Microsoft Teams Meeting Recording, Transcription and AI Privacy Notice

MICROSOFT TEAMS MEETING RECORDING, TRANSCRIPTION AND AI PRIVACY NOTICE

Effective date: 29 July 2026
Version: 1.0

1. Who we are

COMIT Solutions Ltd (“COMIT”, “we”, “us” or “our”) is the controller responsible for the personal data processed when COMIT organises and records or transcribes a Microsoft Teams meeting.

Our contact details are:

COMIT Solutions Ltd
Office 104, Nicosia Business Center
33 Neas Engkomis
2409 Nicosia, Cyprus

Email: info@comit.com.cy
Telephone: +357 22 42 61 42

Privacy-related requests may be submitted using the general company contact details above. Please write “Data Protection Request” in the email subject line.

2. Scope of this notice

This notice applies when a Microsoft Teams meeting organised by COMIT is:

  • audio or video recorded;
  • transcribed;
  • processed using Microsoft 365 Copilot, Teams Facilitator, intelligent recap or a similar Microsoft 365 AI feature;
  • used to generate meeting notes, summaries, chapters, highlights, tasks, decisions or action items; or
  • accompanied by attendance, participation or recording-agreement information.

This notice applies to COMIT employees, customers, suppliers, contractors, professional advisers and other persons who attend such meetings.

Not every COMIT meeting will be recorded or transcribed. Where recording, transcription or AI-assisted processing is used, participants will be informed through the meeting invitation, an in-meeting notification, an announcement by the organiser or a combination of these measures.

3. Personal data we may process

Depending on how you participate in the meeting, we may process:

  • your name, email address, company, job title and Teams account details;
  • your voice and statements made during the meeting;
  • your image, background and other information visible through your camera;
  • screen-shared material, presentations, documents and demonstrations;
  • messages, reactions, polls and other meeting contributions;
  • the date, time, duration and attendance details of the meeting;
  • technical information concerning your participation;
  • the meeting recording and transcript;
  • information showing whether you accepted or declined the Teams recording or transcription agreement;
  • AI-generated notes, summaries, suggested tasks, decisions, chapters, highlights and recaps; and
  • information contained in documents or other material discussed or displayed during the meeting.

Please avoid disclosing personal data that is not necessary for the purpose of the meeting.

4. Purposes of processing

COMIT may record, transcribe or use AI-assisted meeting functions for one or more of the following purposes:

4.1 Meeting administration

To:

  • prepare accurate meeting minutes;
  • identify decisions, responsibilities and action items;
  • assist participants who need to review the discussion;
  • support follow-up activities; and
  • reduce misunderstandings concerning what was discussed or agreed.

4.2 Project and client records

To:

  • document project requirements, instructions and decisions;
  • maintain an accurate record of customer or supplier discussions;
  • evidence approvals, changes, commitments and deliverables;
  • support contract and project management; and
  • resolve questions or disputes concerning a meeting.

4.3 Training and quality assurance

Where specifically disclosed and appropriate, to:

  • review the quality of COMIT services;
  • provide internal employee training;
  • improve meeting, project-management and customer-service practices;
  • identify process improvements; and
  • evaluate whether internal procedures are being followed.

COMIT will not routinely use every recorded meeting for training or quality-assurance purposes. Where this purpose applies, it should be stated in the invitation or meeting notice.

4.4 Security, compliance and legal matters

To:

  • investigate suspected security incidents or misconduct;
  • comply with legal, regulatory, contractual or audit requirements;
  • respond to lawful requests from competent authorities; and
  • establish, exercise or defend legal claims.

4.5 AI-assisted meeting support

To use Microsoft 365 services to:

  • produce draft meeting notes and summaries;
  • identify possible tasks, decisions and action items;
  • create meeting chapters or highlights;
  • help authorised employees locate information discussed during the meeting; and
  • support preparation of follow-up communications.

AI-generated content may be incomplete, inaccurate or misleading. COMIT employees must review material generated by AI before relying on it or using it as an official business record.

5. Lawful bases

COMIT will only process personal data where it has an appropriate lawful basis under the General Data Protection Regulation.

Depending on the meeting and purpose, the lawful basis may be:

5.1 Legitimate interests

COMIT may rely on its legitimate interests under Article 6(1)(f) GDPR, including its interests in:

  • maintaining accurate business and project records;
  • administering meetings efficiently;
  • recording decisions, instructions and action items;
  • managing customer and supplier relationships;
  • improving service quality and internal processes;
  • protecting its legal and commercial interests; and
  • maintaining information and systems security.

Before relying on legitimate interests, COMIT must consider whether the processing is necessary and proportionate and whether the interests, rights or freedoms of participants override COMIT’s interests.

Participants have the right to object to processing based on legitimate interests, as explained below.

