On-Premise Transcription for GDPR: What Your DPO Will Ask

Before a transcription tool goes live, the data protection officer asks where recordings go, who processes them and how long they stay. Here are the questions and the answers an on-premise deployment gives.

By ·

Meeting recordings are personal data almost by definition. A recording carries voices that identify the speakers, names spoken in the course of the conversation, opinions people expressed on the assumption the room was private, and sometimes health details or client matters raised in passing. Once that recording is transcribed, summarized, and filed, the same personal data exists in three or four more places than it did before.

This is why the data protection officer's questions decide whether a transcription tool goes live at all, not just how it gets configured. Sales teams and IT often shortlist a tool on features and price, then bring the DPO in at the end and watch the project fail or slip when the answers do not hold up. Working through these questions before shortlisting, rather than after, is the difference between a rollout that takes weeks and one that stalls for months while contracts get renegotiated.

Where is the audio processed?

This is the first question a DPO asks, and it is usually decisive on its own. With a cloud transcription service, the recording leaves your network the moment it is uploaded and is processed on infrastructure that belongs to the vendor, or to a subprocessor the vendor has contracted. From that point, the recording exists somewhere you do not operate and cannot fully audit. The comparison of self-hosted vs. cloud transcription sets the two architectures side by side.

With an on-premise deployment, processing happens only on your own systems. Scriber runs on a Linux server inside your infrastructure; nothing about the transcription pipeline calls out to an external service, and Determin never holds a copy of a recording, a transcript, or a summary at any point. The answer to "where is the audio processed" is simply: here, on the hardware you already control.

Who is the processor?

Under GDPR Article 28, when a vendor processes personal data on your behalf, that vendor is a processor and you need a data processing agreement (Auftragsverarbeitungsvertrag) with them before any data flows. You remain responsible for the whole chain: your processor's subprocessors, their security measures, and their own contracts all become part of what you have to be able to account for.

That chain is exactly what a self-hosted deployment removes for this workload. No cloud processor touches the recordings, because no recording leaves your network in the first place. There is no processing chain to negotiate, contract, or audit here not because the legal requirement disappears, but because the scenario it applies to does not arise. This supports your compliance work by removing an entire category of vendor risk from the assessment, though it does not substitute for reviewing every other system that touches the same recordings.

Does data leave the EU?

Third-country transfer rules adequacy decisions, standard contractual clauses, transfer impact assessments apply when personal data crosses a border to a country outside the EU, or is accessible from one. These assessments are involved: they require documenting the safeguard relied on, checking it still holds, and revisiting it if the vendor changes infrastructure.

With processing that happens entirely on-premise, no transfer takes place not to a country outside the EU, and not to another company's servers inside it either. The recording, the transcript, and the minutes stay on the server you installed. This section of the assessment becomes short: there is no transfer to document because there is no transfer.

How long is data kept and who can delete it?

Retention periods, backup schedules, and deletion procedures for meeting recordings often need to match a specific policy: a works council agreement, a client confidentiality clause, or a sector-specific retention rule. When a cloud vendor holds the data, enforcing that policy means trusting their deletion process and their backup retention, which you can rarely verify directly.

On a self-hosted installation, storage, backup, and retention sit on infrastructure you already operate, under rules you set. Deletion means deletion on systems you control removing a file from your own storage not a request submitted to a vendor and taken on faith. If your policy says a recording is deleted after a fixed period, or on request, that is a matter of local storage administration, not a support ticket to an external party.

What goes into the records of processing?

Article 30 requires a record of processing activities (Verzeichnis von Verarbeitungstätigkeiten) describing the purpose of each processing operation, the categories of data and data subjects involved, the recipients data is disclosed to, and the retention period applied. For a cloud transcription tool, this entry typically lists an external recipient, a subprocessor chain, and a cross-border transfer basis.

For an on-premise deployment used for meeting transcription, the same entry stays short: the purpose is transcription and minute-taking for internal meetings, the systems involved are the customer's own, and there are no external recipients for this particular workload. Keep the entry accurate to your actual setup rather than treating any description here as a ready-made template; the record still has to reflect what you actually run.

Questions to ask any transcription vendor

Whatever tool you evaluate, cloud or on-premise, the same short list of questions surfaces what actually matters for the DPO's assessment:

  • Where physically is the audio processed, and on whose infrastructure?
  • Does the vendor retain a copy of the recording, transcript, or summary after processing, and for how long?
  • What subprocessors are involved, and where are they located?
  • How is deletion actually executed on request, on a schedule, and on which systems?
  • Does the tool keep working, and keep data in place, if the network connection to the vendor is unavailable?

A vendor that can answer all five plainly, without qualification, has made the DPO's job considerably easier regardless of which architecture they use.

If your organization's honest answer to those five questions needs to be "on our own servers, with no external copy," on-premise transcription is built for exactly that posture. Public sector bodies working through the same questions under additional procurement constraints can see how this applies to their sector at transcription for public sector. To talk through your specific setup with us directly, get in touch.

Ready to See Scriber on Your Own Servers?

Tell us about your infrastructure and workload, and we will answer with a concrete recommendation.