Data Protection and Privacy Skip to main content

Data Protection and Privacy

...with you every step of the way!

Our Data Protection and Privacy team provides comprehensive guidance to help organisations navigate the complex landscape of personal data regulation, including the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 and e-Privacy rules.

We can conduct Data Protection Audits and assist with mapping data flows, identifying compliance gaps, and drafting or updating internal policies such as Privacy Notices, Data Handling and Retention Policies, and Subject Access Request procedures. Our solicitors advise on Lawful Bases for Processing and help to conduct and document Legitimate Interests Assessments (LIAs) and Data Protection Impact Assessments (DPIAs) where required, in particular for high-risk processing such as processing Children’s Data. Our services and experience help you to ensure that your data collection, storage, and sharing practices meet and address applicable statutory and regulatory requirements as well as your client’s expectations.

We draft Data Processing Agreements (DPAs) with controllers and processors, including cross-border transfer mechanisms like Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs) or taking into account Data Adequacy Decisions such as relating to the Data Protection Framework in the USA. For transactional and marketing emails, we help our clients to ensure compliance with the Privacy and Electronic Communications Regulations (PECR) and DPA 2018.

We assist our clients in navigating Data Subject Access Requests (DSARs or SARs) in accordance with legal timescales for responses and in determining what to disclose.

We also advise on Data Breach Responses, advising on notification obligations to the Information Commissioner’s Office (ICO), affected data subjects, and mitigation strategies to minimise reputational harm.

Whether you’re a multinational corporation, SME, or start-up, our data protection specialists offer pragmatic, risk-based advice to protect your customers’ privacy, reduce regulatory exposure, and build trust.

The Legal Challenges of Using AI Notetaker Apps in B2B Meetings

Data protection alongside confidentiality are one of the most common top 5 concerns that customers have when it comes to most tech negotiations. Getting policies and processes ready before entertaining any discussions or service provision to customers is essential. The more technology that we use on a daily basis, the higher these risks become and it's easy to forget that they need consideration even when something seems quite innocent.

One such example that is definitely on trend currently is the uptake in the use of AI‑powered notetaker tools which have become increasingly popular especially in business settings, offering seamless transcription, summarisation and action‑point extraction. But while the technology is convenient, its use in B2B meetings raises a number of legal risks that organisations often overlook. Understanding these risks is essential, particularly where confidential information, contractual obligations or personal data are being processed.

1. Data Protection and Transparency

Any AI notetaker will inevitably process personal data, including voices, names, opinions and sometimes sensitive business context. Under UK GDPR, organisations must be able to identify a lawful basis for this processing. In most B2B scenarios this is likely to be legitimate interests, but that requires a balancing test and clear communication with meeting participants.

Transparency is also key. Every attendee must be informed that an AI tool is recording or transcribing the session. Failure to notify people may render the processing unlawful and expose the business to regulatory complaints.

A further complication is international data transfers. Many notetaker vendors process data in the US or other jurisdictions. Organisations must ensure that appropriate safeguards, such as the UK Addendum or Transfer Risk Assessments, are in place.

2. Confidentiality and Contractual Constraints

One of the biggest risks is inadvertent breach of confidentiality obligations. Using an AI notetaker usually means sending audio and transcripts to a third‑party service provider. If your NDA or client contract prohibits disclosure to third parties, or restricts the use of subcontractors or cloud platforms, you may be in breach simply by using the tool.

Even where disclosure is permitted, you must check the provider’s terms carefully. Some vendors reserve rights to use uploaded data for model training unless you are on an enterprise plan. That can be completely incompatible with many commercial confidentiality commitments.

3. Industry‑Specific Regulation

Certain industries face additional scrutiny. Regulated firms, such as financial services, legal services, healthcare providers or public bodies, must follow strict rules on outsourcing, information governance and client confidentiality.

Using an AI notetaker may require prior approval, contract variations or specific security assurances which may be especially important for regulated businesses.

4. Accuracy, Interpretation and Liability Risks

AI tools do not always transcribe or summarise accurately. Mis‑summaries can lead to misunderstandings, mis‑stated commitments or internal disputes about “what was agreed.” If minutes or actions generated by AI are relied upon uncritically, the business may find itself bound by statements nobody actually made. If you're also operating with poor legal contractual coverage then this can expand risk when it comes to disputes about the scope of services a customer thinks you have agreed to provide to them.

5. Reputational Considerations

Finally, even if compliant, some clients may dislike the idea of their discussions being recorded by an AI too and especially one that could potentially be in scope of US law enforcement discovery.

Failing to manage expectations can damage trust, especially in sensitive negotiations. It is important to plan ahead to cover off issues before they are allowed to become problems.

AI note takers can be used perfectly legally, just as they can be used perfectly illegally, it's just a matter of compliance as to which of those categories you fall into!

