Privacy & GDPR

Voice Dictation and GDPR: Where Does Your Voice Go?

When you dictate an email, a report or a legal brief, you are speaking aloud information that is often confidential: names, amounts, details of a case. The question is not only "is the transcription accurate?", but "where does my voice go, and who can access it?". That is exactly what GDPR governs. This guide explains what the regulation actually requires of a voice dictation tool, why server location is not enough, and how to recognise a compliant, sovereign solution.

Your voice is personal data

First point, often misunderstood: a voice recording is personal data under the GDPR as soon as it makes a person identifiable, directly or indirectly. The voice itself, a name spoken aloud, a client number mentioned out loud: all of it falls under the regulation. GDPR therefore applies to voice dictation the moment a human speaks.

Does that make it "sensitive" data? Not automatically, and the nuance matters. According to the CNIL, the French data protection authority, a voice only becomes biometric data (a sensitive category, covered by Article 9 of the GDPR) when a system uses it to recognise or authenticate a speaker based on their vocal characteristics. A dictation tool does not do this: it turns speech into text, it does not identify anyone by their voice. The practical consequence:

In other words, the danger is not that the tone of your voice could identify you; it is that what you dictate ends up stored, reused, or accessible to a third party. Hence the importance of knowing exactly what the tool does with your audio.

What GDPR actually requires of a voice dictation tool

GDPR is not just a consent banner. For a service that transcribes your voice, six obligations really matter:

These criteria are verifiable. A serious vendor answers each one in writing. It is precisely the last point, transfers outside the EU, that most often falls short, and it is the most misunderstood.

One useful clarification, to clear up a common confusion: the AI Act, the European regulation on artificial intelligence, does not deal with any of this. It governs what an AI system is allowed to do, not where your data is processed or which jurisdiction the vendor answers to. We set out that division of labour in our article on what the AI Act actually requires of your AI tools.

The vendor is your processor: what Article 28 must actually say

This is the part most buyers skip, and it is the part that carries the liability. When you dictate professional content, you are the controller of that data and the vendor is your processor. Article 28 of the GDPR does not leave that relationship to goodwill: it requires a written contract, the data processing agreement, and it lists what that contract must contain.

When you read a DPA, these are the clauses that matter in practice:

A vendor that answers "we are GDPR compliant" without producing that document has not answered. Ask for the DPA before signing, not after an incident.

Retention, and what becomes of your rights

Storage limitation is the obligation dictation tools fail most often, because retaining audio is convenient for the vendor: it feeds quality monitoring and model improvement. GDPR asks a blunt question in return, how long is the audio necessary for the purpose you agreed to, and for transcription the honest answer is the few seconds it takes to produce the text. Anything beyond that is a retention period that has to be justified, documented and disclosed.

Retention also determines how workable your rights are. The right of access, rectification, erasure and portability applies to whatever the vendor holds. That has a practical consequence worth understanding: with a genuine zero retention policy, there is nothing on the server to access or erase, because the audio no longer exists and the text sits on your own machine. Where a tool keeps a history of your dictations, those rights become real work, and the vendor must be able to honour them within one month.

Transfers outside the EU, and the jurisdiction question

Articles 44 and following govern what happens when data leaves the European Union. In practice, a US vendor relies either on the Data Privacy Framework, the adequacy decision adopted on 10 July 2023, or on the European Commission's standard contractual clauses. Either way the transfer becomes lawful, and that is genuinely useful.

It is also only half the analysis. A separate question sits underneath it: which state can compel the vendor to hand over your data once it holds it. The US Cloud Act reaches any provider subject to US jurisdiction regardless of where the servers are, which is why "hosted in Europe" and "beyond the reach of US authorities" are not the same statement. That is a subject in itself, and we cover it in full, with the case law, the pending appeal against the DPF and the four checks to run on any vendor, in our guide on why hosting in Europe is not enough.

