Blog ·

GDPR and KVKK compliance when recording client meetings: a practical guide for agencies

What EU and Turkish agencies need to get right before recording client calls with AI notetakers: consent, data residency, retention, NDA implications and a vendor evaluation checklist.

If your agency records client calls with an AI notetaker, you are a data controller processing personal data: voices, names, opinions, and frequently your client's commercial secrets and their customers' details. Under the GDPR in the EU and the KVKK in Turkey, that is a regulated activity with real obligations, and "the tool did it automatically" is not a defense.

This guide covers the practical questions agencies actually face. It is not legal advice; it is a map of what to ask your lawyer and your vendors. The rules below are the ones that come up in real procurement conversations, not the theoretical edge cases.

Consent and notice: the visible bot question

Both GDPR and KVKK require a lawful basis for processing and transparent information for the people whose data you process. For meeting recordings, the practical translation is simple: every participant must know the call is being recorded and processed, before it happens.

The cleanest mechanical implementation is a visible bot. When the notetaker joins the call with a name and an avatar, notice is built into the meeting itself: everyone sees it, and anyone can object before a word is captured. Tools that capture audio invisibly, without a participant in the call, shift the entire notice burden onto you. That can still be done compliantly, but it means you must give notice through another channel, every time, including to your client's guests who joined late. Ask yourself honestly whether your account teams will do that on every call. Under KVKK, the aydınlatma yükümlülüğü (the obligation to inform) is taken seriously by the Turkish DPA, and secret recording of a business call is also legally risky ground entirely apart from data protection law.

Practical baseline: add recording language to your engagement letters, have the meeting owner announce the notetaker at the start of the first call with any new participant, and prefer tools that make recording visible rather than ambient.

Data residency: where does the recording actually live

GDPR restricts transfers of personal data outside the EU and EEA; KVKK restricts transfers outside Turkey, historically even more strictly. When your notetaker uploads a client call to servers in the United States, that is an international data transfer, and you need a valid mechanism behind it: adequacy, standard contractual clauses, or explicit arrangements under KVKK.

Questions to ask every vendor, in writing: In which region is meeting content stored at rest? Which subprocessors touch the audio and the transcript, and where are they located? Is the content used to train models, and can that be excluded contractually rather than by a settings toggle? Can we get EU-only storage in the contract, not just in the marketing?

If a vendor cannot answer these crisply, that is itself an answer.

Retention: keep less, sleep better

Storage-limitation principles in both regimes mean you should keep recordings only as long as you have a purpose. In practice, agencies rarely need raw audio for long; the durable value is in the decisions, tasks and summaries extracted from it.

A sane default policy: retain raw recordings and transcripts for a defined short window (30 to 90 days is common), retain extracted outcomes in your systems of record indefinitely as normal business records, and delete on client request. Check what your tool actually supports: many notetakers have no retention controls at all, and some free tiers hold your data hostage with storage caps rather than letting you set deletion rules. A zero-day retention option, where raw material is discarded as soon as the outputs are produced, is the strongest position for high-sensitivity clients.

The NDA problem nobody prices in

Here is the issue specific to agencies that generic compliance guides miss: multi-client confidentiality. Most notetakers pour every meeting into a single team-wide searchable archive. If you hold NDAs with two competing clients, and any employee can search across both clients' calls from one box, you have built an internal data leak and are one careless query away from a breach of contract, before any regulator gets involved.

Evaluate tools on structure, not policy. Can meetings be partitioned per client? Can access be scoped so the team on account A cannot search account B? Is there an audit trail showing who accessed and who wrote what? "Please be careful" is not a control. Workspace boundaries are.

The vendor evaluation checklist

Before signing up your agency to any meeting recording tool, get written answers to these:

  • Lawful basis and notice: Does the tool join calls visibly? What notice do participants receive, and can we customize it?
  • Residency: Where is content stored at rest? EU or Turkey options available contractually?
  • Subprocessors: Full list, locations, and notification of changes?
  • Model training: Is our content used to train models? Excluded by contract?
  • Retention: Configurable retention windows? Zero-day option? Verified deletion on request?
  • Partitioning: Per-client separation with scoped access, or one shared archive?
  • Audit: Who accessed what, who approved what, exportable on request?
  • DPA: Will the vendor sign a data processing agreement, and does it survive their acquisition?
  • Exit: Can we export everything and confirm deletion when we leave?

Score candidates against this list and most of the market thins out quickly. That is not cynicism; it is the state of a young category that grew up serving individuals before it met procurement.

One honest disclosure

We build RecapButler, a meeting-to-ops tool for agencies, so we should state our own position against this checklist rather than imply neutrality. RecapButler is built around visible capture (the meeting bot, rolling out in early access, always joins with a name and an avatar and never records in secret), stores meeting content in EU hosting built for GDPR and KVKK, never trains models on customer data, structures everything as per-client workspaces with scoped access, records an audit trail for every write, and has both a zero-day retention option for its Agency plan and self-hosting for Enterprise on the roadmap. Whether it fits your workflow is a separate question from compliance, and this checklist works just as well if you point it at us.

The larger point stands regardless of vendor: recording client calls is now a normal part of agency life, and it can be done properly with modest effort. Decide your policy first, then choose a tool that enforces it by structure. Your future self, sitting across from a client's lawyer with a clean audit trail, will be glad you did.

Tüm yazılar