Recording a Board Meeting: What Are the GDPR Rules?
- Who can read the minutes, and what happens to remarks about absent persons?

Do you record your committee meetings to get a reliable record of decisions? You can, and the question of the right to record is settled quickly, since the participants are your own staff.
The real question lies elsewhere: who will be able to read the minutes, and what becomes of the remarks made about people who are not in the room.
Can you record a board meeting?
Yes, but not without a framework for the processing.
A board meeting names people, discusses their results, and sometimes their future in the organisation. It therefore constitutes processing of personal data within the meaning of the GDPR.
In particular, you must:
- inform the members of the committee before recording;
- determine your legal basis;
- define the purpose of the recording;
- limit the retention period;
- restrict the circulation of the minutes;
- take account of the absent people who are discussed.
Recording without the knowledge of the people present also falls under the French Criminal Code, which punishes "with one year's imprisonment and a fine of €45,000 the act of wilfully violating the privacy of another person by any means whatsoever: 1° by capturing, recording or transmitting, without the consent of their author, words spoken in private or confidentially" (Article 226-1).
Is a recording of a committee meeting personal data?
Yes.
The GDPR defines personal data as "any information relating to an identified or identifiable natural person" (Article 4, point 1).
The participants are identifiable, and so are the people mentioned during the session.
The transcript and the minutes are also covered.
Why is this type of meeting different?
Because the most sensitive data does not concern the participants.
It concerns the people being talked about, who are not in the room: a member of staff whose situation is under discussion, a client, a partner. The framework common to all meetings is set out on the page recording a professional meeting.
You also carry out several successive processing operations:
record → transcribe → write up → circulate to the committee → retain → delete.
What data is recorded?
Depending on the tool used, you may keep:
- the audio of the session;
- the transcript;
- the names of the participants;
- the date and duration;
- the minutes;
- the decisions handed down;
- the actions assigned;
- the mentions of absent people.
Do you have to tell the members of the committee before recording?
Yes.
The information must be given before or at the time the data is collected. The text requires it to be provided "at the time when personal data are obtained" (GDPR, Article 13, paragraph 1).
For a recurring committee, the announcement is made once when the system is introduced, then repeated at the start of each session.
What should you tell them?
The CNIL states that the people concerned "must in particular be informed: of the existence of the system; of the identity of the data controller; of the purposes pursued".
For this type of meeting, one point matters more than the others: the list of people who will have access to the minutes.
You must therefore be able to explain simply:
who is recording → why → who will read the minutes → how long they are kept.
Do you have to inform the people discussed during the session?
The question deserves to be addressed in your internal policy.
The GDPR provides for information to be given to the people whose data is processed. A committee that regularly deals with individual situations is better off handling this point in advance rather than during the session.
Do you have to say that an AI writes the minutes?
Yes.
The audio recording and the processing then carried out by the AI are two operations that are worth distinguishing.
The European AI Regulation provides that "providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system" (Article 50, paragraph 1). These obligations have applied since 2 August 2026, and they target the provider of the system; your obligation to inform comes from the GDPR and the CNIL's guidance.
You can, for example, announce:
"This session is being recorded and an AI assistant automatically writes the minutes."
How do you handle a one-off guest?
You inform them when they arrive.
Their access to the minutes can also be limited to the part that concerns them.
Which legal basis should you use to record a committee meeting?
Legitimate interest is the basis used for internal meetings.
Consent raises a difficulty here that legitimate interest avoids.
Can you rely on legitimate interest?
Yes, in particular for an internal committee.
Article 6 of the GDPR authorises processing "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject" (paragraph 1, point f).
You must therefore in particular carry out a balancing test and inform the participants.
Why not consent?
Because the freedom to refuse is open to question.
Consent must be freely given. Between a chief executive and the members of their committee, that condition is harder to establish. It does not raise the same difficulty in a sales meeting, where your contact can refuse without consequence.
Which purpose should you choose?
Producing a record of decisions and a follow-up of actions.
That is a clear purpose, which justifies the recording and which bounds what you can do with it.
"We keep the sessions just in case" is not a purpose, and it makes it impossible either to justify the processing or to set a retention period.
Can a member of the committee object?
Yes, under the conditions laid down by the GDPR, since the processing is based on legitimate interest.
The data subject has "the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1)" (GDPR, Article 21, paragraph 1).
How long should you keep the recording of a committee meeting?
