The essentials

  • Workplace video surveillance is lawful where it pursues a legitimate, defined and proportionate purpose. It cannot place employees under constant monitoring.
  • Off-limits areas: no camera trained continuously on a workstation, and none in break areas, toilets or staff representative rooms.
  • Core obligations: a legal basis, information of the people filmed, a processing record, security, access control, limited retention, and a data protection impact assessment where the risk is high.
  • AI changes the regime. A camera that analyses behaviour is not treated like a camera that records. The AI Act prohibits emotion recognition in the workplace and regulates biometrics.
  • Penalties: data protection authorities issue fines on video systems regularly. The AI Act provides for up to €35 million or 7 % of worldwide turnover for prohibited practices.

Video has become an operational tool: detecting an event, retrieving a scene in seconds, analysing flows, feeding dashboards. But a workplace camera now sits at the intersection of data protection law, employment law, national security legislation, cybersecurity rules and AI regulation. Those rules do not block innovation — they frame it.

A rising compliance pressure

European data protection authorities have stepped up enforcement, and video systems are explicitly among their inspection topics, with cybersecurity becoming a major axis alongside.

For an estate of cameras, the centre of gravity has moved. It is no longer enough to install a system that works: you must be able to demonstrate that it is governed, secured, traceable and legally framed.

The legal framework

The GDPR foundation

All video surveillance processes personal data. It must be lawful, fair and transparent, pursue a specified purpose, and observe data minimisation, limited retention, integrity and confidentiality. The legal basis is most often legitimate interest, properly documented. The controller must inform the people concerned, maintain a processing record, secure the system, and carry out a data protection impact assessment (DPIA) where the risk is high.

Employment law: proportionality

National labour law generally prohibits restrictions on individual freedoms that are not justified by the task and proportionate to the aim pursued. In France, for instance, that principle is set out in Article L1121-1 of the Labour Code.

In practice: filming a security environment does not authorise filming human activity continuously. You film the till, not the cashier; you frame the high-value area, not the whole warehouse team. Cameras may cover entrances, exits, circulation routes and storage areas — but not workstations, save in exceptional and justified circumstances, and never break areas, toilets or staff representative rooms.

Important — national rules

Authorisation regimes and retention limits are national, not European. In several countries, filming a place open to the public requires prior authorisation from a public authority; in France, that means a prefectural authorisation, and retention is capped at one month in principle. Check the rules applicable where the site is located — this is the part of the framework that does not travel.

Information, access, retention, security

  • Information — visible, permanent signage, supplemented by a detailed notice covering the items required by Article 13 of the GDPR.
  • Access — only authorised people view footage, within their duties, over secured access.
  • Retention — limited to what the purpose requires, within the national cap; a few days is often enough. Where proceedings are under way, the relevant footage is extracted and kept for their duration.
  • Security — encryption, named accounts, strong authentication (MFA for remote access), logging of viewing and exports, and control over subcontractors.

AI and augmented video: what changes

A camera that merely records is not treated like a camera coupled with behavioural analysis algorithms. This is the single biggest shift of the current framework.

🔴 The AI Act prohibits outright: emotion recognition in the workplace; certain biometric categorisations inferring protected attributes; and the untargeted scraping of images to build facial recognition databases. Uses related to employment and to biometrics are classified among high-risk uses.

Penalties for prohibited practices reach €35 million or 7 % of worldwide annual turnover, whichever is higher.

As soon as a system infers or classifies human behaviour for management or monitoring purposes, the project has to be requalified: revisit the legal basis, redo the proportionality analysis and, usually, carry out a reinforced impact assessment.

Worth remembering: the question to ask a supplier is not “does your camera use AI?” — nearly all of them now do. It is “what does the algorithm infer, about whom, and for what decision?” That answer determines the regime that applies.

NIS2: the cybersecurity of your connected cameras

The NIS2 directive establishes a common cybersecurity framework across 18 critical sectors. For the organisations concerned — and for their suppliers — IP cameras, video management systems, control rooms and cloud gateways fall squarely within the assets to be secured: hardening, network segmentation, logging, vulnerability management, continuity planning, and a documented chain of responsibility with service providers.

Sovereignty, cloud and hosting

Sovereignty does not, in law, require hosting within a single country in every case. The GDPR does, however, strictly regulate transfers outside the European Union, which require an adequacy decision or appropriate safeguards. For a video project, favouring EU hosting and documenting where the data actually sits remains sound risk reduction.

What regulators actually sanction

Video surveillance cases are almost always sanctioned for a combination of failures: excessive collection, missing information, retention beyond what was necessary, no processing record, weak security, sometimes no impact assessment or no framework for subcontracting.

The risk is rarely one camera too many. It is incomplete governance around the cameras you have.

Getting compliant without blocking the project

The safest approach is to treat video compliance as a governance project rather than a hardware purchase. That means documenting the purpose before choosing the equipment, assigning roles explicitly, and being able to produce the paperwork on the day someone asks for it.

Signage template — what must appear

Visible and permanent, at every entrance to a monitored area:

  • The fact that the area is under video surveillance
  • The purpose of the system
  • The identity and contact details of the controller
  • The contact details of the data protection officer, where one is appointed
  • The retention period applied
  • The rights of the people filmed, and how to exercise them
  • The right to lodge a complaint with the competent supervisory authority

Items derived from Article 13 of the GDPR. Have the final wording reviewed against the national requirements applicable to your site.

Frequently asked questions

Can employees be filmed at work?

Yes, but not under constant monitoring. Cameras may cover entrances, exits, circulation routes and high-value areas. A workstation may only be filmed exceptionally, where it is justified and proportionate to the aim pursued.

Are there areas where cameras are prohibited?

Yes. Break and rest areas, toilets and staff representative rooms — together with their dedicated access points — are excluded.

How long can workplace footage be kept?

Only as long as the purpose requires, within the cap set by national law — one month in France, for example, though a few days is often sufficient. Where proceedings are under way, the relevant footage is extracted and kept for their duration.

Does the AI Act apply to video surveillance?

Yes, as soon as the system analyses or classifies human behaviour. The AI Act prohibits emotion recognition in the workplace, certain biometric categorisations inferring protected attributes, and untargeted image scraping to build facial recognition databases. Employment-related and biometric uses are classified as high-risk.

What penalties apply under the AI Act?

For prohibited practices, up to €35 million or 7 % of worldwide annual turnover, whichever is higher. Data protection authorities separately issue fines on video systems under the GDPR.

Do IP cameras fall within the scope of NIS2?

For organisations covered by the directive, and for their suppliers, yes: IP cameras, video management systems, control rooms and cloud gateways are part of the assets to be secured, with hardening, network segmentation, logging, vulnerability management and continuity planning.

Do I need prior authorisation to install cameras?

That depends on the country and on whether the area is open to the public. Authorisation regimes are national, not European: in France, filming a place open to the public requires prefectural authorisation. Always check the rules applicable where the site is located.

When is a data protection impact assessment required?

Whenever the processing is likely to result in a high risk, in particular where it involves systematic monitoring on a large scale of an area accessible to the public.

Planning a compliant video project?

Our teams support you from the legal framing through to technical deployment.

Contact us

Primary sources: GDPR, Regulation (EU) 2016/679 (eur-lex.europa.eu) · EU Artificial Intelligence Act (digital-strategy.ec.europa.eu) · NIS2 Directive (eur-lex.europa.eu). National requirements should be checked with the competent authority in the country concerned.

Read next: Public areas or restricted areas: what changes for your CCTV · Why sovereign video protection matters in industry