AI-powered meeting transcription is legally permitted in Switzerland and the EU, but is subject to clear conditions. 15 tools in 5 groups, ranging from strictly local to conditionally suitable for use in the U.S. Includes a checklist, storage rules, and a comprehensive legal comparison.
Voice = personal data; in the case of biometric analysis, it is even considered data requiring special protection. Consent from all participants is required, not just that of the organizer. What matters is the provider’s corporate headquarters, not just the server location. U.S. corporations with servers in the EU are subject to the CLOUD Act. Local tools eliminate most of the complexity associated with compliance.
The real problem isn't the technology, but a lack of knowledge
Four Basic Rules That Always Apply
1. Providing advance notice is mandatory (Art. 13 GDPR / Art. 19 DSG)
Before any recording or transcription takes place, all participants must be informed of the following: the purpose, the tool used, the server location, the retention period, the recipients of the data, and the right to object.
2. Actively obtain consent (Art. 6 GDPR / Art. 6 DSG)
Active, voluntary, informed, unambiguous, and before the recording begins. Merely remaining silent is not enough. Anyone who does not want to be recorded must still be able to participate in the meeting.
3. A visible pop-up does not replace consent
Tools such as tl;dv, Sally AI, or Fireflies join the meeting as identifiable bots. This creates transparency but does not replace actively obtained consent under Article 5(1)(a), Article 13, and Article 6 of the GDPR.
4. Consent from all participants, not just the organizer
15 Data Protection-Compliant Tools in 5 Groups
Group A: Local / On-Device
⭐⭐⭐⭐⭐ Maximum Data Protection
Processing is done entirely on the device. No cloud-related risks, no AVV required, no transfers to third countries.
| # | Tool | Platform | Did you save the audio? | Price | Distinctive Feature | Link |
|---|---|---|---|---|---|---|
| 1 | Notiq | iOS (iPhone/iPad) | Yes, AES-256 locally | Free | No account, no cloud, completely offline, whisper-level AI | notiq-ai.app |
| 2 | Whisper Notes | iOS / Mac | No—text only locally | ~6.99 USD (one-time fee) | No servers, no analytics, completely offline | whispernotes.app |
| 3 | Speakwise | iOS (iPhone/iPad) | Yes, locally, no training | Freemium | On-device, 95%+ accuracy offline, never used for AI training | speakwiseapp.com |
| 4 | MacWhisper (iOS) | iOS (iPhone/iPad) | Yes, locally | Free (Basic) | Local Whisper models; cloud option available for a fee | macwhisper |
Group B: Swiss Cloud
GDPR-compliant · ⚠️ Not available to EU customers
Processing on Swiss servers. No CLOUD Act risk. AVV recommended in accordance with CH-DSG.
| # | Tool | Platform | Server | Did you save the audio? | Price | Distinctive Feature | Link |
|---|---|---|---|---|---|---|---|
| 5 | Meeting Metrics | Web / iOS / Android | 🇨🇭 St. Gallen | Yes, CH server | Freemium (5 free meetings) | Swiss-made, DSG-compliant, Swiss German support, no CLOUD Act | meetingmetrics.ai |
| 6 | töggl.ch ⚠️ | Web app (not a native iOS/Android app) | 🇨🇭 CH Server | Yes, CH server, no training | Freemium (Credits) | "Swiss-made" software label, excellent dialect recognition (SRF material). According to the Terms and Conditions, this applies only to the Swiss market—not to EU customers or partners. | töggl.ch |
Group C: EU Cloud
⭐⭐⭐⭐ GDPR-compliant · Terms of Service required
European headquarters, EU servers. No Schrems II risk. A data processing agreement (DPA) must be entered into in accordance with Article 28 of the GDPR. All providers provide a DPA.
