GDPR check

Is Amberscript GDPR compliant? What universities should check

Amberscript is a Dutch transcription and subtitling service used by many European universities for research interviews and lecture captions. This page sets out what Amberscript publicly documents about hosting, contracts, third parties, human transcribers and AI training, and what that means for a university handling research participant data.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Amberscript Global B.V. is an Amsterdam-based company. It says its platform runs on Google Cloud in Frankfurt, that data is never stored outside Europe, and that audio and transcripts are not used to train the language models it uses. It holds ISO 27001 and ISO 9001 certification, describes itself as a processor for uploaded files and offers a data processing agreement on request. Two points need clarifying before research use: which third parties perform automatic transcription, and how human transcription partners outside the EEA are handled. Whether a university can use it for interviews depends on the contract and on which service researchers order.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers interview transcription with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Amberscript documents publicly

Everything in this table comes from Amberscript's own pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the vendor statesSource
Company and establishmentDocumented Amberscript Global B.V., Herengracht 477, Amsterdam, the Netherlands, and Amberscript GmbH in Berlin are named as contacts. Privacy policy last updated 20 March 2026.[1]
Where recordings and transcripts are storedDocumented Google Cloud Platform infrastructure "located in Frankfurt, Germany", with backups on the same infrastructure. "Your data is never stored in locations outside of Europe."[1] [2]
Role and data processing agreementDocumented For uploaded files, users are the controller and Amberscript "processes this data on behalf of the user" as a processor. Amberscript says it will sign a DPA or NDA if desired, requested through a form.[1] [2]
Third parties for automatic transcriptionUnclear The privacy policy says "for all languages, we use third parties to transcribe your audio", and that personal data in files is sent to them. The security page says personal data "is never shared with these third parties" and that they do not store data or use it for training. Not found publicly The names and locations of these providers, or a subprocessor list.[1] [2]
Human transcribersHuman-made transcripts are handled by transcribers and transcription agencies. Amberscript requires transcribers to sign NDAs and says they work in its secure editor, and that data does not leave its servers for manual transcription. The privacy policy says some partners are outside the EEA, are "considered individual controllers" and that Amberscript has made arrangements with them.[1] [2]
AI training on customer contentDocumented "The audio and transcripts that are being generated, will never be used for training purposes of the language models that are used."[1]
Retention and deletionFiles are deleted automatically six months after upload, with reminders four and two weeks before; users can switch off automatic deletion. Deleted files and accounts are removed permanently.[1] [2]
Security certificationsDocumented ISO 27001 and ISO 9001 certification and a TPN (Trusted Partner Network) badge. Traffic is encrypted with TLS.[2]
Institution controlsBusiness solutions offer access for multiple users, centralised billing and volume discounts. The privacy policy describes SAML 2.0 single sign-on for identity providers in education and says Amberscript complies with the GÉANT Data Protection Code of Conduct for attributes released by identity providers.[1] [2]

Amberscript deserves credit for several things a DPO looks for: EU establishment, EU storage with a named data centre location, a plain no-training statement, a processor role for uploaded files, automatic deletion after six months by default and independent ISO 27001 certification.

What this means for research and teaching

Validemic's analysis

Interview recordings are rarely ordinary data. A recorded research interview contains voices, names and whatever the participant says about health, politics, religion or sexuality. Those are special categories of data under Article 9(1) GDPR [3]. The strengths listed above reduce risk, but they do not replace the university's own legal basis, information sheet and, often, an ethics approval that names the service.

Automatic and human transcription are different services. Automatic transcription keeps files in Amberscript's platform and its unnamed technology providers. Human transcription adds people outside the platform team, some of them outside the EEA [1]. The privacy policy's description of those partners as separate controllers is unusual for a transcription supplier and matters: under Article 28 GDPR [3], a university normally expects everyone touching participant data on its behalf to be a processor or subprocessor bound by the DPA. For sensitive interviews, ask whether you can restrict human work to EEA-based transcribers, or use automatic transcription only.

The third-party question needs one clear answer. The privacy policy and the security page describe the automatic transcription providers differently [1] [2]. Neither names them. A university should get the list of subprocessors, their locations and the transfer mechanism in the DPA annex before approval.

