EU
GDPR Consent for Voice Recording
The short answer. Valid consent under GDPR is four things at once: freely given, specific, informed and unambiguous. A blanket release that covers "recording" does not cover training a model on the recording, because specificity is measured purpose by purpose. Consent also has to be separable from other terms, and as easy to withdraw as it was to give. Most voice dataset consent forms fail on specificity rather than on signature. Read the actual form text before you accept a dataset, not a summary of it.
The law
GDPR Article 4(11)
"consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Four requirements, and a voice dataset usually fails the second. "Specific" means the speaker agreed to this purpose. A form saying the recording may be used "for research and development" describes a category, not a purpose.
GDPR Article 7(2)
If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.
This is the provision that kills the standard production release. When consent is buried inside a contract about payment, scheduling and confidentiality, it is not clearly distinguishable and is not binding. A separate consent page costs nothing and is the cheapest fix available to a data supplier.
GDPR Article 7(3)
The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
Withdrawal is a live operational problem for a distributed dataset, not a paperwork one. Once the corpus is with buyers and the model is trained, a speaker can still withdraw, and processing after that point has no basis. The clause says withdrawal cannot be made difficult.
GDPR Recital 32
Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. ... Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them.
The last two sentences are the granularity rule. Recording, transcription, model training and redistribution are four purposes, and consent has to reach each one. That is why a single checkbox covering "use of my voice" fails for AI training.
Who it applies to
This applies to any project where the speaker is in the EU at the time of recording, regardless of where the company running the project is registered. It also applies to a buyer who never met the speakers, because the buyer relies on a consent it did not obtain and cannot cure.
The obligation sits with the controller, which in most voice projects is whoever decided to collect the data and why. A data supplier acting on instructions is usually a processor, and the buyer is usually a controller or a joint controller for its own training purposes. That allocation is worth writing down, because it determines who answers a withdrawal request two years later.
The scope of the problem is wider than commercial datasets. University corpora, community language projects and app-based collections frequently rely on a research consent that does not extend to commercial training, and buyers who assume a published corpus is clearable discover otherwise during diligence. The age of the corpus is a poor guide: older forms tend to be broader in appearance and narrower in the purposes they actually specify.
One category sits outside this analysis entirely. Where the recording captures a conversation, the other party is also a data subject, and their consent is generally absent. That is why call recordings are treated as unusable rather than as a documentation problem.
- Speakers recruited and recorded specifically for the dataset: the consent can be drafted correctly, so this is a documentation check.
- Existing corpora with research-era consents: usually requires re-consent, which is often impossible, so the dataset is not clearable.
- Recordings where a third party is audible: the missing consent belongs to someone who was never asked.
What it costs to get wrong
Consent that does not meet Article 4(11) is not a weaker basis. It is no basis, and the processing is unlawful from the first file. That places it in the Article 83(5) tier: up to 20 million euros or 4% of total worldwide annual turnover, whichever is higher, because Article 83(5)(a) covers the conditions for consent under Articles 5, 6, 7 and 9.
The commercial consequence usually arrives before any regulator does. A dataset whose consent does not name AI training cannot be sold to an EU enterprise buyer, because their counsel will read the form. If the dataset has already been delivered, the supplier's warranty is the only remedy you hold, and warranties are capped.
There is also a failure mode with no clean fix. Withdrawal of consent does not unwind a model that has already been trained, and the regulation does not offer an exemption for the difficulty. Buyers who plan for this retain speaker identifiers so that affected files can be located and downstream recipients notified, and they accept that the trained model is the residual risk.
Finally, an unusable consent chain does not become usable with time. There is no limitation period that cures a missing basis, so a corpus collected badly stays a liability for as long as it is held.
How to comply when you are buying data
The check is textual. You are not assessing whether the speakers were willing — you are assessing whether the document they signed reaches the thing you intend to do with the recording. A willing speaker and a valid consent are different facts, and only the second one survives a review.
For EU projects we build the consent documentation to these requirements and deliver it alongside the dataset, and we decline work where the consent cannot be drafted to cover the intended use. We are a sourcing company rather than a law firm, so the assessment of whether a given form is sufficient for your use case belongs with your counsel; our job is to make the form and the purpose statement legible and complete, and to say plainly when a form cannot be fixed rather than deliver a dataset with a defect in it.
- Read the consent form itself. Ask for the version that was actually signed, with its date, and check whether the form changed during the collection period — a corpus recorded across eighteen months can contain two different consents.
- Check that AI or machine learning training is named as a purpose in its own right. If the form says "research", "product development" or "improvement of services", assume it does not reach commercial training.
- Check that the consent is separate from the rest of the engagement. Payment terms, scheduling and confidentiality in the same declaration is the Article 7(2) problem, and it is visible in the document.
- Ask how withdrawal works and test the answer. If the supplier cannot explain how a withdrawal request would be actioned against files already delivered, the process does not exist.
- Confirm the onward-disclosure language. The speaker should have been told that the data may be shared with third parties and may leave their jurisdiction, or the redistribution to you was never covered.
Related compliance topics
-
Is Voice Personal Data?
is voice personal data
-
Is Voice Biometric Data?
is voice biometric data
-
Biometric Privacy Laws
biometric privacy laws
-
Two-Party Consent States
two party consent states
-
Voice Recording Consent by State
voice recording consent by state
-
EU AI Act Transparency Requirements
eu ai act transparency requirements
Not legal advice
We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.
Sourcing data under GDPR Consent for Voice Recording?
Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.
- Pilot batch before the full run, so problems surface early.
- Consent documentation delivered with the data.
- No medical or clinical data. No recorded telephone calls.