Knowledge items

Camera Surveillance and Observation under GDPR

Implementing camera surveillance requires adherence to GDPR principles. Here’s how to ensure compliance: 

 

nsecure camera observatie
Alexander Snel
CISSP CIPP/E - Information security & Privacy
4 June 2018

In our previous blog, ‘Keeping your access management in control, even after May 25,’ we mentioned that installing cameras in and around your location(s) is permitted, for example, if it is necessary to protect your business interests. This includes ensuring the safety of individuals on your premises, preventing unauthorized access to certain areas, or deterring theft. However, as of the introduction of the GDPR, the recording, use, and display of footage must comply with several conditions. But what else should your organization be mindful of?

Is Camera Surveillance Necessary? 

Camera usage must meet the criteria of necessity. Organizations must demonstrate that:

  • Surveillance fulfills a legitimate security need.
  • The goal cannot be achieved through other measures.
  • Surveillance is part of a broader security strategy.

A Privacy Impact Assessment (PIA) must document these justifications. 

Minimizing Privacy Intrusion 

To comply with GDPR principles: 

  • Use the minimum number of cameras. 
  • Limit the scope of footage (e.g., exclude public areas unrelated to security needs). 
  • Avoid 24/7 recording unless absolutely necessary. 
  • Restrict access to footage and avoid placing monitors in public spaces. 
  • Do not record audio, as it rarely aligns with security objectives. 
  • Use footage only for its intended purpose (e.g., theft prevention, not monitoring employee breaks). 

Inform Stakeholders 

Organizations must inform employees, visitors, and suppliers about camera usage. This extends beyond signage to include accessible resources, such as personnel handbooks or dedicated website pages explaining their rights. 

Retention Periods for Footage 

GDPR recommends a maximum retention period of 4 weeks unless longer retention is justified (e.g., to address a theft investigation). Organizations must predefine and communicate these retention periods. 

Remote Observation with Nsecure 

For organizations leveraging remote observation services via Nsecure’s Observation Room:

  • Observation involves more significant privacy considerations than static recording.
  • A DPA is mandatory to document the objectives, conditions, and responsibilities.

Key Features of Nsecure Observation Services:

  • Centralized remote security for access and surveillance.
  • Actionable insights and compliance with GDPR.
  • Cost-effective solutions leveraging intelligent systems.

Nsecure ensures full compliance and operational excellence, providing clients with peace of mind while maintaining safety and security standards.

Related

Topics

Alexander Snel CISSP CIPP/E - Information security & Privacy
More information

Question

Want to learn more? Contact us to discuss your GDPR compliance needs for access control and surveillance systems.