Guide

Transcribing research interviews with Whisper: GDPR guide to local and university-run transcription

Whisper is an open-source speech recognition model that many researchers now use to transcribe interviews. The same model can run on your own laptop, on a university server or through OpenAI's paid API, and the GDPR questions differ for each. This guide sets out the options, with sources read on 7 October 2026.

Published 7 October 2026 · Sources checked 7 October 2026

The short answer

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers interview transcription with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Whisper is

OpenAI describes Whisper as "a general-purpose speech recognition model" that handles multilingual transcription, translation into English and language identification. Its code and model weights are released under the MIT licence, and the models come in sizes from "tiny" (about 1 GB of video memory) to "large" (about 10 GB), plus a faster "turbo" variant [1].

Because the weights are open, others have built on them. The National Library of Sweden's KB-Whisper is fine-tuned from whisper-large-v3 on more than 50,000 hours of Swedish speech, released under Apache 2.0, and reports an average 47% lower word error rate than the original on standard Swedish benchmarks [9]. Norway's National Library has done the same for Norwegian with NB-Whisper, which UiT and NTNU use in their services [12][13].

Whisper has known limits. Its model card warns that predictions "may include texts that are not actually spoken" (hallucination), that it can produce repetitive text, and that it performs unevenly across accents, dialects, genders, ages and other groups. It also cautions against use in high-risk decision-making [3]. For research, that means every transcript needs checking against the audio before you quote it.

Three ways to run it

Locally (your laptop or workstation)University or sector serviceOpenAI API
Who processes the audioYou, on a device your university controls (or should)The university or sector bodyOpenAI, as service provider
Processor agreement neededNo vendor involvedInternal, or with the sector bodyYes
Data leaves the deviceNo (after model download)Yes, to the serviceYes, to OpenAI
Main risksDevice loss, weak encryption, copies left behindData class limits, retention rulesTransfers, retention, contract scope
Speaker separation, editing UIDepends on the tool you addOften includedDepends on the model and your code

Running Whisper locally: what stays on the device

The open-source package runs from the command line or Python and needs the ffmpeg tool installed [1]. Two technical points matter for data protection:

Many researchers use a graphical wrapper rather than the command line. One example is aTrain, developed at the University of Graz on top of the faster-whisper implementation. Its developers say it "processes the provided speech recordings completely offline on your own device and does not send recordings or transcriptions to the internet", and it adds speaker detection through pyannote.audio [17]. The University of Helsinki says aTrain is being trialled there, and that Whisper and aTrain can be used in its Interlab research facility [16].

Validemic's analysis "Runs locally" is a property of a specific build, not of Whisper in general. Before relying on a wrapper app, check its documentation for telemetry, crash reporting, update checks and any optional cloud features, and prefer tools your university has reviewed. Also check where the app stores temporary audio and whether it is cleared.

OpenAI's API

OpenAI also offers transcription as a paid API. This is a service in which OpenAI processes the audio, so the normal processor questions apply: an agreement between your university and OpenAI, sub-processors, location and retention. OpenAI's developer documentation states, as of 7 October 2026 [4]:

Validemic's analysis These are favourable terms on paper, but they apply to an organisation's API account under OpenAI's business terms, not to a researcher's personal credit-card account. For research data, the account should be your university's, with its agreement in place and the transfer basis documented. Our ChatGPT fact sheet covers OpenAI's plans and agreements.

University and sector services

Several Nordic institutions now run Whisper-family transcription for their staff and students. Each one sets its own data ceiling.

Sunet Scribe (Sweden)

Sunet, the Swedish university network, describes Scribe as a transcription solution for universities and other organisations in research and education. It runs "i Sunets egna datacenter i Sverige" (in Sunet's own data centres in Sweden) with encrypted file handling, any Sunet-connected organisation can order it, and login uses Swamid federation [5]. Sunet's launch page says it is built on open technology "bland annat språkmodellen KB Whisper" (including the KB Whisper language model) and mentions an integration with Sunet Drive "för särskilt känsligt material" (for particularly sensitive material) [7].

