
Table of Contents
- GDPR Video Conferencing: Key Answers
- Start With the Processing, Not the Platform
- Controller, Processor and Subprocessor: Map the Roles
- Which GDPR Requirements Matter Most?
- Article 6: Choose the Lawful Basis Before Processing
- Articles 13 and 14: Tell Participants What Happens to Their Data
- Article 28: When You Need a DPA
- Article 32: Security Is Risk-Based
- Recording Video Meetings Under GDPR
- AI Transcription Creates a New Processing Chain
- Deployment Model Changes the Compliance Work
- How to Evaluate Video Conferencing Platforms for GDPR
- Video Conferencing Platform Models Compared
- GDPR Video Conferencing Checklist
A video conferencing platform is not GDPR-compliant simply because the vendor says it is.
GDPR compliance belongs to a specific processing activity.
The same platform can present a relatively simple compliance profile for an unrecorded project meeting and a much more demanding one when it is used for recorded HR interviews, medical consultations, board meetings, AI transcription, or calls involving participants outside the EEA.
The useful question is therefore not:
Is this video conferencing platform GDPR-compliant?
It is:
What personal data will we process, for what purpose, who will process it, where will it go, how long will it remain there, and what controls can we actually enforce?
This guide explains how to answer those questions before selecting or configuring a video conferencing system.
This article provides a practical compliance framework and is not a substitute for legal advice for a specific processing activity.
GDPR Video Conferencing: Key Answers
The European Commission currently continues to recognise participating US commercial organisations under the EU-US Data Privacy Framework as providing adequate protection for covered transfers.
Start With the Processing, Not the Platform
Before comparing products, map what actually happens during a meeting.
A single call can create several separate processing operations.
This matters because the controller, processor chain, lawful basis, retention period and transfer mechanism can differ between these operations.
Controller, Processor and Subprocessor: Map the Roles
For business meetings, the organisation arranging the processing will often be the controller for meeting-related personal data because it determines why and how the meeting is used.
A cloud conferencing vendor may act as processor for data it handles on the organisation’s behalf.
That does not mean every activity performed by the vendor necessarily has the same role allocation. Billing, fraud prevention, product telemetry or other vendor-defined processing may involve a different role depending on the actual circumstances and terms.
There may also be subprocessors for:
-
hosting;
-
cloud recording;
-
transcription;
-
customer support;
-
email delivery;
-
AI services;
-
analytics.
The practical task is therefore to create a role map, not merely sign the vendor’s standard agreement.
Which GDPR Requirements Matter Most?
Article 5: Processing Principles
The core GDPR principles include:
-
lawfulness, fairness and transparency;
-
purpose limitation;
-
data minimisation;
-
accuracy;
-
storage limitation;
-
integrity and confidentiality;
-
accountability.
The controller must also be able to demonstrate compliance with these principles.
For video conferencing, these principles translate into practical questions.
Purpose limitation
Why is the meeting being processed?
The reason for holding a live meeting does not automatically justify:
-
recording it;
-
transcribing it;
-
analysing sentiment;
-
generating AI summaries;
-
retaining attendance data indefinitely.
Treat additional processing as additional processing.
Data minimisation
Disable information collection that is not necessary for the business purpose.
Possible examples include:
-
unnecessary participant profiling;
-
optional analytics;
-
persistent recordings;
-
unused transcription;
-
excessive meeting telemetry.
Storage limitation
Define retention for each data category.
A meeting recording, chat history and diagnostic log do not necessarily need the same retention period.
Article 6: Choose the Lawful Basis Before Processing
GDPR provides six lawful bases, including consent, contract, legal obligation, vital interests, public task and legitimate interests. The appropriate basis depends on the purpose and context of the processing.
Do not assume that one lawful basis automatically covers every function of a video platform.
For example, the lawful basis for:
-
holding an employee meeting;
-
recording it;
-
generating an AI transcript;
-
analysing attendance;
may need to be assessed separately.
Consent deserves particular care in employment settings because an imbalance between employer and employee can affect whether consent is genuinely freely given.
Articles 13 and 14: Tell Participants What Happens to Their Data
Transparency must occur before or at the appropriate point in the processing.
Participants may need information about:
-
controller identity;
-
purpose of processing;
-
lawful basis;
-
recipients;
-
retention;
-
international transfers;
-
data-subject rights;
-
contact details;
-
recording;
-
AI transcription.
Article 13 generally concerns personal data collected from the data subject, while Article 14 covers relevant cases where personal data has been obtained elsewhere.
A calendar invitation can be a practical place to provide a concise notice and link to the full privacy information.
A sentence saying only “this meeting may be recorded” is unlikely to explain the entire processing operation.

