Meeting Recording

This standard governs how OSBR records and transcribes meetings: only with prior consent from everyone present, and only for the purpose everyone agreed to. A decision made in a meeting and remembered only in people's heads gets misremembered, disputed, or silently reversed; "I think we agreed toโ€ฆ" is not good enough six months on. Done right, the recording becomes a searchable decision record โ€” usually produced with the help of AI transcription (see the AI Usage Guideline) โ€” that the client and the team both trust. It is bound by the consent and retention discipline of the Data Protection Policy, and the records it produces link back into the Development Guide's tickets and pull requests. Requirement levels follow RFC 2119: MUST / MUST NOT are absolute, SHOULD states a strong default overridable only with a documented reason, MAY marks a free choice.

Recording is where our values meet a hard boundary. Be Nice: nobody has to reconstruct a meeting from memory, and the client can always retrieve the exact record of what was decided and why. Be Kind: we never record someone who did not agree to it โ€” consent comes first, every time, with no exception dressed up as convenience. Be Strong: we build the shared record deliberately, before a dispute needs it, so that under scrutiny the truth is already written down and attributable.

1. Goal

The goal is to preserve the decision-making process, not just the conclusion, as a single shared source of truth. The transcript is the record of what was said; the decisions and action items extracted from it are the record of what was agreed. When the transcript, a ticket, and someone's memory disagree, the decision record is the one that governs.

This exists to serve, not to surveil. A recording captures a conversation people chose to have on the record, and the data is used only within the scope the client agreed to.

2. Responsibility

3. Practices

Recording MUST NOT begin until every participant has given prior, informed consent. This is both a legal requirement and a trust requirement.

Why "prior" and "all-party" matter legally. Many jurisdictions require all-party (two-party) consent to record a conversation, and the strictest applicable law governs a multi-jurisdiction call. As a Malaysian company, OSBR starts with Malaysia's Personal Data Protection Act 2010 (PDPA): a recording of an identifiable person is personal data, so the PDPA's Notice and Choice principle applies โ€” give notice and obtain consent before recording, and use it only for the stated purpose. Japan's APPI likewise treats a recording of an identifiable person as personal information whose acquisition and use must stay within a stated purpose (ๅˆฉ็”จ็›ฎ็š„); the EU GDPR requires consent that is specific, informed, and unambiguous. The safe, universal rule that satisfies all of these: get everyone's consent, in advance, on the record.

3-2. Use only within the client-agreed scope

The recording and everything derived from it MUST be used only for the purpose the client agreed to โ€” preserving the decision record for that engagement.

3-3. Capture decisions as data, not just prose

A wall of transcript text is searchable but not yet useful. Each meeting record SHOULD distil the raw transcript into structured decisions and action items โ€” a decision as a first-class record with attributes, not a paragraph someone has to re-read.

3-4. Make the record searchable and single-source

The transcripts and summaries MUST be stored in a searchable knowledge base so the record is retrievable, not merely archived.

3-5. Shared with the client, not held over them

The record is shared โ€” it belongs to the relationship, not to OSBR alone.

4. Minimum record โ€” checklist

A meeting recording is legitimate only if all of the following hold:

If prior consent cannot be shown, there is no recording โ€” full stop.

References

Consent law

Practice

Related OSBR standards