Skip to main content
Illustrative security worker using an electronic record during a site inspection
Back to the magazine

Bravion security guide

Camera supervision and GDPR: what the controller needs to think through

Rules for camera systems, GDPR, balancing test, information duty and mistakes that can create problems for a company.

Camera system can be a useful tool for protecting property, people and operations. But at the same time, it interferes with the privacy of people who move in the monitored area. Therefore, it is not enough to install the camera and hope that the legal part will be solved by itself.

The data controller needs to know why the cameras are being used, what area they are recording, who has access to the footage, how long the footage is kept and how people are notified. It is these practical questions that decide whether the camera regime makes sense and is defensible.

Scope of this article: This is a practical outline, not a universal retention period or legal opinion. The controller must be able to demonstrate why its setup is appropriate to the specific purpose, area and risks.

1. Purpose is the foundation

Every camera system should start with a clearly described purpose. Typically this can be for property protection, personal safety, vandalism prevention, access control or incident documentation. If the purpose is not specific, it is difficult to assess whether the scope of monitoring is adequate.

It's not enough to say "just in case". The camera should only intervene where there is a reasonable reason to do so and where the same objective cannot be achieved by less invasive measures, such as better lighting, a lock, mode of entry or physical control.

2. Balance test and reasonableness

Security cameras often work with the data controller's legitimate interest. But it is not an automatic pass for any kind of monitoring. The data controller must be able to demonstrate that it has a legitimate goal, that the camera is appropriate for that goal, and that the invasion of privacy is not unreasonable.

Question What the data controller should clarify Typical error
Why do we monitor? What specific problem is the camera supposed to solve. General rationale without risk description.
What does the camera capture? Does the shot extend to places where people expect more privacy. Too wide shot with no masking or limiting settings.
Who can see the recording? Who has authorized access and for what purpose. Shared accesses, missing records or uncontrolled exports.
How long is it stored? Retention period according to purpose, risk and operation. Unnecessarily long retention without justification.

3. Workplace and employee privacy

Employee monitoring requires particular care. CCTV should not replace management or routinely monitor work pace and rest periods. If cameras cover a workplace, the reason must be clearly documented and proportionate.

For workplaces, it is important to separate the safety purpose from performance control. The camera at the entrance to the warehouse may have a different mode than the camera pointing at the workbench. In places where people have a legitimate expectation of privacy, you need to be very careful and usually look for other solutions.

4. Information obligation

People must know they are entering a monitored area. In practice, brief information is used at the entrance and more detailed information available, for example, on the website, reception or in internal documentation. A brief sign without further explanation is usually not enough.

The information should contain the purpose of the monitoring, the identification of the data controller, the basic rights of the data subject and the way to get to the details. For employees, it is advisable to add internal rules that describe the operation of the camera system clearly and without legal fog.

5. Retention and Access to Records

The retention period should correspond to the purpose. A shorter period of time is easier to justify for routine security supervision, a longer period of time needs a specific reason. If an incident occurs, the relevant part of the record can be isolated and retained for incident resolution.

Only a limited group of people should have access to the records. Exports, handing over to the police, service access or work of an external security agency are to be treated contractually and procedurally. Camera footage is not material for social media or informal chat sharing.

6. Apartment buildings and common areas

In apartment buildings, cameras may protect common property, entrances, cellars or bicycle storage. Residents also have a legitimate expectation of privacy. The data controller or owners’ association must assess the camera coverage, resident information, decision-making under the association’s rules and access to recordings.

A typical mistake is scanning an unnecessarily wide area or places that show the movement of specific residents more than is necessary for the safety of common areas. The technical setting of the shot is therefore just as important as the legal documentation.

7. Checklist for data controllers

  • [ ] Purpose: Describe the specific reason for camera surveillance.
  • [ ] Adequacy: Verify that the camera does not take up more than necessary.
  • [ ] Information: Mark the monitored space and access the details.
  • [ ] Retention: Adjust the retention period according to purpose and risk.
  • [ ] Access: Specify who can view, export and to whom the recording is forwarded.
  • [ ] Contracts: Take care of the service, external security and other processors.
  • [ ] Review: Periodically verify that the original purpose and scope still apply.

Conclusion

GDPR does not ban cameras per se. But it does require the data controller to think about purpose, adequacy, informing people, retention period and access to records. A well-set camera mode protects both operations and privacy and is understandable to the people it affects.

Next step

Describe the technology and expected response

Tell us the location, date and what you need to arrange. We will discuss the details with you.

Describe the technology and expected response

Review and sources

Sources used in this guide

Reviewed 4 September 2026

Portrait of Tomas Hozak, managing director and founder of Bravion Group

Tomas Hozak

Founder and Managing Director

Founder and CEO of Bravion Group s.r.o. He personally oversees the company's key engagements, partnerships and operational standards.

Founder and Managing Director of Bravion Group s.r.o.Oversee key projects and business partnershipsResponsibility for service quality and content direction