GDPR-Compliant Video Conferencing: What to Verify

GDPR-Compliant Video Conferencing

Table of Contents

A video conferencing platform is not GDPR-compliant simply because the vendor says it is.

GDPR compliance belongs to a specific processing activity.

The same platform can present a relatively simple compliance profile for an unrecorded project meeting and a much more demanding one when it is used for recorded HR interviews, medical consultations, board meetings, AI transcription, or calls involving participants outside the EEA.

The useful question is therefore not:

Is this video conferencing platform GDPR-compliant?

It is:

What personal data will we process, for what purpose, who will process it, where will it go, how long will it remain there, and what controls can we actually enforce?

This guide explains how to answer those questions before selecting or configuring a video conferencing system.

This article provides a practical compliance framework and is not a substitute for legal advice for a specific processing activity.

GDPR Video Conferencing: Key Answers

Question

Practical answer

Does GDPR apply to video meetings?

Yes when the processing falls within GDPR’s material and territorial scope and personal data is involved

Does a vendor saying “GDPR compliant” prove compliance?

No

Is a DPA enough?

No. It addresses the controller-processor relationship but not lawful basis, transparency, retention, security or international transfers

Does EU hosting automatically solve GDPR?

No. You still need to assess controllers, processors, subprocessors, transfers and actual data flows

Is on-premises automatically compliant?

No. It can reduce third-party processing and transfer exposure, but the customer remains responsible for security and lawful processing

Are recordings personal data?

Usually yes when identifiable people, voices, images or other personal information are captured

Do all breaches have to be reported within 72 hours?

No. Supervisory-authority notification is generally required when the breach is not unlikely to result in risk to individuals; notification to affected people has a higher, high-risk threshold

Can US services be used under GDPR?

Yes, where an appropriate Chapter V transfer mechanism applies, including the EU-US Data Privacy Framework for participating organisations

The European Commission currently continues to recognise participating US commercial organisations under the EU-US Data Privacy Framework as providing adequate protection for covered transfers.

Start With the Processing, Not the Platform

Before comparing products, map what actually happens during a meeting.

A single call can create several separate processing operations.

Processing activity

Typical personal data

Additional question

Account creation

Name, email, organisation, identifier

Who controls the account data?

Live meeting

Voice, video, IP address, device information

Does the vendor process the media?

Meeting metadata

Join time, duration, participants, network data

How long is metadata retained?

Chat

Messages, files, identifiers

Is chat retained after the meeting?

Recording

Voice, image, presentations, shared screens

Where is it stored and when is it deleted?

Attendance report

Name, attendance time, activity data

Is employee monitoring involved?

Transcription

Voice converted to text

Is another AI processor involved?

AI summary

Transcript, meeting content, participant information

Where is AI processing performed?

Support

Logs, screenshots, account data

Can support personnel access EU data?

This matters because the controller, processor chain, lawful basis, retention period and transfer mechanism can differ between these operations.

Controller, Processor and Subprocessor: Map the Roles

For business meetings, the organisation arranging the processing will often be the controller for meeting-related personal data because it determines why and how the meeting is used.

A cloud conferencing vendor may act as processor for data it handles on the organisation’s behalf.

That does not mean every activity performed by the vendor necessarily has the same role allocation. Billing, fraud prevention, product telemetry or other vendor-defined processing may involve a different role depending on the actual circumstances and terms.

There may also be subprocessors for:

  • hosting;

  • cloud recording;

  • transcription;

  • customer support;

  • email delivery;

  • AI services;

  • analytics.

The practical task is therefore to create a role map, not merely sign the vendor’s standard agreement.

Which GDPR Requirements Matter Most?

Article 5: Processing Principles

The core GDPR principles include:

  • lawfulness, fairness and transparency;

  • purpose limitation;

  • data minimisation;

  • accuracy;

  • storage limitation;

  • integrity and confidentiality;

  • accountability.

The controller must also be able to demonstrate compliance with these principles.

For video conferencing, these principles translate into practical questions.

Purpose limitation

Why is the meeting being processed?

The reason for holding a live meeting does not automatically justify:

  • recording it;

  • transcribing it;

  • analysing sentiment;

  • generating AI summaries;

  • retaining attendance data indefinitely.

