Disclaimer: This article is general information for legal professionals, not legal advice. It focuses on the law of England and Wales; legal professional privilege, confidentiality, and data protection rules differ in Scotland and Northern Ireland. Rules, guidance, and vendor practices change. Take advice from your Compliance Officer for Legal Practice, your information governance team, or counsel before changing firm workflows around privileged material.

A forty-minute client conference produces exactly the material you will need later: the client's account, the instructions, the risk advice, the deadlines. Taking full notes mid-conversation is slow, and it changes the meeting. So the pitch from modern transcription tools is tempting. Press record, let the AI listen, get a searchable transcript and a summary minutes later.

For a solicitor, the first question is never "does it work?" It is "where does the audio go?" Almost every popular meeting transcription product, Otter.ai, Fireflies.ai, tl;dv, and their many competitors, is cloud-based. Your audio leaves your machine, travels to a vendor's servers, and is processed there. For an ordinary commercial meeting, that is a data protection question to manage sensibly. For privileged client communications, it is something more uncomfortable: you may be handing a confidential legal communication to a third party that the client never agreed to, in a jurisdiction the client knows nothing about.

This guide walks through the position in England and Wales. What legal professional privilege actually protects, why recording your own client meetings is lawful and useful, why cloud transcription creates avoidable risk, what the SRA and UK GDPR expect of firms, and how a bot-free, local-only workflow removes the problem rather than contracting around it. American readers searching for an "attorney-client privilege recording app" will find the concepts familiar; the terminology and case law here are the UK's.

Can you record client meetings in the UK?

Yes, with ordinary care. Unlike several US states, England and Wales has no statute requiring every party to consent before you record a conversation you are taking part in. Recording a meeting with your own client so the file preserves an accurate record of instructions and advice is lawful. What the recording is, however, is personal data, and often special category data when a matter touches health, employment, or criminal allegations. UK GDPR applies from the moment you press record, not from the moment you transcribe.

In practice that means:

Covert recording deserves its own warning. The SRA Principles, particularly Principle 2 (public trust) and Principle 5 (integrity), have been applied to solicitors who secretly record clients, witnesses, or opponents, and the Solicitors Disciplinary Tribunal treats the practice very differently from open recording. If a record of the meeting is worth having, it is worth the client knowing about. Consent given in the client care letter at onboarding avoids every expensive conversation later.

On admissibility: in civil proceedings a sound recording is generally admissible documentary evidence, subject to authenticity, under the Civil Evidence Act 1995. Keep a simple chain-of-custody note: date, participants, device, and file hash if the matter is contentious.

Legal professional privilege: the essentials

In England and Wales the concept most people mean by "attorney-client privilege" is legal professional privilege (LPP). It has two limbs.

Legal advice privilege covers confidential communications between a lawyer and their client, made for the dominant purpose of giving or receiving legal advice. The courts read this broadly: in Balabel v Air India [1988] Ch 317, the Court of Appeal held that privileged communications sit on a "continuum" of lawyer-client correspondence, and a face-to-face client conference sits on that continuum as firmly as a letter of advice. Practical consequence: the conversation you record in a client meeting is privileged material, and a transcript of it is a transcript of a privileged communication.

Litigation privilege covers communications with third parties, including experts and witnesses, made once litigation is in contemplation or progress, for the dominant purpose of that litigation. The leading modern statement is Three Rivers District Council v Bank of England (No 6) [2004] UKHL 48.

Three features of privilege drive everything else in this article:

  1. Privilege belongs to the client, not the firm. Only the client can waive it, and a firm should generally have the client's authority before doing anything that could.
  2. Privilege is close to absolute. In R v Derby Magistrates' Court, ex p B [1996] AC 487 the House of Lords described it as a fundamental human right that no overriding public interest can displace.
  3. Privilege is only as durable as the confidentiality beneath it. Where confidentiality has been lost, privilege falls with it. And partial disclosure can waive privilege for the subject matter of the disclosed material: the principle in Great Atlantic Insurance Co v Home Insurance Co [1981] 1 WLR 440.

That third point is the one most firms underestimate when they adopt new software. Privilege does not survive sloppy handling of confidential material. A transcript that was privileged on Tuesday does not become unprivileged because a third-party vendor handled it carelessly on Wednesday; the damage is the same.

Why cloud transcription creates privilege risk

First, the honest caveat. There is no definitive English authority deciding that merely uploading an audio file to a cloud transcription processor automatically waives privilege, and an arguable case exists that a processor acting under tight confidentiality terms is an extension of the solicitor's own office. The risk is not a settled rule but an unnecessary dependency: you are wiring privileged conversations into infrastructure you do not control, held by a party the client never chose, governed by terms the client never agreed to. Conservative practice treats that as exactly what it is.

