When You Let AI Summarize Your Meeting Notes -- Where the Privacy Commission Draws the Line
More people are uploading meeting recordings to generative AI services the moment a meeting ends, just to get a summary back. It really does cut down on note-taking time -- but it's easy to forget that the names, remarks, and personal details of everyone else in that meeting go along with it to an outside server. South Korea's Personal Information Protection Commission guidance addresses exactly this point.

What actually gets sent when AI summarizes your meeting
When you feed a meeting recording or transcript into an AI service, it carries along attendee names, affiliations, and remarks -- plus any third-party information mentioned inside it (a client contact, a job candidate, a patient or customer case). Only the summary shows up on your screen, but what actually gets stored and processed on the service's servers is the entire original recording. If the meeting touched on sensitive material like personnel evaluations or compensation, this is the point to stop and reconsider.
The line the Privacy Commission draws -- only what the purpose requires
The "Guidance on Personal Data Handling for Generative AI Development and Use," published by the Personal Information Protection Commission in August 2025, states that the basic principle of Korea's data protection law -- collect and input only the minimum data necessary for the stated purpose -- applies just as much when data goes into an AI service. If the purpose is organizing meeting notes, there's no reason to also feed in information that purpose doesn't need, like an unrelated colleague's HR history or a customer's personal data.
Don't input sensitive data in the first place
If a national ID number, health information, union membership, or political views came up during the meeting, strip or mask them before handing the recording off for summarization. Some companies set internal security policy so these topics are never spoken aloud on the agenda at all. For conversations that carry an evaluation of a specific person -- a hiring interview, a disciplinary meeting -- it's sometimes safer to skip AI summarization entirely. Habits that protect your own personal data directly, like checking for identity theft, belong in the same conversation.
What you type in may end up training the model
Many free generative AI services state in their terms of service that submitted data may be used to improve the model (retraining). Once something becomes training data, a later deletion request can't fully undo it. Before using a service, check its settings menu for a "don't use my conversations for training" option, and turn it on if it isn't already -- that's the minimum precaution.
Enterprise plans versus the free tier
Even on the same AI service, an enterprise-tier plan often specifies contractually that input data won't be used for training, and separately spells out retention periods and deletion procedures. A personal free account processing your company's meeting notes gets none of those contractual protections. An organization planning to make AI note-taking a standing tool should look into a company-held enterprise contract rather than letting employees run it through personal free accounts.

Who should get consent from attendees, and when
As a rule, consent for recording and AI processing should be gathered in advance by whoever runs the meeting or starts the recording, from every attendee. A recording made without saying "we're recording this and will run it through AI for notes" gives you weaker footing if the result is ever disputed later -- more so when outside guests are in the room. Uploading an unannounced recording to an outside AI service can become grounds for an attendee to request access to or deletion of their own data.
Follow your internal policy if one exists -- and write one if it doesn't
If your organization's information security policy already spells out the scope for generative AI tools, that policy comes first. Some organizations ban AI summaries for certain meetings entirely; others allow only specific, approved tools. If there's no policy yet, even a single line -- "no AI summaries for meetings involving HR, evaluations, or sensitive data" -- heads off a meaningful share of real-world incidents. It also helps to know in advance how to check whether your own data has leaked elsewhere, so an incident doesn't spiral further before you notice it.

Order of operations
1. Before the meeting starts, tell attendees you're recording and running it through AI, and get their consent.
2. Strip or mask sensitive content -- national ID numbers, health information -- before it's ever entered.
3. Check the service's settings for a "don't use for training" option and turn it on.
4. If this is becoming a standing work tool, look into an enterprise contract instead of personal free accounts.
5. Check whether your internal security policy already covers AI tool use, and if not, set a minimum standard.
For the specific provisions and latest revisions of the Privacy Commission's guidance, check the original at the Personal Information Portal (privacy.go.kr). This article summarizes general handling principles; whether a specific situation is lawful requires individual review.
All content is fact-checked under our editorial standards.