What to look for in GDPR-compliant video conferencing
Choosing a GDPR-compliant video conferencing platform – or a video API to build on – is harder than it looks, because the label is easy to claim and hard to verify. Much of the difficulty is one distinction: an "EU region" toggle on US cloud infrastructure is not the same as European-owned infrastructure under EU jurisdiction, and the gap between the two is where compliance risk sits. With cumulative GDPR fines reaching about €7.1 billion since 2018 (DLA Piper GDPR Fines and Data Breach Survey, January 2026) and a 2026 enforcement action on transparency under way, getting it wrong is expensive.
If you're a CTO, compliance officer, or developer evaluating video conferencing for your organisation, this guide breaks down what makes selection difficult, what GDPR requires, and what to check before you commit.
Table of Contents
- What makes choosing a GDPR-compliant video API so difficult?
- What GDPR means for video conferencing in 2026
- What makes a video conferencing platform GDPR-compliant?
- GDPR requirements for video conference recordings
- Screen sharing and live streaming under GDPR
- How popular video platforms compare on GDPR compliance
- GDPR video conferencing checklist
- How Digital Samba approaches GDPR compliance
- Frequently asked questions
What makes choosing a GDPR-compliant video API so difficult?
Selection is difficult because "GDPR-compliant" is a marketing claim, not a certificate you can look up, so two platforms can use the same words and mean very different things. To tell them apart you have to check things vendors rarely put on the pricing page, and if you're building on a video API, work out how much of the compliance job lands on your side.
The things that make a provider hard to compare:
- "Hosted in the EU" is not "EU-owned." An EU data centre owned by a US company can still be within reach of the US CLOUD Act, so the server location alone tells you little.
- Hidden sub-processors. Transcription, AI features, and analytics can route data to third parties, and out of the EU, without it being obvious from the product page.
- Transport encryption dressed up as "encryption." TLS protects data while it travels, but the provider can still read it on their servers. That is a weaker guarantee than end-to-end encryption.
- White-label platform vs low-level API. A low-level API gives you control, and also more direct exposure to personal data, so more of the GDPR obligations land on your side.
- Consent and DPAs. You need a signed Data Processing Agreement and a way to handle consent for recordings. Check that a provider gives you both.
- No badge to check. GDPR has no pass-or-fail certificate, so you have to assess the architecture yourself.
If you're comparing providers head to head on features and pricing, our guides to the best video conferencing API and the top video conferencing SDK vendors cover that in depth. This page stays on the GDPR angle and works through each point above, so you can check a provider properly before you sign.
What does GDPR mean for video conferencing in 2026?
GDPR treats almost everything a video call touches as personal data, so the platform you choose becomes part of your compliance posture. The General Data Protection Regulation has been in force since May 2018, and enforcement is getting sharper every year. Here is why that matters for video conferencing right now.
Video calls process a large amount of personal data. Names, email addresses, IP addresses, facial images, voice recordings, chat messages, shared documents, all of it falls under GDPR's scope. And it isn't only about hackers or data breaches. A misrouted meeting invite, an accidental recording, or an unauthorised participant can all trigger compliance obligations.
What has changed recently:
- Fines remain high. Cumulative GDPR fines reached about €7.1 billion between May 2018 and January 2026, according to the DLA Piper GDPR Fines and Data Breach Survey. Regulators issued around €1.2 billion of that in 2025, roughly level with 2024, so enforcement is not easing.
- Transparency is the 2026 focus. The European Data Protection Board selected transparency and information obligations (Articles 12–14) as the focus of its 2026 Coordinated Enforcement Framework, with 25 data protection authorities taking part across Europe. The action targets how controllers explain their processing, so if your own privacy notices can't clearly describe what your video platform does with data, you're exposed.
- The EU AI Act adds new layers. Video platforms increasingly use AI features: noise suppression, background blur, transcription, and summaries. The EU AI Act entered into force in August 2024 and is phasing in between 2025 and 2028, and its transparency duties (Article 50) intersect with GDPR where AI processes personal data. Blur and noise suppression usually run on your device; the privacy questions concentrate on server-side transcription and any third-party AI sub-processors.
