All posts
PrivacyApril 28, 20269 min read

GDPR-compliant interview transcription in 2026: a practical guide

By Tyler Knell

Founder, HireScribe

Why this conversation got louder

GDPR has been law since 2018 but enforcement against AI tooling specifically accelerated through 2024 and 2025. The Italian data protection authority fined OpenAI €15M in late 2024 over ChatGPT data handling. The Irish DPC opened active investigations into multiple US meeting-transcription vendors in 2025. Several mid-market staffing firms in the UK and Germany quietly told their teams to stop using cloud transcription tools entirely while they sorted out the paperwork.

Most recruiters are not GDPR specialists and do not need to be. But the question your DPO or your enterprise client is asking (*where does the candidate audio actually go*) is one you should be able to answer cleanly in 2026, because it now comes up in client RFPs and procurement reviews routinely.

The four questions that actually matter

GDPR is a long document, but for recruiter interview transcription it reduces to four practical questions:

1. Legal basis. What is your legal basis for recording the candidate? In recruiting this is almost always *consent* (the candidate explicitly agrees) or *legitimate interest* (you have a documented assessment that the recording is necessary and proportionate). Consent is cleaner; most professional recruiters use a consent gate at the start of the call.

2. Where the data physically lives. This is the question that has gotten harder, not easier. If your transcription tool processes the audio in a US cloud (most do), you are making a cross-border data transfer. Post-Schrems II, that requires either an adequacy decision (the EU-US Data Privacy Framework, which is currently in effect but politically fragile) or standard contractual clauses plus a transfer impact assessment. Your enterprise clients increasingly want to see that paperwork.

3. Who else can access the data. Each cloud sub-processor in your stack is a separate disclosure your client may need to receive. A vendor like Otter has its own sub-processor list (AWS, OpenAI, etc.). Each addition is a separate trust handoff.

4. Retention and deletion. When the candidate asks you to delete their data, can you actually do it? In the cloud-tool case, you have to file a deletion request with the vendor. In the local-tool case, you delete the file.

What changed about the local-first option

Until roughly 2024, "run everything locally" was a fine idea but a bad product. Local Whisper was slow, local summarization was bad, and the laptop fans spun like jet engines. By 2026 that has changed:

  • MLX Whisper on Apple Silicon transcribes faster than realtime. A 30-minute interview is a 5–10 minute job.
  • Quantized 7B–14B models (Qwen3, Llama, Mistral) produce summaries that are good enough for recruiter scorecards.
  • Speaker diarization with pyannote runs on-device with accuracy comparable to cloud services for two-speaker conversations.

The result: a fully local pipeline now produces an output that is competitive with the cloud option. And the GDPR conversation becomes trivial, because three of the four questions above evaporate when the audio never leaves the recruiter's machine.

The local-first GDPR posture in plain English

If your transcription tool runs entirely on the recruiter's laptop:

  • Where does the data live? On the recruiter's encrypted laptop disk.
  • Who else can access it? No one, unless the recruiter shares it.
  • Sub-processors? None.
  • Cross-border transfer? None.
  • Deletion on request? The recruiter deletes the file.

That is a posture you can write into a client RFP in one paragraph. It is also a posture you can explain to an EU candidate in one sentence.

This does not magically make you GDPR-compliant. You still need the legal basis (the consent gate), the retention policy (when do you delete recordings), and the documentation. But the hard part (the part where you are negotiating sub-processor agreements with a US cloud vendor) disappears.

What you still need to do

Even with a local-first tool, recruiters should:

  1. Use a verbal consent gate at the start of every recording. "I'd like to record this conversation for note-taking purposes. Is that OK with you?" Document the timestamp.
  2. Have a written retention policy. Most agencies land somewhere between "delete after offer accepted/declined" and "delete after 12 months."
  3. Encrypt the laptop disk. FileVault on macOS, BitLocker on Windows. This is table stakes.
  4. Know how to honor a deletion request. If the candidate asks, you find the file and delete it.
  5. Document your assessment. A one-page DPIA covering the points above is enough for most client RFPs.

What about the EU AI Act?

The EU AI Act adds a separate layer specifically for AI systems used in employment decisions. The act classifies AI used to evaluate candidates as "high-risk" and imposes additional documentation requirements. Note that transcription itself is not the high-risk part. The high-risk part is using AI to *score* or *recommend* candidates. A tool that produces a transcript and a structured summary that a human then evaluates is generally outside the high-risk classification. A tool that scores candidates' video for "engagement" or recommends hire/no-hire is clearly inside it.

This is another reason the recruiter community has shifted toward tools that produce transcript + summary and intentionally do not produce candidate scoring or ranking.

What we ship for this

HireScribe is built around this posture: audio, transcript, and summary all stay on the recruiter's laptop. No cloud sub-processors. No cross-border transfer. The consent gate is built into the recording flow. We do not produce candidate scores or rankings, just clean transcripts and structured summaries that humans evaluate. If you are building the GDPR story for your firm in 2026, that is the shape of the answer the auditors and your enterprise clients are looking for.

Nothing in this post is legal advice. Your DPO is. But these are the practical questions you should be able to answer about whichever transcription tool you use.

About the author

Tyler Knell

Founder, HireScribe

Tyler Knell is the founder of HireScribe and builds the app itself. He writes from inside the problem — the consent-law research, privacy reviews, and on-device AI engineering that went into shipping a recruiter note-taker that records, transcribes, and summarizes interviews without ever uploading candidate audio.

More about HireScribe

Try HireScribe

Local-first interview notes for recruiters. Free to download.