Skip to main content Skip to search Skip to main navigation
Menu
Important Video surveillance Score: 9/10

GDPR-Compliant Video Surveillance: A Practical Guide for Operators

GDPR breaches involving video surveillance can become expensive. This practical guide shows what operators need to consider regarding cameras, retention periods and signage.

GDPR breaches in video surveillance: what happens when things go wrong

Video surveillance is a standard element of modern security concepts. Companies use it to protect buildings, production facilities, storage areas or retail spaces against theft, vandalism and sabotage. But regulatory pressure is growing: operators must ensure that their camera surveillance complies with the requirements of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). Mistakes in planning, installation or operation can not only trigger complaints and reputational damage, but also result in substantial fines.

Camera surveillance in Germany in particular often creates tension between security interests and personality rights. Every video recording of personal data is a potential interference with the rights of the individuals concerned.

Legal basis: when is video surveillance permitted?

As a matter of principle, data protection law follows the concept of "prohibition subject to permission". The processing of personal data is initially prohibited unless a legal basis exists. As soon as individuals can be identified in recordings – for example by their face, clothing or vehicle registration plate – the material constitutes personal data.

In practice, operators usually base their video surveillance on:

  • Art. 6 para. 1 lit. f GDPR ("legitimate interest")
  • § 4 BDSG for publicly accessible areas
  • in individual cases, consent under Art. 6 para. 1 lit. a GDPR

The most important legal basis for commercial operators is Art. 6 para. 1 lit. f GDPR. Under this provision, processing is permissible if it is necessary to safeguard legitimate interests and no overriding interests of the data subjects stand in the way.

Typical legitimate interests

  • Protection against burglary and theft
  • Exercise of the right of domicile
  • Protection of employees
  • Securing evidence in the event of criminal offences
  • Safeguarding critical infrastructure

Operator obligations: what needs to be observed?

Operators must not only demonstrate a permissible legal basis, they must also meet extensive information, documentation and protection obligations. Many GDPR breaches are not caused by the camera itself, but by a lack of transparency or inadequate organisational processes.

Transparency obligations under Art. 12 and 13 GDPR

Data subjects must be able to recognise that video surveillance is taking place before they enter the monitored area. The mandatory information includes in particular:

  • Controller: name and contact details of the company
  • Purpose of the surveillance: a specific statement such as "theft prevention" or "protection against vandalism"
  • Legal basis: usually Art. 6 para. 1 lit. f GDPR or § 4 BDSG
  • Retention period: for example "stored for 72 hours" or "automatic deletion after three days"
  • Data subject rights: right of access, right to erasure, right to object

Warning signs: mandatory information for operators

The classic camera sign remains a central component of GDPR-compliant video surveillance. It must be placed so that people recognise the surveillance before they enter the monitored area.

The typical mandatory details on a GDPR-compliant warning sign are:

  • a clearly recognisable camera symbol
  • name of the controller
  • the specific purpose of the surveillance
  • contact details
  • a reference to detailed data protection information

Many companies additionally use QR codes or short URLs through which data subjects can retrieve the full privacy notice.

Retention periods and technical requirements

Article 5 para. 1 lit. e GDPR sets out the principle of storage limitation. Personal data may only be stored for as long as is necessary for the respective purpose. In practice, retention periods of 48 to 72 hours are frequently used as a guideline. However, no fixed statutory period exists.

Longer retention periods must be justified in a comprehensible way, for example by weekend arrangements, public holidays or particular security risks. What matters is a documented deletion routine with automatic overwriting or fixed deletion concepts.

Where may cameras be installed?

Not every area may be monitored. Video surveillance is regularly inadmissible in sanitary facilities, changing rooms, break rooms or sleeping and rest areas. Here the personality rights of those affected almost always prevail.

In entrance areas, car parks or retail spaces, video surveillance is generally possible provided it is necessary and carried out transparently. Cameras may only capture the area that is actually required.

Special considerations for body cams

Body cams are increasingly being deployed in a variety of settings. Deutsche Bahn uses body cams for train crew and security staff in order to protect employees in conflict-prone situations. As a rule, the cameras are only activated on a case-by-case basis.

Body cams are also being trialled in healthcare: Klinikum Dortmund, for example, is testing their use in emergency departments to protect staff against assaults. Use is voluntary and the cameras are only activated in specific conflict situations – not during treatment or confidential conversations.

In legal terms, deployment by private security services and in many civilian areas is governed by the requirements of the GDPR and the BDSG. Art. 6 para. 1 lit. f GDPR (legitimate interest) is frequently considered as the legal basis, but it is subject to strict requirements regarding proportionality, purpose limitation and transparency.

Practical tips for GDPR-compliant implementation

For legally sound video surveillance, operators should observe the following steps:

  • Document the balancing of interests: is the surveillance really necessary? Are there less intrusive means?
  • Two-tier information model: a compact warning sign on site and detailed data protection information via QR code
  • Automatic deletion routines: implement fixed deletion concepts
  • Use privacy functions: deploy privacy masking or redaction features
  • Keep documentation: maintain a record of processing activities

Outlook: growing compliance requirements

Regulatory pressure on operators of video surveillance is rising continuously. Data protection authorities are paying increasing attention to whether processes have been documented in a comprehensible manner. In certain cases a data protection impact assessment (DPIA) becomes necessary, in particular for large-scale surveillance of publicly accessible areas or intelligent video analytics.

Companies should therefore seek legal advice at an early stage and review their video surveillance concepts regularly for GDPR compliance. Careful planning prevents expensive retrofitting and fines.