Treat additional processing as additional processing.

Data minimisation

Disable information collection that is not necessary for the business purpose.

Possible examples include:

  • unnecessary participant profiling;

  • optional analytics;

  • persistent recordings;

  • unused transcription;

  • excessive meeting telemetry.

Storage limitation

Define retention for each data category.

A meeting recording, chat history and diagnostic log do not necessarily need the same retention period.

Article 6: Choose the Lawful Basis Before Processing

GDPR provides six lawful bases, including consent, contract, legal obligation, vital interests, public task and legitimate interests. The appropriate basis depends on the purpose and context of the processing.

Do not assume that one lawful basis automatically covers every function of a video platform.

For example, the lawful basis for:

  • holding an employee meeting;

  • recording it;

  • generating an AI transcript;

  • analysing attendance;

may need to be assessed separately.

Consent deserves particular care in employment settings because an imbalance between employer and employee can affect whether consent is genuinely freely given.

Articles 13 and 14: Tell Participants What Happens to Their Data

Transparency must occur before or at the appropriate point in the processing.

Participants may need information about:

  • controller identity;

  • purpose of processing;

  • lawful basis;

  • recipients;

  • retention;

  • international transfers;

  • data-subject rights;

  • contact details;

  • recording;

  • AI transcription.

Article 13 generally concerns personal data collected from the data subject, while Article 14 covers relevant cases where personal data has been obtained elsewhere.

A calendar invitation can be a practical place to provide a concise notice and link to the full privacy information.

A sentence saying only “this meeting may be recorded” is unlikely to explain the entire processing operation.

Tell Participants What Happens to Their Data

Article 28: When You Need a DPA

When a video conferencing provider processes personal data on your behalf as a processor, the relationship must satisfy Article 28 requirements.

The agreement should cover matters such as:

  • processing subject matter;

  • duration;

  • nature;

  • purpose;

  • data categories;

  • data subjects;

  • controller instructions;

  • confidentiality;

  • security;

  • subprocessors;

  • deletion or return of data;

  • audit rights.

But:

A DPA is not a GDPR compliance certificate.

It solves one part of the governance model.

You still need lawful processing, transparency, appropriate security, retention rules and, where applicable, a lawful international transfer mechanism.

DPA vs International Transfer Mechanism

These are frequently confused.

DPA

Addresses the controller-processor relationship under Article 28.

Transfer mechanism

Addresses qualifying international transfers under Chapter V.

Depending on the destination and recipient, mechanisms may include:

  • adequacy decisions;

  • EU-US Data Privacy Framework for participating US organisations;

  • Standard Contractual Clauses;

  • Binding Corporate Rules;

  • applicable derogations in limited circumstances.

The EDPB describes Standard Contractual Clauses as pre-approved clauses that can be used to provide safeguards for transfers outside the EU.

A vendor can therefore have an excellent DPA while your transfer analysis remains incomplete.

International Transfers: What to Verify

Do not reduce this question to:

Is the server in Europe?

Instead map:

  1. Where is meeting traffic processed?

  2. Where are recordings stored?

  3. Where is metadata stored?

  4. Which entity provides support?

  5. Which subprocessors can access the data?

  6. Does AI processing occur elsewhere?

  7. Can remote administrative access occur from outside the EEA?

  8. What transfer mechanism applies to each relevant recipient?

The European Commission currently recognises US organisations participating in the EU-US Data Privacy Framework for covered transfers.

This does not remove the need to verify that the relevant vendor entity actually participates in the framework and that the transfer falls within the applicable scope.

Article 32: Security Is Risk-Based

GDPR does not prescribe one universal video-conferencing security configuration.

Article 32 requires appropriate technical and organisational measures relative to the risk.

Depending on the meeting, relevant controls can include:

  • encryption in transit;

  • encryption at rest;

  • end-to-end encryption where appropriate;

  • strong authentication;

  • SSO;

  • MFA;

  • waiting rooms;

  • guest controls;

  • meeting passwords;

  • restricted recording permissions;

  • administrative policies;

  • access logs;

  • backup protection;

  • patch management;

  • account lifecycle management.

