Skip to main content
Recording video conferences
Back to all Insights

Insights · Clarius Group

Recording video conferences – a practical feature, but is it GDPR-compliant?

Published
4 March 2024
Reading time
3 min read

Share this article

Video conferences have now become part of everyday business for many people. One practical feature is the recording function, which makes it easy to revisit discussions or bring absent colleagues up to date. As with anything involving the processing of personal data and metadata, however, certain GDPR rules must be observed. But what exactly are they?

Purpose of the data processing

Before a recording is made, the purpose and nature of the data processing must be clearly defined. It is important to note that the purpose of the recording is not necessarily the same as the purpose of the video conference. Each processing operation must be assessed separately.

Data protection law follows the legal principle of “prohibition unless authorised”: the processing of personal data is lawful only where it is legitimised by a legal basis under Article 6 GDPR.

Although legitimate interests may be considered as a basis for legitimising the recording, a balancing of interests rules this out: a recording constitutes a significant intrusion into the personal sphere of everyone involved. Obtaining consent is therefore the appropriate legal basis.

In employment relationships, section 26 of the German Federal Data Protection Act (BDSG), which sets out special requirements for processing employee data, must also be observed.

The General Data Protection Regulation sets high standards for valid consent:

  • The declaration of consent should be worded clearly and intelligibly.
  • Data subjects must be informed who the controller is, which data is processed for which purpose and that they have a right to withdraw consent.
  • Consent must be given freely. This means that the data subject must have a genuine choice regarding the recording. In a professional context, the employee’s dependent position may cast doubt on whether consent is freely given (see section 26(2), sentence 1 BDSG). It is therefore important to offer participants alternatives if they do not agree to the recording.
  • The GDPR does not prescribe a particular form for consent. The controller must, however, be able to demonstrate that valid consent was obtained.

Duty to provide information

Participants must be informed about the data processing and their rights as data subjects. The BDSG stipulates that employees must be informed in text form about the purpose of the data processing and their right to withdraw consent (see section 26(2), sentence 4 BDSG).

What else must the controller consider?

One difficulty with using video conferencing services is the transfer of data to the United States. The GDPR requirements for transferring personal data to third countries must therefore also be met.

To provide correct information about all processing operations, the “video conference” event must be included in the record of processing activities pursuant to Article 30 GDPR. Controllers are also required to assess whether a data protection impact assessment must be carried out pursuant to Article 35 GDPR.

A final note

One principle that applies to the processing of data in almost every case is data minimisation. Only matters necessary for the conference should be discussed during the call.

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email