Sunet's FAQ says the service is built to handle sensitive personal data, that uploaded files and transcripts are not used for model training, that local and Sunet administrators cannot access other users' files, and that material is deleted automatically seven days after upload [6]. Lund University tells its students that "Sunet Scribe is approved for use with material containing sensitive personal data" and warns that it cannot be used as storage [8]. Uppsala's UPPMAX, which documents a Whisper installation on its Bianca cluster, points users to Sunet Scribe "for a richer experience" [15].

Autotekst (University of Oslo)

Autotekst is "a UiO-developed service for transcribing speech to text using Whisper from OpenAI", free for UiO staff and students. UiO states: "The entire service runs on UiO's servers, and no data leaves UiO's infrastructure. The service can therefore be used for classified (red) data, provided you have a workspace approved for this." [10] At UiO, red covers special categories of personal data and health information [11]. OsloMet lists Autotekst among the AI tools available to its staff [21].

Klartekst (UiT) and NTNU speech-to-text (Norway)

UiT's Klartekst uses Whisper together with the National Library's NB-Whisper and "is approved for green, yellow and red data" [12]. NTNU's own speech-to-text service offers Whisper and NB-Whisper Large, keeps audio inside NTNU, and deletes transcribed files after 14 days, but is limited to "public (green) or internal (yellow) data" [13].

Aalborg University, Uppsala and Helsinki

Validemic's analysis The same underlying model is cleared for red data at UiO and UiT, but only for yellow data at NTNU. The difference reflects each institution's own risk assessment and environment, not the model. Use the rule of the service you are actually using.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Securing the laptop

Running Whisper locally moves the security burden from a vendor to you. The EDPB's guidelines on breach notification show why that matters [18]:

The EDPB's list of advisable measures includes turning on device encryption "(such as Bitlocker, Veracrypt or DM-Crypt)", passwords on all devices, multi-factor authentication, device management with remote wipe, and avoiding storing sensitive information on mobile devices where possible [18]. For interview recordings, practical steps are:

If a device with recordings is lost, see our data breach response guide.

Special category data

Interviews often contain special category data: health, ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic data, and biometric data used to uniquely identify a person. UiT's AI page sets out the same list and tells staff to keep such data out of tools UiT has not approved [12]. Processing it needs an Article 9 condition as well as a legal basis under Article 6.

Two points specific to transcription:

For legal bases, pseudonymisation and participant information, see our GDPR guide for researchers using AI tools.

When a DPIA is needed

The EDPB says that "in most cases" processing that meets two of its criteria should be assessed through a DPIA. The criteria include sensitive data or data of a highly personal nature, data concerning vulnerable data subjects, large-scale processing and innovative use of new technology [19].

Validemic's analysis A project transcribing interviews about mental health with an AI model already meets two criteria (sensitive data and new technology). Add participants who are patients, children or asylum seekers and a DPIA is very likely needed. A small project transcribing expert interviews about published policy, on a university service, may not need one, but record the screening decision either way. Our DPIA screening tool gives a first answer.

Where an external service processes the recordings, the contract must meet Article 28 GDPR: processing only on instructions, confidentiality, security, prior approval of sub-processors, help with rights and DPIAs, and deletion or return at the end [20].

Checklist

  1. Pick the route: local, university service, or API under your institution's account. Not a personal account.
  2. Match the data class to the service's ceiling: for example red at UiO's Autotekst with an approved workspace, yellow at NTNU, sensitive data at Sunet Scribe per Lund's guidance.
  3. For local use, confirm the tool is offline after model download, the machine is encrypted and university-managed, and output folders are not synced to an unapproved cloud.
  4. For the API, confirm the agreement, training terms, retention and data residency for your account.
  5. Check legal basis and Article 9 condition before recording.
  6. Screen for a DPIA and document the result.
  7. Tell participants how the recording will be transcribed, where, and when the audio is deleted.
  8. Verify transcripts against the audio; Whisper can hallucinate [3].
  9. Delete audio, temporary files and service copies on schedule. Sunet Scribe and NTNU delete automatically after 7 and 14 days; local copies are your job [6][13].

Sources

All sources retrieved 7 October 2026.

