GDPR and data protection
CCTV systems and GDPR - a practical overview.
Recording people on camera is always processing of personal data. Here is what to ask before installation, based on the methodology of the Czech Office for Personal Data Protection (ÚOOÚ). This is not legal advice - we always discuss the specific solution with your lawyer or data protection officer, if you have one.
Legal basis
Consent usually doesn't work. Legitimate interest does.
For cameras at a business, apartment building or venue, genuine consent to being monitored is practically impossible to obtain - an employee or visitor has no real option to refuse. Under the ÚOOÚ methodology, the usual legal basis is therefore the controller's legitimate interest (protecting property, people, operational safety), supported by a balancing test - assessing whether the operator's interest outweighs the rights of the people being monitored.
What matters is whether the camera captures people in a way that usually allows identification - broadly, where a person takes up a significant part of the frame. That is why we treat the balancing test and camera scope as part of the design, not an afterthought.
Information signs
What they must include.
A visible sign is required at every entry point to a monitored area - before a person enters the camera's field of view.
- 01
A camera pictogram
A clear symbol showing the area is monitored - understandable even without reading the text.
- 02
The controller's identity
Who operates the CCTV system - a specific company or owners' association, not just "the property operator".
- 03
Purpose and legal basis - briefly
A short summary ("protection of property and people"); the full text can be on a website or available from the controller on request.
- 04
Contact details and a link to full information
Where to go for more information or to exercise your rights - email, phone, or a QR code linking to the full text.
- 05
Information about data subjects' rights
At least a reference stating that a monitored person has the right to access information and other rights under GDPR.
Recording retention period
No universal number - just a justifiable range.
The ÚOOÚ does not set one binding deadline for every business - the retention period must be proportionate and justifiable by its purpose: operating hours, how quickly staff can review footage, the typical length of a complaints period in your line of business. In practice this tends to be days to a few weeks; longer retention (typically beyond 30 days) needs a specific justification, not "just in case". We set the actual period for your operation as part of the design.
Specifics
Owners' associations and employees have their own rules.
Apartment buildings and owners' associations
The decision to install cameras in shared areas, and their scope, belongs to the owners' assembly, not just the board - it is a property decision for the whole association. Cameras belong in shared areas (entrance, garage, cellar), never in individual flats.
Employees
Monitoring employees at work is governed by Section 316 of the Czech Labour Code - it must be justified, proportionate, and staff must be informed in advance. Cameras cover processes and spaces (till, storage, entrance), not a specific workstation without a reason.
Rights and registration
What has changed over the past few years.
The duty to notify the ÚOOÚ about operating a CCTV system ended when GDPR took effect (25 May 2018) - cameras are no longer registered with the authority. The usual controller duties still apply: informing monitored people, enabling them to exercise their rights (access to information, and objection where the basis is legitimate interest), and securing the recording against misuse.
We practically never add audio recording to cameras - intercepting conversations is a significantly greater intrusion into privacy and rarely justifiable.
Frequently asked questions
Before you contact us.
- Do we need a DPIA (data protection impact assessment) for a CCTV system?
- For a standard installation at a small business or owners' association, usually not. For extensive monitoring, biometrics or a higher intrusion class, yes - we assess this specifically based on the scope of your project.
- Do we need an appointed data protection officer?
- It depends on the type and size of your organisation, not on whether you have cameras - that is a separate GDPR duty. If you do have one, we recommend discussing the camera scope with them before installation.
- Who is responsible for GDPR compliance - you, or us as the customer?
- The controller (you) is responsible for the processing of personal data. As the supplier, we design the technical solution to enable compliance - signage, retention, controlled access - but legal responsibility stays with the controller.
Konzultace zdarma
Working through a GDPR assessment for your CCTV system?
We cover camera scope, retention and signage as part of the design - not as an afterthought once it's installed.