Article 28: When You Need a DPA
When a video conferencing provider processes personal data on your behalf as a processor, the relationship must satisfy Article 28 requirements.
The agreement should cover matters such as:
-
processing subject matter;
-
duration;
-
nature;
-
purpose;
-
data categories;
-
data subjects;
-
controller instructions;
-
confidentiality;
-
security;
-
subprocessors;
-
deletion or return of data;
-
audit rights.
But:
A DPA is not a GDPR compliance certificate.
It solves one part of the governance model.
You still need lawful processing, transparency, appropriate security, retention rules and, where applicable, a lawful international transfer mechanism.
DPA vs International Transfer Mechanism
These are frequently confused.
DPA
Addresses the controller-processor relationship under Article 28.
Transfer mechanism
Addresses qualifying international transfers under Chapter V.
Depending on the destination and recipient, mechanisms may include:
-
adequacy decisions;
-
EU-US Data Privacy Framework for participating US organisations;
-
Standard Contractual Clauses;
-
Binding Corporate Rules;
-
applicable derogations in limited circumstances.
The EDPB describes Standard Contractual Clauses as pre-approved clauses that can be used to provide safeguards for transfers outside the EU.
A vendor can therefore have an excellent DPA while your transfer analysis remains incomplete.
International Transfers: What to Verify
Do not reduce this question to:
Is the server in Europe?
Instead map:
-
Where is meeting traffic processed?
-
Where are recordings stored?
-
Where is metadata stored?
-
Which entity provides support?
-
Which subprocessors can access the data?
-
Does AI processing occur elsewhere?
-
Can remote administrative access occur from outside the EEA?
-
What transfer mechanism applies to each relevant recipient?
The European Commission currently recognises US organisations participating in the EU-US Data Privacy Framework for covered transfers.
This does not remove the need to verify that the relevant vendor entity actually participates in the framework and that the transfer falls within the applicable scope.
Article 32: Security Is Risk-Based
GDPR does not prescribe one universal video-conferencing security configuration.
Article 32 requires appropriate technical and organisational measures relative to the risk.
Depending on the meeting, relevant controls can include:
-
encryption in transit;
-
encryption at rest;
-
end-to-end encryption where appropriate;
-
strong authentication;
-
SSO;
-
MFA;
-
waiting rooms;
-
guest controls;
-
meeting passwords;
-
restricted recording permissions;
-
administrative policies;
-
access logs;
-
backup protection;
-
patch management;
-
account lifecycle management.
The important phrase is appropriate to risk.
A general sales meeting and a multidisciplinary medical meeting need not have identical controls.
Recording Video Meetings Under GDPR
Recording changes the compliance profile because transient communication becomes persistent personal data.
A recording can contain:
-
faces;
-
voices;
-
names;
-
screens;
-
documents;
-
chat;
-
confidential business information;
-
special-category personal data.