For as long as necessary for the purpose pursued, and no longer.
The GDPR requires data to be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed" (Article 5, paragraph 1, point e).
How long should you keep the audio?
For listening to and recording calls in the workplace, the CNIL states that "recordings may be kept for a maximum of six months".
A board meeting generally has no need of its audio beyond the approval of the minutes, and it is the audio that carries the remarks left out of the final record.
How long should you keep the minutes?
The CNIL states that "analysis documents may be kept for up to one year".
A record of decisions that serves as an institutional memory may call for a longer period, provided that it is written down and justified.
Should every session be treated the same way?
No.
A session that deals with individual situations does not call for the same rules as a review of figures.
An effective policy can provide for:
routine session → standard retention · sensitive session → shorter period and more restricted access.
Who can access the minutes of a committee meeting?
Only the members of the committee.
This is the point that causes the most difficulty in practice for this type of meeting.
Who can view the audio, the transcript and the minutes?
The three files do not necessarily meet the same need.
You can, for example:
- share the minutes with the members of the committee;
- limit access to the transcript;
- keep the audio only for genuinely justified needs.
Access is decided before the first recorded session, not once the minutes have already been produced.
Do you need a separate space for these meetings?
It is simpler to control.
Filing committee minutes in the same space as other meetings means making confidentiality rest on the permissions of each individual file.
Should the data be encrypted?
Security must be appropriate to the risk.
The GDPR requires "appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data" (Article 32, paragraph 1).
What are the participants' rights?
The people recorded have the rights provided for by the GDPR.
Can they request access to their data?
Yes.
The data subject has "the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed" (GDPR, Article 15, paragraph 1). This may concern the audio, the transcript and the minutes.
Can they request rectification?
Yes.
The data subject has "the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her" (GDPR, Article 16).
In a committee meeting, a position wrongly attributed in the minutes can have real consequences.
An AI can mistranscribe:
- a proper name;
- an amount;
- a decision;
- a deadline;
- the identity of the person who spoke.
Can they request erasure?
Yes, under the conditions laid down by the GDPR.
The data subject has "the right to obtain from the controller the erasure of personal data concerning him or her without undue delay" (GDPR, Article 17, paragraph 1).
What about the absent people who are discussed?
They have the same rights.
A member of staff who learns that a session discussed their situation can request access to the data concerning them.
How quickly must you respond?
In principle, within one month. The controller responds "without undue delay and in any event within one month of receipt of the request" (GDPR, Article 12, paragraph 3).
What obligations apply when the AI takes the notes?
The AI adds a processing operation on top of the simple recording.
The way it works can be summarised as follows:
audio → transcript → analysis → record of decisions → circulation.
What does the AI actually do?
It can:
- transcribe the session;
- identify the speakers;
- extract the decisions;
- note the arbitrations made;
- produce minutes;
- organise the deadlines.
Where is the data stored?
This is one of the first questions to ask your provider, and it arises here more than elsewhere, since it is your own decisions that pass through.
At Leexi, recordings, transcripts and minutes stay in the Paris region, on AWS. Above a certain volume of licences, hosting at Scaleway can be chosen. The compliance file details the processors and the certifications.
Who processes the data?
The provider of the tool acts as a processor within the framework laid down by the GDPR.
In Leexi's case, OpenAI supplies the language model and Leexi runs it via Azure France, in a closed circuit.
Do you need a DPA with the provider?
Yes, when the provider acts as a processor.
Article 28 of the GDPR provides that "processing by a processor shall be governed by a contract or other legal act […] that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller" (paragraph 3).
Does the AI use your sessions to train its models?
That depends on the provider.
At Leexi, conversations do not train any model, on all accounts.
How do you announce the recording of a board meeting?
You can use simple, precise wording.
When the system is introduced
"From this month, sessions are recorded and the minutes are written automatically: decisions, arbitrations, actions. Access is limited to the members of the committee. The recording is deleted once the minutes have been approved."
At the start of a session
"A reminder: the session is being recorded and the minutes go to the members of the committee. If a point should stay out of the minutes, say so and I'll stop the recording."
For a one-off guest
"The session is being recorded and the minutes circulate within the committee. You will not have access to them beyond the part that concerns you."
What mistakes should you avoid?
1. Circulating the minutes beyond the committee
This is the leading cause of difficulty for this type of meeting, and it is settled in the settings.
