Back to all essays
Compliance6 min read

Recording Consent at UK Trade Shows: UK GDPR Rules

UK law does not prohibit recording a conversation you are part of. UK GDPR and the ICO are a separate matter — here is what booth teams actually need.

CF
Confee Team
Essay · Compliance

The UK does not prohibit recording a conversation you are taking part in. There is no UK equivalent of Germany's §201 StGB. But UK GDPR and the Data Protection Act 2018 apply in full to the personal data in that recording, and the ICO enforces them.

The UK hosts a substantial B2B events calendar, and post-Brexit its regime is close to but not identical with EU GDPR. For exhibitors, the criminal question is easy and the data-protection question is the real work.

Not legal advice. A practical summary for sales teams. Have your DPO or counsel review your process before an event.

Why recording itself is lawful

Two statutes are often cited and neither prohibits what booth teams do.

The Regulation of Investigatory Powers Act 2000 (RIPA) and its successor the Investigatory Powers Act 2016 address interception of communications in the course of transmission — wiretapping, in ordinary language. A participant recording a face-to-face conversation is not intercepting a communication in transmission.

There is also no general common-law tort of "recording someone." The relevant civil action would be misuse of private information, which requires a reasonable expectation of privacy. A business conversation at a public trade show, held openly, is a weak candidate.

So: one-party consent. If you are in the conversation, you may record it.

Where the obligations actually are

Recording a prospect captures their voice, name, employer and commercial situation. That is personal data, and processing it engages UK GDPR, supervised by the Information Commissioner's Office (ICO).

Required regardless of the criminal position:

  • A lawful basis under Article 6
  • Privacy information at the point of collection (Articles 13–14)
  • Data minimisation (Article 5(1)(c))
  • Defined retention
  • Accountability — being able to demonstrate the above

This is the one place where UK practice diverges usefully from the EU.

The ICO is comparatively open to legitimate interests in B2B contexts, and UK GDPR Recital 47 explicitly acknowledges direct marketing as a possible legitimate interest. If you want to rely on it, you must complete a documented Legitimate Interests Assessment (LIA) covering:

  1. Purpose — what is the interest, and is it legitimate?
  2. Necessity — is processing necessary, or is there a less intrusive route?
  3. Balancing — do the individual's rights override your interest?

For audio recording, step 2 is where it usually falls down. If you could capture the same lead data by typing notes, "necessary" is hard to argue. And in the balancing test, someone who was never asked whether they minded being recorded has a strong case.

Practical recommendation: use consent. It is one question, it takes four seconds, and it removes the entire argument. Reserve legitimate interests for the follow-up marketing that comes afterwards.

What to say at a UK booth

"I'm recording our conversation so my notes are accurate — is that alright with you?"

UK trade show attendees are generally comfortable with this if it is framed around accuracy rather than compliance. You are recording so you do not misremember their requirements.

Then:

  • Wait for an explicit yes
  • Keep the recording indicator visible
  • Log that consent was given, with a timestamp
  • Stop immediately on any objection

Privacy information without a monologue

UK GDPR requires you to tell people who you are, why you are processing, how long you keep it, and their rights — including the right to complain to the ICO.

The ICO explicitly supports layered privacy notices. The workable booth pattern is a short spoken explanation plus a QR code or short link to the full notice. Put the QR code somewhere a person can actually see it while standing at the booth.

Minimisation is the strongest control

If your purpose is capturing an accurate lead, that purpose is complete once name, company, requirement and next step are in the CRM. Keeping raw audio afterwards serves no stated purpose, extends your retention obligation and enlarges your breach surface.

Extract, then delete. This is how Confee is built — the conversation becomes structured CRM fields and the raw recording need not be retained.

UK booth checklist

Before the show

  • Privacy notice published and reachable by QR code
  • Lawful basis documented — consent recommended; LIA completed if relying on legitimate interests
  • Retention period defined
  • ROPA updated (Article 30)

Per conversation

  • Ask before starting
  • Wait for an explicit yes
  • Recording indicator visible
  • Log the consent
  • Stop on objection

After the show

  • Delete raw audio once fields extracted
  • Handle any subject access request within one month
  • Check PECR before any electronic marketing follow-up

One thing people forget: PECR

UK GDPR governs the recording. PECR — the Privacy and Electronic Communications Regulations — governs what you do next. Emailing a prospect you met at a booth is electronic marketing, and PECR has its own rules, including the soft opt-in and the requirement for an unsubscribe route.

Lawful recording does not license unlimited follow-up. They are separate regimes.

The short version

The UK will not stop you recording your own conversation. UK GDPR still governs the data, the ICO still expects privacy information and minimisation, and PECR still governs the follow-up.

Ask, get a yes, keep it visible, log it, delete the audio. Straightforward — and materially easier than Germany.


Related reading:

FAQ

Yes, if you are a participant. UK law contains no general prohibition on recording a conversation you take part in. RIPA 2000 and the IPA 2016 target interception of communications in transmission by third parties, not participants.

Does UK GDPR still apply if recording itself is lawful?

Yes. UK GDPR and the DPA 2018 apply whenever you process personal data. You need a lawful basis, must provide privacy information, and must apply minimisation and retention limits.

Potentially — the ICO is more open to it in B2B contexts than some EU regulators. But you must complete a documented Legitimate Interests Assessment, and the necessity test is hard to pass for audio recording. Consent is usually simpler.

What does the ICO expect at an event?

Clear privacy information at the point of collection, a documented lawful basis, minimisation, defined retention, and the ability to demonstrate compliance. Layered notices — a short spoken explanation plus a QR code — are an accepted pattern.

FAQ

Questions, answered

01

Is it legal to record a conversation at a UK trade show?

Yes, if you are a participant. UK law contains no general prohibition on recording a conversation you take part in. The Regulation of Investigatory Powers Act 2000 and the Investigatory Powers Act 2016 target interception of communications in transmission by third parties, not participants documenting their own conversations. The UK is a one-party consent jurisdiction.

02

Does UK GDPR still apply if recording itself is lawful?

Yes. UK GDPR and the Data Protection Act 2018 apply whenever you process personal data, and a recording of an identifiable prospect is personal data. You need a lawful basis under Article 6, must provide privacy information at collection, and must apply data minimisation and retention limits. The absence of a recording prohibition changes none of that.

03

Can UK businesses rely on legitimate interests instead of consent?

Potentially, and the ICO is more open to legitimate interests in B2B contexts than some EU regulators. But you must complete and document a three-part Legitimate Interests Assessment covering purpose, necessity and balancing. For audio recording of an individual who would reasonably expect to be asked, the balancing test is difficult. Consent is usually simpler and safer.

04

What does the ICO expect at an event?

Clear privacy information at the point of collection, a documented lawful basis, data minimisation, a defined retention period, and the ability to demonstrate compliance. The ICO favours layered privacy notices — a short explanation in person with a QR code to the full notice is an accepted pattern.

Get early access

Never lose a lead again.

Eight quick questions about your team. The first 200 to complete the form get the €200 device fee waived, founder pricing locked, and priority hardware delivery.

No spam · Takes about a minute