AI Meeting Minutes Tools and Confidentiality Obligations: Gaps That Arise When Recording and Inputting NDA-Covered Meetings
Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.
Introducing an AI meeting minutes tool within a company makes transcribing and summarizing meetings dramatically easier. On the other hand, using such a tool in business discussions or meetings with business partners with whom you have signed an NDA (non-disclosure agreement) creates the risk that the counterparty's confidential information will be unintentionally stored on external servers. If a company proceeds with introducing the tool solely to improve internal efficiency and fails to check the handling of confidential information and prior agreement, this may lead to a breach of contract or damage to the relationship of trust.
An AI minutes tool is a convenient instrument that handles everything from recording to summarizing, but as long as it handles other companies' confidential information, if it involves transmission to an external AI service, you should check who the provider is and what processing is performed. It is important to consider the following separately: confirming whether it is lawful to record a meeting with the counterparty and process it with AI; judging whether inputting confidential information defined in the NDA into an external tool breaches the contract; how data is handled under the tool's terms of use; and the operating standards for which meetings and information within the company are covered.
Lawfulness of Recording and AI Processing of Meetings, and Prior Explanation
When recording a meeting, lawfulness should be examined by dividing the matter into three stages: the act of recording, the transmission of data to an external service, and the use after recording. The Q&A of the Personal Information Protection Commission (Japanese) distinguishes between the obligation to notify or publicly announce the purpose of use where the content of a call constitutes personal information and the obligation to tell people that a recording is being made, and explains that the Act on the Protection of Personal Information (APPI) does not go so far as to impose an obligation to give notice of recording. However, this explanation does not remove the need to separately check confidentiality agreements, agreements prohibiting recording, and consideration for personal interests. It is advisable to check each case individually according to the nature of the meeting and how the information is obtained and used.
A point that requires particular care when using AI meeting minutes tools is that the recorded audio is sent as is to an external AI service, and transcription, summarization and even data storage are performed automatically. The counterparty's representatives may not perceive the fact that the meeting is being recorded and the fact that the data is sent to and stored in an external cloud AI in the same way. When using the tool in NDA-covered business discussions or meetings, explain to the counterparty, before recording or the tool's automatic connection begins, that the meeting will be recorded and that it will be processed and stored by an external AI. Where consent is required by contract or law, obtain consent in an appropriate manner from a counterparty with proper authority. The fact that participants present nodded on the spot does not mean they have been given the authority to disclose the company's confidential information outside the company. If it later comes to light that minutes data remained on an external server without any prior explanation, distrust over the lack of prior explanation will come to the fore even more than the lawfulness of the recording itself.
Input into AI Tools and Third-Party Disclosure Under the NDA
Whether inputting confidential information obtained in a meeting with an NDA counterparty into an AI meeting minutes tool falls foul of the NDA's "prohibition on third-party disclosure" can be judged differently depending on the wording of the contract and how the tool actually operates.
Under the view that it constitutes third-party disclosure, because the AI tool provider is not a party to the NDA with the counterparty, the act of sending data to the provider's system for processing is regarded as an act of disclosure in itself, handing confidential information to a third party outside the contract. Even if your company has a usage agreement with the tool provider, that alone does not necessarily mean it qualifies as an exception to third-party disclosure under the NDA with the counterparty.
By contrast, under the view that there is room to interpret it as not constituting third-party disclosure, the scope of disclosure under the NDA is interpreted narrowly on the basis of a mechanism or contractual terms under which the provider cannot view or use the input data. The mere absence of use for independent purposes does not settle that there is no disclosure. In the field of the APPI, regarding the use of cloud services, the Q&A of the Personal Information Protection Commission (Japanese) uses "whether the external business operator is to handle the personal data" as the criterion. Where the contract provides that the external business operator will not handle the personal data and appropriate access controls are in place, the position is that this constitutes neither a third-party provision nor an entrustment. However, this is only the analysis under the APPI. Restrictions on the disclosure and external storage of confidential information under an NDA have conditions specific to each contract, and it is not possible to apply this interpretation directly and conclude that there is no disclosure. Furthermore, for a service that creates transcriptions or summaries from audio, the existence of settings under which no person views the data or an agreement not to use it for training does not mean the provider is "not handling" the data.