2. Setting access rights after the fact
The request to restrict access often arrives once the minutes have already been produced. The settings are decided before the first session.
3. Not defining the purpose
Without a written purpose, neither the retention period nor the scope of access can be justified.
4. Treating every session the same way
A session that deals with individual situations deserves a shorter period and more restricted access.
5. Keeping the audio after the minutes are approved
It is the audio that carries the remarks left out of the final record.
6. Forgetting the absent people being discussed
They have the same rights as the participants.
How do you record a committee meeting with Leexi?
Once the GDPR framework is defined, using the tool comes down to a few steps.
1. Join the session
Leexi can join the meeting from your calendar. In the room, recording can be started from the mobile app, and the rules for in-person meetings apply.
2. Generate the record of decisions
The minutes cover in particular the decisions, the arbitrations, the actions and the deadlines.
3. Restrict access
You define which members of staff are authorised to view the minutes.
4. Review before circulation
The minutes can be reviewed and corrected before being shared.
5. Control the data
Leexi states in particular hosting in the Paris region, a Scaleway option, model execution via Azure France in a closed circuit, encryption of data in transit and at rest, and no training on your conversations.
What difficulties do users actually encounter?
Legal questions are not the only difficulties encountered in practice.
Out of 1,141 support tickets received between January and June 2026, 2 concern the recording of a board meeting. Both relate to the same subject: minutes that do not reach their intended recipient, and the request to withdraw access from participants outside the management team.
None of them asks whether recording is allowed.
This gives another reading of the problem:
the question is not only "am I allowed to record?"
You also need to know:
who receives the minutes → who can reopen them later → what becomes of the audio → what stays out of the record.
Recording a board meeting: what to remember
Before recording your committee meetings, check these six points:
- Information: do the members know that sessions are recorded?
- Purpose: is the record of decisions written down as the purpose?
- Legal basis: is legitimate interest documented, balancing test included?
- Access: is the circulation scope configured before the first session?
- Retention: is the audio deleted once the minutes have been approved?
- Absent people: does your policy provide for informing them?
If an AI is involved, add a seventh point:
do the members know that an AI system processes the recording to produce the minutes?
Frequently asked questions
Is it legal to record a board meeting?
Yes, on the basis of legitimate interest, after informing the participants and carrying out a balancing test.
Do you need the agreement of every member of the committee?
No, legitimate interest does not require consent. Prior information, however, is still owed.
Can a member object to the recording?
Yes, under the conditions laid down by the GDPR, on grounds relating to their particular situation.
Who should have access to the minutes?
The members of the committee. Access rights are configured before the first recorded session.
Can you stop the recording during a sensitive item?
Yes, and that is more reliable than counting on deletion after the fact.
How long should you keep the recording?
The period depends on the purpose. For recordings of calls in the workplace, the CNIL retains a maximum of six months in the context concerned, and up to one year for analysis documents.
Do the people discussed during the session have rights?
Yes, the same as the participants: access, rectification, erasure.
In summary
Recording a board meeting is possible.
But the right reflex is not only to ask:
"Am I allowed to record?"
You should instead check the whole chain, paying attention to circulation:
inform → record → transcribe → review → circulate to the committee → delete the audio.
It is this complete chain that must be governed by your data protection policy.
Do your committee meetings deserve reliable, restricted minutes? See how Leexi manages access
Sources
Texts taken from primary sources on 22 August 2026.
- GDPR, Articles 4, 5, 6, 12, 13, 15, 16, 17, 21, 28 and 32
- French Criminal Code, Article 226-1
- CNIL, Listening to and recording calls in the workplace
- European Artificial Intelligence Regulation, Article 50
This page describes the applicable framework. It does not constitute legal advice.
Recommended Articles

Recording a Work Meeting: What Are the GDPR Rules?
Inform participants, choose legal basis, limit retention, control access: GDPR requirements before recording a meeting.
09/08/2026
Read more
Recording In-Person Meetings: What Are the GDPR Rules?
In-room, no assistant is visible: info is given orally. Legal basis, retention period, and copy on phone explained.
09/08/2026
Read more
The 10 most secure AI note-taking solutions
Discover the 10 most secure AI note-taking applications: privacy, GDPR, advanced AI and data sovereignty.
09/08/2026
Read moreReady to boost your productivity with Leexi?
Leexi AI Notetaker takes notes for you