SPOTRUM
Get started
Guide

GDPR-compliant video conferencing: the practical checklist

Every vendor claims GDPR compliance in a banner; few can show it in an architecture. If you process EU personal data — and every meeting with names, voices and faces is personal data — here is what to actually check before you roll out a conferencing tool.

What GDPR really asks of a meeting tool

Four things: a data controller you can hold accountable, a lawful basis and transparency for recordings, technical measures matching the risk (encryption, access control, retention), and — the part most vendors whisper about — a defensible answer for where the data goes and under whose law it sits.

The checklist

Ask these five questions of any candidate:

  • Who is the controller/processor — and is a DPA offered without an enterprise contract?
  • Where do recordings and transcripts physically live? EU data centres, or 'EU region available on request'?
  • Is there true end-to-end encryption for meetings that should never be recorded at all?
  • Can hosts control retention — and can users exercise deletion rights without a support ticket?
  • If the vendor is US-owned: what is their answer to the CLOUD Act question?

The US-vendor transfer problem, in one paragraph

Since Schrems II, moving EU personal data to US providers means transfer mechanisms, impact assessments and residual risk your DPO has to own — because the US CLOUD Act can compel a US company to disclose data even when it is stored in Europe. The clean way out is structural: an EU vendor under EU law. We wrote up what actually changes in that switch on our European alternative page.

How Spotrum implements it

EU company (Estonian registry, public), EU servers for media, recordings and files, GDPR as home law, a DPA on request for any business customer, E2EE private rooms on every plan including Free, host-controlled retention and built-in account export and deletion. Every claim here is documented on our security page — including the honest limits.

Is it lawful to record meetings under GDPR?

Yes, with a lawful basis and transparency: participants must know. Spotrum makes recording host-initiated and visible to everyone in the room, and E2EE rooms cannot be recorded at all.

Does Spotrum offer a DPA?

Yes — any business customer can request one at legal@spotrum.com. The controller is an EU (Estonian) company, so no cross-border transfer mechanisms are needed for core data.

Where exactly is meeting data stored?

Media servers, recordings, transcripts and files run in European Union data centres. Optional AI features use a named non-EU sub-processor, are off by default, and are documented in the Privacy Policy.

Conferencing your DPO will sign off on

Spotrum Assistant
Online · answers in your language

Hi! I'm the Spotrum assistant. Ask me anything about rooms, recording, AI transcripts, plans or pricing — in any language.

AI assistant · may occasionally be inaccurate