Before Recording
Determine:
-
the purpose;
-
lawful basis;
-
who will have access;
-
retention period;
-
whether participants have been informed;
-
whether recording is genuinely necessary.
Do not enable automatic recording across the organisation simply because the platform supports it.
While the Recording Exists
Restrict access according to purpose.
Consider:
-
role-based access;
-
link sharing;
-
download permissions;
-
audit logs;
-
storage encryption.
At the End of Retention
Delete recordings once the documented purpose and retention requirement have expired, unless another valid legal or regulatory retention requirement applies.
Data-Subject Requests
Make sure a real process exists for:
-
finding recordings;
-
providing access where applicable;
-
deleting data where the conditions for erasure are met;
-
handling objections;
-
documenting the response.
A policy without a technical retrieval and deletion process is not enough.
AI Transcription Creates a New Processing Chain
AI meeting assistants are one of the most important procurement questions in 2026.
Do not treat transcription or meeting summaries as ordinary interface features.
They can introduce:
-
an additional processor;
-
a new subprocessor;
-
another processing location;
-
new retained personal data;
-
new purposes;
-
model-training questions.
Before enabling AI, ask:
For highly sensitive meetings, local or customer-controlled AI processing may materially simplify the data-flow architecture.
Personal Data Breaches: The 72-Hour Rule
The common shorthand “every breach must be reported within 72 hours” is incorrect.
Under Article 33, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a breach unless the breach is unlikely to result in a risk to individuals’ rights and freedoms.
Communication to affected individuals follows a higher threshold: the breach must be likely to result in a high risk to their rights and freedoms.
All breaches should still be documented internally.
For a video platform, an incident-response plan should cover:
-
exposed recordings;
-
stolen meeting credentials;
-
unauthorised meeting access;
-
leaked transcripts;
-
compromised administrator accounts;
-
exposed attendance reports.
Deployment Model Changes the Compliance Work
No deployment model creates GDPR compliance automatically.
It changes which risks and obligations you have to manage.
Important
Self-hosting can reduce external processor and international-transfer exposure, but only if the architecture actually avoids those external processing paths.
Check:
-
licensing;
-
support access;
-
cloud push services;
-
telemetry;
-
remote monitoring;
-
external backups;
-
AI;
-
identity providers.
How to Evaluate Video Conferencing Platforms for GDPR
Do not ask the vendor only:
Are you GDPR-compliant?
Ask for evidence.
Contractual Evidence
-
DPA;
-
subprocessor list;
-
transfer mechanisms;
-
support-access terms;
-
retention terms.
Technical Evidence
-
data-flow diagram;
-
hosting locations;
-
recording architecture;
-
encryption documentation;
-
authentication options;
-
audit logging;
-
backup architecture;
-
deletion behavior.
Operational Evidence
-
security certifications;
-
penetration-test information where available;
-
breach-notification process;
-
vulnerability management;
-
support escalation;
-
change-notification process for subprocessors.
Product Controls
-
recording policy;
-
guest access;
-
meeting authentication;
-
retention;
-
user provisioning;
-
admin controls;
-
AI enable/disable;
-
export and deletion tools.
The best procurement comparison is therefore not:
Which platform claims GDPR compliance?
It is:
Which platform gives us enough control and evidence to operate our chosen meeting scenarios compliantly?
Video Conferencing Platform Models Compared
Zoom currently provides EEA customers on eligible paid accounts with data-residency controls for certain stored data and meeting/webinar traffic.
Microsoft describes the EU Data Boundary as covering Customer Data and personal data for Microsoft 365 and other in-scope services, while also documenting limited circumstances in which data continues to be transferred outside the boundary.
Nextcloud Talk is designed as a self-hosted, on-premises audio/video and chat platform.
Secumeet

Secumeet should be evaluated as a server-connected communications environment, not simply labelled “GDPR compliant” and left at that.
Current public product information confirms that the Secumeet client depends on Secumeet Server for full functionality and combines personal and group messaging, meetings, shared files and other communication functions.
That can be useful when the buyer wants the communications architecture itself to be part of the procurement decision.
The GDPR advantage of this model depends on the actual deployment.
A customer-controlled server can potentially reduce reliance on a public multi-tenant conferencing cloud, but procurement teams should confirm:
-
who hosts Secumeet Server;
-
whether Secumeet personnel can access the environment;
-
whether telemetry leaves the server;
-
how licensing works;
-
whether mobile push services are external;
-
where recordings are stored;
-
whether support involves remote access;
-
what subprocessors exist;
-
whether AI features use another processing service.
Best fit: Organisations that want to evaluate a server-based communication environment and are prepared to validate the complete data flow rather than rely on a generic compliance claim.
Main trade-off: Publicly available technical compliance documentation is less extensive than for several large enterprise providers, so procurement should require more direct architectural verification.
TrueConf Server