Whichever interpretation is taken as the premise, the starting point is the wording of the NDA itself. If there is a provision permitting "disclosure to third parties who bear confidentiality obligations" as an exception, check whether equivalent confidentiality obligations are imposed on the AI provider, as well as the scope of third parties to whom disclosure is permitted, restrictions on the purpose of use, procedures for prior notice or consent, and whether obligations are imposed on subcontractors. On the other hand, if the NDA has no exception and prohibits disclosure to third parties uniformly, inputting into an AI tool carries the risk of a breach of contract. In that case, either obtain the counterparty's prior consent in a form that complies with the contract, or decide not to use the tool in that meeting. If you check the definition of confidential information and the wording of third-party disclosure provisions together with the clause-by-clause checkpoints organized in What Is a Confidentiality Clause? Review Practice for Contracts Other Than NDAs, it becomes clear which parts of your contracts require attention.
Points to Check in the Tool's Terms of Use
Since consistency with the NDA depends on the tool's specifications and contractual terms, reviewing the terms of use before introducing the tool is essential. Specifically, the following three perspectives are central.
The first is whether input data is used for training. Whether input audio and text are used to improve or train AI models differs depending on the contract plan and settings. Whether use for training can be blocked depends on the contract, so check the terms of the plan you will actually subscribe to.
The second is where data is stored. Whether data is stored on domestic servers or sent to overseas servers changes how it fits with your company's policy on cross-border transfers and with contractual restrictions agreed with the counterparty.
The third is the data retention period. Unless you check how long recordings, transcriptions and summaries remain on the server and to what extent they are erased when deletion is requested, you cannot determine whether you are fulfilling the obligations under the NDA to return or destroy confidential information.
In addition to these three points, also check access rights for the service operator and subcontractors, whether data may be used independently, the default settings for shared links, and the handling of backup data after deletion. After hearing the sales representative's explanation, check by comparing the official terms of use and security documentation against the actual settings screens, and it is reassuring to adopt a practice of checking again at contract renewal in preparation for revisions to the terms.
Entrustment and Provision Under the APPI
Meeting recordings may contain information that can identify specific individuals, such as attendees' names and what they said, and may constitute personal information under the APPI. The Personal Information Protection Commission's guidelines also state that audio data that contains names or the like and can identify a specific individual constitutes personal information.
If such recorded data constitutes personal data forming part of a personal information database or the like, the question arises whether sending it to an AI meeting minutes tool for processing is positioned as an "entrustment" to the tool provider. For domestic entrustment within the scope necessary to achieve the purpose of use, the individual's consent for third-party provision under Article 27 of the Act is, as a rule, not required. However, as the entrusting party, you bear the obligation to supervise the entrusted party with respect to necessary and appropriate security control. On the other hand, where the contract provides that the tool provider will not handle the data and appropriate access controls are in place, there is room to judge, in line with the Commission's analysis, that it constitutes neither a third-party provision nor an entrustment. However, if the provider uses the data for its own training or similar purposes, this exception cannot be claimed under the label of entrustment. Check not only the terms of use but also the actual settings and data processing mechanisms. In addition, when providing data to a foreign business operator, the requirements for provision to a third party in a foreign country under Article 28 of the Act must be considered individually, even if it is an entrustment. The fact that a server is located overseas and the fact that the recipient entity is located in a foreign country should be distinguished as separate issues. Even where it does not constitute a third-party provision, your company's own security control measures remain necessary.
Operating Rules and Checking Procedures in Internal Regulations
Having grasped the interpretation of the contract and the analysis under the APPI, what should finally be put in place in practice are operating standards on which meetings may be recorded within the company and which information may be input into the tool. Simply checking contract clauses and the tool's terms makes it difficult for frontline staff to judge each business discussion individually.
