
GDPR and AI meeting assistants: what EU data residency really means

SUMMARY SNIPPET
- EU data residency means a vendor stores your meeting recordings, transcripts and notes in data centres inside the EU, but on its own it neither makes an AI meeting assistant GDPR compliant nor guarantees data sovereignty.
- GDPR allows personal data to leave the EU on the basis of an adequacy decision or appropriate safeguards such as standard contractual clauses, so what matters is where each provider in the chain, including speech-to-text and AI model providers, processes your meetings and whether any of them trains on your content.
- Sovereignty is about whose laws can reach the data: under the US CLOUD Act, a provider subject to US jurisdiction can be ordered to disclose data in its control even when that data is stored in the EU.
- Before you roll out a meeting assistant, ask for the sub-processor list and locations, the training policy, the deletion terms and the vendor's position on foreign government access, and make sure the answers are in the data processing agreement.
Table of Contents
EU data residency means a vendor stores your meeting recordings, transcripts and notes in data centres inside the EU, but on its own it neither makes an AI meeting assistant GDPR compliant nor guarantees data sovereignty. GDPR allows personal data to leave the EU on the basis of an adequacy decision or appropriate safeguards such as standard contractual clauses, so what matters is where each provider in the chain, including speech-to-text and AI model providers, processes your meetings and whether any of them trains on your content. Sovereignty is about whose laws can reach the data: under the US CLOUD Act, a provider subject to US jurisdiction can be ordered to disclose data in its control even when that data is stored in the EU. Before you roll out a meeting assistant, ask for the sub-processor list and locations, the training policy, the deletion terms and the vendor's position on foreign government access, and make sure the answers are in the data processing agreement.
Marko is the operations lead at a 70-person engineering consultancy in Tartu that delivers EU-funded research projects. The project managers want an AI meeting assistant, and a public-sector partner has just asked in writing whether meeting recordings ever leave the EU. Three vendors' websites all say "GDPR compliant" and "EU hosting", but none of them says which companies process the audio, where the AI models run, or whether a US authority could ask for the data. Marko has a week to answer the partner and sign off the tool.
Why does "GDPR compliant" tell you so little about an AI meeting assistant?
Meeting recordings are dense with personal data: voices, names, opinions and, often, client details. When you use an AI meeting assistant, your organisation is usually the controller and the vendor a processor, and Article 28 of the GDPR requires a binding contract, processing only on your documented instructions, and your authorisation before the vendor brings in another processor. An AI meeting assistant often relies on several: a cloud host, a speech-to-text service, one or more AI model providers, and tools for analytics and crash reporting.
Each of those providers is a place your data can travel. Chapter V of the GDPR does not ban transfers outside the EU; it requires an adequacy decision, appropriate safeguards such as standard contractual clauses, or, in limited cases, a specific derogation. The European Commission's list of adequacy decisions includes the United States, but only for commercial organisations participating in the EU-US Data Privacy Framework. A badge that says "GDPR compliant" tells you none of this, which is why the questions below matter more than the badge.
What is the difference between data residency, data sovereignty and a European company?
They answer three different questions. Data residency is about where: the countries or regions in which your data is stored and processed. Data sovereignty has no single legal definition, but it is usually about whose law: which governments can compel access to the data, which depends on the legal jurisdiction of every company that holds it, not only on where the servers are. A "European company" is about who: where the vendor is incorporated, which on its own says nothing about where its providers process your data.
The three can point in different directions. A vendor headquartered in the US can offer EU residency; a European vendor can host your data with a cloud provider headquartered outside the EU; and an EU-hosted service can still send audio to a speech-to-text or AI provider elsewhere. Ask about all three separately.
How Digiotouch AI handles this: Digiotouch AI is developed by Digiotouch, a company with its HQ in Estonia and another office in France. Data for EU customers is hosted in the EU (France and Belgium); customers in the US, India, Japan and South Korea have their data hosted in those regions, and there are no other locations. The region is assigned automatically by location and can be changed by the customer, and the Enterprise plan adds on-premise and private cloud deployment.
Does GDPR require meeting data to stay in the EU?
