Back to all essays
Compliance7 min read

Recording Consent at Nordic Trade Shows: Sweden, Denmark, Norway, Finland

Sweden, Denmark, Norway and Finland all allow participant recording under criminal law — but their data-protection authorities are among Europe's most exacting.

CF
Confee Team
Essay · Compliance

All four Nordic countries permit participant recording under criminal law. If you are part of the conversation, recording it is not eavesdropping in Sweden, Denmark, Norway or Finland.

But the Nordics also have some of Europe's more exacting data-protection authorities, and — less legally but just as practically — some of its highest cultural expectations around privacy. A process that is technically legal can still cost you the relationship.

Not legal advice. A practical summary for sales teams. Have your DPO or counsel review your process before an event.

The criminal position, country by country

Sweden

Chapter 4, Section 9a of the Brottsbalken criminalises olovlig avlyssning — unlawful eavesdropping. It covers secretly listening to or recording, by technical means, conversations to which one is not a party.

A rep recording their own booth conversation is a party. The provision does not apply.

Supervisory authority: Integritetsskyddsmyndigheten (IMY).

Denmark

Straffeloven §263 addresses unauthorised access to communications between other people, including by intercepting or recording conversations one is not part of.

Danish practice is consistent: a participant may record. Notably, Danish courts have accepted such recordings as evidence.

Supervisory authority: Datatilsynet.

Norway

Straffeloven §205 covers secretly listening to or recording telephone conversations or other conversations between others, or negotiations in a closed meeting one is not part of.

The words "between others" do the work. Participant recording is outside the offence.

Supervisory authority: Datatilsynet (Norway's own).

Finland

Rikoslaki Chapter 24, Section 5salakuuntelu, illicit listening — criminalises using technical devices to listen to or record a conversation not intended for the listener.

Finnish courts have consistently held that a participant is an intended recipient. Recording your own conversation is lawful.

Supervisory authority: Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman).

The GDPR layer, which is where the work is

The uniform criminal answer does not translate into a light data-protection regime. All four countries apply GDPR — Norway via the EEA Agreement and the Personopplysningsloven (2018), so its obligations are effectively identical despite not being an EU member.

The Nordic authorities have particular emphases worth knowing:

  • Transparency. All four expect information that a normal person can actually understand. Dense legalese is treated as a failure, not a defence.
  • Data minimisation. The Nordic authorities are notably firm that "we might need it later" is not a purpose.
  • Retention. Indefinite retention attracts attention quickly.

The cultural dimension, which matters commercially

This is not a legal point but it affects outcomes. Nordic business culture has unusually high baseline privacy expectations. Attendees are more likely than in most markets to ask why you are recording, and more likely to decline if the answer is vague.

The practical consequence: frame the request around accuracy, and be ready to explain what happens to the audio. A rep who can say "it becomes four fields in our CRM and the recording is deleted" will get a yes far more often than one who says "it's for our records."

What to say

Swedish: "Jag spelar in vårt samtal så att mina anteckningar blir korrekta — är det okej för dig?"

Danish: "Jeg optager vores samtale, så mine noter bliver præcise — er det i orden med dig?"

Norwegian: "Jeg tar opp samtalen vår så notatene mine blir riktige — er det greit for deg?"

Finnish: "Nauhoitan keskustelumme, jotta muistiinpanoni ovat tarkkoja — sopiiko se sinulle?"

English is universally accepted at Nordic trade shows, but asking in the local language signals that the process was thought about.

Minimisation is the strongest control

If the purpose is capturing an accurate lead, that purpose completes when name, company, requirement and next step reach the CRM. Keeping raw audio beyond that point has no declared purpose — and in a Nordic enforcement context, no declared purpose is a genuine problem.

Extract, then delete. This is how Confee is designed: the conversation becomes structured CRM fields and the raw recording need not be retained. It is also the answer that satisfies a sceptical Nordic prospect on the spot.

Nordic booth checklist

Before the show

  • Privacy notice in the local language, plain-worded, via QR code
  • Lawful basis documented — consent recommended
  • Retention period defined and short
  • Reps able to explain in one sentence what happens to the audio

Per conversation

  • Ask before starting
  • Wait for an explicit yes
  • Recording indicator visible
  • Log the consent
  • Stop on objection

After the show

  • Delete raw audio once fields extracted
  • Handle rights requests within one month

The short version

Sweden, Denmark, Norway and Finland all let you record a conversation you are part of. None of them let you skip GDPR, and all four regulators care about transparency and minimisation more than average.

The bigger risk in the Nordics is not enforcement — it is a prospect who decides you are careless with data. Ask well, explain briefly, delete the audio.


Related reading:

FAQ

Can you record a conversation you take part in in Sweden?

Yes. Brottsbalken Chapter 4 §9a criminalises eavesdropping on conversations you are not part of. A participant recording their own conversation falls outside it, though GDPR applies in full via IMY.

What about Denmark, Norway and Finland?

All three take the same approach — Denmark's Straffeloven §263, Norway's Straffeloven §205, and Finland's Rikoslaki 24:5 all target listening to conversations between others. Participants may record.

Are Nordic data protection authorities strict?

Yes. Norway's and Denmark's Datatilsynet, Sweden's IMY and Finland's Tietosuojavaltuutettu are among the more rigorous European authorities, particularly on transparency and minimisation.

Does Norway follow GDPR if it is not in the EU?

Yes. Norway is in the EEA, and GDPR was incorporated through the Personopplysningsloven of 2018. Obligations are effectively identical to an EU member state.

FAQ

Questions, answered

01

Can you record a conversation you take part in in Sweden?

Yes. Chapter 4, Section 9a of the Swedish Brottsbalken criminalises olovlig avlyssning — unlawful eavesdropping — which covers secretly listening to or recording conversations you are not part of. A participant recording their own conversation falls outside it. Sweden is a one-party consent jurisdiction, though GDPR obligations apply in full via Integritetsskyddsmyndigheten (IMY).

02

What about Denmark, Norway and Finland?

All three take the same approach. Denmark's Straffeloven §263 targets unauthorised access to communications between others. Norway's Straffeloven §205 covers secret listening to conversations you are not part of. Finland's Rikoslaki Chapter 24 §5 addresses illicit surveillance of others. In all three, a participant may record their own conversation.

03

Are Nordic data protection authorities strict?

Yes. Norway's Datatilsynet, Denmark's Datatilsynet, Sweden's IMY and Finland's Tietosuojavaltuutettu are among the more rigorous European supervisory authorities, particularly on transparency and data minimisation. Nordic business culture also has high baseline expectations around privacy, so a process that is merely legal may still damage trust.

04

Does Norway follow GDPR if it is not in the EU?

Yes. Norway is in the European Economic Area, and GDPR was incorporated into the EEA Agreement and Norwegian law through the Personopplysningsloven of 2018. The obligations on a business operating at a Norwegian trade show are effectively identical to those in an EU member state.

Get early access

Never lose a lead again.

Eight quick questions about your team. The first 200 to complete the form get the €200 device fee waived, founder pricing locked, and priority hardware delivery.

No spam · Takes about a minute