Data protection worldwide
Last updated: 19 September 2026
The regimes below all treat a voice recording — and a transcript in which speakers can be told apart — as personal data. The obligations rhyme: a lawful basis, a notice, stricter handling of sensitive categories, individual rights, and rules about moving the data across borders.
| Place | Law | Regulator | Worth knowing |
|---|---|---|---|
| EU / EEA | GDPR (2016/679) | National DPAs / EDPB | See GDPR. Criminal recording law can be stricter than the GDPR. |
| United Kingdom | UK GDPR + Data Protection Act 2018 | ICO | Same framework, separate regulator. |
| Türkiye | KVKK (No. 6698) | KVKK | See KVKK. Separate duty to inform under Art. 10. |
| Switzerland | revFADP (2023) | FDPIC | GDPR-adjacent, not identical. |
| Brazil | LGPD (Law 13.709/2018) | ANPD | Closely modelled on the GDPR. |
| Canada | PIPEDA (federal) + provincial laws | OPC | Recording by a participant is lawful under s. 184 Criminal Code; commercial handling still falls under PIPEDA. |
| United States | CCPA/CPRA (California) and a growing set of state laws | CPPA and state AGs | No single federal privacy law. The recording-consent rules are the sharper risk — several states require all parties to consent. |
| India | DPDP Act 2023 | Data Protection Board (being established) | Consent-centric; rules were still being phased in at the time of writing. «Yayın öncesi güncellik doğrulanacak.» |
| Japan | APPI | PPC | See APPI. |
| South Korea | PIPA | PIPC | See PIPA. |
| China | PIPL + DSL + CSL | CAC | See PIPL. Voiceprints are biometric data. |
| Saudi Arabia | PDPL | SDAIA | See PDPL. |
| United Arab Emirates | Federal Decree-Law 45/2021 (+ DIFC, ADGM) | UAE Data Office | Free zones run their own regimes. |
| Thailand | PDPA (2019) | PDPC | GDPR-shaped. |
| Indonesia | PDP Law (No. 27/2022) | «kurulmakta olan otorite» | Phased implementation. |
| Vietnam | Decree 13/2023 on personal data protection | Ministry of Public Security | Notification duties are distinctive. |
| Russia | Federal Law 152-FZ | Roskomnadzor | Localisation requirements for citizens' data. |
| Ukraine | Law on Personal Data Protection | Ombudsman | Reform toward GDPR alignment was in progress. «Güncellik doğrulanacak.» |
| Australia | Privacy Act 1988 | OAIC | Recording rules differ by state under surveillance-devices acts. |
The pattern behind the table
Almost every obligation above becomes heavier the moment a recording leaves your machine: a processor has to be appointed, a transfer mechanism found, a vendor's security assessed, a breach path planned. Processing on the device removes that whole category of work — not by an assurance, but because there is nothing in transit.
What Caliptic Translate actually does
Speech recognition, translation, speaker separation and meeting transcription run entirely on your own computer. Audio, transcripts and meeting titles are never transmitted to us or to any third party. In Meeting mode the raw audio is not stored at all — only the transcribed text is written to your own disk, under your own user account.
Because of this, for the content of your conversations we are not a controller or a processor: we never receive that data. The person who starts the recording is the one who decides why and how it is processed, and is therefore the controller of it.
We do hold a small amount of data as the seller: order and subscription metadata through Paddle, our Merchant of Record. That is covered by our Privacy Policy.
What this means for you
On-device processing removes the transfer and vendor-access questions. It does not remove your own obligations. If you record a meeting, you are the one who must have a lawful basis for it, inform the participants, honour their requests about the recording, keep it only as long as you need it, and delete it when you do not. The app gives you the tools — a visible recording notice, local storage you control, and one-click deletion — but the duty is yours.