The important phrase is appropriate to risk.

A general sales meeting and a multidisciplinary medical meeting need not have identical controls.

Recording Video Meetings Under GDPR

Recording changes the compliance profile because transient communication becomes persistent personal data.

A recording can contain:

  • faces;

  • voices;

  • names;

  • screens;

  • documents;

  • chat;

  • confidential business information;

  • special-category personal data.

Recording Video Meetings Under GDPR

Before Recording

Determine:

  • the purpose;

  • lawful basis;

  • who will have access;

  • retention period;

  • whether participants have been informed;

  • whether recording is genuinely necessary.

Do not enable automatic recording across the organisation simply because the platform supports it.

While the Recording Exists

Restrict access according to purpose.

Consider:

  • role-based access;

  • link sharing;

  • download permissions;

  • audit logs;

  • storage encryption.

At the End of Retention

Delete recordings once the documented purpose and retention requirement have expired, unless another valid legal or regulatory retention requirement applies.

Data-Subject Requests

Make sure a real process exists for:

  • finding recordings;

  • providing access where applicable;

  • deleting data where the conditions for erasure are met;

  • handling objections;

  • documenting the response.

A policy without a technical retrieval and deletion process is not enough.

AI Transcription Creates a New Processing Chain

AI meeting assistants are one of the most important procurement questions in 2026.

Do not treat transcription or meeting summaries as ordinary interface features.

They can introduce:

  • an additional processor;

  • a new subprocessor;

  • another processing location;

  • new retained personal data;

  • new purposes;

  • model-training questions.

Before enabling AI, ask:

Question

Why it matters

Where is audio processed?

Determines processor and transfer exposure

Is the transcript retained?

Creates a new persistent data set

Who can access summaries?

Changes access-control requirements

Is the content used to train models?

May introduce another processing purpose

Can AI be disabled centrally?

Needed for different risk classes

Does deletion of the meeting also delete AI outputs?

Rights and retention

Is an external AI vendor involved?

Subprocessor and transfer analysis

For highly sensitive meetings, local or customer-controlled AI processing may materially simplify the data-flow architecture.

Personal Data Breaches: The 72-Hour Rule

The common shorthand “every breach must be reported within 72 hours” is incorrect.

Under Article 33, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a breach unless the breach is unlikely to result in a risk to individuals’ rights and freedoms.

Communication to affected individuals follows a higher threshold: the breach must be likely to result in a high risk to their rights and freedoms.

All breaches should still be documented internally.

For a video platform, an incident-response plan should cover:

  • exposed recordings;

  • stolen meeting credentials;

  • unauthorised meeting access;

  • leaked transcripts;

  • compromised administrator accounts;

  • exposed attendance reports.

Deployment Model Changes the Compliance Work

No deployment model creates GDPR compliance automatically.

It changes which risks and obligations you have to manage.

Deployment model

Main advantage

Main GDPR work

Vendor-managed EU cloud

Low infrastructure burden

DPA, subprocessors, retention, security, transfer analysis

Global SaaS with EU residency

Familiar cloud model with regional controls

Verify what EU residency actually covers and any transfers

Customer-hosted / on-premises

Greater control over processing location

Customer owns infrastructure security, retention and access

Self-hosted open source

High technical control and software transparency

Full operational responsibility

Private cloud

Infrastructure choice can be controlled

Hosting and managed-service processors still need assessment

Important

Self-hosting can reduce external processor and international-transfer exposure, but only if the architecture actually avoids those external processing paths.

Check:

  • licensing;

  • support access;

  • cloud push services;

  • telemetry;

  • remote monitoring;

  • external backups;

  • AI;

  • identity providers.

How to Evaluate Video Conferencing Platforms for GDPR

Do not ask the vendor only:

Are you GDPR-compliant?

Ask for evidence.

Contractual Evidence

  • DPA;

  • subprocessor list;

  • transfer mechanisms;

  • support-access terms;

  • retention terms.

Technical Evidence

  • data-flow diagram;

  • hosting locations;

  • recording architecture;

  • encryption documentation;

  • authentication options;

  • audit logging;

  • backup architecture;

  • deletion behavior.

