Security of Teleconferences in Light of GDPR: How to Protect Personal Data During Virtual Meetings

23 August 2023

The pandemic has elevated the protection of personal data to a new level of reality. The transition to broadly understood remote work necessitated the use of video conferencing systems and platforms such as Zoom, Microsoft Teams, and Google Meet. Over the course of the following months, this type of communication became one of the main channels of business collaboration for many organizations, both public and private. It enabled, for example, the organization of business meetings and video conferences, which are often recorded and shared online. However, the increased usability of video conferencing tools and systems is also associated with a greater threat to the privacy and security of personal data.

Each of us remembers the beginnings of remote work – situations when connections could not be established, meetings were interrupted due to loss of video or audio, or even when unexpected background characters appeared (such as incompletely dressed roommates or mischievous children). Initially, the primary need was to ensure business continuity. Only later was greater attention paid to the protection of content and the security of personal data processed during video conferences. Unfortunately, despite the passage of three years since the outbreak of the pandemic, legal solutions are still hard to find. Neither the GDPR nor other regulations from European authorities have addressed the issue of personal data processing during video conferences. Although on January 29, 2020, the European Data Protection Board (EDPB) issued guidelines 3/2019 on the processing of personal data through video devices, these primarily concern monitoring, including visual monitoring. Nevertheless, this may serve as a reference point, for example, when determining the legal bases for data processing or the periods for their retention.

Security of Personal Data of Users During Video Conferences

Information shared by participants in video conferences and those conducting them, such as name, surname, image, voice, email, IP address, or cookies, constitutes personal data within the meaning of Article 4(1) of the GDPR and is subject to protection. Organizing video conferences, broadcasting them live, or recording them for later publication on the internet is nothing more than processing this data.

The Polish Data Protection Authority issued guidance in 2020 titled “How to Use Video Conferences Safely.” It provides valuable tips that can help resolve issues and minimize threats related to the security of personal data. Initially, it was indicated that before starting any video conference, the user should pay attention to several key aspects, primarily to familiarize themselves with the privacy policy and/or the terms of use of the video conferencing services. It is important to remember that the video conferencing service provider will process users' personal data. Therefore, knowledge of what information is collected and how it is processed is extremely important.

As can be inferred from the arguments presented by the Polish DPA, if an organization uses a video conferencing system, it should enter into a data processing agreement to ensure an adequate level of data protection (some service providers include data processing clauses in their terms of service, but it is advisable to verify this carefully). At the same time, it is important to understand the extent to which the service provider will act as a separate data controller and to what extent as a data processor. In the context of recording conversations, it is essential to define the purposes for which the data will be used and to obtain the appropriate consents from users. Transparency in this regard is crucial to avoid violations of data protection principles. It is also important to pay attention to whether the data required from video conferencing users is not collected excessively, for example, whether the user is not asked to share their location or contact list.

The Polish Data Protection Authority recommends using the official websites of video conferencing applications. Additionally, the user should check whether the application provides necessary security measures, such as encryption, and whether it is web-based (rather than desktop-based).

The Wi-Fi used for the video conferencing connection should be secured with a strong password. The security of users' personal data is a priority, so it is advisable to choose tools from a trusted provider that will ensure adequate data protection. Adhering to the principle of "trust but verify," it is also a good idea to scan the video conferencing software with antivirus or anti-malware programs. The user should check whether third parties have access to the screen and pay attention to whether the connection to the video conference was made using access codes or PINs.

DPO Function - it is well communicated

During the video conference, one must not forget to adequately secure the system. It is recommended to limit the provision of personal data to a minimum (preferably using a pseudonym and a work email address). The password for the video conference should be different from the passwords used for everyday services (it cannot be, for example, the password for banking or for logging into a personal email account). It is also advisable to enable default password protection and manage screen sharing settings. Links to video conferences should not be shared on various platforms, especially on social media.

