GDPR-Compliant Dictation Software in 2026
For dictation, the GDPR question is unusually narrow: does the recording leave your device? If it does, the vendor is a processor, you need an Article 28 agreement, and a provider outside the EEA adds a Chapter V transfer to justify. If it does not, none of that arises for the transcription step.
Eight tools below, with what each one actually says about processing location. We separate the two honest answers that get blurred together: tools that keep audio on your machine, and cloud tools that keep it on EU servers. Both are defensible. They are not the same thing.
Three answers, and only one of them removes the processor
On your machine
Whisper, Speecher, superwhisper, MacWhisper. No transfer, no processor for the transcription step, no sub-processor list. Works offline. You are still the controller and you still have to secure the device.
On EU servers
Sprecho states that all voice data is stored exclusively in Germany and offers an Article 28 agreement. A processor, contracted properly, inside the EEA. Defensible, and it needs the paperwork.
On servers elsewhere
Otter.ai, Wispr Flow, Philips SpeechLive and the operating-system cloud modes. Workable, and it adds a third-country transfer to justify plus a supplier your clients may ask you to name.
Nothing on this page is legal advice, and we do not claim that any product makes you compliant. We publish the architecture and quote the vendors' own words so your data protection officer can decide.
The comparison
| Tool | Published price | Where audio is processed | Platforms | Best for |
|---|---|---|---|---|
| Whisper | $29/year, first seat | 100% on-device | Mac, Windows, Linux | Confidential work, low yearly cost, whole-team rollout |
| Sprecho | Not published | German servers, not on-device | Desktop | Buyers who accept a cloud, provided it is a German one |
| Speecher | 4.99 EUR / month | On-device | Windows, Mac, Linux | Offline dictation on a monthly subscription |
| Philips SpeechLive | $12.90–$17.90 /user/month | Cloud | Web, Windows, Mac, iOS, Android | Firms that want a dictate-and-typist workflow with hardware |
| Wispr Flow | Free, $15/user/mo Pro, from $23/user/mo Growth | Cloud for dictation | Mac, Windows, iOS, Android | Cross-device dictation where a cloud round trip is acceptable |
| Otter.ai | Free, $16.99 or $30 /user/month | Cloud | Web, Mac, Windows, iOS, Android | Team meeting notes, not private dictation |
| Apple Dictation | Free | On-device or Apple servers, depending on settings | macOS, iOS | Short, casual dictation on Apple hardware |
| Windows Voice Typing | Free | Local or Microsoft cloud, depending on settings | Windows 10, Windows 11 | Light use where nothing confidential is dictated |
Green tick: audio is processed on your own device. Amber: EU servers, or it depends on a setting. Red: audio is sent to the vendor's servers.
What each vendor publishes
Whisper
- Published price:
- $29/year, first seat — +$15/year for each additional seat, no subscription, no auto-renewal
- Where audio is processed:
- 100% on-device
- BAA / data agreement:
- No BAA needed for the transcription step, because no audio or transcript is sent to us
Sprecho
- Published price:
- Not published
- Where audio is processed:
- German servers, not on-device
- BAA / data agreement:
- Offers a data processing agreement under Art. 28 GDPR and cites § 203 StGB for regulated professions
Speecher
- Published price:
- 4.99 EUR / month — 7 days free after registration; billed monthly, cancellable at any time.
- Where audio is processed:
- On-device
- BAA / data agreement:
- No BAA or DPA is published
Philips SpeechLive
- Published price:
- $12.90–$17.90 /user/month — Basic $12.90, Pro $17.90 per user per month on annual billing. Speech recognition add-on $25.90/user/month. Speech Recognition Legal from $43.80/user/month; Legal AI Assistant from $54.00/user/month as a 2026 introductory rate, listed at $76.80 from 2027.
- Where audio is processed:
- Cloud
- BAA / data agreement:
- Page cites GDPR conformity; no data centre location is named on it
Wispr Flow
- Published price:
- Free, $15/user/mo Pro, from $23/user/mo Growth — Pro $12/user/mo and Growth from $18/user/mo billed annually. Growth with Notetaker $33/user/mo, $26/user/mo annually. Free plan: "2,000/week on desktop".
- Where audio is processed:
- Cloud for dictation
- BAA / data agreement:
- States "HIPAA-ready for dictation with a signed BAA" and "SOC 2 Type II and ISO 27001 compliant"
Otter.ai
- Published price:
- Free, $16.99 or $30 /user/month — Pro $16.99/user/month, $8.33 billed annually. Business $30/user/month, $19.99 annually. Enterprise on request.
