GDPR-compliant video surveillance for businesses

This article covers the technical and organisational side of video surveillance at a business and is not legal advice. Whether and to what extent a specific camera setup is permitted depends on the individual case – when in doubt, have it reviewed by a law firm specialising in data protection or by your data protection officer before you install any cameras.
Video surveillance at a business always needs a clearly stated legal basis, a limited retention period, visible signage for the monitored areas, and an access concept that defines who is allowed to view the footage and when. Installing cameras "just to be safe" everywhere and sorting out the legal details later almost always results in a setup that has to be corrected afterwards – usually at more effort than getting it right from the start would have cost.
What legal basis does video surveillance at a business need?
Video surveillance is processing of personal data, and under the GDPR it needs a legal basis. In business practice this is usually a legitimate interest – protection against theft, break-ins or property damage, for example – which has to be weighed against the interests of the people being filmed. That balancing test isn't a formality: a camera that also captures half the pavement or a neighbouring property, or continuous monitoring of workstations with no specific reason, will generally not survive that test. That's why it matters to justify each individual camera – why it needs to be at that spot, with that field of view – rather than just justifying the setup as a whole.
- Record a specific purpose for each camera (e.g. access control at the warehouse entrance, not "general security")
- Choose fields of view that avoid public space, neighbouring properties and break rooms wherever possible
- Avoid continuous monitoring of workstations unless there's a specific, documented reason for it
- Document the balancing-of-interests assessment in writing, not just in your head
How long is footage allowed to be kept?
The principle of data minimisation requires that footage only be kept as long as it's actually needed for its stated purpose. In practice that usually means short retention periods, often just a few days, after which footage is automatically overwritten – unless a specific incident, such as a break-in, requires certain sequences to be kept longer as evidence. Blanket long-term storage "just in case" is difficult to justify under data protection law. What's appropriate in any individual case depends on the purpose of that particular camera and should be determined with legal advice on a case-by-case basis.
- Automatic deletion after a fixed, short period as the default setting
- Extended retention only for specific sequences actually relevant to a genuine incident
- Implement retention limits technically (automatic overwriting), not just as a rule on paper
How does video surveillance need to be signposted?
Anyone entering a monitored area needs to be able to tell they're being filmed before they enter it – not afterwards. That means a clearly visible sign at the entrances to the monitored area showing the key information at a glance: that filming is taking place, who's responsible, and where to find further information about the processing, for example via a QR code linking to a detailed privacy notice. A single, poorly visible sign at reception isn't enough if several entrances or areas are monitored.
- A sign at every entrance to a monitored area, not just the main entrance
- A brief notice on the sign plus a reference (e.g. QR code) to a detailed privacy notice
- Signs placed clearly visibly and legibly, not hidden or papered over
Who's allowed to access the footage?
A common weak point in practice isn't the camera itself but access to the footage afterwards. If the entire staff, or an app on the owner's personal phone, has access to the live stream and the archive, the setup is difficult to justify from a data protection standpoint, even if the cameras themselves are correctly positioned. Access should be limited to the people who genuinely need it for their role, with a log that shows who viewed which footage and when.
- Access to the live view and archive limited to named individuals who need it for their role
- Every access to stored footage is logged
- Exporting or sharing footage (e.g. with authorities) follows a defined, documented process
What belongs in a privacy notice for video surveillance?
Beyond the on-site sign, the GDPR requires a more detailed notice under Article 13 – covering things like who's responsible, the specific legal basis, the retention period, who footage might be shared with in a given case, and what rights the people being filmed have, such as the right to access their data. This information doesn't need to be printed on the sign itself, but it should be reachable through a simple route, for example on the company website or via the QR code mentioned earlier. It matters that this notice actually reflects the specific system in place, rather than being a generic block of text with no connection to the cameras actually installed.
Do you also need a data protection impact assessment?
For systematic, large-scale monitoring of publicly accessible areas, a data protection impact assessment can be required – a structured risk assessment carried out before the system goes live. Whether that applies in a given case depends on factors like the number of cameras, the extent of the monitoring and the type of areas covered, and can't be answered in general terms. Where a business has staff representation, Austria and Slovakia often also require the works council, or the relevant employee representative body, to have a say before cameras are installed. That, too, should be clarified before installation, not afterwards.
What does a properly run system look like on the technical side?
Beyond legal basis, retention period, signage and access rights, the technical setup matters too. Cameras and the recorder belong on their own network segment, separate from the rest of the company network – a compromised camera shouldn't open a path to workstations or servers. Default settings such as factory passwords need to be changed before the system goes live, and firmware should be updated regularly, just like any other network equipment. A record of the video surveillance processing activity in the register of processing activities also belongs in complete documentation. Anyone taking over an existing system – after a refit or a change of IT provider, for example – should go through all these points again from scratch, rather than assuming they were done correctly at the original installation.
Planning video surveillance for your premises, or want to bring an existing system up to a clean technical standard? We handle the technical side – cameras, network separation, storage and access concept.
Get in touchYou'd rather not work this out yourself? The solution page explains how we plan, build and then run it.
See video surveillanceQuestions about your IT infrastructure?
Talk directly to our team — no obligation, no detours.

