Speech data · Consent framework
Consent is captured before the first recording. It travels with the dataset for as long as the model runs.
How YPAI designs, documents and defends participant consent for speech data used in production AI systems. Written for DPOs, legal and compliance teams, procurement and the enterprise AI teams they review.
Supports internal review and vendor due diligence. The DPA and engagement agreement carry the contractual terms.
The framework Platform closed, controlled Rights Arts. 12 to 23 Withdrawal at any time Transfers SCCs outside the EEA Consent · GDPR Article 7, per record
The consent record one per participant · linked to every file
The form the participant signs is the record the auditor reads.
Captured electronically before the first recording, versioned, tied to the engagement's scope, and linked to every file the participant records.
- Participant
- Recruited and vetted by YPAI, identity verified
- Engagement
- The named project, its scope and its intended use
- Purpose
- AI training, evaluation, or the use stated in the information materials
- Data categories
- Voice recordings, transcripts, the speaker metadata the quota table defines
- Rights explained
- Access, rectification, erasure, restriction, objection, and how to contact YPAI
- Consent
- Explicit, affirmative, its own action, recorded with timestamp and version
- Withdrawal
- At any time. Processed against every affected dataset, documented
- Provenance link
- Consent id carried on every recording in the delivered dataset
Recorded before the session starts · enforced in the workflow
Purpose and principles six principles · one platform
Six principles the framework rests on. Each one shows up in the delivered dataset.
Speech data is collected inside a closed, controlled platform designed for lawful and auditable collection. Consent is explicit, informed and documented before any recording, and the consent record stays linked to the dataset as audit evidence.
- Platform
- Speech data collected inside a closed, controlled platform designed for lawful and auditable collection
- Consent
- Explicit, informed and documented prior to any recording
- Frameworks
- Defined per engagement, aligned to the intended use of the dataset
- Provenance
- Consent records linked to dataset provenance and retained as audit evidence
- Sourcing
- Vetted participants recruited by YPAI; every recording has a named, consented speaker
- Design
- Consent handling built for long-term production use, from training through retraining
Why consent personal data · biometric
Speech is personal data. A consent gap surfaces years after deployment.
Speech data frequently constitutes personal data under GDPR, and depending on use it can intersect with biometric considerations. For enterprises training or fine-tuning AI systems, a deficiency in consent surfaces as three exposures.
- Inability to demonstrate lawful basis during audits
- Data subject rights exposure years after deployment
- Regulatory and reputational risk tied to upstream data sources
For this reason YPAI treats consent as a core design constraint of the collection platform, engineered into the workflow rather than added afterwards.
The consent model closed · vetted · traceable
A closed collection model, with consent traceable at dataset level.
All speech data is collected inside YPAI's controlled platform, from vetted participants, under a defined consent framework, before dataset creation and delivery.
-
Recruitment
Participants are recruited and vetted by YPAI for the specific engagement.
-
Information
The task, the data categories, the purpose, YPAI's role and their rights are explained before anything is recorded.
-
Consent capture
Explicit, affirmative consent is recorded electronically, tied to the engagement scope.
-
Recording
Consent status is enforced in the workflow; a session records only against a live consent.
-
Provenance
The consent record is linked to every file in the delivered dataset.
Every recording in a delivered dataset comes from a participant YPAI recruited and informed, under the engagement's own consent framework. Traceability holds at dataset level, so a delivered corpus can be verified as a whole.
Lawful basis art. 6 · explicit
The basis is chosen at scoping. Where it is consent, it is explicit and documented.
Consent sits within the broader framework of GDPR Article 6 lawful bases. The basis that applies to a dataset is defined during engagement scoping.
- Where consent is the basis.
- It is obtained explicitly and documented, as its own affirmative action, at the moment of collection. Where an alternative lawful basis applies, participant information and rights are communicated just as clearly.
- Where it shows up.
- The selected lawful basis and consent structure are reflected in the participant information materials, aligned with the contractual documentation, and consistent with the intended downstream use of the dataset.
Participant information six disclosures · before recording
Before participating, every speaker is told six things.
