Voice Dictation and GDPR: Where Does Your Voice Go?
When you dictate an email, a report or a legal brief, you are speaking aloud information that is often confidential: names, amounts, details of a case. The question is not only "is the transcription accurate?", but "where does my voice go, and who can access it?". That is exactly what GDPR governs. This guide explains what the regulation actually requires of a voice dictation tool, why server location is not enough, and how to recognise a compliant, sovereign solution.
Your voice is personal data
First point, often misunderstood: a voice recording is personal data under the GDPR as soon as it makes a person identifiable, directly or indirectly. The voice itself, a name spoken aloud, a client number mentioned out loud: all of it falls under the regulation. GDPR therefore applies to voice dictation the moment a human speaks.
Does that make it "sensitive" data? Not automatically, and the nuance matters. According to the CNIL, the French data protection authority, a voice only becomes biometric data (a sensitive category, covered by Article 9 of the GDPR) when a system uses it to recognise or authenticate a speaker based on their vocal characteristics. A dictation tool does not do this: it turns speech into text, it does not identify anyone by their voice. The practical consequence:
- The audio is personal data, but not biometric data, because there is no voice identification.
- The dictated content, on the other hand, can be anything but trivial: a medical file mentioned, banking details, a client's name and the nature of their dispute. That is where the real risk sits.
In other words, the danger is not that the tone of your voice could identify you; it is that what you dictate ends up stored, reused, or accessible to a third party. Hence the importance of knowing exactly what the tool does with your audio.
What GDPR actually requires of a voice dictation tool
GDPR is not just a consent banner. For a service that transcribes your voice, six obligations really matter:
- A clear purpose and legal basis. Your data is used only to produce your transcription, nothing else.
- Data minimisation. The tool should process only what is strictly necessary. The CNIL, in its white paper on voice assistants, even recommends sending to the servers only the data that is indispensable.
- Storage limitation. GDPR forbids keeping data longer than necessary. For dictation, the best option is simple: zero retention, the audio is deleted as soon as it is transcribed.
- No reuse. Your voice and your text must not be used to train AI models without your consent.
- A governed processor. The vendor must offer you a data processing agreement (DPA, Article 28 of the GDPR) that lists its sub-processors and their safeguards.
- Security and controlled transfers. Encryption, serious technical measures, and above all a strict framework if data leaves the European Union (Articles 44 and following).
These criteria are verifiable. A serious vendor answers each one in writing. It is precisely the last point, transfers outside the EU, that most often falls short, and it is the most misunderstood.
One useful clarification, to clear up a common confusion: the AI Act, the European regulation on artificial intelligence, does not deal with any of this. It governs what an AI system is allowed to do, not where your data is processed or which jurisdiction the vendor answers to. We set out that division of labour in our article on what the AI Act actually requires of your AI tools.
The vendor is your processor: what Article 28 must actually say
This is the part most buyers skip, and it is the part that carries the liability. When you dictate professional content, you are the controller of that data and the vendor is your processor. Article 28 of the GDPR does not leave that relationship to goodwill: it requires a written contract, the data processing agreement, and it lists what that contract must contain.
When you read a DPA, these are the clauses that matter in practice:
- Documented instructions. The vendor may process your data only on your instructions, and for the purpose you defined. That single clause is what forbids reuse for model training.
- Confidentiality of personnel. Anyone with access to the data must be bound by a confidentiality obligation.
- Security measures under Article 32. Encryption in transit and at rest, access control, and a stated ability to restore availability after an incident.
- Sub-processors, named and authorised. The vendor cannot bring in another provider without your authorisation, and must inform you before any change. A DPA that does not name the chain is not doing its job.
- Assistance with data subject rights. If someone asks you for access or erasure, the vendor must help you answer within the deadline.
- Deletion or return at the end of the contract, and the audit information you need to verify all of the above.
A vendor that answers "we are GDPR compliant" without producing that document has not answered. Ask for the DPA before signing, not after an incident.
Retention, and what becomes of your rights
Storage limitation is the obligation dictation tools fail most often, because retaining audio is convenient for the vendor: it feeds quality monitoring and model improvement. GDPR asks a blunt question in return, how long is the audio necessary for the purpose you agreed to, and for transcription the honest answer is the few seconds it takes to produce the text. Anything beyond that is a retention period that has to be justified, documented and disclosed.
Retention also determines how workable your rights are. The right of access, rectification, erasure and portability applies to whatever the vendor holds. That has a practical consequence worth understanding: with a genuine zero retention policy, there is nothing on the server to access or erase, because the audio no longer exists and the text sits on your own machine. Where a tool keeps a history of your dictations, those rights become real work, and the vendor must be able to honour them within one month.
Transfers outside the EU, and the jurisdiction question
Articles 44 and following govern what happens when data leaves the European Union. In practice, a US vendor relies either on the Data Privacy Framework, the adequacy decision adopted on 10 July 2023, or on the European Commission's standard contractual clauses. Either way the transfer becomes lawful, and that is genuinely useful.
It is also only half the analysis. A separate question sits underneath it: which state can compel the vendor to hand over your data once it holds it. The US Cloud Act reaches any provider subject to US jurisdiction regardless of where the servers are, which is why "hosted in Europe" and "beyond the reach of US authorities" are not the same statement. That is a subject in itself, and we cover it in full, with the case law, the pending appeal against the DPF and the four checks to run on any vendor, in our guide on why hosting in Europe is not enough.
