This guide covers the United States, United Kingdom, Canada, Australia and India. It is general information, not legal advice. The lawful answer depends on every participant's location, the purpose and method of recording, the people and organisations involved, and what happens to the audio and transcript afterwards.
Do not treat one country as the rule for English-speaking meetings. A participant's authority to make a recording is one question. An organisation's duties when it collects, transcribes, stores, transfers, accesses, reuses or shares that recording are separate questions.
The safest practice in all five markets is consistent: explain the purpose, ask everyone, offer manual notes, stop for sensitive or off-record discussion, restrict access, retain the material only while it is needed, and share verified notes rather than raw audio.
The five-market answer at a glance
| Market | Participant recording | Organisation duties |
|---|---|---|
| United States | Federal law supplies a participant-consent baseline; state law may be stricter | State, sector, employment, privacy, confidentiality and security rules can add duties |
| United Kingdom | ICO data guidance does not establish broad participant permission; review the facts locally | UK GDPR and DPA 2018 duties apply to worker monitoring and call recording |
| Canada | Criminal Code §184 has a consent exception that can cover a participant; facts still matter | PIPEDA, provincial, territorial, sector and employment rules vary |
| Australia | No nationwide participant shortcut; state and territory surveillance laws vary | The Privacy Act and APPs may apply, alongside workplace and local surveillance laws |
| India | The DPDP Act does not authorise recording; participant authority needs separate review | The DPDP framework is phased, while confidentiality, employment and sector rules remain separate |
United States
May a participant record?
The federal baseline is in 18 U.S.C. §2511(2)(d). It generally permits a person to record a communication when that person is a participant or one participant gave prior consent, unless the recording is made for a criminal or tortious purpose.
That is a federal floor, not a complete answer. Official state statutes show why a federal shortcut is unsafe. California Penal Code §632 generally requires every party's consent before intentionally recording a confidential communication. Massachusetts General Laws chapter 272, §99 defines interception to include secretly recording a wire or oral communication without prior authority from all parties, subject to its stated exceptions. Other states have their own statutes and decisions, and the result can depend on whether the meeting is in person or remote, whether the communication is confidential, and what device is involved. Identify every relevant state; for a sensitive, covert or disputed recording, ask US counsel which law governs.
What must an organisation consider?
Permission to make the audio does not settle how an employer or business may use it. The organisation should identify applicable state privacy and employee-monitoring laws, sector rules, contractual confidentiality, and any special rules for health, financial, biometric or other sensitive information. A voice recording used to identify a person can create different issues from an ordinary transcript.
Document the purpose before collection. Tell participants what will be captured, who can access it, which provider will process it, where it will be stored, how long it will be kept, and whether it will be reused or shared. Limit collection and access to that purpose. A verbal yes at the start of a call does not replace the organisation's other privacy, employment, security or record-keeping duties.
United Kingdom
May a participant record?
The current ICO worker-monitoring pages do not answer whether a private participant may secretly record every kind of meeting. They govern data protection for employers and organisations, and the ICO says the main monitoring guidance does not cover purely personal or household activity unless professional or commercial activity is involved. Do not infer a broad participant permission from that material.
The answer may depend on the participant's role, purpose, workplace policy, contract, confidentiality and later use. If no official source or local advice clearly supports the proposed recording, explain the purpose, ask everyone and do not record if anyone objects. Use UK legal review for covert, disciplinary, privileged or otherwise sensitive meetings.
What must an organisation consider?
The ICO's worker-monitoring guidance requires monitoring to be lawful, fair, necessary and proportionate. The controller must identify a UK GDPR lawful basis and, where relevant, a special-category condition. It should define the purpose, use the least intrusive method, give clear privacy information, assess high-risk monitoring through a DPIA, respect access and objection rights, secure the material, limit access and follow a justified retention schedule.
The ICO's call-recording guidance says recording call content is not usually proportionate in every case. Workers and outside callers must be told that a call is being recorded and why. A third-party service requires clear controller and processor roles, appropriate contracts and security checks. Making information accessible outside the UK may be a restricted transfer requiring an adequacy route, safeguards and a transfer risk assessment, or a valid exception.
Asking everyone remains the safest meeting practice, but an employer should not assume that a worker's agreement is automatically the right UK GDPR basis. The ICO flags this guidance as under review following the Data (Use and Access) Act, so recheck it before a new monitoring programme goes live.
Canada
May a participant record?
Criminal Code §184 makes knowing interception of a private communication an offence, then provides an exception in §184(2)(a) when the interceptor has express or implied consent from the communication's originator or intended recipient. That exception can cover a participant who is an originator or intended recipient and consents to the interception.
The label often used for this rule hides important facts. Confirm who originated and was intended to receive each communication, whether the device captured anyone else's conversation, and whether another offence, court order, professional duty or confidentiality rule applies. Seek Canadian legal review before covert, evidentiary or high-risk recording.
What must an organisation consider?
Canada's privacy duties vary by organisation, sector, province and data flow. PIPEDA applies to many private-sector commercial activities, interprovincial or international personal-data flows, federally regulated organisations, and employee information in federally regulated businesses. Its principles include accountability, identified purposes, meaningful consent where required, limited collection, limited use, disclosure and retention, accuracy, safeguards, openness and access.
