AVAY

Meeting Transcription Consent: What the Law Actually Requires

14 August 2026

If anyone on the call is in California, Illinois, Florida, or one of the other all-party consent states, one person clicking record is not enough — every participant has to agree before transcription starts, not after. The same is true under GDPR if anyone dials in from the EU or UK. Below is what that actually requires, what gets stored once you have consent, and where the audio goes in between.

Consent law is not one law

The US federal baseline, the Wiretap Act, is one-party consent: if you're on the call, you can record it without telling anyone else. Most states default to that federal rule. A meaningful minority don't. In those states, every participant has to know and agree before the recording or transcription starts — not implicitly, not by staying on the call after you mention it in passing, but with a clear yes.

GDPR adds a second layer that has nothing to do with wiretap statutes. Recording or transcribing someone's voice is processing their personal data, full stop, and you need a lawful basis for it — consent, or a documented legitimate interest you can defend if challenged. Anyone dialing in from the EU or UK also has the right to object and to ask what happens to their data afterward, which most meeting tools have no interface for answering.

What a transcript actually stores

A transcript is rarely just the words. Most AI note-takers attach a speaker label to each line, timestamp every sentence, and extract a running list of decisions and action items that gets written to a doc separate from the raw transcript. That extracted layer usually outlives the original recording and is searchable across every meeting in the workspace, not just the one it came from.

This matters for consent because the thing you're really asking permission for is the persistence, not the thirty minutes of audio. AVAY, for example, keeps a running notes and decision log tied to the transcript that people can search weeks later — the consent conversation at the top of the call should cover that retention and search, because that's the part participants usually don't picture when they hear "this call is being transcribed."

Where the audio goes with browser speech recognition

Browser-based transcription tools generally use the Web Speech API, which does not run recognition locally on the device. It streams the raw audio to a cloud recognition service — Google's for Chrome, Microsoft's for Edge — which converts it to text and sends the text back to the browser. The audio leaves the participant's machine before anyone sees a word of transcript.

This is also why browser support is inconsistent. The API only works reliably in Chromium-based browsers. Firefox and Safari either don't support it or handle it differently, so a guest joining from Safari on an iPad may not get transcribed the same way everyone else does. AVAY's live transcription runs on this same mechanism, so it works in Chrome and Edge; it's worth checking who's on the call before you tell the room "this is being transcribed," because for some of them it might not be.

How to tell a room without it being weird

The awkwardness usually comes from treating it as a confession instead of a scheduling detail. Putting it in the calendar invite removes most of the friction because people see it before they've committed their attention to the call.

Saying it out loud at the top still matters in all-party consent states, because a line in an invite that nobody read is not the same as informed consent once someone objects.

What changes once the transcript can leave the room

Consent for the call is not the same as consent for where the notes go next. If decisions or action items get pushed automatically into Slack, a CRM, or a ticketing system through a connector, that's a second disclosure most teams skip. Someone who agreed to be transcribed for internal notes did not necessarily agree to have a line from the call show up in a support ticket a client can see.

AVAY's connectors are attached by the team itself rather than turned on by default, which means the team, not the platform, decides what a transcript is allowed to touch — and that decision is exactly the thing worth naming out loud before the call, not discovering after.

Who must agreeWhat triggers it
US one-party consent states (most states)One participant, e.g. the hostFederal Wiretap Act baseline
US all-party consent states (CA, FL, IL, MA, WA, and others)Every participant on the callState wiretap statutes
EU / UK (GDPR)Consent or a documented legitimate interest for everyoneRecording voice is processing personal data
Illinois specifically (BIPA)Separate written consent for voice/speaker matchingUse of a biometric identifier, not just the recording
Who has to agree before you transcribe a meeting, by regime
  1. 1 Put it in the invite A one-line note in the calendar description gives people time to object before they've committed to the call.
  2. 2 Say it out loud State it plainly in the first thirty seconds so it's captured in the transcript itself as evidence of consent.
  3. 3 Show it in the interface A visible indicator that transcription is running lets a late joiner see it without anyone having to repeat the announcement.
  4. 4 Handle an objection without drama Turn off transcription for that session or let the person join without a speaker label attached to their name.
Getting consent handled before you press record

Common questions

Do I need consent if I'm just taking AI notes, not recording audio?

Yes, treat it the same as recording. All-party consent laws are about intercepting and transcribing the conversation, not specifically about whether a raw audio file gets saved afterward.

Does an AI bot joining silently count as recording under these laws?

It does. A bot joining and transcribing without anyone announcing it is exactly the scenario these statutes were written to catch — there's no automation exception.

What if a guest joins from Safari and doesn't get transcribed the same way?

That's a real gap with browser speech recognition, which mainly works in Chrome and Edge. Check the transcription indicator per participant rather than assuming a blanket announcement covers everyone equally.

How long should I keep a transcript once someone has consented to it?

State a retention window as part of the consent, not as an afterthought — many teams keep the raw transcript for 90 days and the extracted decisions and action items longer. Leaving retention unstated is one of the most common gaps in an otherwise compliant announcement.

Is saying it out loud enough, or do I need written consent?

Verbal consent captured in the transcript itself is generally sufficient and doubles as your evidence that it happened. The exception is biometric use, like Illinois's BIPA covering voice matched to identity, which requires separate written consent regardless of what's said on the call.

The short version

Get consent for what happens to the transcript after the call — retention, search, and any connector it feeds — not just for turning transcription on, and say it out loud early enough that it's captured in the transcript as proof.

Try it on your next call

Meetings that take their own notes, in the browser: avay.ai.