- Cross-border transfers remain a live issue. If data leaves the EU you need a lawful transfer tool: adequacy (the EU-US Data Privacy Framework, in force since July 2023), Standard Contractual Clauses, or Binding Corporate Rules, plus a transfer impact assessment in many cases. The Data Privacy Framework is valid but under legal challenge, and concerns persist about US surveillance powers. The European Commission's Digital Omnibus proposal, published in late 2025, aims to simplify parts of GDPR and ePrivacy, but the outcome isn't settled.
The key GDPR articles that apply to video conferencing are:
- Article 5 – Data must be processed lawfully, fairly, and transparently, collected for specific purposes, and kept only as long as necessary.
- Article 25 – Privacy by design and by default. Your video platform must build in data protection from the start, not as an afterthought.
- Article 28 – If your video provider processes data on your behalf, you need a Data Processing Agreement (DPA) in place.
- Article 32 – Appropriate technical and organisational security measures are required. This is where encryption, access controls, and secure storage come in.
- Articles 44–49 – Rules governing international data transfers. If your video data leaves the EU, you need a lawful transfer mechanism.
What makes a video conferencing platform GDPR-compliant?
A video conferencing platform earns the label when it can prove, not just assert, that personal data is processed lawfully and kept within a jurisdiction you trust. In practice that comes down to a few things: where data is hosted and who controls it, strong encryption, strict data minimisation, clear sub-processor disclosure, and real support for data-subject rights. Here is what each one looks like when you check it.
Data hosting: location matters, but ownership matters more
There is a difference between "hosted in the EU" and "hosted on EU infrastructure owned by a European company." Many providers offer an "EU region" option on Amazon Web Services, Google Cloud, or Microsoft Azure. The data physically sits in an EU data centre. But the company that owns and operates those servers is often a US corporation, subject to the US CLOUD Act.
The CLOUD Act lets US authorities compel US-headquartered companies to produce data they hold, wherever it is stored. So even if your call data sits in Frankfurt, a US infrastructure provider could be within reach of US law. The precise reach is contested, and EU providers face their own lawful-access regimes too, so the realistic goal is lower, more predictable jurisdictional exposure rather than a perfect guarantee. This is really a question of data sovereignty: which government can compel access to your data, whatever the server's location.
In practice, GDPR-compliant hosting leans towards European-owned infrastructure operated under EU law, which simplifies your transfer-risk assessment. For a fuller explanation of the model, see our guide to sovereign cloud.
End-to-end encryption vs transport encryption
The word "encryption" alone tells you little, so ask which kind. Most providers offer TLS (Transport Layer Security), which protects data in transit between your device and the provider's servers. That is a good baseline, but it means the provider can still access the content on their servers.
End-to-end encryption (E2EE) is a stronger standard: only the meeting participants can decrypt the content, not the provider, its staff, or anyone who reaches the servers. For sensitive data in healthcare, legal, or financial work, E2EE is a sensible default. Bear in mind it is strong risk reduction rather than a legal requirement under the risk-based Article 32, and it disables server-side features like recording and transcription while leaving some metadata visible to the provider.
When evaluating a platform, ask directly: "Is your encryption end-to-end, or transport-level only?"
Who are the sub-processors, and where do they run?
A sub-processor is any third party a platform uses to help deliver the service: cloud hosting, transcription, AI features, analytics. Each one is a point where your data can leave the EU or reach a company under non-EU law. Ask for the full sub-processor list in the Data Processing Agreement, and check where each one actually runs, as well as where it is incorporated. A provider that can't name its sub-processors can't help you stay compliant.
White-label platform vs low-level API: who carries the GDPR load?
The more control a video API gives you, the more of the data handling it puts in your hands, and the more GDPR responsibility sits with you. A white-label platform handles rooms, recordings, and storage inside one compliant environment, so the provider carries more of the load. A low-level API that streams raw media into your own stack means your code, your storage, and your sub-processors all fall inside your compliance scope. Neither model is wrong, but you need to know which one you're buying. If you build on an API, securing that video API becomes part of your own compliance work.
What stays your responsibility?
