Interview transcription and the GDPR
A great deal has been written about transcription software and almost nothing about the data protection behind it. Yet it is the question most reliably asked in ethics applications, supervision meetings and vivas. This guide sorts out what applies, what is negotiable, and where projects actually come unstuck.
Why an interview is more than an audio file
A voice recording identifies the person speaking even when no name is mentioned. That makes it personal data within the meaning of Article 4 GDPR, and the transcript does not change that; it inherits the status of the recording.
Two things are routinely overlooked. First, interviews almost always contain data about third parties: managers, colleagues, family members, patients. Those people never consented. Second, health, trade union membership, religion, sex life and political opinions fall under Article 9 GDPR as special categories. An interview about strain in the nursing profession produces such data more or less inevitably.
In practice this means the protection your recording needs is higher than most project plans assume.
The four questions an examiner will ask
1. What is your lawful basis?
In research it is usually consent under Article 6(1)(a), and for special categories additionally Article 9(2)(a). Consent must be freely given, informed and withdrawable, and you must be able to demonstrate it. A spoken yes at the start of the recording rarely satisfies that burden of proof.
What a defensible consent form contains:
- Who processes the data, for what purpose, and for how long
- Whether a recording is made and what happens to it after the project
- Which processors are involved, named, with their processing location
- Whether and how the transcript will be anonymised
- How withdrawal works and what it triggers
The fourth item is where template consent forms fail. If you only decide which tool will transcribe after collecting the data, you never obtained consent for it.
2. Who else processes the data?
The moment a recording is uploaded to an external service, that service is a processor under Article 28 GDPR. You need a data processing agreement, often called a DPA. Reputable providers publish one without being asked, either as a downloadable document or as part of their terms.
If transcription happens entirely on your own machine, using a locally running model, no DPA is needed. That is precisely why universities often favour local solutions despite the extra effort.
3. Where does the data go?
Transfers to the United States have been possible since the adequacy decision on the EU-US Data Privacy Framework of July 2023, provided the vendor is certified under it. Alternatively, standard contractual clauses together with a transfer impact assessment will carry the transfer.
That is the legal position. The practical one differs: certifications change, the checking is on you, and many universities and hospitals now require processing inside the EU regardless, because it ends the discussion before it starts. If you want to keep that route open, choose a provider that processes in the EU.
4. What happens to the content at the vendor?
The question that appears in almost no consent form and matters anyway: are uploaded recordings used to train models? With free tools that is frequently the price. The answer belongs in the vendor's privacy policy, and if it is not there, that is itself an answer.
Anonymising or pseudonymising
The two terms are used interchangeably in everyday speech. In law they are not.
Pseudonymisation replaces identifying features with codes, B1 instead of Beate M. The link remains restorable through a key file. Pseudonymised data is still personal data and remains fully within scope of the GDPR.
Anonymisation removes the link so far that attribution is no longer possible with additional knowledge and reasonable effort. Only then does the GDPR cease to apply.
For interviews, genuine anonymisation is harder than it sounds. Replacing the name is not enough. A combination of occupation, location, organisation size and length of service can pin down a person in a small sector without any name at all. Indirect features therefore belong on the list:
- Place and organisation names, replaced by categories such as “a large teaching hospital”
- Rare job titles and functions
- Specific years where they attach to life events
- Distinctive speech features, where dialect or idiolect is identifying
A workable compromise in research: work pseudonymised, keep the key file separate and encrypted, and produce an anonymised transcript for publication. The full method is set out in Anonymising interview transcripts.
Deletion belongs in the plan, not at the end
The storage limitation principle requires that data exists only as long as the purpose demands. For dissertations that purpose usually ends with the examination process; in funded research, with the end of analysis or with the retention period set by research integrity rules.
Writing the period into the consent form saves the argument later. A pattern that works: raw recordings are deleted once the work is accepted, the anonymised transcript remains for verifiability.
This assumes the service you use actually permits deletion, verifiably. An account from which recordings cannot be removed makes the deletion promise in your consent form worthless.
Checklist before the first interview
- Written consent form exists and names the transcription service
- Lawful basis established, including Article 9 for sensitive topics
- DPA with the vendor is in place, or processing runs locally
- Processing location known and documented
- It is settled whether content is used for model training
- Retention periods defined and technically achievable
- Anonymisation rules fixed before the first transcript exists
- Key file kept separately and encrypted
Note: this article is a practical overview, not legal advice.
Where Nodl fits into this picture
Nodl is a tool for spoken recordings that produces a transcript and, from it, a structured document. Four properties matter for the data protection part, and they are verifiable rather than asserted:
- Recordings, transcripts and transcript segments are encrypted at field level in the database
- Processing and storage take place in Germany; the language models used run inside the EU
- Content is not used to train models
- Recordings and documents can be exported and deleted
Also relevant for interviews is speaker separation: with several voices, Nodl assigns the passages to speakers and colours them differently in the transcript. Each passage carries a timestamp that jumps straight to the matching point in the audio. When checking a disputed passage, that is the difference between two minutes and twenty.
One limit belongs here: a single recording may currently be up to one hour long. Longer interviews have to be split first.
Common questions
It may be valid, but it is rarely demonstrable. The GDPR requires you to be able to evidence consent. A signed form or a documented digital agreement is far more robust than a spoken yes sitting inside the very dataset you have promised to delete.
Those people did not consent, so their names do not belong in your working material. It works best to replace them during the first pass through the transcript, using the role rather than the name. The later you do it, the more copies already exist.
Many institutions keep a record of processing activities and expect the tool to be named in the ethics or data protection application. Ask early which tools are already approved. A pre-cleared vendor saves weeks compared with one the office has to assess from scratch.
Withdrawal takes effect for the future. That person's recording and transcript must be deleted unless another lawful basis applies. Material that is already genuinely anonymised is unaffected, because it no longer relates to an identifiable person. That is exactly why anonymising early pays off.