Operational Evidence

  • security certifications;

  • penetration-test information where available;

  • breach-notification process;

  • vulnerability management;

  • support escalation;

  • change-notification process for subprocessors.

Product Controls

  • recording policy;

  • guest access;

  • meeting authentication;

  • retention;

  • user provisioning;

  • admin controls;

  • AI enable/disable;

  • export and deletion tools.

The best procurement comparison is therefore not:

Which platform claims GDPR compliance?

It is:

Which platform gives us enough control and evidence to operate our chosen meeting scenarios compliantly?

Video Conferencing Platform Models Compared

Platform

Deployment model

Data-location control

Third-party processor exposure

Transfer considerations

What to verify

Secumeet

Server-connected communication environment

Potentially high, depending on server deployment

Architecture-dependent

Depends on hosting, licensing, support and external services

Exact Server hosting model, support access, subprocessors, retention, offline dependencies

TrueConf Server

Customer-operated on-premises / private infrastructure

High

Can be reduced for core conferencing

Can be reduced substantially in fully internal deployments

Licensing, support, external integrations, recording and AI configuration

Digital Samba

Vendor-managed European cloud

Vendor-defined EU infrastructure

Vendor and subprocessors

Review subprocessor and transfer documentation

DPA, hosting, processors, recording and retention

Zoom

Vendor-managed cloud with EEA residency controls for eligible customers

Regional controls available

Vendor and subprocessors

DPF and/or other applicable mechanisms

What data residency covers, support data, subprocessors, recordings, AI

Microsoft Teams

Microsoft cloud with EU Data Boundary commitments

EU Boundary for covered services, with documented exceptions

Microsoft and subprocessors

Review applicable transfer framework and exceptions

Exact Teams workloads, support/telemetry, AI/Copilot data flows

Jitsi Meet self-hosted

Customer-operated open source

High

Depends on hosting and optional services

Controlled by deployment

Hosting, authentication, analytics, recording and optional external services

Nextcloud Talk

Self-hosted / private cloud

High

Depends on infrastructure and service provider

Controlled by chosen deployment

Hosting provider, Talk backend, recording, AI/integrations

Zoom currently provides EEA customers on eligible paid accounts with data-residency controls for certain stored data and meeting/webinar traffic.

Microsoft describes the EU Data Boundary as covering Customer Data and personal data for Microsoft 365 and other in-scope services, while also documenting limited circumstances in which data continues to be transferred outside the boundary.

Nextcloud Talk is designed as a self-hosted, on-premises audio/video and chat platform.

Secumeet

Secumeet

Secumeet should be evaluated as a server-connected communications environment, not simply labelled “GDPR compliant” and left at that.

Current public product information confirms that the Secumeet client depends on Secumeet Server for full functionality and combines personal and group messaging, meetings, shared files and other communication functions.

That can be useful when the buyer wants the communications architecture itself to be part of the procurement decision.

The GDPR advantage of this model depends on the actual deployment.

A customer-controlled server can potentially reduce reliance on a public multi-tenant conferencing cloud, but procurement teams should confirm:

  • who hosts Secumeet Server;

  • whether Secumeet personnel can access the environment;

  • whether telemetry leaves the server;

  • how licensing works;

  • whether mobile push services are external;

  • where recordings are stored;

  • whether support involves remote access;

  • what subprocessors exist;

  • whether AI features use another processing service.

Best fit: Organisations that want to evaluate a server-based communication environment and are prepared to validate the complete data flow rather than rely on a generic compliance claim.

Main trade-off: Publicly available technical compliance documentation is less extensive than for several large enterprise providers, so procurement should require more direct architectural verification.

TrueConf Server

TrueConf

TrueConf Server provides a clearer documented example of the customer-operated deployment model.

TrueConf’s current documentation states that the server can operate on-premises without an internet connection and supports up to 2,000 participants, SIP/H.323 interoperability and corporate communication functions.

From a GDPR perspective, the useful characteristic is not a generic claim of “compliance.”

It is control over the data path.

A fully internal deployment can reduce the number of third parties involved in meeting-content processing and can eliminate many ordinary cross-border meeting-data paths.