No platform makes you compliant on its own. GDPR does not require EU ownership; it requires you to process data lawfully. Whatever you buy, you remain the controller for your own use: you set the lawful basis, run a data protection impact assessment where needed, keep records of processing, honour data-subject requests, and put a DPA in place that binds the provider to your instructions as controller. If you embed video for your own customers, you are often a processor to them and the vendor becomes your sub-processor. A good platform makes these jobs easier and shrinks your transfer risk; it does not remove your accountability.
Data minimisation and no-tracking policies
GDPR's data minimisation principle (Article 5(1)(c)) requires that you collect only the personal data that is strictly necessary. In a video conferencing context, ask: does the platform track user behaviour? Does it collect analytics about meeting habits? Does it retain metadata after the call ends?
Some platforms monetise usage data or use it for product improvement without clear consent. A privacy-first platform collects only what is needed to deliver the service, and no more.
Consent management and user rights
Your video platform needs to support the rights GDPR gives to individuals:
- Right to be informed – Participants should know what data is being collected before a call begins.
- Right to access – Anyone can request a copy of their personal data.
- Right to rectification – Individuals can ask you to correct inaccurate data.
- Right to erasure – The "right to be forgotten". If a participant asks you to delete their data, your platform needs to make that possible.
- Right to object – Users can object to certain types of data processing, including recordings.
So your platform should give you clear consent flows, easy data export, and straightforward deletion.
What are the GDPR requirements for recording a video call?
Recording a call needs a lawful basis, secure storage, and a way to honour deletion requests, and this is where organisations most commonly slip up. A recording creates a persistent record of personal data: faces, voices, names, and sometimes sensitive discussions. Treat it as a deliberate decision.
Before you hit record
You need a lawful basis for recording. Consent is one option, but it is often a poor fit in the workplace, where the power imbalance makes it hard to call freely given; legitimate interests or a legal obligation, with clear notice, can suit better. Whatever the basis, inform participants before recording starts, and consider a data protection impact assessment for routine recording. A consent checkbox in the lobby or a verbal acknowledgement at the start can work, but it needs to be genuine, not a buried "by joining, you agree" clause.
Participants who don't consent should be able to leave the meeting or take part without being recorded, where that is technically feasible.
Storing recordings securely
Once you have recorded a meeting, GDPR Articles 5 and 32 apply in full:
- Access control – Only authorised people should be able to view recordings, usually the meeting organiser and designated roles like the Data Protection Officer. Don't store recordings in shared drives where anyone can stumble across them.
- Encryption at rest – Recordings should be encrypted in storage, as well as in transmission.
- EU data residency – Store recordings within the EU, on infrastructure subject to EU law, where your risk assessment calls for it.
- Retention policies – Don't keep recordings forever. Define how long you need them, and delete them when that period expires. Personal data must not be kept longer than necessary.
- Audit trails – Keep logs of who accessed a recording and when, so you can show accountability if a regulator asks.
Handling deletion requests
If a participant exercises their right to erasure under Article 17, you need to be able to act on it (subject to the Article 17 exceptions, such as legal-hold obligations). Removing one person from a group recording isn't straightforward. Some platforms offer redaction tools that can remove a specific individual; if yours doesn't, you may need to delete the whole recording. Remember that deleted data can persist in backups until the backup window rolls over.
The bottom line: record only when there is a genuine business need, inform everyone, and keep a clear retention and deletion process.
How does GDPR apply to screen sharing and live streaming?
Both can expose personal data to people who were never meant to see it, which brings them inside GDPR's scope. Screen sharing carries a risk that is easy to overlook: inadvertent data exposure. A notification pops up from a personal app, an open browser tab reveals confidential information, or a document preview shows client names. All of this can count as a personal data disclosure under GDPR.
Good practice for screen sharing:
- Close unnecessary applications and browser tabs before you share.
- Use the "share a specific window" option rather than your entire desktop.
- Turn off notification pop-ups during the meeting.
- If recording while sharing, take extra care: everything on screen becomes part of the recording.
Live streaming raises a further issue. Unlike a private call, a stream reaches a wider audience, potentially outside the EU. If you stream an event that includes personal data (participant names, Q&A, chat messages), you need to handle GDPR for everyone whose data is processed. That means clear notice about what data is processed and, where relevant, consent for participants who appear on stream.
Which popular video platforms are GDPR-compliant?
