SYNFIALabs
    Back to Journal
    Methodology · July 19, 2026 · 11 min read

    Governance & Privacy for Conversational Data

    Governance reference for conversational data with GDPR and EU AI Act symbols

    Conversational data is more sensitive than survey data. It contains voice, phrasing, context. That is exactly why governance — not method — decides whether a program ever launches. This guide is the reference document legal, procurement and works council should have on the table before the first invitation goes out.

    Why this matters

    An insight program that fails at the legal or works-council gate burns more trust than it can ever deliver in value. Governance is therefore not an add-on but the first work step.

    Seven steps to defensible governance

    1. Determine the legal basis. Usually Art. 6(1)(a) GDPR (consent) for customer conversations and (f) legitimate interest or a works-council agreement for employee conversations. The choice has to be documented.
    2. Classify under the EU AI Act. Running conversations without automated decisions about people is typically low risk — provided no scoring or hiring decision is attached.
    3. Anchor non-retention. Audio is discarded immediately after transcription; only the transcript is stored. This rule belongs in the contract, the consent notice, and the record of processing activities.
    4. Define roles and access. Who sees raw transcripts, who only the analysis, who the verbatims in the board pack? Principle: as little as possible, as much as needed.
    5. Check DPIA triggers. As soon as special categories under Art. 9 GDPR are possible (health, beliefs) or a large workforce is involved, a data protection impact assessment is part of the package.
    6. Works-council sign-off. For employee conversations, involving the works council is mandatory, not optional. Disclose purpose, voluntariness, anonymisation, retention, and analysis logic.
    7. Make it auditable. Who had which access when? Logs, deletion records, and a clear data-flow diagram are required.

    Sign-off checklist (10 points)

    1. Program purpose in writing
    2. Legal basis documented
    3. Consent text or works-council agreement in place
    4. Non-retention (audio) technically demonstrable
    5. Anonymisation logic described
    6. Roles and access defined
    7. Retention and deletion timelines set
    8. Data processing agreement (DPA) signed
    9. DPIA completed or documented as not required
    10. Auditability (logs, data-flow diagram) ensured

    Pitfalls

    • Consent hidden in the small print. If participants can't clearly see what they're agreeing to, the consent is invalid.
    • Keeping audio 'just for quality assurance'. Non-retention means discard immediately. Anything else opens a new legal question.
    • Re-identification via small groups. Analyses of teams under five people are effectively identifiable.
    • Training data. Conversations must not be used for model improvement. Full stop.

    Frequently asked questions

    Do we always need a DPIA?

    Not always. But whenever special categories are possible or large groups of employees are involved, a DPIA is the safe choice.

    What does non-retention mean in practice?

    Audio is discarded immediately after transcription and is not used for training or improvement. Only the transcript is stored, within the agreed scope.

    Is consent enough, or do we need a works-council agreement?

    For customer conversations, informed consent is usually enough. For employee conversations, a works-council agreement is the more defensible basis because voluntariness in an employment relationship can be contested.

    Next step

    See what a program would look like for you.

    A 45-minute expert consultation. We map your intelligence gaps and share comparable engagements.