Provincial, territorial, public-sector and health privacy laws can apply instead of or alongside PIPEDA. Québec's private-sector law is one example, not the rule for all Canada. Alberta and British Columbia also have substantially similar private-sector laws, and several provinces have health-information laws. Map the organisation and sector before deciding which duties govern collection, transcription, vendor access, storage, retention or sharing.
For a processor outside Canada, document accountability, the purpose and authority for the transfer, safeguards, access controls and what participants were told. Interprovincial and international handling can bring PIPEDA back into scope even where a provincial private-sector law governs local activity.
Australia
May a participant record?
There is no safe country-wide participant shortcut. The OAIC says the federal Privacy Act 1988 does not specifically cover workplace surveillance and that an employer must follow relevant Australian, state and territory laws, including laws on recording telephone conversations. It also notes that some jurisdictions have specific workplace-surveillance laws.
The result can depend on the state or territory, the kind of device, whether the meeting is in person or remote, the parties' expectations, and how the recording will be used. Identify every relevant state and territory before recording. If participant authority is not clearly established for the exact facts, ask everyone and obtain local legal review.
What must an organisation consider?
The OAIC workplace-monitoring guidance separates surveillance law from privacy duties. Where an employer keeps a monitoring record, the Australian Privacy Principles may apply, although the employee-records exemption and other coverage rules need fact-specific analysis. Do not assume the exemption covers applicants, contractors, clients, unrelated uses or every item captured in a meeting.
The APP Guidelines, updated in May 2026, expressly use online meeting recordings and AI-generated transcripts as examples of collected personal information. An APP entity should check that collection is reasonably necessary, proportionate, lawful and fair; give the required notice; restrict secondary use and disclosure; secure the material; support access and correction; and destroy or de-identify it when no longer needed. Sensitive information usually needs consent unless an exception applies. Overseas disclosure requires an APP 8 assessment and reasonable steps concerning the recipient.
State or territory workplace and surveillance rules remain separate even when the APPs apply. Satisfy both layers.
India
May a participant record?
The Digital Personal Data Protection Act 2023 is India's statutory framework for processing digital personal data. It does not state that a participant may record a meeting, and it should not be used as permission to do so.
Participant authority can depend on the facts and on rules outside the DPDP Act, including contractual confidentiality, employment conditions, professional duties, court or investigation rules and sector requirements. India does not have a shortcut established by the DPDP sources used for this guide. Explain the purpose, ask everyone, and require Indian legal review for any covert, sensitive, disputed or regulated meeting.
What must an organisation consider?
India's DPDP framework is in phased commencement. G.S.R. 843(E) brought specified institutional and other provisions into force on publication in November 2025. It scheduled sections 3 to 5, most of section 6, and sections 7 to 17 for 18 months after publication; section 6(9) begins after one year. Those core processing provisions were therefore not yet in force on 24 August 2026. The final DPDP Rules 2025 use the same phased pattern: some rules began on publication, rule 4 begins after one year, and the main notice, security and related operational rules begin after 18 months.
An organisation preparing for the later phases should identify the Data Fiduciary and processors, map audio, transcript and derived notes, define the purpose and applicable processing ground, prepare notices, control access, set retention and erasure rules, support applicable individual rights, secure vendor processing and track any cross-border restriction. This preparation does not replace current confidentiality, employment, information-security, evidence or sector-specific duties. Those require a separate legal review now.
How to handle a cross-border meeting
A remote meeting can engage more than one recording rule and more than one privacy regime. Run this check before the call:
- Record every participant's physical location, including the US state, Canadian province, or Australian state or territory.
- Identify who is making the recording and which organisation, controller, APP entity or Data Fiduciary decides its purpose and use.
- List where the audio, transcript and notes will be stored, every processor and subprocessor location, who can access them, and every cross-border transfer or remote-access path.
- Assess separately every regime that may apply to making the recording and every privacy, employment, confidentiality, security, retention and transfer duty. A more protective internal policy can reduce operational risk, but it does not decide which law governs.
- If a location, role, legal basis, transfer or participant rule is uncertain, pause. Use manual notes and escalate to the privacy or legal team before recording.
A calendar notice or platform banner helps, but it is not the whole workflow. Repeat the explanation aloud at the start, ask each person, and repeat it for late arrivals.
A safe script and follow-up routine
Use plain language before the substantive discussion:
“I'd like to record this meeting so I can prepare accurate notes and action items. Only the people who need to prepare and check the notes will have access. We will keep the recording only as long as needed, then share verified notes rather than the audio. Is everyone comfortable with that? If not, I'll take manual notes.”
If someone says no, use manual notes. If the discussion becomes sensitive or someone asks to go off the record, stop recording before they speak. Do not restart until everyone agrees.
After the meeting, restrict access to the smallest useful group. Check names, decisions, quotations and action items before sharing. Follow any lawful retention schedule or legal hold, then remove the raw audio when it is no longer needed. In Meeting.ai, you can delete a recording while retaining the transcript and notes, or set processed recordings to auto-delete under your privacy controls.

Recording authority, privacy compliance and workplace trust are separate. When the facts do not fit a clearly supported rule, do not guess. Pause the recording and ask a lawyer in the relevant jurisdiction.