| # | Tool | Platform | Server | Did you save the audio? | Price | Distinctive Feature | Link |
|---|---|---|---|---|---|---|---|
| 7 | tl;dv | iOS + Android + Web | EEA (GCP/Hetzner) | Yes, AES-256, EU servers | Freemium (Pro: ~25 USD/month) | SOC 2 Type 1, EU AI Act compliant, choice of EU or U.S. AI hosting, dedicated EU hosting available upon request, no training using customer data, visible bot | tldv.io |
| 8 | Bliro | iOS (In-Person) + Desktop | Frankfurt/Munich | ❌ No audio saved | Subscription (upon request) | Made in Germany, real-time transcript stored only in RAM, not subject to criminal liability according to the provider, no visible bot | bliro.io |
| 9 | Jamie AI | iOS + macOS + Windows | Frankfurt (exclusive) | ❌ Audio deleted immediately after transcription | Freemium (Pro: ~24 EUR/month) | No visible bot, ISO 27001 + DORA, no training with user data, AES-256, ideal for confidential projects | meetjamie.ai |
| 10 | Sally AI | iOS + Android + Web | Germany (EU) | Yes, EU servers, encrypted | Freemium (Pro ~29 EUR/month) | ISO 27001 + SOC2, visible bot, no sentiment analysis, no training with user data | sally.io |
| 11 | HappyScribe | Web + iOS + Android | Barcelona / EU | Yes, EU servers | Freemium (Pro starting at ~17 EUR/month) | SOC 2 Type II, ISO 27001, Tier IV data center, PCI DSS compliant, 120+ languages | happyscribe.com |
Group D: Self-Hosted
⭐⭐⭐⭐⭐ Maximum Control
| # | Tool | Platform | Data Management | Did you save the audio? | Price | Distinctive Feature | Link |
|---|---|---|---|---|---|---|---|
| 12 | Nextcloud Talk | iOS + Android | Dedicated Server | Yes, on our own server | Free (Open Source) | GDPR-compliant, integrated consent feature for recordings, no metadata sharing, recommended by German data protection authorities | nextcloud.com |
Group E: U.S.-based tools
⚠️ Risky without SCCs + TIA
Data processing on U.S. servers. Following the Schrems II ruling, the U.S. is no longer considered a safe third country. U.S. companies with servers in the EU remain subject to the CLOUD Act. SCCs and TIA are mandatory.
| # | Tool | Platform | Server | Risk | Conditions for Compliant Use | Link |
|---|---|---|---|---|---|---|
| 13 | Otter.ai | iOS + Android + Web | AWS USA | Schrems II, CLOUD Act; 2025 Lawsuit Over Lack of Consent | DPF-certified, SCCs available; no EU hosting; high manual effort required for GDPR compliance | otter.ai |
| 14 | Fireflies.ai | iOS + Android + Web | AWS USA | Schrems II, CLOUD Act; EU Hosting for Enterprise Only | EU hosting: Enterprise tier only, upon request; SCCs + TIA required; visible bot | fireflies.ai |
| 15 | Fathom AI | iOS + Android + Web | United States | Schrems II, CLOUD Act; no EU hosting known | DPF-certified, visible bot; SCCs + TIA required for EU data | fathom.video |
Storage Rules by Data Location
| Location | Requirement | Risk | CH Customers | EU Customers |
|---|---|---|---|---|
| 🟢 Local on device | Passcode/Face ID enabled, backup encrypted | Device theft; Check iCloud backup | ✅ Ideal | ✅ Ideal |
| 🇨🇭 CH-Cloud (töggl, Meeting Metrics) | AVV Recommended in Accordance with the CH-DSG | No CLOUD Act; no Schrems II | ✅ Ideal | ⚠️ Only if GDPR-compliant (no exceptions!) |
| 🇪🇺 EU Cloud (tl;dv, Bliro, Jamie, Sally, HappyScribe) | Privacy Notice pursuant to Article 28 of the GDPR | No Schrems II; external access permitted | ✅ Good | ✅ Good |
| 🏢 Self-Hosted (Nextcloud) | Take Responsibility for Your Own Infrastructure | Full control, no third parties | ✅ Ideal | ✅ Ideal |
| ⚠️ U.S. Cloud (Otter, Fireflies, Fathom) | SCCs + TIA + AVV required | Schrems II, CLOUD Act | ⚠️ Risky | ❌ Illegal without coverage |
A Practical Checklist for Every Meeting
Before the meeting
- Inform all participants: purpose, tool, server location, retention period, recipients
- Actively obtain and document consent (screenshot, email, form)
- Allow opt-out: It must be possible to participate without being recorded
- For EU customers: Ensure that the tool is GDPR-compliant (no töggl.ch, no U.S. tool without SCCs)
- AVV signed with a cloud provider and is currently in effect
During the meeting
- If a bot is visible (tl;dv, Sally, Fireflies): A brief announcement at the start of the meeting: «I’m recording this meeting with [Tool]»
- For invisible tools (Bliro, Jamie, Speakwise, Notiq): Announce verbally: «I’m using a transcription app today.»