5.2 Performance of a contract

COMIT may rely on Article 6(1)(b) GDPR where processing is objectively necessary to take steps at an individual’s request before entering into a contract or to perform a contract directly with that individual.

The existence of a commercial agreement with a participant’s employer does not automatically mean that all recording or transcription is necessary for performance of a contract with the individual participant.

5.3 Compliance with a legal obligation

COMIT may rely on Article 6(1)(c) GDPR where recording, retaining or disclosing information is necessary to comply with an applicable legal or regulatory obligation.

5.4 Consent

For optional meetings or particular secondary uses, COMIT may request consent under Article 6(1)(a) GDPR.

Where consent is the lawful basis:

  • consent must be freely given, specific, informed and unambiguous;
  • refusing consent must not result in unjustified disadvantage;
  • consent may be withdrawn at any time; and
  • withdrawal will not affect processing lawfully carried out before consent was withdrawn.

COMIT will not ordinarily rely solely on employee consent where the employment relationship means that consent may not be freely given.

The Microsoft Teams participant-agreement prompt confirms whether a participant permits their audio, video or shared content to be technically included in the recording or transcript. It does not necessarily mean that COMIT is relying on consent as its GDPR lawful basis. The applicable lawful basis is described in this notice and, where necessary, in the meeting-specific notice.

6. Recording and transcription notifications

When recording or transcription starts, Microsoft Teams may display a visual notification and may require participants to accept or decline the inclusion of their contributions.

A person who joins after recording or transcription has started should also receive an in-meeting notification.

The meeting organiser should also announce the recording or transcription verbally where:

  • participants are joining by telephone;
  • participants may not be able to see the Teams notification;
  • accessibility considerations require an additional announcement; or
  • the nature of the meeting makes an additional warning appropriate.

Participants should raise an objection or concern as early as possible, preferably before recording or transcription starts.

Where reasonably practicable, COMIT may offer an alternative, such as:

  • stopping the recording for part of the meeting;
  • allowing the participant to join without camera or microphone;
  • receiving the participant’s information separately;
  • holding an unrecorded discussion; or
  • recording written minutes instead.

Whether an alternative is possible will depend on the purpose of the meeting and the reason the recording or transcript is required.

7. Special-category and highly sensitive information

Meeting participants should not disclose special-category personal data unless it is necessary for the meeting.

Special-category data may include information concerning:

  • health;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • genetic or biometric data used for identification; or
  • a person’s sex life or sexual orientation.

Participants should also avoid unnecessarily disclosing criminal-offence information, passwords, authentication codes, payment-card information or confidential personal documents.

Where COMIT expects a meeting to involve special-category or similarly sensitive information, it will assess whether recording or transcription is appropriate and identify any additional legal condition and safeguards required before the processing begins.

COMIT will normally avoid recording or transcribing disciplinary, grievance, medical, privileged legal or similarly sensitive meetings unless there is a documented and proportionate reason for doing so.

8. Who may access meeting data

Access to recordings, transcripts and AI-generated meeting content is restricted to authorised COMIT employees who require access for the stated business purpose.

Access may include:

  • the meeting organiser;
  • relevant project or account team members;
  • authorised managers;
  • authorised IT, information-security or compliance personnel; and
  • personnel responsible for investigating a complaint, incident or legal matter.

Meeting data will not be routinely distributed to all COMIT employees.

COMIT does not sell meeting recordings, transcripts or AI-generated meeting content.

COMIT will not routinely disclose this information to external persons. External disclosure may occur where:

  • the participant has requested or authorised the disclosure;
  • the disclosure was identified as part of the meeting purpose;
  • it is necessary to perform an applicable agreement;
  • COMIT is required to disclose it by law or by a competent authority;
  • disclosure is necessary for an audit, investigation or legal claim; or
  • an approved service provider processes the information on COMIT’s behalf.

9. Microsoft and other service providers

COMIT uses Microsoft 365 and Microsoft Teams to provide meeting, recording, transcription and AI-assisted recap services.

Microsoft and its approved subprocessors may process personal data on COMIT’s behalf to provide, secure, support and maintain these services. Such service providers are required to process the information under applicable contractual and data-protection obligations.

Although meeting content is made available within COMIT only to authorised personnel, Microsoft and approved subprocessors may technically process the information as service providers. They are not authorised by COMIT to use the data for their own unrelated purposes.

10. International transfers

COMIT seeks to use Microsoft 365 data-location and residency settings appropriate to its organisation and licensing arrangements.

Where Microsoft or another approved service provider processes personal data outside Cyprus or the European Economic Area, COMIT will require an applicable transfer mechanism under Chapter V GDPR. This may include:

  • an adequacy decision;
  • European Commission standard contractual clauses;
  • supplementary technical and organisational measures; or
  • another lawful transfer mechanism.

Further information concerning applicable safeguards may be requested using the contact details in this notice.