Information is given in clear, accessible language appropriate to the participant context, so each speaker knows how their data will be used before the first take.
- The nature of the recording task
- The categories of data collected
- The purpose of collection, such as AI training or evaluation
- The role of YPAI in processing the data
- The rights available to them under GDPR
- How to contact YPAI on data protection matters
Capture and scope explicit · purpose-bound · enforced
Consent is captured before recording, and it is bound to the purpose it was given for.
Consent is explicit and affirmative, tied to the specific engagement scope, and stored as part of YPAI's compliance documentation.
- Enforced in the workflow.
- Consent status is technically enforced in the collection workflow: a session records only against a live consent, and the consent stays attached to the dataset it governs. Delivered datasets are backed by verifiable consent records.
- Consent scope.
- Consent is purpose-bound. It applies to the defined scope of collection and use; a change to the intended use triggers reassessment through the formal engagement process, with new participant information where required.
- Consent language.
- Consent language names the purpose and the scope. It is written so that an audit review years later can read exactly what each participant agreed to.
Data subject rights access · rectification · erasure
Rights handling in operational terms. A request maps to the datasets it affects.
The framework supports data subject rights handling in practice: identification and authentication of requests, mapping each request to the affected datasets, coordination with clients where contractually required, and documentation of the actions taken.
- Access
- Rectification
- Erasure
- Restriction
- Objection, where applicable
Handling follows the engagement-specific agreements, the applicable GDPR timelines and the audit documentation requirements.
Consent and provenance per dataset · per file
Consent records are part of provenance. They answer the inquiry that comes years later.
For each delivered dataset, YPAI can support traceability between dataset components and the consent framework, verification that the data was collected under the defined terms, and evidence suitable for internal or external audit review.
That linkage carries the model through long-term use, retraining and fine-tuning, and regulatory inquiries that arrive years after collection.
The wider system dpa · security · residency · retention
Consent is one control among several. Together they govern how speech data is collected, delivered and defended.
Why purpose-bound consent matters. Generic consent, self-selected tasks without context, provenance that cannot be reconstructed, and rights handling that fails at scale are the four ways a consent review fails. YPAI's closed model answers each one: purpose-bound consent, informed participants, per-file provenance, and rights requests mapped to datasets.
Relationship to the other controls. The consent framework operates alongside the Data Processing Agreement, the security and access controls, the data residency governance and the retention and deletion policies. One coherent system governs how speech data is collected, delivered and defended.
Legal and procurement
Basis, withdrawal and roles
What lawful basis does YPAI rely on for speech data collection?
The lawful basis is defined per engagement. For most client projects, explicit consent (Art. 6(1)(a)) is the primary basis. Alternative bases may be used when appropriate to the specific use case and documented accordingly.
Can participants withdraw their consent?
Yes. Participants can withdraw consent at any time by contacting YPAI. Withdrawal is processed in accordance with GDPR requirements and engagement-specific agreements. YPAI maintains systems to track and action withdrawal requests across affected datasets.
How is consent documented and stored?
Consent is captured electronically before any recording begins. Records include timestamp, consent version, participant identifier and scope of consent. These records are linked to dataset provenance and retained for the required retention period.
Does YPAI act as a data controller or processor?
This depends on the engagement structure. In some cases YPAI acts as an independent controller for the collection phase. In others, YPAI acts as a processor under client instruction. The applicable role is defined in the Data Processing Agreement for each engagement.
How are cross-border transfers handled?
Data transfers outside the EEA are governed by appropriate safeguards including Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures. Transfer mechanisms are documented and available for client review.
What happens to data when a contract ends?
Data retention and deletion are governed by the engagement agreement. On contract termination, data is returned to the client, deleted, or retained for the agreed period, in accordance with documented retention schedules and applicable law.
Bring the jurisdiction and the use case. The consent documentation follows.
A conversation gives you the specific compliance documentation relevant to your jurisdiction and use case, including the participant agreements used for a comparable dataset.
Speech data overview GDPR-native speech data DPA overview Retention and deletion Data residency and sub-processors