- Do not process any sensitive information (patient data, client confidential information) using U.S. tools
After the meeting
- Do not share the transcript with anyone other than authorized individuals
- Monitor the retention period; delete data after it expires (recommended: 30–90 days)
- Process requests for erasure without delay (Art. 17 GDPR / Art. 32 DSG)
- No export of sensitive transcripts to U.S. cloud services without SCCs
Recommendations by Use Case
What is often underestimated: Choosing a tool is not purely a technical decision. It determines which legal requirements must be met and how much effort compliance management will entail. Processing data locally is always the simplest option because it eliminates most of the legal complexity.
DSG vs. GDPR: The Key Differences
| Aspect | GDPR (EU) | DSG (Switzerland) |
|---|---|---|
| Legal Basis for Recording | Art. 6, para. 1, subpar. a (Consent) | Art. 6 DSG + Art. 179bis StGB-CH |
| Duty to Disclose Information | Art. 13 of the GDPR | Art. 19 DSG |
| Right to be Forgotten | Art. 17 of the GDPR | Art. 32 DSG |
| Transfer to a Third Country | Art. 44 et seq. (SCCs, Adequacy Decision) | Art. 16 DSG |
| AI Applicability | EU AI Act (fully effective as of August 2026) | Effective immediately as of September 2023 |
| Biometric Data (Voice) | Art. 9 of the GDPR – Special Protection | Art. 5, para. 1, subpar. c of the DSG – data requiring special protection |
| Fines for Violations | Up to 20 million EUR or 4% in annual revenue | Up to 250,000 CHF |
| Swiss companies with EU customers | Also subject to the GDPR (market location principle, Art. 3 of the GDPR) | |
Summary of Key Points
→Voice = personal data, which may be biometric. Consent from all participants is required, not just that of the organizer (Otter.ai lawsuit 2025).
→What matters is the provider's corporate headquarters, not just the server location. U.S. corporations with servers in the EU are subject to the CLOUD Act.
→Local tools (Notiq, Whisper Notes, Speakwise, MacWhisper) eliminate the AVV requirement, transfers to third countries, and most of the complexity associated with compliance.
→Bliro and Jamie AI do not store audio. According to the provider, there is no criminal liability risk, but the GDPR transparency requirement still applies.
→töggl.ch is intended exclusively for the Swiss market. Do not use it for EU customers or EU partners.
→In short, Sally AI, Jamie AI, and HappyScribe are suitable for EU customers, with AVV and EU AI mode.
→U.S. tools (Otter.ai, Fireflies, Fathom) are not recommended for sensitive meetings: the CLOUD Act and Schrems II apply. SCCs and TIA are mandatory.
Disclaimer
This article was compiled manually based on my own knowledge and supplemented by AI-assisted research (Perplexity.ai and Claude), and then simplified using Deepl.com/write. The text is then reviewed and critically evaluated by two people of my choice. The image is AI-generated (Ideogram/Adobe Firefly). This article is purely educational and does not claim to be exhaustive. Please let me know if you notice any inaccuracies—thank you.
Sources (APA)
- EDÖB. (2023). Recording of Conversations. edoeb.admin.ch
- EDÖB. (2023). Update: The current data protection law is directly applicable to AI. edoeb.admin.ch
- Lutzabel. (2024). AI Transcription of Meetings: Legally Sound Without Consent? lutzabel.com
- b-pisec. (2024). Data Protection-Compliant Logging of Online Meetings. b-pisec.com
- The Data Protection Officer. (2023). The GDPR and Switzerland. die-datenschuetzerin.ch
- Data Protection News. (2025). U.S. Lawsuit Against AI Assistant for Meeting Transcription. datenschutzticker.de
- tl;dv. (2025). Privacy & Security. tldv.io
- Jamie AI. (2025). Top 5 GDPR Note-Takers in Europe. meetjamie.ai
- Sally AI. (2025). Security & GDPR Compliance. sally.io
- HappyScribe. (2025). Best GDPR-Compliant AI Note-Taking Apps. happyscribe.com
- töggl.ch. (2025). Privacy Policy & Terms and Conditions. töggl.ch
- Nextcloud. (2025). Nextcloud Talk: GDPR-Compliant Online Meetings. nextcloud.com
- eRecht24. (2024). GDPR-Compliant Video Conferencing. e-recht24.de
- Meetingmetrics.ai. (2025). Local Transcription vs. the Cloud: Where Is Your Meeting Data Safest? meetingmetrics.ai