11. Retention

COMIT will normally retain the following information for no longer than 90 days from the meeting date:

  • the audio or video recording;
  • the transcript;
  • intelligent recap content;
  • AI-generated meeting notes and summaries;
  • meeting chapters and highlights; and
  • meeting-specific AI prompts and outputs retained with the meeting.

At the end of the 90-day period, the information will be deleted or made subject to an automated deletion policy, unless an exception applies.

Information may be retained for longer where:

  • COMIT is required to preserve it by law;
  • it is subject to a legal hold;
  • it is needed for an ongoing complaint, investigation, audit or dispute;
  • it is necessary for the establishment, exercise or defence of legal claims; or
  • a competent authority has lawfully required its preservation.

Where information is retained beyond 90 days, access will be restricted and the reason for extended retention will be documented. The information will be deleted when the exceptional purpose ends.

Final approved minutes, decisions, agreed actions or project records extracted from a meeting may be transferred into COMIT’s normal business systems. Once incorporated into another official business record, those items may be retained under the retention period applicable to that record rather than the Teams meeting-retention period.

12. Security

COMIT applies technical and organisational measures intended to protect meeting data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

  • identity and access controls;
  • multi-factor authentication;
  • role-based permissions;
  • meeting-access restrictions;
  • Microsoft 365 security and compliance controls;
  • retention and deletion policies;
  • encryption provided by the Microsoft 365 service;
  • audit logging;
  • employee confidentiality obligations; and
  • internal information-security policies.

No electronic system can be guaranteed to be completely secure. Participants should therefore avoid sharing unnecessary or excessively sensitive information during a recorded meeting.

13. Your data-protection rights

Subject to the conditions and limitations in the GDPR, you may have the right to:

  • request confirmation as to whether COMIT processes your personal data;
  • obtain access to your personal data and a copy of it;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

These rights are not absolute. For example, COMIT may need to retain information to comply with a legal obligation, protect the rights of other participants or establish, exercise or defend a legal claim.

When responding to a request, COMIT may need to protect personal data and confidential information relating to other meeting participants. This may require information to be redacted or access to be provided in another appropriate form.

To exercise a right, email info@comit.com.cy with the subject line “Data Protection Request” and provide sufficient information to identify the relevant meeting and your involvement.

COMIT may request reasonable evidence of identity before acting on a request.

14. Right to object

Where COMIT relies on legitimate interests, you may object to the processing on grounds relating to your particular situation.

You may object:

  • before the meeting;
  • when the recording or transcription is announced;
  • during the meeting; or
  • after the meeting by contacting COMIT.

Following an objection, COMIT will consider:

  • your reasons for objecting;
  • the purpose and necessity of the recording or transcript;
  • whether a less intrusive alternative is available;
  • the rights and expectations of other participants; and
  • whether COMIT has compelling legitimate grounds to continue processing or needs the information for a legal claim.

Submitting an objection does not automatically require deletion or cessation in every case, but COMIT will assess the objection and provide a response in accordance with applicable law.

15. AI-generated content and automated decision-making

Microsoft 365 AI services may analyse the meeting transcript or speech-to-text information to generate summaries, notes, suggested actions, highlights or other meeting content.

Such outputs are generated automatically and may contain errors. They must not be treated as a verbatim or authoritative record unless reviewed and approved by an authorised person.

COMIT does not use Teams meeting recordings, transcripts or AI-generated recaps to make decisions based solely on automated processing that produce legal effects or similarly significant effects on participants.

Where a significant employment, contractual, disciplinary or other decision is being considered, the decision must be subject to meaningful human review and must not be based solely on an AI-generated meeting summary.

16. Complaints

You are encouraged to contact COMIT first so that we can investigate and attempt to resolve your concern.

You also have the right to lodge a complaint with:

Office of the Commissioner for Personal Data Protection
15 Kypranoros Street
1061 Nicosia, Cyprus

Postal address:
P.O. Box 23378
1682 Nicosia, Cyprus

Telephone: +357 22 818 456
Email: commissioner@dataprotection.gov.cy

The Commissioner may require the appropriate complaint form to be completed.

You may also lodge a complaint with another competent EU or EEA supervisory authority, particularly in the country where you normally reside, work or believe the alleged infringement occurred.

17. Changes to this notice

COMIT may update this notice to reflect changes in:

  • applicable law or regulatory guidance;
  • Microsoft 365 functionality;
  • COMIT’s meeting practices;
  • security or retention controls; or
  • the purposes for which recordings and transcripts are used.

The current version will be published through the privacy-policy link included in COMIT’s Microsoft Teams meeting notifications and invitations.

Material changes will be communicated where required.

18. Contact us

Questions, objections and requests concerning meeting recordings, transcription or AI processing should be sent to:

COMIT Solutions Ltd
Email: info@comit.com.cy
Telephone: +357 22 426 142

Please use the subject line:

Data Protection Request – Microsoft Teams Meeting