Speech data · Consent framework

Consent is captured before the first recording. It travels with the dataset for as long as the model runs.

How YPAI designs, documents and defends participant consent for speech data used in production AI systems. Written for DPOs, legal and compliance teams, procurement and the enterprise AI teams they review.

Supports internal review and vendor due diligence. The DPA and engagement agreement carry the contractual terms.

The framework Platform closed, controlled Rights Arts. 12 to 23 Withdrawal at any time Transfers SCCs outside the EEA Consent · GDPR Article 7, per record

The consent record one per participant · linked to every file

The form the participant signs is the record the auditor reads.

Captured electronically before the first recording, versioned, tied to the engagement's scope, and linked to every file the participant records.

Consent record · one participant, one engagement
Participant
Recruited and vetted by YPAI, identity verified
Engagement
The named project, its scope and its intended use
Purpose
AI training, evaluation, or the use stated in the information materials
Data categories
Voice recordings, transcripts, the speaker metadata the quota table defines
Rights explained
Access, rectification, erasure, restriction, objection, and how to contact YPAI
Consent
Explicit, affirmative, its own action, recorded with timestamp and version
Withdrawal
At any time. Processed against every affected dataset, documented
Provenance link
Consent id carried on every recording in the delivered dataset

Recorded before the session starts · enforced in the workflow

Purpose and principles six principles · one platform

Six principles the framework rests on. Each one shows up in the delivered dataset.

Speech data is collected inside a closed, controlled platform designed for lawful and auditable collection. Consent is explicit, informed and documented before any recording, and the consent record stays linked to the dataset as audit evidence.

Platform
Speech data collected inside a closed, controlled platform designed for lawful and auditable collection
Consent
Explicit, informed and documented prior to any recording
Frameworks
Defined per engagement, aligned to the intended use of the dataset
Provenance
Consent records linked to dataset provenance and retained as audit evidence
Sourcing
Vetted participants recruited by YPAI; every recording has a named, consented speaker
Design
Consent handling built for long-term production use, from training through retraining

The consent model closed · vetted · traceable

A closed collection model, with consent traceable at dataset level.

All speech data is collected inside YPAI's controlled platform, from vetted participants, under a defined consent framework, before dataset creation and delivery.

Every recording in a delivered dataset comes from a participant YPAI recruited and informed, under the engagement's own consent framework. Traceability holds at dataset level, so a delivered corpus can be verified as a whole.

Lawful basis art. 6 · explicit

The basis is chosen at scoping. Where it is consent, it is explicit and documented.

Consent sits within the broader framework of GDPR Article 6 lawful bases. The basis that applies to a dataset is defined during engagement scoping.

Where consent is the basis.
It is obtained explicitly and documented, as its own affirmative action, at the moment of collection. Where an alternative lawful basis applies, participant information and rights are communicated just as clearly.
Where it shows up.
The selected lawful basis and consent structure are reflected in the participant information materials, aligned with the contractual documentation, and consistent with the intended downstream use of the dataset.

Participant information six disclosures · before recording

Before participating, every speaker is told six things.

Information is given in clear, accessible language appropriate to the participant context, so each speaker knows how their data will be used before the first take.

  • The nature of the recording task
  • The categories of data collected
  • The purpose of collection, such as AI training or evaluation
  • The role of YPAI in processing the data
  • The rights available to them under GDPR
  • How to contact YPAI on data protection matters

Capture and scope explicit · purpose-bound · enforced

Consent is captured before recording, and it is bound to the purpose it was given for.

Consent is explicit and affirmative, tied to the specific engagement scope, and stored as part of YPAI's compliance documentation.

Enforced in the workflow.
Consent status is technically enforced in the collection workflow: a session records only against a live consent, and the consent stays attached to the dataset it governs. Delivered datasets are backed by verifiable consent records.
Consent scope.
Consent is purpose-bound. It applies to the defined scope of collection and use; a change to the intended use triggers reassessment through the formal engagement process, with new participant information where required.
Consent language.
Consent language names the purpose and the scope. It is written so that an audit review years later can read exactly what each participant agreed to.

Data subject rights access · rectification · erasure

Rights handling in operational terms. A request maps to the datasets it affects.

The framework supports data subject rights handling in practice: identification and authentication of requests, mapping each request to the affected datasets, coordination with clients where contractually required, and documentation of the actions taken.

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection, where applicable

Handling follows the engagement-specific agreements, the applicable GDPR timelines and the audit documentation requirements.

Consent and provenance per dataset · per file

Consent records are part of provenance. They answer the inquiry that comes years later.

For each delivered dataset, YPAI can support traceability between dataset components and the consent framework, verification that the data was collected under the defined terms, and evidence suitable for internal or external audit review.

That linkage carries the model through long-term use, retraining and fine-tuning, and regulatory inquiries that arrive years after collection.

The wider system dpa · security · residency · retention

Consent is one control among several. Together they govern how speech data is collected, delivered and defended.

Why purpose-bound consent matters. Generic consent, self-selected tasks without context, provenance that cannot be reconstructed, and rights handling that fails at scale are the four ways a consent review fails. YPAI's closed model answers each one: purpose-bound consent, informed participants, per-file provenance, and rights requests mapped to datasets.

Relationship to the other controls. The consent framework operates alongside the Data Processing Agreement, the security and access controls, the data residency governance and the retention and deletion policies. One coherent system governs how speech data is collected, delivered and defended.

Legal and procurement

Basis, withdrawal and roles

What lawful basis does YPAI rely on for speech data collection?

The lawful basis is defined per engagement. For most client projects, explicit consent (Art. 6(1)(a)) is the primary basis. Alternative bases may be used when appropriate to the specific use case and documented accordingly.

Can participants withdraw their consent?

Yes. Participants can withdraw consent at any time by contacting YPAI. Withdrawal is processed in accordance with GDPR requirements and engagement-specific agreements. YPAI maintains systems to track and action withdrawal requests across affected datasets.

How is consent documented and stored?

Consent is captured electronically before any recording begins. Records include timestamp, consent version, participant identifier and scope of consent. These records are linked to dataset provenance and retained for the required retention period.

Does YPAI act as a data controller or processor?

This depends on the engagement structure. In some cases YPAI acts as an independent controller for the collection phase. In others, YPAI acts as a processor under client instruction. The applicable role is defined in the Data Processing Agreement for each engagement.

How are cross-border transfers handled?

Data transfers outside the EEA are governed by appropriate safeguards including Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures. Transfer mechanisms are documented and available for client review.

What happens to data when a contract ends?

Data retention and deletion are governed by the engagement agreement. On contract termination, data is returned to the client, deleted, or retained for the agreed period, in accordance with documented retention schedules and applicable law.

Bring the jurisdiction and the use case. The consent documentation follows.

A conversation gives you the specific compliance documentation relevant to your jurisdiction and use case, including the participant agreements used for a comparable dataset.