TrueConf Server provides a clearer documented example of the customer-operated deployment model.
TrueConf’s current documentation states that the server can operate on-premises without an internet connection and supports up to 2,000 participants, SIP/H.323 interoperability and corporate communication functions.
From a GDPR perspective, the useful characteristic is not a generic claim of “compliance.”
It is control over the data path.
A fully internal deployment can reduce the number of third parties involved in meeting-content processing and can eliminate many ordinary cross-border meeting-data paths.
That still leaves the controller responsible for:
-
lawful basis;
-
participant transparency;
-
recording policies;
-
user access;
-
retention;
-
backups;
-
patching;
-
breach response;
-
administrator privileges.
Best fit: Organisations that specifically want conferencing, recordings and user communication to remain on customer-operated infrastructure.
Main trade-off: Infrastructure control also means infrastructure responsibility.
Digital Samba

Digital Samba represents the European managed-cloud approach.
It currently positions its video conferencing service around European hosting and GDPR-oriented processing rather than customer-operated infrastructure.
This model can reduce the operational burden compared with self-hosting.
The buyer should still review:
-
DPA;
-
hosting architecture;
-
subprocessors;
-
support locations;
-
recording storage;
-
retention;
-
AI features.
Being incorporated in Europe or hosting in Europe is useful evidence, but it does not replace a complete processing assessment.
Zoom

Zoom can be used in GDPR-governed environments, but configuration and contract terms matter.
Zoom currently offers eligible EEA customers controls for EEA data residency and publishes GDPR, subprocessor and transfer documentation.
A procurement review should identify exactly what regional controls cover:
-
real-time meeting traffic;
-
cloud recordings;
-
support data;
-
AI processing;
-
account data;
-
subprocessors.
Do not reduce the assessment to the physical location of one data centre.
Microsoft Teams

Microsoft’s EU Data Boundary is relevant to GDPR procurement because Microsoft commits to storing and processing covered Customer Data and personal data within the boundary for in-scope enterprise online services.
Microsoft also documents limited circumstances where transfers outside the boundary continue.
For Teams, review:
-
which workload processes the data;
-
recording and transcription;
-
Copilot;
-
support;
-
telemetry;
-
external guest identities;
-
retention;
-
data residency.
The word “Teams” can cover several different processing operations.
Jitsi Meet

Jitsi is particularly relevant when the organisation wants to operate the conferencing stack itself.
Jitsi explicitly supports private self-hosting. Its security documentation also distinguishes self-hosted deployments from the public meet.jit.si service, which has its own account and analytics processing.
This distinction is critical.
Jitsi software is not the same processing environment as meet.jit.si.
A self-hosted deployment lets the organisation control much more of the infrastructure, but external services can still reappear through:
-
hosting;
-
authentication;
-
recording;
-
analytics;
-
telephony;
-
monitoring.
Nextcloud Talk

