Regulation
Data protection and security cameras: what to watch for at work

Installing cameras at a workplace is a technical job. Keeping the footage lawfully is a separate responsibility, and that responsibility rests with the employer operating the system, not with the company that installed it.
What follows is not legal advice but a summary of the topics we most often encounter in the field. Consult your legal adviser for an assessment specific to your site.
Who is the data controller
The business operating the camera system is the data controller. The company that installs or maintains the system is, depending on the contract, a data processor. Most obligations sit with the controller.
The duty to inform
At entrances to areas with cameras, there must be visible notice that monitoring takes place. That notice should not consist only of the words "under camera surveillance"; it should also show the identity of the controller and how to reach the detailed information text.
For employees, written information is additionally expected, whether through employment documents or internal regulations.
Where cameras do not belong
Under the principle of purpose limitation, monitoring is not carried out where the security purpose does not require it. Changing rooms, toilets, rest areas and prayer rooms fall into this category. Installations where an employee is continuously monitored in close-up, turning into productivity measurement, are also outside the purpose.
A camera whose field of view spills onto a neighbouring plot or public area creates a separate problem; angle limitation or privacy masking should be planned during the survey.
Retention period
Recordings should not be kept longer than the security purpose requires. In practice, a range of 15–30 days is discussed for most businesses; if legislation specific to your sector prescribes a longer period, that governs.
The technical connection here matters: the retention period determines disk capacity. The approach of "keep as much as we can" leads both to unnecessary data retention and to unpredictable deletions. Decide the period first, then size the disk accordingly.
Access authorisation
Who may access recordings should be defined, and that definition should be technically enforced on the system. The most common shortcoming in practice is all managers sharing the same full-privilege account; in that case there is no way to trace who downloaded a recording.
In a good installation, users are defined individually, download rights are kept limited, and access is logged.
When a request arrives
A data subject may request information about recordings concerning them. Such a request may require masking other people's images. Whether the system has the software support to do this should be assessed at installation, not after the request arrives.
A short checklist
- Is there visible notice at entrances?
- Have employees been informed in writing?
- Are private areas excluded, and is spillover onto neighbouring plots masked?
- Has the retention period been decided, and was the disk sized to match?
- Are users defined individually, download rights limited, and access logged?