No. GDPR regulates transfers rather than banning them. Under Article 46, a controller or processor may transfer personal data outside the EU when appropriate safeguards are in place, such as standard data protection clauses adopted by the Commission, provided the people concerned have enforceable rights and effective remedies, and Article 45 allows transfers to countries with an adequacy decision.
The catch is stability. The Court of Justice struck down the two previous EU-US frameworks, Safe Harbor in 2015 and Privacy Shield in 2020. The current EU-US Data Privacy Framework was upheld by the EU General Court on 3 September 2025, and an appeal to the Court of Justice followed in October 2025. Keeping data in the EU reduces how much of your setup depends on any single transfer mechanism surviving the next ruling.
How Digiotouch AI handles this: Digiotouch AI keeps EU customers' data in the EU. The full list of providers and sub-processors is mentioned in the Terms of Service page.
Do AI meeting assistants train their models on your meetings?
Some do, and the answer is usually in the privacy policy or terms rather than on the product page. Look for phrases such as "improve our services" or "develop new features", and check whether training uses de-identified or aggregated data, and whether it is on by default with an opt-out or off unless you opt in.
GDPR gives you leverage here. Under Article 28, a processor handles personal data only on your documented instructions, and Article 5 requires that personal data is collected for specified purposes and not further processed in a way that is incompatible with them. If a vendor also uses your meetings to improve its own models, that is a separate purpose, so check how it is described and whether your contract covers it. The same question applies to the AI model providers behind the vendor: ask whether they may keep or train on what they receive.
How Digiotouch AI handles this: Digiotouch AI does not train AI models on customer meeting content. You can connect your own Anthropic, OpenAI or Mistral account to Digiotouch AI. This lets you power the chat features or bring your Digiotouch AI data straight into those tools. Either way, the requests run on your own account with that provider, under the terms you agreed with them.
How do you check an AI meeting assistant's GDPR and residency claims?
Ask for the evidence, not the badge. Before you roll out a meeting assistant, get written answers to these questions:
- Processors: the full sub-processor list, including speech-to-text and AI model providers, with the country where each one processes data.
- Residency: whether every copy stays in the region you chose, including backups, logs and support access.
- Transfers: the transfer mechanism for anything that leaves the EU, such as the Data Privacy Framework or standard contractual clauses.
- Training: whether your meetings are used to train any model, by the vendor or its providers, and how to switch it off.
- Deletion: what happens to recordings, transcripts and backups when you delete a meeting or close the account.
- Government access: which companies in the chain are subject to non-EU jurisdiction, and how the vendor responds to a request.
Put the answers in the data processing agreement, not only in a sales email, and check that the vendor will tell you before adding a new processor, as Article 28 requires under a general authorisation. To see how EU residency differs between plans and vendors in practice, read how EU data residency compares from the Free plan up.
How Digiotouch AI handles this: Digiotouch AI acts as a processor under a data processing agreement. Deleting a recording or an account removes the stored media, not only the database record, and Digiotouch AI does not train AI models on your meeting content. For a sub-processor list, consult its Terms of Service page. If you have a security questionnaire, contact the Digiotouch team at support@digiotouch.ai.
What each claim guarantees, and what it does not
Vendors use these terms loosely. The table shows what each one actually tells you, and what to ask to close the gap.
| Claim | What it tells you | What it does not tell you | What to ask |
|---|---|---|---|
| "GDPR compliant" | The vendor says it meets its GDPR obligations | Where data goes, which processors are used, or whether your content trains models | The data processing agreement and the sub-processor list |
| "EU data residency" | Where your data is stored | Where speech-to-text and AI providers run, or which laws can reach the data | The location of every processor and every copy, including backups |
| "European company" | Where the vendor is incorporated | Where its cloud and AI providers are, or which jurisdiction they fall under | The jurisdiction of each provider in the chain |
| "Data sovereignty" | That the vendor aims to keep data under EU law and control | There is no single definition, so it can mean different things | Who can be compelled to disclose the data, and who holds the encryption keys |
| "No AI training" | Your content is not used to train the vendor's models | Whether its AI providers keep or train on what they receive | Written terms covering the vendor and each AI provider |
| "On-premise or private cloud" | Data is stored on dedicated infrastructure, on your premises or in a cloud environment reserved for you | Who operates it and has admin access, or whether every feature works without an external service | Who runs the environment, and which features depend on outside providers |
Sources: the GDPR (Regulation (EU) 2016/679) on EUR-Lex, the European Commission's adequacy decisions page, 18 U.S.C. section 2713 and the 2019 EDPB-EDPS assessment of the CLOUD Act, checked 7 October 2026 (listed in the citation index below). This is general information, not legal advice. Digiotouch AI is the vendor of one of the tools discussed in this article. Corrections: notes@digiotouch.ai.
