Sovereignty
GDPR and recording meetings: what the law actually says
Consent, retention periods, the right to erasure: what you need to know to record professional conversations in compliance.

Recording professional conversations with an AI raises fair questions. Here is a clear legal overview, based on the GDPR and on French employment law.
Note: this article is informative and does not constitute legal advice. Speak to your data protection officer or to a specialist lawyer about your own situation.
Is consent mandatory?
Recording a conversation means processing personal data: voices, the identity of participants. The GDPR requires a legal basis for that processing. The two most common are:
- consent, where participants are informed and agree to the recording
- legitimate interest, where the company can justify that recording is necessary to its activity, for instance to record decisions
In practice we recommend always informing participants that a recording tool is in use. It is good practice, and it builds trust.
Retention period
The GDPR requires that data is not kept beyond what is necessary. With Gilbert:
- raw audio can be deleted automatically once the deliverable has been generated
- the deliverables are kept for as long as you decide
- deletion is irreversible, with no shadow copy
The right to erasure
Any participant can ask for their data to be deleted. Gilbert supports this natively: one click erases all data tied to a conversation or to a specific participant.
What about employment law?
Recording employees at work is governed by the French labour code. The key points:
- Prior information: employees must be told that a recording tool is used
- A legitimate purpose: the recording must serve a clear professional objective, such as minuting decisions
- Proportionality: the tool must not be used to monitor employees
- Works council consultation: in companies with 50 employees or more, the works council must be informed and consulted
Good practice
- Write a usage policy explaining clearly how the tool is used and why
- Inform people at each meeting: a simple line at the start is enough
- Give people control: participants must be able to ask not to be recorded
- Set the retention period: do not keep data longer than necessary
- Choose sovereign hosting: it is the heart of GDPR compliance
Why Gilbert makes compliance easier
Gilbert was designed from the start to be GDPR compliant:
- hosting entirely in France, on OVHcloud
- end-to-end encryption
- deletion on request, irreversible
- no use of your data for training
- access logs and a built-in audit trail
Compliance is not a constraint. It is a competitive advantage, and a mark of trust for your teams and your clients.



