Privacy

Is it safe to upload client calls? A secure transcription checklist

Secure transcription checklist for consultants, lawyers and therapists: eight questions to ask before uploading a client call, and a local alternative.

It can be, if you can answer eight questions first. A client call is personal data about someone who isn’t you, so uploading it makes the transcription service a processor acting on your behalf, and the GDPR attaches specific duties to that relationship. Secure transcription starts before the upload: the right to share the call, a data processing agreement, storage location, retention, model training, sub-processors, deletion, and encryption. Here is each question, why it matters, and what a good answer sounds like.

Check that you may share the recording at all

The first question is about you, not the service. Under Article 4(7), the controller is whoever “determines the purposes and means of the processing of personal data”. You decided to record the call and you’re choosing where it goes, so that’s you. The recording is personal data about the client: the EDPB’s guide for small businesses lists “photos, videos and audio recordings containing images or sounds of individuals” among its examples.

Three things to check. Notice: did the other person know they were recorded, and that the file might go to a third party. Article 5(1)(b) says data must be “collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes”, so “I’m recording this for my notes” doesn’t obviously cover a vendor upload. Contracts: many client agreements and NDAs restrict passing confidential material to third parties, and a vendor is one. Professional rules: lawyers, therapists and journalists generally have confidentiality duties from a professional body or national law on top of the GDPR. Check yours first.

If any of those is a no, the checklist stops here. Get the permission or keep the file on your own machine.

Ask for a data processing agreement and read what’s in it

Once you upload, the service is a processor, which Article 4(8) defines as a body that “processes personal data on behalf of the controller”. Article 28(3) requires a contract or other legal act, binding on the processor, that governs the processing. That contract is what people call a data processing agreement, or DPA. Article 28(9) says it must be “in writing, including in electronic form”, so a verbal promise doesn’t count.

A DPA is where the service commits to doing only what you tell it with the recording. Article 28(3) lists what it must say. The processor:

  • processes the data only on your documented instructions, including any transfer abroad (28(3)(a));
  • makes sure its staff are bound to confidentiality (28(3)(b));
  • takes all the security measures Article 32 requires (28(3)(c));
  • follows the rules on engaging other processors (28(3)(d));
  • helps you answer access or erasure requests from the people recorded (28(3)(e));
  • deletes or returns the data at your choice when the service ends, and deletes existing copies (28(3)(g));
  • gives you the information you need to check compliance, and allows audits (28(3)(h)).

Article 28(1) puts a duty on you too: use only processors that give sufficient guarantees they’ll meet the regulation’s requirements. Reading the DPA is how you meet it. A good answer to “do you sign a DPA” is a link to a written document covering those points; “we take privacy seriously” isn’t one.

Secure transcription depends on where the file goes and who else touches it

A DPA and a security page should answer the rest.

Where is it stored. Article 44 allows a transfer of personal data to a third country, meaning outside the EU and EEA, only if the conditions in Chapter V are met. If the servers sit there, the DPA should name the transfer mechanism. Ask for the country, not the continent.

How long is it kept. Article 5(1)(e) requires data to be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed”. For a transcript job, that’s usually the moment you download the text. The EDPB’s guide asks you to record “where possible, the storage period” and who has access, including “service providers”. A good answer is a fixed number of days, or delete-on-download.

Is it used to train models. Article 28(3)(a) limits the processor to your documented instructions, and Article 5(1)(b) bars processing incompatible with the original purpose. Training a speech model on your client’s voice is a different purpose from transcribing that call. Look for a clear no in the DPA, or at least an off-by-default setting.

Who are the sub-processors. Article 28(2) says the processor may not engage another processor without your prior written authorisation, specific or general, and must tell you about intended changes so you can object. Under 28(4) the same obligations flow down, and the first processor remains fully liable. A good answer is a published list of who hosts or recognises the speech, and where.

Can you delete it and get confirmation. Article 28(3)(g) gives you the choice of deletion or return, existing copies included, and 28(3)(h) requires “all information necessary to demonstrate compliance”. Ask for a delete button, written confirmation and a stated window for backups.

