Therapy session transcription without a data processor agreement
Therapy session transcription usually involves special category health data. What Article 28 asks before you send audio out, and what changes if you don't.
You generally can, if the audio never leaves the machine in front of you. Therapy session transcription is not the same problem as transcribing a sales call. What a client says in a session is usually data concerning health, which the GDPR puts in a special category with a higher bar. Send the file to a transcription service and that service becomes your processor, which Article 28 says needs a written contract. Keep the file local and there is no processor for that step. Everything else you owe the client is unchanged.
Session content is very likely special category data
Article 9(1) prohibits processing a listed set of categories: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone uniquely, data concerning health, and data about a person’s sex life or sexual orientation.
Article 4(15) defines data concerning health as personal data about a person’s physical or mental health, including the provision of health care services, that reveals information about their health status. A counselling or therapy session is generally about mental health, and is usually itself the provision of care, so the recording and the transcript will normally land inside that definition.
Coaching is less clear cut. A session about a promotion plan may contain nothing from the Article 9 list. But sessions wander into burnout, medication, a bereavement, a faith, a marriage, and any of those turns part of the file into special category data. You find out afterwards. Plan as though a session will not stay clear of the list.
Landing in Article 9 means prohibition is the starting point: processing is allowed only where an exception in Article 9(2) applies. Two are worth knowing. Under 9(2)(a) the client “has given explicit consent to the processing of those personal data for one or more specified purposes”. Under 9(2)(h) processing is “necessary for the purposes of … medical diagnosis, the provision of health or social care or treatment”, a route Article 9(3) narrows to data handled by or under the responsibility of a professional “subject to the obligation of professional secrecy”. Which one fits depends on your role and where you practise.
Therapy session transcription needs both a lawful basis and an Article 9 exception
A client saying “yes, record it” is one thing. The lawful basis for what you then do with the recording is another.
Article 6(1) says processing “shall be lawful only if and to the extent that at least one of the following applies”, and consent under 6(1)(a) is first on that list. Article 4(11) sets the bar for what counts as consent at all: a “freely given, specific, informed and unambiguous indication of the data subject’s wishes”. Read “freely given” slowly if the person is in your consulting room and needs the appointment.
Article 9 then sits on top: for special category data you generally need both a basis under Article 6 and an exception under Article 9(2). Consent to the recording also does not stretch to a new recipient on its own. Article 5(1)(b) requires data to be “collected for specified, explicit and legitimate purposes”, and not processed further in a way incompatible with them, and a vendor is a purpose the client probably never heard about.
Write down which basis and exception you picked. Article 5(2) makes the controller “responsible for, and be able to demonstrate compliance with” the principles, and an unrecorded decision is hard to demonstrate.
Professional confidentiality sits on top of all of this
Data protection law is the floor, not the ceiling. The regulation says so itself: Article 9(3) leans on the “obligation of professional secrecy under Union or Member State law or rules established by national competent bodies”, a duty that comes from outside the regulation.
Duties of this kind generally apply to therapists, counsellors and psychologists, and to many coaching accreditations, and they differ by body and by country. Read your own code, and ask your supervisor or your professional body how it treats sending session audio to an outside company. Getting the GDPR right does not settle that question.
A data processor agreement is what Article 28 asks for before a session leaves your machine
You are the controller here: Article 4(7) defines that as whoever “determines the purposes and means of the processing of personal data”, which is you the moment you decide to record. Article 4(8) defines a processor as a body which “processes personal data on behalf of the controller”, which a transcription service becomes as soon as you upload.
Article 28(1) says the controller “shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures”. Article 28(3) says the processing “shall be governed by a contract or other legal act … that is binding on the processor”, setting out the subject matter, duration, nature and purpose of the processing, and the type of personal data and categories of people involved. Article 28(9) says that contract must be “in writing, including in electronic form”. That document is what people mean by a data processing agreement, or DPA.
Three of the clauses Article 28(3) requires matter more than usual for session audio. Everyone the processor lets near the data has to have committed to confidentiality, or be under a statutory obligation of confidentiality (28(3)(b)). The processor has to help you answer the client’s requests under Chapter III (28(3)(e)). And at your choice it “deletes or returns all the personal data to the controller … and deletes existing copies” (28(3)(g)). Article 28(2) adds that it may not bring in another processor without your prior written authorisation, specific or general, so ask who else is in the chain.
