Data Protection

The Always-Listening Watch: What Apple's Audio Intelligence Means Under GDPR

Published 21 Sep 2026 · 6 min read

At its September event, Apple turned the watch on your wrist into something that listens. The Apple Watch Series 12 and Ultra 4 ship with a set of features Apple groups under "Audio Intelligence." Live Rewind lets you replay the last fifteen seconds of whatever was just said as a text transcript. Siri Recap listens across the day and hands you a written summary of your conversations on your iPhone. Apple's pitch is that this is private by design: the processing happens on the device in a hardware-isolated part of the new chip, the features are opt-in, and, crucially, no raw audio is kept. That last point is doing a lot of work, and it is worth being precise about what it actually fixes.

An Apple Watch resting on a light surface, its screen showing the grid of app icons.
Photo: Simon Daoudi / Unsplash

None of this is speculation; it is Apple's own description, and the early coverage has been blunt about where it leads. For anyone who has to answer to a regulator, the question that matters is who is now processing whose data, and on what basis. Asked that way, the reassuring line about raw audio is where the compliance work starts.

"We don't keep the audio" is not the GDPR test

Personal data under the GDPR is any information relating to an identified or identifiable person. It is not limited to audio files, and it never was. A transcript that quotes what someone said in a meeting is personal data about that person. A daily summary that notes you argued with a named colleague, or that a client mentioned a health problem, is personal data too, arguably more sensitive than the recording, because it has already been interpreted. Deleting the waveform after you have extracted a written record of what a person said does not take that record outside the regulation. It just changes the format.

On-device processing helps with security, and it is a genuinely better design than shipping everyone's speech to a server. But "on-device" only describes where the computation happens. It says nothing about whether a controller is now holding personal data. The moment Siri Recap writes a summary of your day to your phone, there is a durable record of other people's words sitting on a device you control. If you are an individual using it for yourself, that is your own business. If you are wearing it as an employee, in rooms full of colleagues, customers and third parties, the picture changes.

The consent no one in the room gave

Processing personal data needs a lawful basis. Consent is the obvious candidate, and it is also the one that collapses fastest here. GDPR consent has to be freely given, specific, informed and unambiguous. The wearer can give that for their own data. The five other people in the meeting, the person behind you in the queue, the client on the other side of the table, gave nothing, were never asked, and have no practical way to opt out short of leaving. You cannot consent on someone else's behalf, and a feature that captures bystanders by default cannot manufacture their agreement after the fact.

THE CONSENT GAP The wearer Opts in, chooses when and where it listens. CONSENT GIVEN Everyone within earshot Never asked. Cannot opt out. Often unaware. NO CONSENT On-device processing Live Rewind · Siri Recap · no raw audio kept A transcript / summary on the wearer's phone a record of people who never agreed
The consent gap: only the wearer opts in. Everyone else is captured by default.

Legitimate interests, the other basis people reach for, does not rescue it either. That test weighs your interest against the rights and reasonable expectations of the people affected, and "I wanted an AI summary of my day" is a weak interest set against a stranger's reasonable expectation that their private remarks are not being transcribed by the person next to them. It gets worse where the words touch special-category data: health, religion, politics, sexual life, trade-union membership. People say those things out loud all the time. Article 9 puts a much higher bar on processing them, and a passive listening feature does nothing to clear it.

This is not only a European worry

The same instinct is showing up in US law from a different direction. Several states, including California, Massachusetts, Pennsylvania and Washington, require every party to a private conversation to agree before it is intercepted. Lawyers in those states are openly unconvinced that on-device processing and a deleted audio file keep users clear of wiretap and eavesdropping statutes. The Electronic Frontier Foundation has called always-on monitoring of conversations an unacceptable burden on our conversational privacy. It comes from a different legal tradition and lands on the same concern: capturing people who never agreed is the problem, and the storage detail does not change that.

Why this lands on organisations, not just individuals

Here is the part that turns a consumer-gadget story into a governance problem. When an employee wears one of these into your building, your meetings and your customer calls, a device is generating written records of third parties' speech in the course of your business. Depending on how it is used, your organisation can find itself acting as a controller of personal data it never decided to collect, cannot map, and did not tell anyone about. That is the opposite of the accountability the GDPR expects you to be able to demonstrate.

Because this is new technology used for what can amount to systematic monitoring, a Data Protection Impact Assessment is the right first move before you allow it anywhere near regulated work. This is exactly the terrain ISO/IEC 27701 is built for: it extends your ISO 27001 information-security management system into a privacy information management system, forces you to state clearly where you are a controller and where you are a processor, and gives you the records-of-processing and DPIA discipline to answer the question a regulator will eventually ask. You do not need to ban smartwatches. You need to decide, deliberately, which rooms an always-listening feature is allowed to run in.

A short checklist for teams

  • Run a DPIA before permitting always-listening wearables in any setting where third parties or regulated data are present.
  • Update your acceptable-use and BYOD policy to name these features explicitly, rather than hoping "be sensible" covers it.
  • Prohibit them outright in the obvious high-risk rooms: HR, legal, clinical, and anywhere customer or special-category data is discussed.
  • Where devices are managed, use MDM controls to disable the features on corporate profiles rather than trusting each person to switch them off.
  • Tell staff why, in plain terms, so the rule reads as protecting the people around them, not policing the wearer.
  • If you cannot identify a lawful basis for processing a bystander's words, the honest answer is not to process them.

This article is general information from a security and privacy governance practice, not legal advice. For a binding view on your specific obligations, take formal advice in your jurisdiction.

Not sure where always-listening tech leaves your obligations?

HOUSE603 runs GDPR and ISO/IEC 27701 readiness, including the DPIA and acceptable-use work that turns questions like this into a policy your team can actually follow. It sits inside our Information Security practice.

Talk to us about a DPIA →

Sources: Apple Support: Audio Intelligence on Apple Watch; TechCrunch; 9to5Mac. Device features are as announced in September 2026 and may change; confirm current behaviour with Apple.