Frequently Asked Questions

Is it legal to use an AI notetaker in the UK?

Yes. AI notetakers can be used lawfully in the UK provided that the business has a valid lawful basis under UK GDPR, provides transparency to all meeting participants and complies with any confidentiality or contractual restrictions. They can equally be used unlawfully if these requirements are ignored.

Do I need consent from meeting participants?

Consent is rarely an appropriate lawful basis in B2B settings because it is difficult to treat it as freely given. Most organisations rely on legitimate interests. However, even when consent is not required, you must still tell every attendee that an AI tool is recording or transcribing the meeting. Without notification, the processing is not transparent and may breach UK GDPR.

Are AI notetakers compliant with UK GDPR?

This depends on the provider. Many tools process personal data in the United States or other third countries. Your organisation is responsible for ensuring that any international transfers are covered by appropriate safeguards such as the UK Addendum or a Transfer Risk Assessment. You must also check whether the vendor uses customer data for training their models because this may conflict with your confidentiality obligations.

Can using an AI notetaker breach confidentiality or NDAs?

Yes. Many contracts and NDAs restrict disclosure of confidential information to third parties. Sending audio or transcripts to an external AI vendor may amount to a disclosure. You should check contracts for restrictions on subcontractors, cloud service providers and data sharing. You must also review the vendor’s terms to ensure they do not reserve the right to reuse or analyse your data.

Are AI notetakers suitable for regulated industries?

Regulated firms such as financial services, legal services, healthcare providers and public bodies face additional governance requirements. They may need prior approval for outsourcing, enhanced security assurances or client consent. Some regulators expect firms to maintain full control and auditability over any service provider that handles confidential or personal data.

How accurate are AI notetakers?

Accuracy varies significantly between tools. Mis‑summaries can lead to misunderstandings, mistaken commitments or internal disagreement about what was said. Minutes and action points generated by AI should be reviewed rather than accepted at face value. Poor accuracy can increase the risk of scope disputes in commercial contracts.

What steps should a business take before using an AI notetaker?

Businesses should carry out a short compliance review that includes:

  • checking whether the tool is permitted under NDAs and client contracts
  • reviewing the vendor’s terms and data processing commitments
  • confirming the locations where data will be stored or processed
  • preparing a short transparency notice for meeting attendees
  • deciding which meetings are suitable for AI tools and which are not
  • documenting the legitimate interest assessment where applicable

Can a client refuse the use of an AI notetaker?

Yes. Some clients are uncomfortable with recordings or AI‑based processing, especially where data could be accessed by foreign jurisdictions or used for training models. If a client objects, you must respect that preference. Using the tool without agreement can damage trust and may breach the contract.

Should my business have an AI notetaker policy?

A simple internal policy is strongly recommended. It should cover when AI notetakers may be used, how attendees are informed, which providers have been approved, how data is stored and when recordings must be deleted. A clear policy helps staff avoid accidental breaches of confidentiality or data protection law.

Do I need to physically come into your offices to work with you?

Eaton Smith are based in Huddersfield but we provide our services to clients globally, so no matter where you are located if you are looking to comply with UK Consumer Law we can work with you remotely. We have systems in place to support working with clients entirely remotely and this often reduces your overall costs compared to needing to attend an office as some law firms may still require.  

Sam Crich is a partner at Eaton Smith LLP and has a specialism in data protection which he has developed over the past decade working with technology and data driven businesses including those using AI in the delivery of education products to schools and much more. Sam has hosted many data protection horizon scanning seminars at Leeds Digital Festival over the years and has helped clients conduct data protection audits, prepare data processing impact assessments, and advised and trained lawyers and commercial organisations on data protection compliance.

If you are looking for solutions to your questions, why not give us a call today on a no obligation basis?

  • Unsure how to update your Privacy Notice to comply with UK GDPR requirements and the latest developments in the law? Speak with a solicitor experienced in data protection.
  • Need help drafting a compliant Data Processing Agreement for your customers, vendors or service providers? Consult our solicitors specialising in DPAs.
  • Concerned about lawfully relying on consent or legitimate interests for your marketing campaigns? Talk to a solicitor knowledgeable in lawful bases for processing.
  • Facing a data breach and need guidance on notification obligations to the ICO and data subjects? Reach out to a solicitor who has handled breach responses.
  • Wondering how to implement Standard Contractual Clauses for cross-border data transfers post-Brexit or make use of a supplier’s DPF certification? Speak with a solicitor experienced in international data transfers.

You can contact Sam directly by email at Samcrich@eatonsmith.co.uk

Team for Business – Data Protection and Privacy

T: 01484 821411
Chris Taylor
Chris Taylor
Partner
T: 01484 821390
Sam Crich
Sam Crich
Partner

contact

By submitting this form you agree to our Privacy Policy. We will use your details to respond to your enquiry.