If a service offers no written agreement, you have no Article 28 contract, and a session recording is the wrong file to test that with.
The two routes, question by question
| Question | Sending it to a vendor | Doing it on your own machine |
|---|---|---|
| Is there a processor in the chain? | Yes, from the moment the file leaves (Art. 4(8)) | No processor for the transcription step |
| Do you need a written contract for it? | Yes, in writing (Art. 28(3), 28(9)) | Not for that step |
| Who else can touch the audio? | Vendor staff plus any sub-processor you authorised, specifically or generally (Art. 28(2), 28(3)(b)) | Anyone who can use your computer |
| Do you still need a basis and an Art. 9 exception? | Yes | Yes, unchanged |
| Who has to secure the file? | You and the processor, both (Art. 32(1)) | You, alone (Art. 32(1), Art. 5(1)(f)) |
| How is an erasure request handled? | You ask the vendor, and the contract has to make it help (Art. 28(3)(e), (g)) | You delete your own copies |
| Whose retention period applies? | Theirs as well as yours (Art. 5(1)(e)) | Yours |
Keeping it local removes the processor, not the obligations
Transcribe on your own computer and the right-hand column is yours.
FreeTranscribe does that in a browser tab. It runs OpenAI’s open-source Whisper model on your graphics card through WebGPU, reads the file from your disk and never uploads it, and there is no account, so no company holds a copy. There is no length cap either, which matters for a 50 minute session. See why free transcription sites cap you at 30 minutes for what that limit is usually about.
The limits, plainly:
- Desktop Chrome or Edge with a working WebGPU adapter. No Firefox, Safari or phones yet.
- English only for now.
- The base model, around 200 MB downloaded once and cached. Names, medication names, accents and a quiet second voice are its weak spots. Read the transcript against the audio before it becomes your notes.
- About 1.5x real time on a desktop with a graphics card in our test. A thin laptop takes roughly as long as the recording.
Local processing is not a compliance shortcut. Article 32(1) puts the duty to implement measures “to ensure a level of security appropriate to the risk” on controller and processor alike, and with no processor that is entirely you: disk encryption on, a login nobody else uses, exports out of any synced folder. Article 5(1)(e) still wants the file kept “no longer than is necessary”, so the audio goes once the notes exist. The client’s rights under Chapter III still apply, now only against you, and the Article 9 prohibition with whichever 9(2) exception you rely on has not moved. You removed one party, not one duty.
Frequently asked questions
Is the client’s agreement to be recorded enough on its own? Usually not. Article 4(11) sets what counts as consent, Article 6(1) asks for a lawful basis, and special category data generally needs an Article 9(2) exception as well, where 9(2)(a) asks for explicit consent to specified purposes. Agreeing to be recorded is also not agreeing to the file going to a company the client never heard of.
Are coaching sessions special category data too? It depends on what comes up. Article 9(1) covers health, beliefs, sex life, political opinions and trade union membership, and a coaching conversation can touch any of them without warning. Treating a session recording as though it might is the safer default.
Does keeping the audio on my laptop mean I don’t have to tell the client anything? No. Transparency comes from Article 5(1)(a), which asks for data “processed lawfully, fairly and in a transparent manner in relation to the data subject”. Local transcription changes who receives the data, not whether the client is told.
Can I send the recording to my supervisor? That is another disclosure, with its own lawful basis and Article 9 exception to find, and your professional code may have a view. A transcript you made locally is still a file about a client’s health once you forward it.
This post is general information about what the regulation says, not legal advice. Before you record or transcribe a session, check with your supervisor or professional body about what your own code allows.
Sources, checked 15 September 2026
- https://gdpr-info.eu/art-4-gdpr/ : Article 4, definitions of controller, processor, consent and data concerning health
- https://gdpr-info.eu/art-5-gdpr/ : Article 5, the principles, including purpose and storage limitation, security and accountability
- https://gdpr-info.eu/art-6-gdpr/ : Article 6, lawfulness of processing
- https://gdpr-info.eu/art-9-gdpr/ : Article 9, special categories and the exceptions in 9(2) and 9(3)
- https://gdpr-info.eu/art-28-gdpr/ : Article 28, processor obligations, contract terms and written form
- https://gdpr-info.eu/art-32-gdpr/ : Article 32, security of processing