That still leaves the controller responsible for:

  • lawful basis;

  • participant transparency;

  • recording policies;

  • user access;

  • retention;

  • backups;

  • patching;

  • breach response;

  • administrator privileges.

Best fit: Organisations that specifically want conferencing, recordings and user communication to remain on customer-operated infrastructure.

Main trade-off: Infrastructure control also means infrastructure responsibility.

Digital Samba

Digital Samba

Digital Samba represents the European managed-cloud approach.

It currently positions its video conferencing service around European hosting and GDPR-oriented processing rather than customer-operated infrastructure.

This model can reduce the operational burden compared with self-hosting.

The buyer should still review:

  • DPA;

  • hosting architecture;

  • subprocessors;

  • support locations;

  • recording storage;

  • retention;

  • AI features.

Being incorporated in Europe or hosting in Europe is useful evidence, but it does not replace a complete processing assessment.

Zoom

Zoom for Healthcare

Zoom can be used in GDPR-governed environments, but configuration and contract terms matter.

Zoom currently offers eligible EEA customers controls for EEA data residency and publishes GDPR, subprocessor and transfer documentation.

A procurement review should identify exactly what regional controls cover:

  • real-time meeting traffic;

  • cloud recordings;

  • support data;

  • AI processing;

  • account data;

  • subprocessors.

Do not reduce the assessment to the physical location of one data centre.

Microsoft Teams

Microsoft Teams

Microsoft’s EU Data Boundary is relevant to GDPR procurement because Microsoft commits to storing and processing covered Customer Data and personal data within the boundary for in-scope enterprise online services.

Microsoft also documents limited circumstances where transfers outside the boundary continue.

For Teams, review:

  • which workload processes the data;

  • recording and transcription;

  • Copilot;

  • support;

  • telemetry;

  • external guest identities;

  • retention;

  • data residency.

The word “Teams” can cover several different processing operations.

Jitsi Meet

Jitsi Meet

Jitsi is particularly relevant when the organisation wants to operate the conferencing stack itself.

Jitsi explicitly supports private self-hosting. Its security documentation also distinguishes self-hosted deployments from the public meet.jit.si service, which has its own account and analytics processing.

This distinction is critical.

Jitsi software is not the same processing environment as meet.jit.si.

A self-hosted deployment lets the organisation control much more of the infrastructure, but external services can still reappear through:

  • hosting;

  • authentication;

  • recording;

  • analytics;

  • telephony;

  • monitoring.

Nextcloud Talk

Nextcloud Hub

Nextcloud Talk is another self-hosted model.

Nextcloud describes Talk as a fully self-hosted on-premises audio/video and chat communication service and supports private-cloud or customer-operated deployment.

Its GDPR profile therefore depends heavily on who operates:

  • the Nextcloud server;

  • Talk backend;

  • hosting;

  • recording;

  • integrations;

  • AI services.

It can be attractive when an organisation already operates Nextcloud and wants meetings to use the same controlled infrastructure.

GDPR Video Conferencing Checklist

Processing

  • Each meeting use case is documented.

  • Personal-data categories are identified.

  • Lawful basis is documented.

  • Article 9 condition is identified where special-category data is processed.

  • Recording is assessed separately.

  • AI/transcription is assessed separately.

Roles and Contracts

  • Controller and processor roles are mapped.

  • DPA is signed where required.

  • Subprocessor list is reviewed.

  • Managed support access is included in the processing map.

Transfers

  • Data locations are documented.

  • Remote access locations are known.

  • Appropriate transfer mechanism is documented.

  • DPF participation is checked where relied upon.

  • SCCs or other mechanisms are reviewed where applicable.

Security

  • Authentication controls are configured.

  • Meeting access is restricted appropriately.

  • Recording permissions are centrally managed.

  • Encryption architecture is understood.

  • Administrator access is limited.

  • Patching and vulnerability management are defined.

Retention and Rights

  • Recording retention is defined.

  • Chat retention is defined.

  • Transcript retention is defined.

  • Deletion workflow is tested.

  • Access-request workflow is tested.

  • Departed-user data is handled consistently.