1. The bot is a third party in a privileged conversation

Tools like Otter.ai and Fireflies.ai work by sending a bot that joins the meeting as a participant and records it. In a privileged client meeting, that bot is neither the client nor the lawyer. It is an automated third party listening to legal advice, run by a company the client has never heard of, governed by terms the client has never seen. Whatever the eventual legal analysis, inviting an unvetted participant into a privileged conference is the same category of decision as cc'ing a stranger on an advice email. Some platforms now block third-party bots entirely, which is its own signal.

2. Uploading may damage the confidentiality privilege rests on

Privilege protects confidential communications. Confidentiality can be destroyed without anyone intending harm: a vendor breach, a vendor employee with dashboard access, data used to train models on consumer subscription tiers, or compelled disclosure to a government. Waiver arguments of the Great Atlantic type follow from disclosure beyond the privileged circle, and where the subject matter of the disclosure is the advice itself, the waiver can be irretrievable. The conservative position many firms now take: privileged material should not reach any third party at all. Where a cloud tool is genuinely useful, get the client's informed authority first, and put the vendor's confidentiality terms in writing on the file.

3. Disclosure reaches your vendors

In an English dispute, opposing parties can seek specific disclosure, and material held by third parties is reachable through third-party disclosure applications. In cross-border litigation, US subpoenas are a routine way of obtaining material from US-headquartered vendors without any English court order at all. Under the US CLOUD Act 2018, US providers can be compelled to disclose stored data regardless of where it physically sits. Attendance logs, retention settings, and deletion records all become discoverable facts about your client meetings. None of this applies to a local recording, because there is no vendor to subpoena.

4. Consumer plans rarely fit privileged material

The subscription tier most individual practitioners buy is not designed for regulated data. Enterprise tiers add controls, contractual confidentiality, and sometimes audit reports, but those are risk allocation, not risk removal. If the vendor's cloud holds the audio, the vendor is a data processor under Article 28 UK GDPR, the firm needs a written processing agreement, and the firm still owns the client-facing consequences of anything the vendor does. Read the current terms yourself, and re-read them when the vendor changes them; "improving our services" clauses matter a great deal when the data is privileged.

Privilege is only as durable as the confidentiality underneath it. An architecture in which no third party ever receives the audio is the cleanest way to keep both intact.

What the SRA and UK GDPR expect

Two regimes apply to a recorded client meeting, and they overlap.

The SRA's confidentiality expectations

Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs and RFLs requires you to keep the affairs of current and former clients confidential unless permitted to use or disclose it. The SRA has also issued guidance on the use of cloud-based services, which points firms toward a proper risk assessment of providers, continuity of access, and confidentiality before client data moves to the cloud. The Law Society's guidance for solicitors on cloud computing and the Legal Sector Affinity Group's UK GDPR guidance for the legal sector make the same point from the data side, and the NCSC's cloud security principles give firms a vocabulary for the assessment. None of that guidance prohibits outsourcing; all of it expects a decision, made deliberately and recorded, rather than an individual solicitor signing up for a free tool on a personal laptop.

UK GDPR hooks that apply whether or not you use the cloud

Run the two regimes against a local-only workflow and the obligations nearly vanish: no processor to contract with under Article 28, no cross-border transfer to paper under Chapter 5, and a far smaller breach surface to monitor. That is a case worth writing into your risk register and data map like any other compliance decision.

How local transcription solves the problem

Local processing means the speech recognition model runs on your own machine. The audio waveform becomes text on your CPU or GPU, and no audio packet crosses a network interface at any point. Modern local models, the Whisper family being the best known, land close to cloud accuracy on consumer hardware, and they keep working with the wifi off, which matters more in law than in most trades: client sites with no guest network, secure environments, strict device policies.

Clearminutes works this way. It captures system and microphone audio directly, so there is no bot to admit and nothing to explain to the client beyond the consent you have already documented. Transcription runs locally through a Whisper model, transcripts and recordings live in a local database on your machine, and optional summaries can be generated by a local Gemma model, so the default workflow sends no data anywhere. Exports come out as Word, PDF, or markdown, ready to file against the matter, and full-text search runs across every transcript you keep, which turns a year of client conferences and advocacy prep into something you can query in seconds.

One check belongs in every firm's process: some local-first tools offer optional cloud summarisation, and Clearminutes is no exception. The architectural guarantee applies with cloud features off. If a meeting is privileged, keep them off, or confine cloud features to internal material where the client's authority is already on file. Verify the settings after major app updates.

Tools compared for privileged client meetings

The table below summarises how the common options behave for a solicitor recording a privileged client meeting. Vendor practices change, so verify against current terms before relying on any row.

