AI Meeting Transcription: A Comparison of 15 Apps That Comply with Data Privacy Regulations

These days, many of us transcribe meetings using AI as a matter of course. Some app that automatically generates the text

These days, many of us transcribe meetings using AI as a matter of course—some app that automatically generates the text. What is often overlooked is that a person’s voice is legally considered personal data. When used for biometric analysis, it is even classified as special-category data under Article 9 of the GDPR.

In Switzerland and the EU, the recording of meetings is subject to a dual legal framework: criminal law (Art. 179bis/ter of the Swiss Criminal Code (StGB-CH) and § 201 of the German Criminal Code (StGB-DE)) and data protection law (GDPR/DSG). In most cases, the consent of all participants is mandatory.

The revised Swiss Data Protection Act has been in effect since September 2023. According to the FDPIC, it applies directly to AI-supported data processing. Swiss companies with EU customers must also comply with the GDPR. This affects virtually every consultant in the DACH market.

An important principle that many overlook: What matters is the tool provider’s headquarters, not just the server location. U.S. companies with servers in the EU remain subject to the U.S. CLOUD Act.

Four Basic Rules That Always Apply

1. Providing advance notice is mandatory

Before any recording or transcription takes place, all participants must be informed of the purpose, the tool being used, the server location, the retention period, and the recipients of the data. The right to object must be clearly communicated.

2. Actively obtain consent

Consent must be active, voluntary, informed, and unambiguous. Merely remaining silent is not sufficient. Consent must be obtained before recording begins. Anyone who does not wish to be recorded must still be able to participate in the meeting.

3. A visible pop-up does not replace consent

Tools such as tl;dv, Sally, or Fireflies join the meeting as identifiable bots. This creates transparency, but does not replace actively obtained consent. The GDPR additionally requires compliance with Article 5(1)(a), Article 13, and Article 6.

4. Consent from all participants, not just the organizer

In 2025, a lawsuit was filed against Otter.ai because meeting participants without an Otter account were not informed that their conversations were being used to train the AI. The consent of the meeting organizer alone is not sufficient.

15 Data Protection-Compliant Tools in 5 Groups

Group A: Local / On-Device (maximum data protection)

These tools process data entirely on the device. No cloud-related risks, no AVV required, no data transfers to third countries.

Notiq (iOS) processes 100% locally, stores audio on the device with AES-256 encryption, requires no account, and is free. Direct link: notiq-ai.app

Whisper Notes (iOS/Mac) works entirely offline, stores only text locally—no servers, no analytics—and costs a one-time fee of $6.99. Direct link: whispernotes.app

Speakwise (iOS) processes audio offline on the device with over 95% accuracy and never uses audio data for AI training. Direct link: speakwiseapp.com

MacWhisper (iOS) offers local transcription using Whisper models for free with its basic features; an optional cloud extension is available. Direct link: macwhisper.goodsnooze.com

Group B: Swiss Cloud (DSG-compliant, no CLOUD Act)

These tools process data on Swiss servers. They comply with the DSG, but should be used with caution for EU customers.

Meeting Metrics (Web/iOS/Android) stores data on Swiss servers in St. Gallen, is DSG-compliant, supports Swiss German, and is free from CLOUD Act risks. Freemium model; 5 free meetings. Direct link: meetingmetrics.ai

töggl.ch (web app, not a native iOS/Android app) processes data exclusively on Swiss servers and offers excellent Swiss German/dialect recognition based on SRF training material. Important limitation: According to the Terms of Service, töggl is explicitly limited to the Swiss market. The processing of data subject to the GDPR is excluded. Do not use for EU customers or EU partners. Direct link: töggl.ch

Group C: EU Cloud (GDPR-compliant, headquartered in Europe)

These tools are hosted and processed within the EU. A data processing agreement (DPA) pursuant to Article 28 of the GDPR must be concluded.

tl;dv (iOS/Android/Web) hosts all data in European data centers: Google Cloud Platform, AWS, and Hetzner, all exclusively within the EEA. You can choose between EU and U.S. AI hosting. For meetings involving sensitive data: Enable EU mode. SOC 2 Type 1, EU AI Act compliant, dedicated private AI hosting available upon request, no training with customer data. Freemium; Pro plan approx. 25 USD/month. Direct link: tldv.io

Bliro (iOS app + desktop) does not store any audio. Only real-time transcripts are stored in RAM on EU servers in Frankfurt and Munich. According to the provider, this means the offense under Section 201 of the German Criminal Code (StGB) does not apply. The obligation to maintain transparency toward participants remains in effect. Made in Germany. Direct link: bliro.io

