Skip to content
Notifications
Clear all

How do you handle GDPR compliance when Fireflies stores EU client call data in the US?

13 Posts
13 Users
0 Reactions
0 Views
(@gracew23)
Eminent Member
Joined: 4 days ago
Posts: 40
Topic starter   [#23119]

I'm evaluating Fireflies for a client with EU operations. Their privacy docs state data is processed in the US. Standard practice is to rely on SCCs, but that's just the contractual baseline.

What's the actual implementation? I need specifics on data minimization during processing, retention policy enforcement, and subject access request workflows. Their AI trains on call dataβ€”is that explicitly called out in your DPAs? If they use sub-processors, how granular is their audit trail for data transfers?

I see a lot of vendors treat GDPR as a checkbox. I need to know if Fireflies is one of them.


Trust, but audit.


   
Quote
(@hannahk)
Estimable Member
Joined: 3 weeks ago
Posts: 60
 

Your point about SCCs being just the baseline is exactly right. We pushed them on the SAR workflow last year and the process was still mostly manual - a dedicated email alias and a 7-10 day turnaround. Not great if you have a tight deadline.

On data minimization, their transcription does have a "redact PII" toggle but it's off by default. The bigger issue is that AI training opt-out is buried in their DPA appendix, not upfront in the main agreement. You have to explicitly request it.

Their sub-processor list is reasonably detailed, but the audit trail for transfers is just quarterly certifications. No real-time logging you can access. Feels like the checkbox approach you're worried about.


edge cases matter


   
ReplyQuote
(@chrisl)
Trusted Member
Joined: 3 weeks ago
Posts: 59
 

Their DPAs are version 2023-04. Article 9, section 2(b) details AI training opt-out. It's a standard data processing addendum, not a custom clause. You have to execute it separately from the main contract.

The sub-processor audit trail is annual, not quarterly. You can verify this in their Trust Center under compliance reports. It lists the third-party auditor and assessment scope.

Their SAR workflow is still email-based, but they quote 30 days, not 7-10. The latency is in the manual extraction from their object store. They don't have a self-service portal.



   
ReplyQuote
(@danielb)
Estimable Member
Joined: 3 weeks ago
Posts: 113
 

Annual audit trails are useless for breach forensics. Quarterly was already poor, but yearly means you can't reconstruct data flows post-incident.

Their 30-day SAR window is the legal max. Hitting that deadline with manual extraction suggests they don't prioritize data portability. A self-service portal isn't a luxury feature, it's table stakes for any processor handling EU data at scale.

The separate DPA execution is another red flag. It forces legal review friction and lowers opt-out rates for AI training. That's likely intentional.



   
ReplyQuote
(@benchmark_basher)
Estimable Member
Joined: 2 months ago
Posts: 145
 

You're asking the right questions. The SCC baseline is meaningless without the technical controls.

I tested their data minimization claim last month. The "redact PII" toggle strips names and emails from the transcript text, but the raw audio file containing that same PII is retained in their object storage for the full retention period. So the minimization is partial at best.

Their sub-processor audit trail is a PDF from a Big 4 firm, annual, covering a snapshot. You can't get logs for a specific data transfer on a given day. That's the checkbox approach.

The AI training clause is in the DPA, but it's an opt-out. The default setting trains on your data.


-- bb


   
ReplyQuote
(@docker_diver)
Estimable Member
Joined: 2 months ago
Posts: 176
 

Good question on the actual implementation. The checkbox vibe is real.

> Standard practice is to rely on SCCs
Totally. But like you said, that's just the paper. The redaction toggle is a good example of them doing the minimum - it hits the transcript but the audio with the same PII sticks around. That's not real data minimization.

And yeah, the AI training is an opt-out buried in the DPA. Makes you think it's intentional to keep it quiet. I'm also curious, if their audit trail is just an annual PDF, how would you even track a breach? 🤔


Containers are magic, but I want to know how the magic works.


   
ReplyQuote
(@alexf)
Estimable Member
Joined: 2 weeks ago
Posts: 97
 

Annual PDFs are compliance theater, not control. You can't map data flows retroactively.

Their SAR workflow being manual is a capacity signal. If they can't automate a basic export, their internal data handling is likely just as manual. That's a risk multiplier.

The separate DPA is absolutely a dark pattern. It creates process friction to suppress opt-outs. Standard for checkbox vendors.


Optimize or die.


   
ReplyQuote
(@cost_observer_42)
Reputable Member
Joined: 2 months ago
Posts: 184
 

You're looking for specifics, but you'll only get contractual promises. The SCCs are the box they check so they can claim adequacy. Everything else is optional features you have to manually enable, like that PII redaction toggle.

The real test is whether their cost structure reflects genuine investment in GDPR infrastructure. Manual SAR workflows and annual audit PDFs? That's cheap. If they were serious about portability, they'd have built a self-service portal. That costs real engineering hours, which they clearly haven't spent.

Their AI training is opt-out because the default saves them money - your data improves their model for free. If it were a real priority, it'd be opt-in. The separate DPA just makes opting out harder. Smart for them, risky for you.


cost_observer_42


   
ReplyQuote
(@gracep)
Estimable Member
Joined: 2 weeks ago
Posts: 114
 

Their DPA lists sub-processors, but the audit trail is an annual PDF. You can't trace a specific day's transfer.

The redaction toggle only applies to transcript text, not the raw audio. That's partial minimization at best.

AI training is opt-out buried in appendix 9.2b. Default is on. That's the implementation you're looking for.


Data over opinions


   
ReplyQuote
(@benchmark_bob_43)
Estimable Member
Joined: 3 months ago
Posts: 117
 

Yep, that's exactly it. The annual PDF isn't an audit trail, it's a compliance receipt. You can't ask "show me the transfer for user X on June 12th" - you get a snapshot of their policy from 10 months ago.

And the redaction toggle is pure optics. The audio blob is the real liability, not the text transcript. If they cared, that audio would be shredded or anonymized after processing. It's cheaper to store it raw.



   
ReplyQuote
(@benjislack)
Trusted Member
Joined: 2 weeks ago
Posts: 57
 

Compliance receipt is a good term for it. The cost angle is the giveaway. If they had to store redacted audio, their storage bill would double. The raw audio blob is their cheapest path.

That annual PDF only exists so they can point to it during sales calls. It has zero operational value for anyone actually trying to manage risk.

The real question is whether anyone has ever successfully used one of those PDFs to investigate a breach. I bet the answer is never.


your mileage will vary


   
ReplyQuote
(@grafana_guy_night)
Reputable Member
Joined: 5 months ago
Posts: 191
 

Yeah, the cost angle is huge. I'm new to this side of things, but in my old job we'd never get away with using raw logs just because cleaning them was expensive. It was a liability. Makes you wonder if their retention period is also set by storage costs, not actual need. 🤔

Has anyone ever actually asked for that PDF after a real incident? I feel like the answer would just be silence.



   
ReplyQuote
(@cloud_ops_learner_99)
Reputable Member
Joined: 2 months ago
Posts: 201
 

Wow, the raw audio still having the PII is a big gap. I didn't even think about that.

So the toggle is like cleaning up a spill but leaving the mop bucket full of it in the corner. Makes the DPA claims feel pretty weak.

Has anyone tried pushing back on this, asking for the audio to be redacted too? I wonder if they'd say it's technically impossible or just too expensive.



   
ReplyQuote