Recording meetings in Croatia.
Croatia is a useful place to start, because it shows the two-layer structure clearly: European data protection law applying directly, with domestic criminal provisions sitting on top of it.
Croatia has been an EU member state since 2013, so the General Data Protection Regulation applies of its own force rather than through a national translation of it. The domestic act that accompanies the Regulation handles the parts member states are left to decide for themselves, and the supervisory authority enforces both. Separately, the Criminal Code contains provisions on unauthorised sound recording and eavesdropping that predate all of this and answer a different question.
For an ordinary business meeting, the data protection layer is the one that governs day to day. You need a reason for recording that you can state before you start, you need to tell people at the time rather than afterwards, and you need to keep the recording only as long as that reason holds. The criminal provisions become relevant at the point where a recording is covert, or captures a conversation the recorder had no part in, or is passed to someone it was never meant for.
- The data protection instrument
- Zakon o provedbi Opće uredbe o zaštiti podataka (Act on the Implementation of the General Data Protection Regulation), Narodne novine 42/2018
- Who supervises this
- Agencija za zaštitu osobnih podataka (Personal Data Protection Agency)
Criminal provisions
These sit alongside data protection law rather than replacing it. They generally address conduct that is covert or that involves conversations the recorder was not part of, which is a narrower category than everyday meeting recording, and a considerably more serious one.
Kazneni zakon, Article 144
Criminal Code
Unauthorised sound recording and eavesdropping. The provision addresses recording or listening to a conversation that was not intended for the person doing it, and separately addresses making such a recording available to someone else.
Kazneni zakon, Article 143
Criminal Code
Unauthorised image recording, which is the companion provision covering video rather than audio.
What is specific to this country
- The GDPR applies directly in Croatia rather than through a national equivalent. A meeting recording that identifies the people in it is personal data, so making, storing and sharing it is processing, and it needs a lawful basis under Article 6.
- Transparency is a separate obligation from lawful basis. Article 13 requires that people are told what is being collected and why at the time it is collected, which for a meeting means at the start rather than afterwards.
- The criminal provisions sit alongside data protection law rather than replacing it. Complying with one does not answer the other.
- Sharing a recording is its own act. A recording that was fine to make can still create exposure when it is forwarded, published, or used for a purpose nobody was told about.
What to do in practice
The practice below is not the legal minimum in every jurisdiction. It is the practice that is defensible in all of them, which is a more useful target when your calls cross borders.
- Say it out loud at the start, before anything substantive is discussed, and say what the recording is for. Not a line in the invite nobody read.
- Give people a real way to decline. An announcement that leaves no room to object is closer to a notification than to consent.
- Write it down. A line in the notes recording that the meeting was recorded, and that nobody objected, is worth more later than anyone's memory of the moment.
- Keep external meetings to a higher standard than internal ones. Colleagues share an employment context; a customer, a candidate, or a supplier does not.
- Decide how long you keep recordings, and actually delete them. Indefinite retention converts a small, well-handled recording into a growing liability.
- Treat sharing as a fresh decision. The question is not whether you were allowed to record, it is whether this particular person was meant to hear it.
Questions
Does the GDPR apply to a meeting recording in Croatia?
A recording that identifies the people in it is personal data, and making, storing and sharing it is processing. That brings the Regulation's requirements into play, including a lawful basis under Article 6 and the transparency obligations in Article 13. Croatia applies the Regulation directly as an EU member state.
Is it enough to mention the recording in the calendar invite?
Transparency obligations are framed around telling people at the point the data is collected, which for a meeting is when it starts. An invite line is worth having, but it is a supplement to saying it at the top of the call rather than a replacement for it.
What changes when the meeting includes people outside Croatia?
Jurisdiction follows the participants. A call with people in several countries can engage several sets of rules at once, which is the practical argument for holding every meeting to the same announced-and-agreed standard rather than tracking each one separately.
Where can I check this myself?
The consolidated Criminal Code and the Personal Data Protection Agency are both linked in the sources below, along with the consolidated text of the Regulation. For a specific situation, ask a lawyer qualified in Croatia.
Sources
Primary sources, so you can check this rather than take our word for it.
Recording that announces itself.
Canto's notetaker joins as a named participant the organiser admits, and the recording, the transcript and who can see it stay under your control. 300 minutes a month, free forever.