Nextcloud Talk is another self-hosted model.
Nextcloud describes Talk as a fully self-hosted on-premises audio/video and chat communication service and supports private-cloud or customer-operated deployment.
Its GDPR profile therefore depends heavily on who operates:
-
the Nextcloud server;
-
Talk backend;
-
hosting;
-
recording;
-
integrations;
-
AI services.
It can be attractive when an organisation already operates Nextcloud and wants meetings to use the same controlled infrastructure.
GDPR Video Conferencing Checklist
Processing
-
Each meeting use case is documented.
-
Personal-data categories are identified.
-
Lawful basis is documented.
-
Article 9 condition is identified where special-category data is processed.
-
Recording is assessed separately.
-
AI/transcription is assessed separately.
Roles and Contracts
-
Controller and processor roles are mapped.
-
DPA is signed where required.
-
Subprocessor list is reviewed.
-
Managed support access is included in the processing map.
Transfers
-
Data locations are documented.
-
Remote access locations are known.
-
Appropriate transfer mechanism is documented.
-
DPF participation is checked where relied upon.
-
SCCs or other mechanisms are reviewed where applicable.
Security
-
Authentication controls are configured.
-
Meeting access is restricted appropriately.
-
Recording permissions are centrally managed.
-
Encryption architecture is understood.
-
Administrator access is limited.
-
Patching and vulnerability management are defined.
Retention and Rights
-
Recording retention is defined.
-
Chat retention is defined.
-
Transcript retention is defined.
-
Deletion workflow is tested.
-
Access-request workflow is tested.
-
Departed-user data is handled consistently.
Transparency
-
Privacy notice covers video conferencing.
-
Recording is disclosed before it begins.
-
AI transcription is disclosed where used.
-
External participants receive appropriate information.
Incident Response
-
Video-meeting incidents are included in the breach plan.
-
72-hour assessment workflow is documented.
-
Risk threshold for authority notification is understood.
-
High-risk threshold for individual notification is understood.
Special-Category Data Changes the Risk
A video call can contain health data, political opinions, trade-union information, religious beliefs or other special-category data.
Article 9 creates additional restrictions for this processing.
That means a platform that is acceptable for routine sales calls may require a different architecture or configuration for:
-
healthcare;
-
HR investigations;
-
occupational health;
-
legal consultations;
-
union discussions.
Do not create a single company-wide “GDPR approved video platform” policy without considering use-case risk.
Employee Monitoring and Works Councils
Video platforms can also create employee-monitoring implications through:
-
attendance tracking;
-
activity reports;
-
participation metrics;
-
recording;
-
transcription;
-
AI summaries.
GDPR is only one part of that analysis.
Depending on the country and organisation, national employment and co-determination rules may also apply.
This should be checked locally rather than treated as a universal EU-wide rule.
Frequently Asked Questions
What makes video conferencing GDPR-compliant?
There is no single product feature that creates compliance.
The organisation needs an appropriate lawful basis, transparency, appropriate security, controlled retention, valid processor arrangements and lawful international transfers where applicable.
Is a DPA enough?
No.
A DPA addresses the Article 28 processor relationship. It does not establish lawful basis, solve retention, determine security configuration or automatically provide a Chapter V transfer mechanism.
Is EU data residency enough?
No.
It is useful, but you still need to understand subprocessors, support access, AI, metadata and other data flows.
Is self-hosted video conferencing automatically GDPR-compliant?
No.
Self-hosting gives the organisation more control over infrastructure, but the organisation still has to comply with GDPR and secure the environment.
External processors may also remain if hosting, support, AI or other services are outsourced.
Are video recordings covered by GDPR?
Usually yes when they contain identifiable personal data such as a participant’s image, voice, name or shared information.
The purpose, lawful basis, access and retention should be documented.
Do I need consent to record a meeting?
Not necessarily.
Consent is one possible lawful basis, but the correct basis depends on the specific processing context.
If consent is relied upon, it must satisfy GDPR requirements for valid consent.
Can US video conferencing providers be used legally?
Yes.
The appropriate transfer mechanism depends on the recipient and processing arrangement. The European Commission currently recognises participating US commercial organisations under the EU-US Data Privacy Framework.
Other mechanisms such as SCCs may also apply in appropriate cases.
Do all data breaches have to be reported within 72 hours?
No.
Article 33 requires supervisory-authority notification when a breach is not unlikely to result in risk to individuals’ rights and freedoms. Communication to individuals applies when a breach is likely to result in high risk.
Does end-to-end encryption make a platform GDPR-compliant?
No.
E2EE may be an appropriate security measure for certain risks, but GDPR compliance also includes lawful basis, transparency, data minimisation, retention, rights, processors and transfers.
Final Decision Framework
Do not begin procurement by asking vendors whether they are GDPR-compliant.
Begin with five questions:
-
What personal data will this meeting scenario process?
-
Why are we processing it and what lawful basis applies?
-
Who will process the data besides us?
-
Where will every major data category be processed and stored?
-
Can we technically enforce the retention, access and security rules we have documented?
Only then compare video platforms.
A public-cloud product may be appropriate when the organisation has the right contracts, transfer mechanism, configuration and risk profile.
A European cloud provider may reduce certain jurisdictional and transfer complexities.
A self-hosted system such as TrueConf Server or a private communication environment built around Secumeet may reduce dependence on external meeting infrastructure when correctly deployed.
The central GDPR question is therefore not whether a vendor can display a compliance badge.
It is whether the actual processing architecture can be explained, justified, controlled and demonstrated.
Author
Helga Afon is a technology writer specializing in video conferencing, collaboration software, and workplace communication. She writes articles and reviews that help readers better understand enterprise communication tools and industry trends.