Tool Bot joins the meeting Where audio is processed Where recordings live Fit for privileged material
Clearminutes ✓ No On your device, offline capable Your machine, local database ✓ Strong: no third party receives the audio
Otter.ai ✗ Yes Vendor cloud, US-hosted Vendor cloud storage ✗ Poor on consumer tiers; enterprise controls only
Fireflies.ai ✗ Yes Cloud, via subprocessors Vendor cloud storage ✗ Poor without enterprise contractual cover
tl;dv ✗ Yes Vendor cloud Vendor cloud storage ✗ Poor: consistent third-party storage of the call
Granola ✓ No Cloud transcription API after upload Vendor cloud ✗ Weak: feels local, audio still leaves the machine
Dragon Professional (Windows) ✓ No On-device dictation engine available Your machine if configured locally ✓ Workable, but dictation-focussed and priced for specialists
Human transcriber under NDA ✓ No Manual, off your premises Depends on the arrangement ✓ Workable only with written confidentiality terms and vetting

Two rows deserve comment. Granola is the trap most likely to catch a busy practitioner: it presents as a Mac desktop app with no bot, but the audio it captures is sent to cloud speech APIs for processing. From a privilege and data protection standpoint it belongs in the cloud column. Dragon remains the professional's choice for dictating letters, and an offline profile keeps dictation on the device, but it is built for one voice speaking at a document, not for capturing and summarising a two-hour multi-speaker conference.

The traditional route, handing a recorder to a vetted in-house secretary or an external transcriber under a tight NDA, can sit comfortably alongside privilege, because a transcriber engaged to type the record of a meeting is easier to characterise as acting for the solicitor than a SaaS platform is. It is also slower, costlier per hour of audio, and only as safe as the written terms and the transcriber's own security.

A privilege-safe recording workflow

Here is the end-to-end pattern, in the order firms typically deploy it:

  1. Document consent first. Add a recording clause to the engagement terms, mention it in the client care letter, and say at the start of the first recorded meeting that the session is being recorded. Log the consent on the file.
  2. Record locally. Use desktop software that captures system and microphone audio directly. No bot, nothing added to the meeting, and it works as well for in-person conferences as for video calls.
  3. Transcribe on-device. Keep the pipeline local end to end. Verify names, citations, and figures against the audio, exactly as you would with a transcript from any other source.
  4. Summarise locally. Generate first-draft attendance notes, case summaries, and action lists with a local model. If you choose cloud summarisation for anything, restrict it to material that is not privileged, with the client's authority and the reasoning on the file.
  5. Store like a lawyer. Local database with access limited to the working team, full disk encryption switched on (FileVault or BitLocker), and recordings included in the firm's approved backup regime.
  6. Apply the retention schedule. Give transcripts and audio the same retention and deletion rules as the rest of the file, and delete securely when the matter closes.
  7. File into the matter system. Export the transcript and summary as Word, PDF, or markdown and save them against the matter in Clio or whichever practice management platform the firm runs. The export is a deliberate, one-way act you control, not a standing integration piping client data anywhere.
  8. Write it down. Record the workflow in the firm's risk register and data map, complete the Article 35 assessment if your rollout meets the threshold, and train fee earners on the consent script and the settings that keep cloud features off for privileged matters.

Step 7 is where local tools and cloud tools genuinely converge: every practice management system accepts an exported document. What differs is that with local processing, the only copy that ever exists outside your machine is the one you chose to put there.

A practical recommendation

For meetings involving privileged client communications, the defensible position is architectural: remove the third party rather than negotiate terms around one. Local transcription is the least expensive privilege insurance available. You give up access to vendor AI features that depend on your data, and in exchange you get a workflow with no processor to contract with, no cross-border transfer to justify, no vendor logs to explain in a disclosure exercise, and no 72-hour scramble if a vendor you picked on a free tier suffers a breach.

Clearminutes is the strongest fit for this workflow if you practise in England and Wales. It runs a local Whisper model for transcription and a local Gemma model for summaries, stores everything in a local database on your machine, and works fully offline, so it behaves identically in chambers, at a client's office with no wifi, and on a train. It is not a case management system and replaces none of your existing stack; it produces the transcript, the summary, the searchable archive, and a billable-time log you can reconcile, then hands you Word, PDF, or markdown exports for the matter file. Plans cost £12 per month or £108 per year, with a £249 lifetime desktop licence; a companion iOS app is available at $4.99 per month for recording away from the desk. Clearminutes holds no legal-sector certification, and this article is not a compliance sign-off: the case for it is the architecture, and the decision belongs to your COLP and your information governance lead.

Try it on your next client meeting. Test the workflow on an anonymised recording first, then roll it out with the consent clause in place. The Clearminutes for Legal page has the full privilege-focused picture, feature detail for depositions, case notes, and billable-time capture, and testimonials from practitioners who moved off cloud transcription. Or go straight to the download page and start free.