Recording and transcribing a conversation raises two separate questions, and people routinely answer only the first one.

1. **Are you allowed to record it?** That's consent law, and it depends on where everyone in the conversation is sitting.
2. **Are you allowed to keep it?** That's data handling — storage, access, retention, and who else's systems your audio passes through. If the recording contains health information, this is the question that carries the real risk.

This is a plain-English overview of both. It is general information, not legal advice — the rules vary by jurisdiction and change over time, so for your specific situation, check with a qualified attorney or your compliance team.

## Question one: are you allowed to record?

Most recording laws come down to a single question: how many people in the conversation need to consent to it being recorded?

- **One-party consent:** Only one person involved in the conversation needs to agree. Since you're recording your own meeting, that one person can be you. This is the rule in most U.S. states and at the U.S. federal level.
- **All-party consent** (sometimes called two-party consent): *Everyone* in the conversation must agree to be recorded. If even one participant hasn't consented, recording can be illegal.

The safe practice in either case is the same: tell people you're recording and get their agreement before you start.

### All-party consent states in the U.S.

Around a dozen U.S. states require all-party consent. The ones most commonly cited include California, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington. The exact rules — and how they apply to video calls versus phone calls — vary by state and change over time, so treat this as a starting point rather than the final word.

### What about calls that cross state lines?

This is where it gets tricky. If you're in a one-party state and the person you're recording is in an all-party state, it's not always obvious which law applies — and courts have gone both ways. The conservative approach for any multi-state or international meeting is to **follow the strictest rule that could apply**: get everyone's consent.

### Outside the United States

Many countries treat meeting recordings as personal data, which raises the bar:

- **European Union / UK:** Under the GDPR and UK GDPR, a recording of identifiable people is personal data. You generally need a lawful basis (often consent), should tell people why you're recording, and must store and delete the recording responsibly.
- **Canada:** Federal law allows recording a conversation you're part of, but privacy legislation like PIPEDA can apply to how you handle the recording in a business context.
- **Australia:** Rules vary by state and territory, several of which require all-party consent.

If your meetings include international participants, default to asking for consent. It's simpler than mapping every jurisdiction.

## Getting consent without making it weird

You can stay on the right side of these rules with a few habits:

1. **Announce it.** Say at the top of the call that you're recording, and why.
2. **Get clear consent.** A verbal "yes, that's fine" from the group is good; for sensitive meetings, get it in writing.
3. **Make the recording visible.** A recording that everyone can see is happening is far less likely to cause problems than a hidden one.
4. **Store it responsibly.** Limit who can access recordings, and delete them when you no longer need them.
5. **Be careful with sensitive topics.** Health, legal, and HR conversations carry extra obligations.

### How AI notetakers handle disclosure

This is one reason a visible notetaker can be an advantage. When you use [Blazescribe](/ai-meeting-note-taker), the notetaker joins your call as a participant everyone can see, named "Blazescribe Notetaker." It's obvious to the room that a recording is happening, which makes the "announce it" step natural rather than an afterthought.

It still falls to you to let people know and get their consent — but a notetaker that shows up openly makes that easy, whether you're on [Zoom](/zoom-note-taker), [Google Meet](/google-meet-note-taker), [Microsoft Teams](/microsoft-teams-note-taker), or [Webex](/webex-note-taker). If you want to weigh visible-bot recording against quieter approaches, see [bot vs. bot-free AI note takers](/blog/ai-meeting-notes-guide).

## Question two: are you allowed to keep it?

Consent gets you permission to press record. It says nothing about what you may do with the file afterwards — and that second question is where most of the actual exposure sits.

A recording of identifiable people is data about those people, so the ordinary data-protection questions all apply: what are you storing, where, for how long, who can reach it, and what happens when someone asks you to delete it. Under the GDPR and UK GDPR this is spelled out — a recording of identifiable people is personal data, you need a lawful basis for holding it, and you're expected to store and delete it responsibly. Elsewhere the picture is more fragmented, but the practical obligations end up looking similar.

Three habits cover most of it:

- **Limit access.** The people who need the transcript are usually a much smaller group than the people who can currently reach it. Default to the smaller group.
- **Delete on a schedule.** A recording you deleted can't leak, can't be subpoenaed, and can't be misused. Decide up front how long you keep meeting audio and transcripts, and actually enforce it — "forever, by default" is a decision too, and rarely the one you'd have chosen deliberately.
- **Know your vendors.** When you upload audio to a transcription tool, you've handed a copy of that conversation to another company. That's fine — it's how the tools work — but it's a decision you should make on purpose.

## When the recording contains health information

If your recordings capture patient health information — clinical consultations, telehealth sessions, anything a patient tells you in the course of care — you're in a stricter regime, and consent is the floor rather than the ceiling. HIPAA brings the *handling* of that information into scope: how it's stored, who can reach it, and who processes it on your behalf, including third-party tools.

Here is the honest guidance, and it's shorter than you'd like: **we're not going to tell you which transcription tools clear your compliance bar, and you shouldn't take any blog post's word for it — including this one.** Compliance is a property of your contract with a vendor and of your own controls. It isn't a badge you can read off a marketing page, and any article that assures you a given tool is fine for patient data is not a substitute for checking.

So check. Before you upload a single recording containing patient information, get written answers from the vendor to these:

- **Will you sign the agreement my compliance team requires for handling patient data?** In U.S. healthcare, the contract you'll usually be asked to put in place with a vendor that handles this kind of data is a business associate agreement (BAA). Ask directly, get the answer in writing, and let your compliance lead — not a comparison article — decide whether it's sufficient.
- **What happens to the audio?** Where is it stored, is it encrypted in transit and at rest, and who inside the company can access it?
- **Is my content used to train models?** Ask explicitly. Assume nothing.
- **Who else touches it?** Which sub-processors, infrastructure providers, and model providers does the audio pass through on its way to becoming a transcript?
- **Can I delete it, and does deletion mean deletion?** Both the recording and the transcript, on demand.

If you can't get clear written answers to those five, that is your answer.

You can read [Blazescribe's privacy policy](/privacy) for how we handle your data. Read it against your own requirements rather than against our summary of them — and if patient information is involved, route it through your compliance team before you upload anything.

## Other conversations that carry extra weight

Health isn't the only category where the bar rises above ordinary consent:

- **HR and employee relations.** Investigations, grievances, and performance conversations create records that may be disclosable later. Decide deliberately whether a transcript should exist at all.
- **Legal.** Recording a conversation covered by legal privilege, or storing it somewhere third parties can reach, can have consequences well beyond the recording itself.
- **Financial and client data.** Sector rules and client contracts often impose their own storage, residency, and retention obligations that have nothing to do with recording law.

In all three cases, the useful instinct is the same: the question isn't only "may I record this?" but "should this recording exist, where will it live, and for how long?"

## The bottom line

In most of the U.S. you can legally record a meeting you're part of, but a number of states — and many countries — require everyone's consent. Rather than memorize a patchwork of laws, adopt one simple rule: **tell people you're recording and get their agreement first.** It keeps you compliant almost everywhere, and it's just good manners.

Then handle what you recorded like it matters: limit who can see it, delete it when you're done with it, and — if there's health, HR, legal, or client data in it — get written answers from your vendor and sign-off from your compliance team before it leaves your machine.

If you're also weighing what transcription costs and which tier fits your work, see [what transcription actually costs](/blog/transcription-pricing-guide).

*This article is general information, not legal advice. Laws vary by jurisdiction and change over time. For your specific situation — and before you process any regulated data — consult a qualified attorney or your compliance team.*
