Recording meetings in the Netherlands.
The Netherlands draws a cleaner line than most: its criminal provision is aimed squarely at people recording conversations they are not part of, which leaves the everyday meeting case to data protection law.
The General Data Protection Regulation applies here of its own force rather than through a national translation of it, and the national act below handles the parts member states are left to decide for themselves. The supervisory authority enforces both. Alongside it, Article 139a of the Wetboek van Strafrecht addresses intentionally recording a conversation using a technical device, framed around someone who is not taking part in it.
Because Article 139a targets the non-participant, a participant recording their own meeting is usually a data protection question rather than a criminal one. That does not make it a free hand: you still need a lawful basis under Article 6, you still have to tell people at the time under Article 13, and you still have to keep the recording only as long as the stated purpose holds. The Autoriteit Persoonsgegevens publishes specific guidance on recording in the workplace, which is the practical starting point for employers.
- The data protection instrument
- Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act), UAVG, 2018
- Who supervises this
- Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Criminal provisions
These sit alongside data protection law rather than replacing it. They generally address conduct that is covert or that involves conversations the recorder was not part of, which is a narrower category than everyday meeting recording, and a considerably more serious one.
Wetboek van Strafrecht, Article 139a
Criminal Code
Recording a conversation using a technical device. The provision addresses intentionally recording a conversation by someone who is not taking part in it, which is a narrower category than meeting recording generally.
What is specific to this country
- The GDPR applies directly in the Netherlands rather than through a national equivalent. A meeting recording that identifies the people in it is personal data, so making, storing and sharing it is processing, and it needs a lawful basis under Article 6.
- Transparency is a separate obligation from lawful basis. Article 13 requires that people are told what is being collected and why at the time it is collected, which for a meeting means at the start rather than afterwards.
- Article 139a is framed around recording a conversation you are not part of, which is a different question from a participant recording a meeting they are in. The data protection layer is the one that governs the ordinary case.
- The Autoriteit Persoonsgegevens publishes specific guidance on recording in the workplace, which is the practical reference for employers.
What to do in practice
The practice below is not the legal minimum in every jurisdiction. It is the practice that is defensible in all of them, which is a more useful target when your calls cross borders.
- Say it out loud at the start, before anything substantive is discussed, and say what the recording is for. Not a line in the invite nobody read.
- Give people a real way to decline. An announcement that leaves no room to object is closer to a notification than to consent.
- Write it down. A line in the notes recording that the meeting was recorded, and that nobody objected, is worth more later than anyone's memory of the moment.
- Keep external meetings to a higher standard than internal ones. Colleagues share an employment context; a customer, a candidate, or a supplier does not.
- Decide how long you keep recordings, and actually delete them. Indefinite retention converts a small, well-handled recording into a growing liability.
- Treat sharing as a fresh decision. The question is not whether you were allowed to record, it is whether this particular person was meant to hear it.
Questions
Is Article 139a about recording my own meetings?
It is framed around recording a conversation by someone not taking part in it, which is a narrower category. A participant recording a meeting they are in is generally analysed under data protection law instead. That is a description of how the provisions are structured, not advice about a specific recording.
What does the Autoriteit Persoonsgegevens require?
The Regulation's obligations, applied to your situation: a lawful basis, transparency at the time of collection, proportionality, and retention limited to the purpose. It publishes guidance specifically on workplace recording, which is worth reading before deploying anything that records staff routinely.
Does the UAVG add anything?
The UAVG is the Dutch implementation act. It handles the choices the Regulation leaves to member states rather than replacing it, so the substantive obligations for a meeting recording come from the Regulation itself.
Sources
Primary sources, so you can check this rather than take our word for it.
Recording that announces itself.
Canto's notetaker joins as a named participant the organiser admits, and the recording, the transcript and who can see it stay under your control. 300 minutes a month, free forever.