Transparency

  • Privacy notice covers video conferencing.

  • Recording is disclosed before it begins.

  • AI transcription is disclosed where used.

  • External participants receive appropriate information.

Incident Response

  • Video-meeting incidents are included in the breach plan.

  • 72-hour assessment workflow is documented.

  • Risk threshold for authority notification is understood.

  • High-risk threshold for individual notification is understood.

Special-Category Data Changes the Risk

A video call can contain health data, political opinions, trade-union information, religious beliefs or other special-category data.

Article 9 creates additional restrictions for this processing.

That means a platform that is acceptable for routine sales calls may require a different architecture or configuration for:

  • healthcare;

  • HR investigations;

  • occupational health;

  • legal consultations;

  • union discussions.

Do not create a single company-wide “GDPR approved video platform” policy without considering use-case risk.

Employee Monitoring and Works Councils

Video platforms can also create employee-monitoring implications through:

  • attendance tracking;

  • activity reports;

  • participation metrics;

  • recording;

  • transcription;

  • AI summaries.

GDPR is only one part of that analysis.

Depending on the country and organisation, national employment and co-determination rules may also apply.

This should be checked locally rather than treated as a universal EU-wide rule.

Frequently Asked Questions

What makes video conferencing GDPR-compliant?

There is no single product feature that creates compliance.

The organisation needs an appropriate lawful basis, transparency, appropriate security, controlled retention, valid processor arrangements and lawful international transfers where applicable.

Is a DPA enough?

No.

A DPA addresses the Article 28 processor relationship. It does not establish lawful basis, solve retention, determine security configuration or automatically provide a Chapter V transfer mechanism.

Is EU data residency enough?

No.

It is useful, but you still need to understand subprocessors, support access, AI, metadata and other data flows.

Is self-hosted video conferencing automatically GDPR-compliant?

No.

Self-hosting gives the organisation more control over infrastructure, but the organisation still has to comply with GDPR and secure the environment.

External processors may also remain if hosting, support, AI or other services are outsourced.

Are video recordings covered by GDPR?

Usually yes when they contain identifiable personal data such as a participant’s image, voice, name or shared information.

The purpose, lawful basis, access and retention should be documented.

Do I need consent to record a meeting?

Not necessarily.

Consent is one possible lawful basis, but the correct basis depends on the specific processing context.

If consent is relied upon, it must satisfy GDPR requirements for valid consent.

Can US video conferencing providers be used legally?

Yes.

The appropriate transfer mechanism depends on the recipient and processing arrangement. The European Commission currently recognises participating US commercial organisations under the EU-US Data Privacy Framework.

Other mechanisms such as SCCs may also apply in appropriate cases.

Do all data breaches have to be reported within 72 hours?

No.

Article 33 requires supervisory-authority notification when a breach is not unlikely to result in risk to individuals’ rights and freedoms. Communication to individuals applies when a breach is likely to result in high risk.

Does end-to-end encryption make a platform GDPR-compliant?

No.

E2EE may be an appropriate security measure for certain risks, but GDPR compliance also includes lawful basis, transparency, data minimisation, retention, rights, processors and transfers.

Final Decision Framework

Do not begin procurement by asking vendors whether they are GDPR-compliant.

Begin with five questions:

  1. What personal data will this meeting scenario process?

  2. Why are we processing it and what lawful basis applies?

  3. Who will process the data besides us?

  4. Where will every major data category be processed and stored?

  5. Can we technically enforce the retention, access and security rules we have documented?

Only then compare video platforms.

A public-cloud product may be appropriate when the organisation has the right contracts, transfer mechanism, configuration and risk profile.

A European cloud provider may reduce certain jurisdictional and transfer complexities.

A self-hosted system such as TrueConf Server or a private communication environment built around Secumeet may reduce dependence on external meeting infrastructure when correctly deployed.

The central GDPR question is therefore not whether a vendor can display a compliance badge.

It is whether the actual processing architecture can be explained, justified, controlled and demonstrated.

Author

Helga Afon

Helga Afon is a technology writer specializing in video conferencing, collaboration software, and workplace communication. She writes articles and reviews that help readers better understand enterprise communication tools and industry trends.