sits in a vendor's system, potentially used to train models, indexed for search, and accessible to anyone in your organisation with a login.

The practical fix is not to abandon AI notetakers for sensitive meetings - it is to build a pause-and-mute habit into how teams use them, and to ensure whoever owns the tool has actually mapped which meeting types are likely to surface special category data. HR, legal, and any client-facing team handling regulated advice should be treated as higher risk by default, with the notetaker either switched off or configured to exclude sensitive segments.

The Data Processing Agreement most firms still do not have

This is the single most commonly missed step, and the one with the most direct regulatory consequence. Where your organisation uses a third-party AI notetaker, you are the data controller and the vendor is a data processor. Article 28 of UK GDPR requires a written contract - the Data Processing Agreement - governing that relationship before processing begins, not retrospectively once a regulator asks for it.

Legal commentary published in early 2026 covering AI meeting transcription tools makes the liability point starkly: deploying an AI transcription tool without a formalised DPA exposes the organisation to direct regulatory liability before the ICO, regardless of whether the vendor was actually at fault for any incident. In other words, a data breach at Otter, Fireflies or Fathom's end does not shield your business if you never had the Article 28 paperwork in place - you carry the exposure as controller either way.

A compliant DPA needs to specify, at minimum: the subject matter, duration, nature and purpose of the processing; the categories of personal data and data subjects involved; the vendor's obligations around confidentiality, security and sub-processors; deletion or return of data at contract end; and cooperation obligations if a data subject exercises their rights. Most consumer-facing AI notetaker sign-up flows do not surface this document at all - it typically has to be requested from the vendor's enterprise or legal team, and smaller teams signing up on a personal card frequently never get it.

If your finance team is expensing an AI notetaker subscription that was never run through procurement, there is a good chance no DPA exists for that tool at all. That is worth checking this week, not at renewal.

Records of Processing Activities: the paperwork the ICO will actually ask for

Alongside the DPA, UK GDPR Article 30 requires most organisations to maintain a Record of Processing Activities - a live internal register describing what personal data you process, why, and how. Legal analysis of AI meeting transcription specifically calls out that the data controller must include the activity "automated meeting transcription" in its RoPA, as a distinct entry from general meeting notes or general customer relationship management processing.

This matters practically for two reasons. First, if the ICO ever investigates a complaint - and complaints about recorded calls are exactly the kind of thing employees and clients do raise - the RoPA is one of the first documents requested, and a missing entry for a tool your whole sales team uses daily looks worse than an imperfect entry. Second, maintaining the RoPA forces the internal conversation that most firms have skipped: which teams use which AI notetaker, on what call types, with what retention period, and who is accountable for the vendor relationship.

In practice, this is a short but specific exercise: list each AI notetaker in active use, the business function using it, the categories of data subjects whose voices or information get captured, the lawful basis relied on, retention period, and whether a DPA is on file. Where retention periods are vendor defaults rather than deliberately configured, review them - transcripts kept indefinitely on a vendor's servers are a larger liability than the same transcript deleted after 90 days.

Firms that have already built an AI governance register for other tools - model access, browser agents, MCP connectors - should simply extend that same register to cover meeting AI rather than treating it as a separate exercise. The accountability discipline is identical.

What this means in practice for procurement decisions

Comparisons between Otter, Fireflies, Fathom and Granola tend to focus on transcription accuracy, integration depth and price - and those comparisons are genuinely useful once the compliance groundwork is done. Fathom has built a reputation as the strongest free tier for individuals and small teams; Fireflies leans into built-in analytics dashboards tracking speaker time and sentiment; Otter offers broader integration coverage; Granola has carved out a bot-free niche that avoids a visible recording participant joining the call, which some clients find less intrusive but does not change the underlying data protection obligations.

None of those product differences answer the questions that actually determine legal exposure: does the vendor offer an enterprise DPA at all, where are the servers that store transcripts, what is the default retention period, is transcript data used to train the vendor's own models unless you opt out, and can data subjects' erasure requests actually be honoured across the vendor's systems within the required timescale. These should be procurement questions asked before contract sign-off, not discovered afterwards.

For UK firms already thinking about this in terms of a wider AI governance register - tracking which AI tools are in use, what data they touch, and who owns the vendor relationship - meeting notetakers should sit on that register with the same rigour as any other tool that handles customer or employee personal data. The uncomfortable truth is that many organisations have far more mature governance around their CRM or their finance system than around the AI bot that has been sitting in every client call for the past six months.

The fix is not complicated. It is unglamorous procurement and documentation work: get the DPA, add the RoPA entry, set a sensible retention period, and build a habit of pausing the bot for anything that strays into special category territory. None of that requires new technology. It requires treating the notetaker with the same seriousness as any other system that now holds a permanent, searchable record of what people said.

Frequently Asked Questions

Do we need to tell meeting attendees an AI notetaker is recording?

Yes. Transparency is a core UK GDPR principle regardless of which lawful basis you rely on. Most video platforms now show a visible bot or on-screen notice when a notetaker joins, but you should also state this explicitly in meeting invites or an internal policy, particularly for external client calls where attendees may not expect it.

Does using an AI notetaker mean we need a new lawful basis?

Not necessarily. If your organisation already had a valid lawful basis for producing and sharing meeting notes, that basis generally still applies when an AI tool performs the task instead of a human, because the underlying purpose has not changed. You do still need to document why the basis extends to the new method and assess whether the added risk (external storage, longer retention, searchability) warrants a Data Protection Impact Assessment.

What exactly needs to be in the Data Processing Agreement?

Under Article 28, it must cover the subject matter, duration, nature and purpose of processing, the categories of data and data subjects involved, the processor's confidentiality and security obligations, rules on sub-processors, what happens to data at contract end, and cooperation duties if someone exercises their data subject rights. Enterprise-tier vendor contracts usually include this; free or personal-tier sign-ups frequently do not.

Is a meeting transcript special category data?

Not by default, but it can become special category data the moment someone discloses health information, religious belief, trade union membership, or another protected characteristic during the call, and the tool transcribes it verbatim. Unlike a human note-taker who exercises judgement, an AI notetaker captures everything, so the risk of accidentally creating special category records is higher than with traditional minutes.

Who is liable if the AI notetaker vendor has a data breach?

As the data controller, your organisation carries direct liability to the ICO even if the vendor was at fault, unless you can demonstrate you had appropriate contractual and technical safeguards in place, including a valid DPA. This is precisely why the DPA is not optional paperwork - it is part of your defensible position if something goes wrong.

Can employees just sign up for AI notetakers on their own initiative?

This is exactly how most firms end up with shadow AI notetaker use and no DPA on file. Any tool that will record, transcribe or store personal data from meetings should go through procurement and legal review before rollout, even if the individual signing up has good intentions and a free trial in hand.

Does switching to a bot-free tool like Granola remove the compliance obligations?

No. Whether the tool joins as a visible bot or runs locally without an obvious meeting participant does not change the fact that personal data is being recorded, transcribed and typically stored on the vendor's infrastructure. The DPA, RoPA and lawful basis requirements apply regardless of how the tool captures the audio.