GDPR-compliant video conferencing (2026): what it actually takes (and a Zoom alternative that translates)
"GDPR-compliant" on a video platform's homepage is close to content-free. GDPR is not a certification you pass — it's a set of obligations on you, the data controller, that a vendor either helps you meet or quietly leaves on your desk. The useful question isn't "is this tool GDPR-compliant?" It's "what does this tool make me responsible for, and where does my meeting data actually go?"
🔒 Update — we did this to ourselves. Since this post went up, we ran InterMIND's own codebase through the full checklist below and closed every item — erasure, retention, EU runtime, sub-processors — verified against the code, not asserted on a page. → Read the audit close-out, line by line.
This post is the plain-terms version of that question: the checklist a DPO actually works through, where Zoom sits on it (fairly — it's more compliant-capable than the internet implies), and where an EU-runtime alternative changes the answer. If you want the broader "how should real-time meetings work" frame, that's the pillar guide; this one is specifically about the data-protection layer.
The plain-terms checklist
Strip the marketing and "GDPR-compliant video conferencing" comes down to seven things you can actually verify:
- A signed DPA. A Data Processing Addendum that names the vendor as your processor, with documented purposes and instructions. No DPA, no lawful processing — full stop.
- A real sub-processor list. Every third party that touches meeting data — transcription, storage, email, analytics, AI features — named, with what they do and where they're domiciled.
- Where data is processed at runtime. The physical region your audio, transcripts, recordings, and metadata are handled in. This is what most data-residency clauses are actually about.
- The international-transfer mechanism. If any data leaves the EEA, on what legal basis? Standard Contractual Clauses (SCCs), adequacy, or a residency setup that avoids the transfer entirely. This is the Schrems II question, and it doesn't go away because a homepage says "compliant."
- Security posture you can audit. ISO 27001, ISO 27701, SOC 2 — independent attestations, not self-assertions.
- Data-subject rights tooling. Can you actually fulfil access, deletion, and portability requests for meeting data, or only in theory?
- Retention and deletion you control. Recordings, transcripts, and AI summaries deleted on your schedule, not the vendor's default.
A tool is "GDPR-compliant" for your purposes only when all seven have concrete answers. Most homepages answer zero of them.