  1. OpenAI, openai/whisper (GitHub repository README).
  2. OpenAI, whisper/__init__.py (model download and cache code).
  3. OpenAI, Whisper model card.
  4. OpenAI, Data controls in the OpenAI platform.
  5. Sunet, Sunet Scribe (in Swedish).
  6. Sunet Wiki, Sunet Scribe: vanliga frågor och svar (FAQ, in Swedish).
  7. Sunet Wiki, Om Sunet Scribe, vår nya tjänst för transkribering (in Swedish).
  8. Lund University, Sunet Scribe (student guidance).
  9. KBLab, National Library of Sweden, KB-Whisper Large model card.
  10. University of Oslo, Autotekst: speech to text with Whisper from OpenAI.
  11. University of Oslo, Classification of data and information.
  12. UiT The Arctic University of Norway, Information about the use of artificial intelligence.
  13. NTNU, Speech to text.
  14. Aalborg University, CLAAUDIA lancerer ny AI-transskriptionsløsning til forskere, 21 November 2023 (in Danish).
  15. UPPMAX, Uppsala University, Whisper.
  16. University of Helsinki IT Helpdesk, Captioning and transcription.
  17. University of Graz BANDAS-Center, aTrain (GitHub repository).
  18. European Data Protection Board, Guidelines 01/2021 on examples regarding personal data breach notification, version 2.0, cases 10 and 11 and section 5.4.
  19. European Data Protection Board, Be compliant: how to conduct a DPIA (SME data protection guide).
  20. European Data Protection Board, Data controller or data processor (SME data protection guide).
  21. OsloMet, AI tools at OsloMet (staff page).

About this page

Sources checked on 7 October 2026. We read OpenAI's Whisper repository, code and model card, OpenAI's API data controls page, and the service pages of Sunet, Lund University, UiO, UiT, NTNU, Aalborg University, UPPMAX, the University of Helsinki and the aTrain project, plus EDPB guidance. Translations from Swedish, Norwegian and Danish are ours. University service rules and retention periods change; check the current page for the service you use. This is general information for researchers and DPOs, not legal advice, and not an assessment of any service. If you spot an error or run a service we should add, please contact us and we will correct it.

Frequently asked questions

Is Whisper GDPR compliant?

Whisper is a model, not a service, so the question is how you run it. Run locally, the audio stays on your machine and no vendor processes it, but your university is still controller and you must secure the device. Through OpenAI's API, OpenAI processes the audio as a service provider and you need your institution's agreement and transfer analysis. University services such as Sunet Scribe or Autotekst add the institution's own approval for defined data classes.

Does Whisper send my audio to OpenAI when I run it locally?

The open-source Whisper package processes audio on your own computer. It does contact the internet once to download the model weights, which by default are fetched from an OpenAI-hosted address and cached on the machine. After that, transcription runs locally. Wrappers and apps built on Whisper may behave differently, so check each one.

Can I transcribe interviews with health data using Whisper?

Possibly, but health data is special category data, so you need an Article 9 condition, a secure environment and usually a DPIA. Some university services are cleared for it: Lund University says Sunet Scribe is approved for sensitive personal data, and UiO allows Autotekst for red data if you have a workspace approved for it. NTNU's own service is limited to green and yellow data.

What is Sunet Scribe?

Sunet Scribe is a national transcription service for Swedish universities, run by Sunet in its own data centres in Sweden. It uses open models including KB Whisper, fine-tuned for Swedish by the National Library of Sweden. Uploaded files are deleted automatically seven days after upload, and Sunet says material is not used for model training.

Do I need a DPIA to transcribe interviews with AI?

Not always. The EDPB says a DPIA is needed in most cases where processing meets two of its criteria, such as sensitive data, vulnerable data subjects or innovative technology. Interviews on health or other sensitive topics, especially with vulnerable participants, will often meet that threshold. Screen the project and ask your DPO.

Is a Whisper transcript accurate enough to use without checking?

No. OpenAI's model card warns that Whisper can produce text that was not spoken (hallucination) and performs unevenly across accents and demographic groups. Check transcripts against the audio before analysis or quotation.