Recording meetings in Ireland.
Ireland matters far out of proportion to its size, because so many technology companies have their EU establishment in Dublin and inherit its regulator as their lead authority for the whole Union.
The General Data Protection Regulation applies here of its own force rather than through a national translation of it, and the national act below handles the parts member states are left to decide for themselves. The supervisory authority enforces both. In Ireland that is the Data Protection Act 2018, supervised by the Data Protection Commission.
Ireland is the clearest example in this cluster of a jurisdiction where the data protection layer does nearly all the work. We have not found an Irish criminal provision that maps cleanly onto a participant recording a meeting they are taking part in, and we would rather say so than name one that does not fit; Irish interception legislation is aimed at postal and telecommunications interception. The more consequential Irish point is structural: under the one-stop-shop mechanism, an organisation whose main EU establishment is in Ireland deals with the Data Protection Commission as its lead supervisory authority across the EU.
- The data protection instrument
- Data Protection Act 2018 (Data Protection Act 2018), No. 7 of 2018
- Who supervises this
- Data Protection Commission (Data Protection Commission)
No single criminal provision on point
We have not found a criminal provision here that maps cleanly onto a participant recording a meeting they are taking part in, and we would rather say so than name an article that does not fit. The data protection obligations below still apply, and a local lawyer can confirm whether something specific to your situation does too.
What is specific to this country
- The GDPR applies directly in Ireland rather than through a national equivalent. A meeting recording that identifies the people in it is personal data, so making, storing and sharing it is processing, and it needs a lawful basis under Article 6.
- Transparency is a separate obligation from lawful basis. Article 13 requires that people are told what is being collected and why at the time it is collected, which for a meeting means at the start rather than afterwards.
- Ireland matters out of proportion to its size here: many US technology companies have their EU establishment in Dublin, which makes the Data Protection Commission their lead supervisory authority for the whole EU under the one-stop-shop mechanism.
- There is no single Irish criminal provision that maps neatly onto a participant recording a meeting, so the data protection layer does nearly all the work. That is a genuine difference from Germany or France rather than a gap in this page.
What to do in practice
The practice below is not the legal minimum in every jurisdiction. It is the practice that is defensible in all of them, which is a more useful target when your calls cross borders.
- Say it out loud at the start, before anything substantive is discussed, and say what the recording is for. Not a line in the invite nobody read.
- Give people a real way to decline. An announcement that leaves no room to object is closer to a notification than to consent.
- Write it down. A line in the notes recording that the meeting was recorded, and that nobody objected, is worth more later than anyone's memory of the moment.
- Keep external meetings to a higher standard than internal ones. Colleagues share an employment context; a customer, a candidate, or a supplier does not.
- Decide how long you keep recordings, and actually delete them. Indefinite retention converts a small, well-handled recording into a growing liability.
- Treat sharing as a fresh decision. The question is not whether you were allowed to record, it is whether this particular person was meant to hear it.
Questions
Is there an Irish criminal provision on recording meetings?
Not one we are confident maps onto a participant recording a meeting they are part of. Irish interception law is aimed at postal and telecommunications interception. That is a real difference from Germany or France rather than an omission on this page, and an Irish lawyer can confirm whether anything specific to your situation applies.
Why does the Irish regulator come up so often?
Because of the one-stop-shop mechanism. An organisation with its main EU establishment in Ireland has the Data Protection Commission as its lead supervisory authority for cross-border processing across the whole EU, which is why so many large technology cases run through Dublin.
Does that mean only Irish rules apply?
No. The Regulation is the same law across the EU. The lead authority mechanism decides who supervises, not which rules apply, and other authorities retain a role for issues affecting people in their own state.
Sources
Primary sources, so you can check this rather than take our word for it.
Recording that announces itself.
Canto's notetaker joins as a named participant the organiser admits, and the recording, the transcript and who can see it stay under your control. 300 minutes a month, free forever.