Most mainstream platforms can be configured for GDPR; the residual risk depends on who owns the infrastructure and which laws they answer to. Here is the picture across widely used platforms, as of 2026. The aim is an informed decision, not a competitor takedown.
Zoom
Zoom has improved its security since the "Zoombombing" incidents of 2020. It offers end-to-end encryption (an option you enable), EU data residency for eligible paid customers, and a Data Processing Agreement. Zoom is a US company whose infrastructure relies on US cloud providers, which leaves a residual jurisdiction risk around US law such as the CLOUD Act for organisations in regulated industries.
Microsoft Teams
Teams is deeply integrated into the Microsoft 365 ecosystem, which is convenient but comes with trade-offs. In 2022, Germany's Data Protection Conference (DSK) concluded that proof of GDPR-compliant use of Microsoft 365 could not be provided, citing insufficient transparency about how Microsoft processes personal data for its own purposes; Microsoft disputed the finding. Microsoft has since completed its EU Data Boundary (2025) and updated its data processing terms, but it remains a US company processing large amounts of data globally.
Google Meet
Google Meet encrypts data in transit and at rest, and Google offers a DPA for Workspace customers. Google states it does not use Workspace data for advertising. As with other US providers, the residual question for EU buyers is jurisdiction: Google is a US company, so data can fall within reach of US law.
Jitsi Meet
An open-source option that can be self-hosted, which gives you full control over data. In its 2020 provider review, Berlin's data protection authority rated commercially hosted Jitsi instances favourably where a compliant DPA is in place. The trade-off: self-hosting makes you responsible for hosting, maintenance, and security, and running it on a US cloud brings back the same jurisdiction question. It takes real technical expertise.
Digital Samba
Digital Samba is built in Europe and hosted on European infrastructure, with no US hyperscaler in the media path. With optional end-to-end encryption, anonymised user IDs, scoped session tokens, and no advertising profiling, it is designed for GDPR compliance from the ground up rather than as a bolt-on. More on this below.
GDPR video conferencing checklist: what should you check before you buy?
Before you commit to a platform or a video API, work through this list.
Platform selection:
- Does the platform host data within the EU on European-owned infrastructure? (Ask who owns and operates the servers, not just the region.)
- Does it offer true end-to-end encryption, not just transport encryption?
- Is a Data Processing Agreement (DPA) available and up to date?
- Can the provider name every sub-processor and say where each one runs?
- Does the provider have a clear, transparent privacy policy?
- Is the platform privacy by design, or are privacy features optional add-ons?
Building on a video API:
- What data actually reaches your own backend, and where is it stored?
- Can you pin processing and storage to an EU region?
- Who stores recordings and transcripts, you or the provider, and under whose keys?
- How are session tokens scoped, and can you limit them per participant?
- Which sub-processors sit behind TURN, the media server, and any AI features?
- Are you the controller, processor, or sub-processor for this data, and does your DPA reflect that?
Consent and rights:
- Can you inform participants about data processing before meetings begin?
- Does the platform support consent handling for recordings?
- Can participants exercise their right to access, correct, or delete their data?
- Can you honour erasure requests for recordings?
Security and recordings:
- Are recordings encrypted at rest and in transit, and who holds the keys?
- Is access to recordings restricted by role-based permissions?
- Do you have defined retention policies for recordings?
- Are audit trails kept for recording access?
Organisational measures:
- Have you trained employees on GDPR obligations during video calls?
- Do you include privacy policy links in meeting invitations?
- Do you review your video conferencing setup for compliance regularly?
- Have you documented your lawful basis for processing video call data?
How does Digital Samba approach GDPR compliance?
Digital Samba builds for GDPR by default: European infrastructure, encryption in transit and at rest as standard plus optional end-to-end encryption, and no advertising or data monetisation. Here is who we are and how the platform handles your data.
Digital Samba is a European video conferencing company founded in 2003 in Barcelona. We've focused exclusively on video conferencing for over two decades, since before Zoom or Teams existed, and we build the platform to keep your data private rather than to monetise it.
European hosting under EU law
We don't rent an "EU region" from a US cloud giant. Digital Samba is a European company (Digital Samba S.L., based in Barcelona and under EU law), and we run the platform on European data-centre providers across Europe, not a US hyperscaler. There's no US hyperscaler in the media path, so your call content doesn't live on infrastructure owned by a US cloud provider, which is the usual route the CLOUD Act relies on. The full sub-processor list is in our Data Processing Agreement.