What GDPR asks of you, not just of the tool

Choosing a compliant vendor does not discharge your own obligations. Three of them apply as soon as you dictate professional content:

Professions bound by confidentiality: lawyers, notaries, accountants

For a lawyer, a notary or a chartered accountant, GDPR comes with an even stricter obligation: professional secrecy. Dictating a client's name and the nature of their case into a tool that could be compelled to disclose that data means exposing information covered by professional privilege.

The French National Bar Council (CNB) made this clear in its ethics guide on artificial intelligence: the use of AI tools can never justify lifting professional secrecy, and you must never entrust data covered by it to a consumer generative AI. The guide also stresses that solutions hosted in the European Union, which do not reuse queries to train their models, present a markedly lower risk profile than consumer tools.

That is exactly the test to apply to a dictation tool: processing in the EU, zero retention, no reuse, and a vendor that is not subject to extraterritorial legislation. We go into this in detail for law firms in our dedicated guide on voice dictation for lawyers.

5 questions to ask before choosing a voice dictation tool

A simple way to decide: ask any vendor these five questions. The answers should be clear and in writing.

  1. Do you keep my audio and my transcriptions? The right answer is: no, immediate deletion after transcription.
  2. Is my data used to train your models? The right answer is: no.
  3. Where is my data processed, and by which company? Look for processing in the EU by a European company, not just a "datacenter in Europe".
  4. Are you subject to the Cloud Act or another extraterritorial law? A European vendor not owned by a US parent company can answer no. If the answer is evasive, our guide on the Cloud Act sets out how to verify it yourself.
  5. Do you offer a DPA compliant with Article 28 of the GDPR? Essential for professional use.

The strictest option: 100% local

Let's be honest: if you want the absolute guarantee that your voice never leaves your computer, the most protective solution is not the cloud, it is 100% local processing. Nothing goes online: neither GDPR nor the Cloud Act is even in play, since no data is sent to a third party. Open source tools like Handy (free, open source licensed, for Windows, macOS and Linux) run the transcription directly on your machine, with nothing sent to a server.

The trade-off is real, and we cover it in our comparison local vs cloud voice dictation: 100% local most often comes down to a raw transcript, without AI cleanup or formatting, and it demands a fairly powerful machine. For many professionals, the challenge is therefore to regain the comfort of the cloud, clean text, in any application and on any computer, without giving up sovereignty. That is exactly what Fast Dictate aims for.

The Fast Dictate approach

Fast Dictate is a European alternative built to answer these questions head-on:

Privacy should not be a paid option that nobody explains.

On every plan, nothing is kept. And when the work is confidential, the Pro plan keeps your data in France, under European law alone. You keep the speed of the cloud without giving up sovereignty. See our pricing.

Frequently asked questions

Is voice dictation GDPR compliant?

It can be. A voice recording is personal data, so GDPR applies. A compliant tool rests on a clear purpose, data minimisation, limited storage (ideally zero retention), a processor governed by a DPA, security measures, and a strict framework for transfers outside the EU. Compliance depends on the vendor, not on the technology itself.

Is the voice sensitive data under GDPR?

A voice recording is always personal data. It only becomes sensitive (biometric) when it is used to recognise or authenticate a person from their voice. A dictation tool simply transcribes: it does no biometric identification. The dictated content, however, can be highly confidential.

Do I need a DPIA to use a voice dictation tool?

Usually not on its own. A data protection impact assessment is required where processing is likely to result in a high risk to people's rights. Dictation that converts your own speech into text, with zero retention and no biometric identification, does not normally reach that threshold. Dictating sensitive data at scale, health data for instance, changes the assessment, and it falls to you as controller rather than to the vendor.

Where does Fast Dictate process my data?

Zero data retention on every plan: the audio is transcribed and then immediately deleted, never reused for training. The Pro plan processes your data exclusively in France on ISO 27001 servers, outside the scope of the Cloud Act, with an advanced GDPR DPA. The Free and Standard plans run on fast international infrastructure.

Try Fast Dictate for free →

Related articles

Reference guide

How Does Speech Recognition Work? The 2026 Guide

By Pierrick Michel · June 2026