GDPR check

Is Otter.ai GDPR compliant? What universities should check

Researchers ask whether they can use Otter.ai to record and transcribe interviews. This page sets out what Otter.ai publicly documents about hosting, contracts, subprocessors, transfers and AI training, and what that means for a university handling research participant data.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Otter.ai is a US company that stores data with Amazon Web Services in the United States. It offers a data processing agreement inside its Terms of Service, uses the EU Standard Contractual Clauses and is an active participant in the EU-U.S. Data Privacy Framework. Its privacy policy describes training its own AI on de-identified recordings and transcripts, while Enterprise workspaces are opted out of training by default. Whether a university can use it for research interviews depends on the plan, the contract and how the recording features are configured.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers interview transcription with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Otter.ai documents publicly

Everything in this table comes from Otter.ai's own pages or the official Data Privacy Framework list, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the vendor statesSource
Company and establishmentOtter.ai, Inc., a Delaware company based in Mountain View, California. Otter.ai is the controller for its own services, except where a Business or enterprise agreement makes the customer the controller. An EU representative under Article 27 GDPR was not found in public documentation (checked 7 October 2026).[1]
Where recordings and transcripts are storedAmazon Web Services, "based in the United States", for compute and data storage. Data is held in AWS S3 with AES-256 encryption at rest. All listed subprocessors are in the United States. Not found publicly An EU data residency option on any plan.[1] [2] [3]
Data processing agreementDocumented A Data Processing Attachment (Appendix 1 of the Terms of Service) applies to data in scope of the GDPR or UK GDPR. Terms effective 19 September 2025.[4]
SubprocessorsPublic list. Hosting: AWS, Google Cloud Platform and Crusoe. AI: Anthropic ("backend support of AI-enabled functionality") and OpenAI (evaluating Otter's language models and checking for harmful content); Otter.ai states that neither trains on or stores customer data. Research Transcriptions annotates training and evaluation data. Support, billing and messaging tools are also listed.[3]
International transfersDocumented Active participant in the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF (non-HR data), per the official list. The DPA incorporates the 2021 Standard Contractual Clauses and the UK Addendum.[1] [4] [5]
AI training on customer contentPlan-dependent The privacy policy lists "training our proprietary AI technology on de-identified audio recordings and on transcriptions". Otter.ai says de-identification is automatic and training data is not manually reviewed. Enterprise workspaces "are opted out of AI model training by default".[1] [2] [6]
Retention and deletionDeleted conversations go to the trash and are removed automatically after 30 days. Custom retention policies and removal of audio (keeping only transcripts) are Enterprise settings.[2] [6]
Security certificationsSOC 2 Type II, according to the help centre. The trust centre also offers a HECVAT Full, VPAT and penetration test report on request. ISO 27001 was not found in public documentation (checked 7 October 2026).[7] [8]
Institution controlsPlan-dependent Enterprise: SAML SSO, SCIM, domain capture, enforced two-factor authentication, locking the notetaker's auto-join setting, turning off speaker learning, enforced pre-recording emails and custom retention. An institution-wide academic licence was not found publicly.[6] [9]

Two further points matter for research use. Otter's meeting notetaker joins meetings automatically: the default workspace setting is meetings with a video conference link, which an Enterprise admin can change and lock [10]. And the Terms of Service make the user "solely responsible for providing any notices to, and obtaining consent from" the people recorded [4].

Otter.ai deserves credit for several things a DPO looks for: a public subprocessor list with locations, written no-training commitments for its third-party AI providers, a long-standing DPF certification, a HECVAT for higher education buyers, and detailed help articles on recording consent.

What this means for research and teaching

Validemic's analysis

Interview recordings are rarely ordinary data. A recorded research interview contains voices, names and whatever the participant chooses to say about health, politics, religion or sexuality. Those are special categories of data under Article 9(1) GDPR [11]. Voice recordings are personal data in every case, and Otter.ai's privacy policy mentions "Speaker Identification Information" generated from recordings [1]. Where voice features are used to uniquely identify a person, they can amount to biometric data under Article 4(14) GDPR [11]. The Enterprise switch to disable speaker learning is therefore worth discussing with your DPO.

Plan tier decides the training question. On plans below Enterprise, the privacy policy describes training Otter's own models on de-identified recordings and transcripts, and we found no self-serve opt-out for those plans. De-identification is a safeguard, but participant information sheets usually promise that recordings are used only for the study. If a researcher uses an individual account, the information sheet, the consent form and the ethics application should reflect the vendor's terms, or the researcher should use an institutional Enterprise workspace where training is off by default.