When defining the range of meetings in which recording is permitted, classify meetings with NDA counterparties, internal meetings, meetings dealing only with public information and so on, and set a rule that NDA-covered meetings require prior explanation and any necessary consent. As for the range of information that may be input, set internal rules that for meetings dealing with highly confidential content such as technical information or pricing terms, use is limited to approved enterprise plans, and recording with free plans or personal accounts is prohibited. However, keep in mind that using an enterprise plan or paid contract does not in itself guarantee compliance with the NDA.
When translating this into frontline operations, putting the following three mechanisms in place prevents hesitation in judgment. First, establish a contact point so that, once a meeting is found to be covered by an NDA, whether the tool may be used is not decided by the frontline alone but in consultation with the legal or information systems department. Second, create a list of tools approved for internal use and make a table summarizing whether data is used for training, where it is stored and how long it is retained, available for frontline reference. Third, prepare template notices for prior explanation to business partners and establish a system for presenting them before connecting. Before a meeting, check whether the NDA's input conditions are met, whether an approved tool is being used with the designated settings, and whether prior explanation and, where necessary, consent from a person with authority have been completed. Also set a procedure so that if confidential information not anticipated in advance comes up during the meeting, recording and AI processing can be paused on the spot. Positioning these operating rules as part of the company-wide rules on the use of generative AI avoids a situation in which the AI minutes tool alone is treated as an exception. How to Create a Generative AI Use Policy: Checkpoints for Internal Rules, Information Management and Allocation of Responsibility explains the procedure for designing such internal rules.
Consideration for the Confidentiality Obligations of Licensed Professionals
When professionals on the business partner's side, such as attorneys, certified public accountants, tax accountants or labor and social security attorneys, attend a meeting, the confidentiality obligations specific to each qualification come into play in addition to contractual confidentiality obligations. A professional may, citing their own confidentiality obligations, ask that recording or external processing be refrained from, or set conditions for use. In such situations, check the conditions the counterparty requires together with your company's internal rules, and if they cannot be reconciled, decide to refrain from using the tool in that meeting.
When introducing an AI minutes tool company-wide, in situations where three elements overlap, namely NDA-covered meetings, the counterparty's confidential information and recordings containing personal information, unexpected external storage and the risk of breach of contract will arise unless the four stages of prior notice, contract interpretation, review of terms, and internal rules are worked through in order. Deciding, at the point of deciding to introduce the tool, who will check each of these four stages and how forms the foundation for safe use.
If you need help with whether to introduce an AI minutes tool, reviewing terms of use or establishing internal regulations, we accept consultations through Legal Consultation on Generative AI. We also handle the treatment of recordings containing personal information and the establishment of systems for supervising entrusted parties through Personal Information Protection and Data Protection.
Frequently asked questions
What needs to be checked when using an AI meeting minutes tool in a meeting covered by an NDA?
It is necessary to separate and check four stages: legality, whether there is a breach of contract, how data is handled under the tool's terms, and internal operating standards. This is because with AI minutes tools, the recorded audio is sent to an external service, and transcription, summarization and data storage are all performed automatically. Having another company's confidential information stored on external servers without prior explanation or agreement is likely to lead to a breach of contract or damage to the relationship of trust.
Does entering confidential information from a meeting into an AI meeting minutes tool constitute disclosure to a third party under an NDA?
The conclusion depends on the wording of the contract and how the tool actually works. Because the provider of the AI tool is not a party to the NDA, one view regards the external transmission itself as disclosure, while there is also room to interpret the scope of disclosure narrowly on the basis of a mechanism under which the provider cannot view or use the data. Under an NDA that has no exception provisions and uniformly prohibits disclosure to third parties, there is likely a risk of breach of contract.
What should be checked in the terms of use before introducing an AI meeting minutes tool?
The three central points are whether input data is used for training, where the data is stored, and how long it is retained. Whether input data is used to improve the model differs by plan and settings, and the storage location bears on cross-border transfer policies and contractual restrictions. In addition, unless you confirm the retention period and the scope of erasure upon deletion, you likely cannot determine whether you are fulfilling the return and destruction obligations under the NDA.