Jamie AI (iOS/macOS/Windows) operates without a visible bot in the meeting, a key advantage for confidential conversations. Audio data is immediately and permanently deleted after transcription; only the transcript remains. Servers are located exclusively in Frankfurt and are ISO 27001 and DORA-certified; no training is conducted using user data. Freemium; Pro plan costs approximately 24 EUR/month. Direct link: meetjamie.ai

Sally AI (iOS/Android/Web) is hosted exclusively in German data centers, is ISO 27001 and SOC 2 certified, deliberately avoids sentiment analysis, and does not train on user data. The bot is visible, which simplifies consent documentation. Freemium; Pro plan approx. 29 EUR/month. Direct link: sally.io

HappyScribe (Web/iOS/Android) uses EU data centers in Barcelona, is SOC 2 Type II and ISO 27001 certified, and supports over 120 languages. Freemium; Pro starting at approximately 17 EUR/month. Direct link: happyscribe.com

Group D: Self-Hosted (maximum control)

Nextcloud Talk (iOS/Android) is open source, allows for full self-hosting on your own server, does not share metadata, and has a built-in consent feature for recordings. Recommended by German data protection authorities. Free. Direct link: nextcloud.com/de/talk

Group E: U.S.-based tools (can be used in compliance with the GDPR with some effort)

These three primarily process data on U.S. servers. Under the post-Schrems II ruling, the U.S. is not considered a safe third country. The U.S. CLOUD Act allows U.S. authorities to access data even if the servers are located in the EU, as long as the parent company is based in the U.S. Standard Contractual Clauses (SCCs) and a Transfer Impact Assessment (TIA) are mandatory for these tools.

Otter.ai (iOS/Android/Web): AWS USA, DPF-certified, SCCs available, no EU hosting. 2025: Lawsuit filed due to lack of consent from non-account participants.

Fireflies.ai (iOS/Android/Web): AWS USA; EU hosting available only for Enterprise customers upon request; SCCs and TIA required; visible bot.

Fathom AI (iOS/Android/Web): Hosted in the U.S.; no known hosting in the EU; DPF-certified; SCCs and TIA required for EU data.

A Practical Checklist for Every Meeting

Before the meeting:

  • Inform all participants: purpose, tool, server location, retention period, recipients
  • Actively obtain and document consent (screenshot, email, form)
  • Allow opt-out: It must be possible to participate without being recorded
  • For EU customers: Ensure that the tool is GDPR-compliant (no töggl.ch, no U.S. tool without SCCs)
  • AVV signed with a cloud provider and is currently in effect

During the meeting:

  • When the bot is visible (tl;dv, Sally, Fireflies): A brief announcement at the start of the meeting
  • For invisible tools (Bliro, Jamie, Speakwise, Notiq): Announce verbally: «I’m using a transcription app today.»
  • Do not process any sensitive information (patient data, client confidential information) using U.S. tools

After the meeting:

  • Do not share the transcript with anyone other than authorized individuals
  • Monitor the retention period; delete data after it expires (recommended: 30–90 days)
  • Process requests for erasure without delay (Art. 17 GDPR / Art. 32 DSG)
  • No export of sensitive transcripts to U.S. cloud services without SCCs

Recommendations by Use Case

Confidential meetings in Switzerland (government agencies, doctors, lawyers): Notiq or Whisper Notes. 100% on-premises, no account, no cloud.

CH meetings with Swiss German participants: Meeting Metrics or töggl.ch. CH server, dialect intensity. Note: töggl is for meetings within Switzerland only.

Consulting with EU clients: tl;dr (EU AI mode). GDPR-compliant, EU hosting, SOC 2, and AVV available.

Discreet recording without a visible bot: Jamie AI. Bot-free, Frankfurt, audio deleted immediately.

The simplest solution with no consent issues: Bliro. No audio is stored; made in Germany.

Teams with extensive language needs (120+ languages): HappyScribe. EU data centers, SOC 2, ISO 27001.

Enterprise / In-House IT Infrastructure: Nextcloud Talk (Self-Hosted). Maximum control, open source, consent feature.