Controller or processor. The privacy policy says Otter.ai is the processor where a Business or enterprise agreement applies, and the controller otherwise [1]. For research data, universities normally want the vendor to act as processor under Article 28 GDPR [11], which points towards an institutional agreement rather than personal accounts.

DPIA likelihood. Processing special category data about research participants with a new AI tool will often meet the criteria for a data protection impact assessment under Article 35 GDPR [11], especially for large studies or vulnerable groups. Use our DPIA screening tool for a first view.

Transfers. Data is stored in the United States. Otter.ai's active DPF certification gives a transfer route for EU personal data, and the SCCs in the DPA are a second mechanism. Some universities and ethics boards still require EU storage for sensitive research data as a matter of policy, so check your institution's rules.

Meetings with other people. Automatic joining is convenient in a business setting but can surprise research participants or students. For interviews, set the notetaker to join only manually selected meetings and tell participants before recording starts.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Otter.ai before approving it

  1. Which plan will our staff use, and does our agreement make Otter.ai a processor for all research data?
  2. Can recordings and transcripts be stored in the EU, and if not, which AWS regions are used?
  3. Is training on de-identified recordings switched off for our whole workspace, and can this be written into the contract?
  4. How does the de-identification method work for audio, and has it been tested against re-identification of voices?
  5. Do Research Transcriptions or any human annotators ever access our content, and under what conditions?
  6. Can we disable speaker learning and voice profiles for all users?
  7. Can we lock the notetaker so that it never joins meetings automatically?
  8. What retention period can we enforce, and are backups covered by deletion requests?
  9. Can we see the current SOC 2 Type II report and the HECVAT under NDA?
  10. How will we be notified of subprocessor changes, and what right to object do we have?

The EU AI Act angle

The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [12]. For a university using a transcription tool, three points matter.

Sources

  1. Otter.ai Privacy Policy, effective 16 June 2026, retrieved 7 October 2026
  2. Privacy & Security | Otter.ai, retrieved 7 October 2026
  3. Otter.ai Subprocessors, retrieved 7 October 2026
  4. Otter.ai Terms of Service (including Appendix 1, Data Processing Attachment), retrieved 7 October 2026
  5. Data Privacy Framework List, entry for Otter.ai, Inc., retrieved 7 October 2026
  6. Enterprise Admin Controls Overview, Otter.ai Help Center, retrieved 7 October 2026
  7. HIPAA | Otter.ai Help Center, retrieved 7 October 2026
  8. Otter.ai Trust Center, retrieved 7 October 2026
  9. Otter.ai for Enterprise, retrieved 7 October 2026
  10. Recording Permissions with Otter, Otter.ai Help Center, retrieved 7 October 2026
  11. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4(14), 9, 28 and 35, retrieved 7 October 2026
  12. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(39), 4, 5(1)(f), 113 and Annex III, retrieved 7 October 2026
  13. Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026

About this page

We read Otter.ai's privacy policy, terms, subprocessor list, trust centre and help centre on 7 October 2026, and checked the official Data Privacy Framework list on the same day. EUR-Lex was partly unavailable on that date, so the legal texts were read from the Official Journal copies published by the EU Publications Office. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it. Plans, terms and features change, so confirm the current position with Otter.ai before relying on it.

This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Otter.ai and see an error, please contact us and we will correct it.

Frequently asked questions

Can I use Otter.ai for research interviews under GDPR?

It depends on your institution's contract, plan and configuration, not on the tool alone. Otter.ai offers a data processing agreement in its Terms of Service and is certified under the EU-U.S. Data Privacy Framework. Recordings are stored in the United States, and on plans other than Enterprise the privacy policy describes training on de-identified recordings. Ask your DPO before recording participants.

Where does Otter.ai store recordings?

Otter.ai's privacy policy names Amazon Web Services, based in the United States, for compute and storage, and every entry on its subprocessor list is located in the United States (one support provider also lists the Philippines and Honduras). An EU data residency option was not found in public documentation (checked 7 October 2026).

Does Otter.ai use my recordings to train AI?

The privacy policy says Otter.ai trains its proprietary AI technology on de-identified audio recordings and on transcriptions. Its help centre says Enterprise workspaces are opted out of AI model training by default. Otter.ai also states that Anthropic and OpenAI, listed as subprocessors, do not train on customer data.

Does Otter.ai sign a DPA?

Yes. A Data Processing Attachment is built into the Terms of Service as Appendix 1 and applies to personal data within the scope of the GDPR or UK GDPR. It incorporates the 2021 EU Standard Contractual Clauses and the UK Addendum.

Is Otter.ai certified under the EU-U.S. Data Privacy Framework?

Yes. On 7 October 2026 the official Data Privacy Framework list showed Otter.ai, Inc. as an active participant under the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF, and its privacy policy states the same.