DPIA likelihood. Processing special category data about research participants with an AI transcription service will often meet the criteria for a DPIA under Article 35 GDPR [3]. An EU-hosted service with a DPA makes the assessment simpler, not unnecessary. Our DPA checker helps review the agreement Amberscript sends.

Retention fits research practice, if you plan for it. Six-month automatic deletion is a sensible default. Researchers should download transcripts to approved institutional storage and should not switch off automatic deletion unless the data management plan says so.

Lectures and teaching. Captioning recorded lectures involves the teacher's voice and, when students speak, theirs too. That is lower risk than research interviews, but it still needs a lawful basis, a note in the privacy information for the course and a decision on who holds the account. Individual staff accounts paid by card sit outside the university's DPA, so central procurement of an institutional account is the safer route for both captions and interviews.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Amberscript before approving it

  1. Which third parties perform automatic transcription for each language, where are they located, and is personal data in our files sent to them?
  2. Can we see the full subprocessor list that will be annexed to our DPA?
  3. For human transcription, can we restrict work to transcribers in the EEA, and will every transcriber act as a subprocessor rather than an independent controller?
  4. Which transfer mechanism applies to any transcription partner outside the EEA?
  5. Can we enforce retention and deletion settings for all users in our institutional account?
  6. Which identity federations does your SAML 2.0 single sign-on support, and can we enforce it for all users?
  7. Can we see the ISO 27001 certificate and its scope, including whether the transcription workforce is covered?
  8. How will we be notified of new subprocessors, and what right to object do we have?

The EU AI Act angle

The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [4]. Transcribing research interviews and captioning lectures are not among the education uses listed as high-risk in Annex III (such as admission decisions, evaluating learning outcomes or monitoring students during tests), and the Annex III obligations now apply from 2 December 2027 under Regulation (EU) 2026/1744 [5]. Automatic captions can be an accessibility measure, which is a benefit worth recording. The obligation that applies today is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff and others using AI systems on their behalf [6]. Researchers should check automatic transcripts against the recording before analysing or quoting them.

Sources

  1. Amberscript Privacy Policy, last updated 20 March 2026, retrieved 7 October 2026
  2. Amberscript Data Security and Privacy, last updated March 2026, retrieved 7 October 2026
  3. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 9, 28 and 35, retrieved 7 October 2026
  4. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Annex III, retrieved 7 October 2026
  5. Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
  6. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Amberscript's privacy policy, data security and privacy page and terms and conditions on 7 October 2026. Amberscript is an EU company that says it stores data in Europe, so the EU-U.S. Data Privacy Framework is not relevant to its own hosting; we did not check it. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it. A DPA and subprocessor list are available on request and may answer the open questions above, so confirm the current position with Amberscript before relying on this page.

This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Amberscript and see an error, please contact us and we will correct it.

Frequently asked questions

Can I use Amberscript for research interviews under GDPR?

It depends on your institution's contract and how the service is used, not on the tool alone. Amberscript is an EU company, says it stores data only in Europe, offers a data processing agreement on request and states that audio and transcripts are not used to train its language models. Check with your DPO which service type (automatic or human-made) is approved for your study.

Where does Amberscript store data?

Amberscript says its infrastructure runs on Google Cloud Platform in Frankfurt, Germany, and that data is never stored outside Europe. It also uses third parties for transcription; ask which of them process your files and where.

Does Amberscript use recordings to train AI?

Amberscript's privacy policy says the audio and transcripts it generates will never be used to train the language models it uses, and its security page says the third parties it uses do not store data or use it for training.

Does Amberscript sign a DPA?

Yes. Amberscript's privacy policy says it will sign a data processing agreement or NDA on request, and its security page links a form for requesting one. The policy describes Amberscript as processing uploaded files on behalf of the user, who is the controller.

Do human transcribers see my recordings?

Only if you order human-made or human-checked transcription. Amberscript says transcribers sign NDAs and work in its secure editor. Its privacy policy also says some transcription partners are outside the EEA and act as separate controllers, which a university should raise before using that service for sensitive data.