End-to-end encryption that locks us out
Every session is encrypted in transit (TLS 1.3 where your browser supports it, TLS 1.2 as the floor) and at rest (AES-256-GCM) as standard. When you switch on end-to-end encryption, only the meeting participants can decrypt the content, not us, not our engineers, nobody with access to the servers. As proof that our E2EE is genuine, server-side recording and transcription are refused in an E2EE session rather than quietly downgraded, because the servers cannot read the media. That matters in healthcare, legal, financial, and public sector work, where confidentiality is a legal requirement.
No advertising, no data monetisation
We don't profile your users for advertising. We store what's needed to run your meetings and what you choose to save, such as recordings you switch on, and that stays private and under your control. We don't sell your meeting content, profile it, or use it to train AI models. Delete a recording or a room and its data is removed from the platform, and it ages out of our encrypted backups within the rolling 90-day backup window.
Privacy-first architecture
The platform runs on data centres operated by ISO 27001:2022-certified providers, with anonymised user IDs and scoped session tokens, each limited to one session and participant. The account owner decides who inside your account can open recordings or download transcripts, restricted to admins by default. Internally, we are building an information security management system structured around ISO 27001:2022; Digital Samba is not yet certified in its own right.
A focus that has lasted
We've stayed focused on video conferencing the whole time, through multiple shifts in the market. When you pick a vendor for something as sensitive as video, that continuity is worth weighing.
To build GDPR-compliant video conferencing into your product, sign up for free or book a demo with us.
Frequently asked questions
What makes choosing a GDPR-compliant video conferencing API so difficult?
Because "GDPR-compliant" is a marketing claim rather than a certificate, you have to verify it yourself. The hard part is checking things vendors rarely advertise: where data is hosted and who controls it, which sub-processors touch the data, whether encryption is end-to-end or only in transit, how much of the compliance job the API hands to you, and the fact that there is no certificate to confirm any of it.
Is hosting in the EU enough for GDPR compliance?
Not on its own. An EU data centre owned by a US company can still be within reach of the US CLOUD Act, so who owns and operates the infrastructure matters as much as where it sits. And GDPR still puts the lawful basis, records, and data-subject requests on you as the controller, whatever platform you use.
Do I need a Data Processing Agreement with a video conferencing provider?
Yes. Under GDPR Article 28, any provider that processes personal data on your behalf must sign a Data Processing Agreement with you. It sets out what they can do with the data, which sub-processors they use, and how breaches are handled.
Is Zoom GDPR-compliant?
Zoom offers EU data residency for eligible paid customers, a Data Processing Agreement, and optional end-to-end encryption, so it can be configured for GDPR. The residual risk is that Zoom is a US company on US cloud infrastructure, which keeps it within reach of US law such as the CLOUD Act.
What are the GDPR requirements for recording a video call?
You need a lawful basis, which at work is often legitimate interests with clear notice rather than consent. Recordings should be stored securely, encrypted at rest, access-controlled, kept only as long as necessary, and deletable on request under the right to erasure.
Does GDPR apply to live streaming?
Yes. A live stream that shows participant names, faces, chat, or Q&A is processing personal data, and it often reaches a wider audience than a private call. You need clear notice about what data is processed and, where relevant, consent from anyone who appears on stream.
What is the difference between a white-label video API and a low-level API for GDPR?
A white-label platform handles rooms, recordings, and storage inside one compliant environment, so the provider carries more of the GDPR load. A low-level API streams raw media into your own stack, which brings your code, storage, and sub-processors into your compliance scope.
Ready to switch to genuinely GDPR-compliant video conferencing? Sign up for free and get 10,000 participation minutes a month on the Embedded Start plan, or schedule a demo with our team to see how Digital Samba can work for your organisation.
Digital Samba's GDPR-native video platform for legal services was designed inside the EU from day one, with no transatlantic data routing in any tier.
Share this
You May Also Like
These Related Stories

Video Conferencing Security: Risks, Best Practices, and How Encryption Works

10-Step Checklist: How to Become Compliant with GDPR
.webp)