Key takeaways
- Residency is location: it tells you where data is stored, not who can reach it.
- GDPR allows transfers: adequacy decisions or contractual clauses can make non-EU transfers lawful, so check every provider.
- Sovereignty is jurisdiction: a provider under US jurisdiction can be compelled by the CLOUD Act, wherever its servers are.
- Training is a contract question: get "no training on customer content" in writing, for the vendor and its providers.
- Check the whole chain: ask for sub-processors, locations, deletion terms and the government access policy.
Next step
If you are choosing a meeting assistant for an EU organisation, send the questions above to each vendor, including us, and compare the written answers. Then test the tool on a real meeting before you roll it out.
Related reading
- Best Otter.ai alternative for European companies: EU data residency and AI training, compared plan by plan.
- Best Fireflies alternative for European companies: when EU storage is included and when it costs extra.
- 7 in 10 professionals would let AI take their meeting notes: why security decides whether teams adopt AI meeting notes.
Citation index
- European Union, "Regulation (EU) 2016/679 (General Data Protection Regulation)", EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj
- European Commission, "Adequacy decisions": commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
- Legal Information Institute, Cornell Law School, "18 U.S. Code section 2713": www.law.cornell.edu/uscode/text/18/2713
- EDPB and EDPS, joint response to the LIBE Committee on the impact of the US CLOUD Act, 10 July 2019: edps.europa.eu/sites/default/files/publication/19-07-10_edpb_edps_cloudact_coverletter_en.pdf
- IAPP, "European General Court dismisses Latombe challenge, upholds EU-US Data Privacy Framework": iapp.org/news/a/european-general-court-dismisses-latombe-challenge-upholds-eu-us-data-privacy-framework
- WilmerHale, "European Court of Justice to Review Challenge to EU-U.S. Data Privacy Framework", 1 December 2025: www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework
No. GDPR allows transfers outside the EU when the destination has an adequacy decision or when safeguards such as standard contractual clauses are in place. EU residency is a choice that reduces transfer risk, not a GDPR requirement in itself, although some sector rules or contracts may require it.
Not automatically. EU hosting covers where data is stored, but GDPR also depends on the processor contract, every sub-processor and its location, the purposes the data is used for, and how deletion works. Ask for the data processing agreement and the sub-processor list.
Data residency is where your data is stored and processed. Data sovereignty is whose laws can reach it, which depends on the jurisdiction of every company that holds the data. A provider can offer EU residency and still be subject to non-EU law.
Some vendors' terms allow it, often with de-identified data and an opt-out. Check the privacy policy and the contract for training on customer content, by the vendor and by its AI model providers. Digiotouch AI does not train AI models on customer meeting content.
The subject and purpose of processing, the processor's duty to act only on your instructions, confidentiality and security measures, the rules for using other processors, and deletion or return of data at the end of the contract. Article 28(3) of the GDPR sets this minimum; a sub-processor list with locations and the transfer safeguards are worth adding on top.
Data for EU customers is hosted in the EU. Customers in the US, India, Japan and South Korea have their data hosted in those regions, and there are no other locations. The region is set automatically by location and can be changed by the customer.
Not with Digiotouch AI: EU customers' data is hosted in the EU on every plan, including Free. Plan details are on digiotouch.ai/en/pricing.
Do you have more questions?
You may also be interested in:


Where do your meeting recordings and AI notes actually go?

Best Granola Alternative That Records Meeting Video

