Church translation and the GDPR: where does the sermon audio go?

The audio leaves the building the moment you translate it live. That is fine under the GDPR, as long as you know where it goes, how long it stays, and that you can have it erased. Most vendors can answer those questions; few volunteer them.

Why this is not a formality

A recording of a service is not only the preacher’s words. It carries the prayers people asked for, the testimony somebody gave, the names mentioned from the front. Under Article 9 of the GDPR that is special-category data, about religious belief and about every person present. A church is allowed to process it; it is not allowed to be careless with it.

The five things to settle

1. Where it is stored

Ask for the country. Storage inside the EU keeps you under one legal regime; storage elsewhere is possible but needs the vendor to show you the transfer basis. “The cloud” is not an answer.

2. Who else touches it

Live translation is built on speech recognition, translation and voice models, and those are often other companies. Ask for the list of sub-processors and where each of them runs. A vendor who cannot produce that list has not looked.

3. Whether it trains anyone’s AI

The question to ask word for word: is our audio or transcript used to train or improve any model, yours or a provider’s? The answer you want is no, in writing, and it should be true of every sub-processor on the list.

4. How long it stays

Live translation does not require keeping the audio at all. If you want the transcript and the drafts afterwards, decide how long, and make sure the vendor lets you choose rather than keeping everything forever by default.

5. How it is erased

A person who asked for prayer from the front is entitled to have that erased. Ask how one service, with everything derived from it, is deleted, and how long that takes. “Send us an email” is a process; a button is a better one.

The paperwork

  • A data processing agreement with the vendor, naming the sub-processors.
  • A line in your own privacy notice saying that services are translated live and, if so, recorded.
  • A sign or a slide telling the room the same thing in plain words.
  • A retention decision written down somewhere a successor can find it.

How Sanctavo does it

Recordings, transcripts and generated content are stored in Frankfurt, Germany. The sub-processor register is public on our website and generated from the running configuration, not written by hand. The AI providers we use do not train on your service content. Source audio is off unless you turn it on, transcripts follow the retention window you choose, and one service with everything made from it can be erased in a single action. Listeners are counted, never identified, and become known to the church only by their own opt-in.

Our privacy notice, sub-processor register and AI transparency page are linked from the foot of every page. Read them before the demo, and ask us anything they leave open.

Diese Antwort auf Deutsch