All four Nordic countries permit participant recording under criminal law. If you are part of the conversation, recording it is not eavesdropping in Sweden, Denmark, Norway or Finland.
But the Nordics also have some of Europe's more exacting data-protection authorities, and — less legally but just as practically — some of its highest cultural expectations around privacy. A process that is technically legal can still cost you the relationship.
Not legal advice. A practical summary for sales teams. Have your DPO or counsel review your process before an event.
The criminal position, country by country
Sweden
Chapter 4, Section 9a of the Brottsbalken criminalises olovlig avlyssning — unlawful eavesdropping. It covers secretly listening to or recording, by technical means, conversations to which one is not a party.
A rep recording their own booth conversation is a party. The provision does not apply.
Supervisory authority: Integritetsskyddsmyndigheten (IMY).
Denmark
Straffeloven §263 addresses unauthorised access to communications between other people, including by intercepting or recording conversations one is not part of.
Danish practice is consistent: a participant may record. Notably, Danish courts have accepted such recordings as evidence.
Supervisory authority: Datatilsynet.
Norway
Straffeloven §205 covers secretly listening to or recording telephone conversations or other conversations between others, or negotiations in a closed meeting one is not part of.
The words "between others" do the work. Participant recording is outside the offence.
Supervisory authority: Datatilsynet (Norway's own).
Finland
Rikoslaki Chapter 24, Section 5 — salakuuntelu, illicit listening — criminalises using technical devices to listen to or record a conversation not intended for the listener.
Finnish courts have consistently held that a participant is an intended recipient. Recording your own conversation is lawful.
Supervisory authority: Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman).
The GDPR layer, which is where the work is
The uniform criminal answer does not translate into a light data-protection regime. All four countries apply GDPR — Norway via the EEA Agreement and the Personopplysningsloven (2018), so its obligations are effectively identical despite not being an EU member.
The Nordic authorities have particular emphases worth knowing:
- Transparency. All four expect information that a normal person can actually understand. Dense legalese is treated as a failure, not a defence.
- Data minimisation. The Nordic authorities are notably firm that "we might need it later" is not a purpose.
- Retention. Indefinite retention attracts attention quickly.
The cultural dimension, which matters commercially
This is not a legal point but it affects outcomes. Nordic business culture has unusually high baseline privacy expectations. Attendees are more likely than in most markets to ask why you are recording, and more likely to decline if the answer is vague.
The practical consequence: frame the request around accuracy, and be ready to explain what happens to the audio. A rep who can say "it becomes four fields in our CRM and the recording is deleted" will get a yes far more often than one who says "it's for our records."
What to say
Swedish: "Jag spelar in vårt samtal så att mina anteckningar blir korrekta — är det okej för dig?"
Danish: "Jeg optager vores samtale, så mine noter bliver præcise — er det i orden med dig?"
Norwegian: "Jeg tar opp samtalen vår så notatene mine blir riktige — er det greit for deg?"
Finnish: "Nauhoitan keskustelumme, jotta muistiinpanoni ovat tarkkoja — sopiiko se sinulle?"
English is universally accepted at Nordic trade shows, but asking in the local language signals that the process was thought about.
Minimisation is the strongest control
If the purpose is capturing an accurate lead, that purpose completes when name, company, requirement and next step reach the CRM. Keeping raw audio beyond that point has no declared purpose — and in a Nordic enforcement context, no declared purpose is a genuine problem.
Extract, then delete. This is how Confee is designed: the conversation becomes structured CRM fields and the raw recording need not be retained. It is also the answer that satisfies a sceptical Nordic prospect on the spot.
Nordic booth checklist
Before the show
- Privacy notice in the local language, plain-worded, via QR code
- Lawful basis documented — consent recommended
- Retention period defined and short
- Reps able to explain in one sentence what happens to the audio
Per conversation
- Ask before starting
- Wait for an explicit yes
- Recording indicator visible
- Log the consent
- Stop on objection
After the show
- Delete raw audio once fields extracted
- Handle rights requests within one month
The short version
Sweden, Denmark, Norway and Finland all let you record a conversation you are part of. None of them let you skip GDPR, and all four regulators care about transparency and minimisation more than average.
The bigger risk in the Nordics is not enforcement — it is a prospect who decides you are careless with data. Ask well, explain briefly, delete the audio.
Related reading:
- Is Recording Sales Conversations Legal? — the cross-jurisdiction overview
- Recording Consent at German Trade Shows — the strictest European regime
- GDPR-Compliant Lead Capture — the data-protection side in full
FAQ
Can you record a conversation you take part in in Sweden?
Yes. Brottsbalken Chapter 4 §9a criminalises eavesdropping on conversations you are not part of. A participant recording their own conversation falls outside it, though GDPR applies in full via IMY.
What about Denmark, Norway and Finland?
All three take the same approach — Denmark's Straffeloven §263, Norway's Straffeloven §205, and Finland's Rikoslaki 24:5 all target listening to conversations between others. Participants may record.
Are Nordic data protection authorities strict?
Yes. Norway's and Denmark's Datatilsynet, Sweden's IMY and Finland's Tietosuojavaltuutettu are among the more rigorous European authorities, particularly on transparency and minimisation.
Does Norway follow GDPR if it is not in the EU?
Yes. Norway is in the EEA, and GDPR was incorporated through the Personopplysningsloven of 2018. Obligations are effectively identical to an EU member state.