Is transfer encrypted. Article 32(1) obliges controller and processor to implement security “appropriate to the risk”, and lists “the pseudonymisation and encryption of personal data” first among its examples. Article 32(2) covers data “transmitted, stored or otherwise processed”, so ask for encryption in transit and at rest.

The checklist in one table

Paste this into your email to the vendor.

Question Why it matters What a good answer looks like
Do I have the right to share this recording? Controller duties (Art. 4(7)); purpose limitation (Art. 5(1)(b)); contracts; professional rules The person was told the file may go to a third party; nothing forbids it
Will you sign a data processing agreement? Required in writing for any processor (Art. 28(3), 28(9)) A written DPA covering the Article 28(3) points above
Where is the file stored? Transfers outside the EU and EEA need a Chapter V basis (Art. 44) A named country and, if outside the EU and EEA, the transfer mechanism
How long do you keep it? Storage limitation (Art. 5(1)(e)) A fixed retention period in days, or delete-on-download
Do you use it to train models? Documented instructions only (Art. 28(3)(a)); no incompatible purposes (Art. 5(1)(b)) A plain no, or an off-by-default setting, in the DPA
Who are your sub-processors? Prior authorisation and flow-down (Art. 28(2), 28(4)) A published list with countries, and notice before changes
Can I delete it and get confirmation? Delete or return at your choice (Art. 28(3)(g)); demonstrate compliance (Art. 28(3)(h)) A delete button plus written confirmation, backups included
Is the transfer encrypted? First example in Art. 32(1)(a); covers data transmitted and stored (Art. 32(2)) Encryption in transit and at rest, stated in the DPA

Processing on your own machine removes most of the checklist

There’s a second answer to “is it safe to upload”: don’t. If the recording never leaves your computer there’s no processor, so no DPA, no transfer and nothing to chase at a vendor. Questions two to eight disappear. Question one stays, and the transcript is still personal data on your disk.

FreeTranscribe is one way to do that. It runs OpenAI’s open-source Whisper model in the browser tab on your graphics card through WebGPU. The file is read from disk and never uploaded; there’s no account, so nobody else holds a copy. The cost side is in Otter vs Rev vs Descript vs local transcription.

The limits belong in the decision:

  • Desktop Chrome or Edge with a working WebGPU adapter. No Firefox, Safari or phones yet.
  • English only for now.
  • The base model, about 200 MB downloaded once and cached. Names, technical terms, heavy accents and noisy rooms are the weak spots. Read it through before relying on it, especially anything you’d quote to a client.
  • About 1.5x real time on a desktop with a graphics card in our test; a thin laptop takes roughly as long as the recording.

And the machine itself has to be secure. Article 32 binds the controller as much as the processor, and Article 5(1)(f) requires “appropriate security of the personal data”. In practice that generally means disk encryption on, a login nobody else uses, the exported TXT or SRT kept out of a synced downloads folder, and the audio deleted once the transcript has done its job. Local processing removes the vendor, not the responsibility.

Frequently asked questions

Do I need a DPA if the service is free? Article 28 doesn’t distinguish paid from free. If a company processes personal data on your behalf it’s a processor, and Article 28(3) requires a written contract.

Is a privacy policy the same as a DPA? Usually not. A DPA is the binding contract under Article 28(3) setting out what the processor may do and on whose instructions. A privacy policy is generally written for the service’s own users.

Does encryption on its own make an upload safe? It answers one line. Article 32(1)(a) names encryption in its first example of a security measure and says nothing about retention, sub-processors or training. Encrypted audio held indefinitely by a company you can’t name is still a problem.

This post is general information about what the regulation says, not legal advice for your situation.

Sources, checked 14 September 2026

secure transcriptionclient callsdata processing agreementgdprlocal transcription
FreeTranscribe

Written by the people who build FreeTranscribe. We test every claim on our own files and date every price. About the site.

Transcribe a file now. Free, in your browser.
Open the transcriber