Of everything AI does for a business, meeting notes convert sceptics fastest. Nobody enjoys writing them up, the output is checkable in seconds and the time saving is obvious in week one.
It is also the AI use most likely to quietly create a compliance problem, because a transcript is personal data about everybody in the room, it is created automatically and it tends to be kept forever. Here is what the rules actually say and what a workable house policy looks like.
What UK law actually requires
Two things get conflated. Whether you may record a conversation, and whether you may process the personal data in it.
On the first, recording a conversation you are a party to is not a criminal offence in the UK. The Investigatory Powers Act concerns interception of communications you are not part of. That is why the answer to is it illegal to record a meeting is usually no, and why that answer is also unhelpful.
On the second, a transcript that names people and records what they said is personal data, and processing it engages UK GDPR in full. That means you need a lawful basis, you must tell people and you must not keep it longer than you need it.
Consent is usually the wrong basis
This surprises people. Consent under UK GDPR must be freely given, and an employee cannot freely refuse in a meeting their manager called. That imbalance is precisely why the Information Commissioner's Office discourages consent as the basis for most workplace processing.
For internal meetings, legitimate interests is the usual basis: you have a genuine business need for an accurate record, it is a reasonable expectation in a work context and the impact on individuals is low provided you are transparent. Document that reasoning once, in a legitimate interests assessment, and you have covered every internal meeting from then on.
For external calls, the position is the same in law but different in practice. Announce it, every time.
The legal question is which lawful basis applies. The commercial question is whether your client would be annoyed to discover it afterwards. Answer the second one and the first takes care of itself.
Where businesses actually get caught out
Not in the law. In the tooling.
Microsoft Teams is reasonably well behaved: recording and transcription raise a visible indicator for everyone, and Copilot's presence in a meeting is surfaced in the interface. If you are running Microsoft 365 across the business and using its own note taking, disclosure largely happens by itself.
The problem is third-party note takers that join as a participant. They appear in the attendee list under a product name, they do not always announce what they are and a client who is not paying close attention will not register that a bot has joined and is transcribing. Three specific failure patterns recur:
- The bot joins meetings the organiser did not intend. Calendar-connected note takers that join every meeting on the diary, including one-to-ones and interviews.
- The transcript syncs somewhere unexpected. Into a personal account, or a workspace outside your tenancy, which is a transfer of personal data you probably have not assessed.
- Nobody ever deletes anything. Two years of transcripts including a disciplinary discussion and a redundancy consultation.
A house policy that works
Five rules. Short enough that people follow them.
1. One approved tool
Pick it and disallow the rest. If everyone is on Microsoft 365, use the note taking that comes with it rather than bolting on a bot with its own data residency. Fewer tools means fewer places transcripts live and one retention setting to manage.
2. Announce it at the top of every external call
One sentence. I have notes running on this call so I can send you a summary afterwards, do say if you would rather I did not. That sentence does four jobs: it discloses, it gives a route to object, it explains the purpose, and it makes you sound organised rather than furtive.
3. Name the meetings where it is switched off
Interviews, disciplinaries, grievances, redundancy consultations, appraisals, anything involving health or a safeguarding matter and any board discussion under privilege. Write the list down, because the person who most needs it is the one who has just been asked to sit in on a difficult conversation at short notice.
4. Set a retention period and automate it
Thirty days for routine internal meetings, ninety for client work where the summary feeds a proposal. Configure it once in the platform rather than relying on somebody remembering. Microsoft 365 retention policies do this properly and apply to Teams recordings and transcripts.
5. Say it in your privacy notice
One paragraph covering what you transcribe, why, on what lawful basis and for how long. This is the paragraph a client's procurement team will ask for, and having it ready is faster than writing it under time pressure during a tender.
The bit that is genuinely worth the effort
None of the above is difficult, and it takes an afternoon to put in place. Do it before the habit spreads rather than after, because retrofitting a policy onto eighteen months of accumulated transcripts is a much less pleasant job.
If you would like the retention policies, the sharing controls and the tenancy settings configured properly rather than left at their defaults, that is standard work for our managed IT team. Ask us to review how your meetings are being recorded and we will tell you where the transcripts are actually going.