What GDPR asks of you, not just of the tool
Choosing a compliant vendor does not discharge your own obligations. Three of them apply as soon as you dictate professional content:
- Your record of processing activities (Article 30). If you dictate content containing personal data, the tool belongs in your record: purpose, categories of data, the vendor as processor, retention period, and any transfer outside the EU. It is a line in a table, not a project, but an inspection will ask for it. Article 30(5) exempts organisations under 250 employees, but the exemption falls away where the processing is more than occasional or involves confidential client data, which is exactly the case for a practice that dictates every day.
- A data protection impact assessment (Article 35), or not. A DPIA is required where processing is likely to result in a high risk to people's rights. Dictation that simply converts your own speech into text, with no retention and no biometric identification, does not usually meet that threshold on its own. Dictating sensitive data at scale, health information for instance, changes the calculation, and there the assessment is on you rather than on your vendor.
- The people you talk about. When you dictate a client's file, that client is a data subject too. Your existing privacy notice generally covers it, but it should reflect the reality that a processor transcribes the content. The same applies to a prospect whose meeting notes you dictate, which we cover in our guide to voice dictation for sales teams.
Professions bound by confidentiality: lawyers, notaries, accountants
For a lawyer, a notary or a chartered accountant, GDPR comes with an even stricter obligation: professional secrecy. Dictating a client's name and the nature of their case into a tool that could be compelled to disclose that data means exposing information covered by professional privilege.
The French National Bar Council (CNB) made this clear in its ethics guide on artificial intelligence: the use of AI tools can never justify lifting professional secrecy, and you must never entrust data covered by it to a consumer generative AI. The guide also stresses that solutions hosted in the European Union, which do not reuse queries to train their models, present a markedly lower risk profile than consumer tools.
That is exactly the test to apply to a dictation tool: processing in the EU, zero retention, no reuse, and a vendor that is not subject to extraterritorial legislation. We go into this in detail for law firms in our dedicated guide on voice dictation for lawyers.
5 questions to ask before choosing a voice dictation tool
A simple way to decide: ask any vendor these five questions. The answers should be clear and in writing.
- Do you keep my audio and my transcriptions? The right answer is: no, immediate deletion after transcription.
- Is my data used to train your models? The right answer is: no.
- Where is my data processed, and by which company? Look for processing in the EU by a European company, not just a "datacenter in Europe".
- Are you subject to the Cloud Act or another extraterritorial law? A European vendor not owned by a US parent company can answer no. If the answer is evasive, our guide on the Cloud Act sets out how to verify it yourself.
- Do you offer a DPA compliant with Article 28 of the GDPR? Essential for professional use.
The strictest option: 100% local
Let's be honest: if you want the absolute guarantee that your voice never leaves your computer, the most protective solution is not the cloud, it is 100% local processing. Nothing goes online: neither GDPR nor the Cloud Act is even in play, since no data is sent to a third party. Open source tools like Handy (free, open source licensed, for Windows, macOS and Linux) run the transcription directly on your machine, with nothing sent to a server.
The trade-off is real, and we cover it in our comparison local vs cloud voice dictation: 100% local most often comes down to a raw transcript, without AI cleanup or formatting, and it demands a fairly powerful machine. For many professionals, the challenge is therefore to regain the comfort of the cloud, clean text, in any application and on any computer, without giving up sovereignty. That is exactly what Fast Dictate aims for.
The Fast Dictate approach
Fast Dictate is a European alternative built to answer these questions head-on:
- Zero data retention on every plan. Your audio is transcribed and then immediately deleted, and is never reused to train models.
- Pro plan: processing exclusively in France, on ISO/IEC 27001-certified servers, outside the scope of the US Cloud Act, with an advanced GDPR DPA. Designed for lawyers, notaries and anyone handling confidential files.
- Free and Standard plans: fast international infrastructure, still with zero data retention.
- Works everywhere: Word, Gmail, Notion, your browser, any text field, with a single shortcut on Windows and Mac.
- Free plan: 2,000 words per week, no credit card.
Privacy should not be a paid option that nobody explains.
On every plan, nothing is kept. And when the work is confidential, the Pro plan keeps your data in France, under European law alone. You keep the speed of the cloud without giving up sovereignty. See our pricing.
Frequently asked questions
Is voice dictation GDPR compliant?
It can be. A voice recording is personal data, so GDPR applies. A compliant tool rests on a clear purpose, data minimisation, limited storage (ideally zero retention), a processor governed by a DPA, security measures, and a strict framework for transfers outside the EU. Compliance depends on the vendor, not on the technology itself.
Is the voice sensitive data under GDPR?
A voice recording is always personal data. It only becomes sensitive (biometric) when it is used to recognise or authenticate a person from their voice. A dictation tool simply transcribes: it does no biometric identification. The dictated content, however, can be highly confidential.
Do I need a DPIA to use a voice dictation tool?
Usually not on its own. A data protection impact assessment is required where processing is likely to result in a high risk to people's rights. Dictation that converts your own speech into text, with zero retention and no biometric identification, does not normally reach that threshold. Dictating sensitive data at scale, health data for instance, changes the assessment, and it falls to you as controller rather than to the vendor.
Where does Fast Dictate process my data?
Zero data retention on every plan: the audio is transcribed and then immediately deleted, never reused for training. The Pro plan processes your data exclusively in France on ISO 27001 servers, outside the scope of the Cloud Act, with an advanced GDPR DPA. The Free and Standard plans run on fast international infrastructure.
Related articles
Reference guideHow Does Speech Recognition Work? The 2026 Guide
By Pierrick Michel · June 2026