DSG vs. GDPR: The Key Differences

Legal basis for recording: Art. 6(1)(a) GDPR (consent) / Art. 6 DSG + Art. 179bis StGB-CH Duty to provide information: Art. 13 GDPR / Art. 19 DSG Right to erasure: Art. 17 GDPR / Art. 32 DSG Transfer to third countries: Art. 44 et seq. GDPR (SCCs, Adequacy) / Art. 16 DSG Applicability of AI: EU AI Act (fully effective as of Aug. 2026) / Directly applicable as of September 2023 Biometric data (voice): Art. 9 GDPR (special protection) / Art. 5(1)(c) DSG (data requiring special protection) Fines: Up to 20 million EUR or 4% of annual turnover / Up to 250,000 CHF Swiss companies with EU customers: Also subject to the GDPR (place of market principle)

Summary of Key Points

  • Voice = personal data and, where applicable, biometric data. Consent from all participants is required, not just that of the organizer.
  • What matters is the provider's corporate headquarters, not just the server location. U.S. corporations with servers in the EU are subject to the CLOUD Act.
  • Local tools (Notiq, Whisper Notes, Speakwise, MacWhisper) eliminate the AVV requirement, transfers to third countries, and most of the complexity associated with compliance.
  • Bliro and Jamie AI are the only options that do not store audio. According to the provider, there is no criminal liability, but the transparency requirement remains.
  • töggl.ch is intended exclusively for the Swiss market: Do not use it for EU customers or EU partners.
  • In short, Sally AI, Jamie AI, and HappyScribe are suitable for EU customers, with AVV and EU AI mode.
  • U.S. tools (Otter.ai, Fireflies, Fathom) are not recommended for sensitive meetings: the CLOUD Act and Schrems II apply.

And that’s why I remain convinced: The future no longer lies in blindly trusting just any cloud service, but in the mindful use of data and technology. Those who choose the right tools today protect not only themselves but also their customers. Feel free to reach out via CONTACT

Disclaimer: This article was compiled manually based on my own knowledge and supplemented by AI-assisted research (Perplexity.ai and Claude), and then simplified using Deepl.com/write. The text is then reviewed and critically evaluated by two people of my choice. The image is AI-generated (Ideogram/Adobe Firefly). This article is purely educational and does not claim to be exhaustive. Please let me know if you notice any inaccuracies—thank you.

 

More Information

EDÖB. (2023). Recording of Conversations. https://www.edoeb.admin.ch/de/aufzeichnung-von-gespraechen

EDÖB. (2023). Update: The current data protection law is directly applicable to AI. https://www.edoeb.admin.ch/de/update-geltendes-datenschutzgesetz-ist-auf-ki-direkt-anwendbar

Lutzabel. (2024). AI Transcription of Meetings: Legally Sound Without Consent? https://www.lutzabel.com/artikel/ki-transkription-von-meetings-datenschutz-201-stgb-und-die-grenzen-der-einwilligung/

b-pisec. (2024). Data Protection-Compliant Logging of Online Meetings. https://b-pisec.com/news/datenschutzkonforme-protokollierung-von-online-meetings/

die-datenschuetzerin.ch. (2023). The GDPR and Switzerland. https://die-datenschuetzerin.ch/die-dsgvo-und-die-schweiz/

Data Protection News. (2025). U.S. Lawsuit Against AI Assistant for Meeting Transcription. https://www.datenschutzticker.de/2025/10/us-klage-gegen-ki-assistent-zur-meeting-transkription/

tl;dv. (2025). Privacy & Security. https://tldv.io/de/privacy/

Jamie AI. (2025). Top 5 GDPR Note-Takers in Europe. https://www.meetjamie.ai/blog/gdpr-note-takers-in-europe

Sally AI. (2025). Security & GDPR Compliance. https://www.sally.io/gdpr-and-security

HappyScribe. (2025). Best GDPR-Compliant AI Note-Taking Apps. https://www.happyscribe.com/de/blog/beste-dsgvo-konforme-ki-notizassistenten

töggl.ch. (2025). Privacy Policy. https://töggl.ch

Nextcloud. (2025). Nextcloud Talk: GDPR-Compliant Online Meetings. https://nextcloud.com/de/talk/

Contents

More on this...

Do you want to understand how to use AI meaningfully, safely, and responsibly?

Technology provides a clue
But no judgments. The crucial point is,
how we deal with uncertainty.

Roger Basler de Roca

More articles

AI in construction: Why Swiss companies fail at data storage

The short answer: Swiss construction companies rarely use AI productively because their data is not

AI expert for workshops in Switzerland: Roger Basler de Roca

"We are looking for an AI expert for a workshop in Switzerland. Who can you recommend?"

Beware of ChatGPT phishing: new emails with false information are circulating.

An email with the ChatGPT logo, an invoice, and a large green button often looks suspicious today.