- Where audio is processed:
- Cloud
- BAA / data agreement:
- Lists "HIPAA compliance (add-on)" on the Enterprise plan only
Apple Dictation
- Published price:
- Free
- Where audio is processed:
- On-device or Apple servers, depending on settings
- BAA / data agreement:
- Covered by Apple's own terms; no BAA
Windows Voice Typing
- Published price:
- Free
- Where audio is processed:
- Local or Microsoft cloud, depending on settings
- BAA / data agreement:
- Covered by Microsoft's own terms; no BAA
What a European team pays
What a team actually pays
$29 for the first seat, $15 for each additional seat, per year. No subscription, no auto-renewal.
| Seats | Total per year |
|---|---|
| 1 seat | $29 |
| 5 seats | $89 |
| 10 seats | $164 |
| 25 seats | $389 |
| 50 seats | $764 |
Prices are shown in US dollars, per year, charged once per purchase with no auto-renewal. See security for what we do and do not hold, and die deutsche Fassung dieser Seite.
Questions European buyers ask
Is any dictation software GDPR compliant?
Not by itself. Under the GDPR you are the controller, and compliance is a property of your whole processing operation: your legal basis, your records, your retention, your agreements. A tool can make that easier or harder. The narrow, useful question for dictation is whether the recording leaves your device. If it does, the vendor is a processor, you need a written agreement under Article 28, and if they process outside the EEA you also have a Chapter V transfer to justify. If it does not, none of that arises for the transcription step.
Which dictation tools keep audio inside the EU?
There are two different answers and they are worth separating. Whisper, Speecher, superwhisper and MacWhisper keep audio on your own machine, so there is no transfer at all, in the EU or anywhere else. Sprecho is a different model: it is a cloud service that keeps processing on German servers and states "All voice data is stored exclusively in Germany", offers an Article 28 agreement, and cites § 203 StGB for regulated professions. That is a genuinely good answer if you accept a cloud. It is still a processor, and it still needs the paperwork.
Do I need a data processing agreement for dictation software?
You need one with any vendor that processes personal data on your behalf. So yes for Otter.ai, Wispr Flow, Philips SpeechLive, Sprecho and every other cloud service on this page. For a tool that transcribes entirely on your own device and receives nothing, there is no processing by the vendor to agree about, and the licence is an ordinary software licence. That is a smaller compliance surface, not an exemption from the GDPR.
What about US-based dictation providers and the CLOUD Act?
This is the concern that drives most of the questions we get from European buyers, and it is a fair one. A US provider processing your recordings creates a third-country transfer that you have to justify under Chapter V, and it puts the data within reach of a legal system you do not control. Sprecho makes this argument explicitly on its own site. Our answer is different and simpler: if the recording never leaves the device, there is no provider to compel.
Is speech an especially sensitive category of personal data?
The recording is personal data, and it can easily contain more. A lawyer's dictated attendance note contains a client's data. A doctor's note contains health data, which is a special category under Article 9 and attracts stricter conditions. A recruiter's note may contain data about a candidate who never agreed to be recorded by a third party. This is why the processing location matters more for dictation than for most productivity software: the content is other people's data, not yours.
What does Whisper do with my voice?
Nothing, because it never receives it. The speech model runs on your own computer. We do not receive the audio, we do not receive the transcript, and there is nothing for us to store, share or be compelled to produce. What we do handle is ordinary business data: your licence and your billing details. We set out exactly what that covers on our security page, and we do not claim certifications we do not hold.
What we could not verify
These vendors publish no price we could read at the source. We print the gap rather than fill it with someone else's estimate.
- Sprecho — No price is shown on the home page. Its own claim is server-side, not on-device: "All voice data is stored exclusively in Germany."
Sources
Every figure above is copied from the vendor's own page on the date shown. Nothing is estimated, and nothing is taken from a review site.
- Whisper:https://get-whisper.com/#pricing(read 2026-09-08)
- Sprecho:https://sprecho.ai/(read 2026-09-08)
- Speecher:https://speecher.de/en/(read 2026-09-08)
- Philips SpeechLive:https://www.speechlive.com/us/pricing/(read 2026-09-08)
- Wispr Flow:https://wisprflow.ai/pricing(read 2026-09-15)
- Otter.ai:https://otter.ai/pricing(read 2026-09-08)
- Apple Dictation:https://support.apple.com/en-us/102524(read 2026-09-08)
- Windows Voice Typing:https://support.microsoft.com/en-us/windows/use-voice-typing-to-talk-instead-of-type-on-your-pc-fec94565-c4bd-329d-e59a-af033fa5689f(read 2026-09-08)
No transfer, because there is no transmission
$29 for the first seat, $15 for each additional seat, per year. No auto-renewal.