In business video conferences, it is recommended to use an encrypted VPN connection to enhance the security of transmitted data. Business documents shared with other participants in the video conference are safest when sent via encrypted email rather than shared in the chat. During the video conference, it is advisable to use the background blur option to avoid the possibility of disclosing confidential information to third parties, as well as the "waiting room" option, which allows for controlling meeting participants. When logging into the video conference, it is important to remember to turn off the camera and microphone (they should only be turned on when necessary). After the video conference has ended, the user should turn off the microphone and camera, then ensure that they have ended the online meeting and closed the application. Checking that the video conferencing software is not running in the background is also crucial for data protection.

Adhering to the above guidelines can significantly enhance the security of video conferencing. Taking care of personal data protection during such meetings is essential for maintaining confidentiality and building trust both within the organization and in relationships with clients or contractors. However, the question arises whether such universal instructions, created without regulated legal frameworks, will be sufficient in the era of rapidly evolving communication technologies.

Are video conferencing systems compliant with GDPR

The security of personal data of video conference participants has become a pressing issue, particularly for large corporations managing messaging and video conferencing systems. Although they have privacy policies and terms of service, these documents are often formulated too generally, which may raise users' concerns regarding the security of their data.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
In connection with this, organizations responsible for selecting a video conferencing provider should pay particular attention to the security of personal data. An analysis of current systems conducted by German supervisory authorities has shown that the offerings of many international video conferencing providers do not meet the data protection requirements from both a technical and legal standpoint. This is particularly concerning for public authorities, which have specific obligations regarding the protection of personal data. In this situation, valuable assistance is provided by the Saxon Data Protection Officer, to whom German public organizations can turn with questions regarding the compliance of video conferencing systems with GDPR regulations. These organizations aim to adapt the temporary solutions that emerged during the pandemic in such a way as to ensure an adequate level of personal data protection. The selection of an inappropriate solution may indeed lead to serious difficulties and threats to user privacy.

A fundamental issue is the thorough analysis of the contract with the provider, especially when utilizing cloud services offered by international corporations. This task can be challenging, as it requires an understanding of complex legal relationships, identification of subcontractors, and determination of the conditions regarding the assignment of rights and obligations. Before signing a contract or accepting the terms of use for the video conferencing service, it is important to ensure that the system owner is capable of fulfilling the information obligation and respecting the rights of the individuals whose data is being processed. Attention should be paid to employee data. Organizations – as data controllers managing this data – have an obligation to ensure its security. It is also essential that, at the stage of implementing video conferencing systems (privacy by design), they utilize the knowledge and experience of their Data Protection Officers.

Purposes of data processing in video conferencing systems

There are many purposes for processing participants' data in video conferencing systems, such as live broadcasting, further publication on the internet, screen sharing, and active participation by guests through commenting or asking questions. It is extremely important that the data of video conferencing participants is not used in a manner inconsistent with the original purposes of processing. For example, this data cannot be used for marketing purposes or to further the interests of video conferencing system providers, such as improving service quality.

The principle of data minimization plays a key role both during data collection and subsequent processing. This means that only data necessary to achieve specific objectives should be collected and processed, while avoiding the collection of excessive information. Based on several years of experience in actively participating in video conferences, one can identify "typical" data that is processed, such as email address, first name (or user nickname), image, voice, and IP address. Therefore, sharing a participant's location or even processing their image or voice when they are not actually participating in the discussion during the video conference should be subjected to thorough analysis or even deemed excessive.

It is worth emphasizing that to ensure an appropriate level of security for video conferences, organizers and service providers should not only adhere to the principle of data minimization but also adopt a thoughtful approach to processing participants' data. Proper management of personal data in video conferences is a decisive element in building user trust and meeting the requirements of data protection regulations, particularly the GDPR.

Legal basis for data processing in video conferencing systems

The processing of personal data (including images) during video conferences should be deemed compliant with data protection regulations if at least one of the conditions listed in Article 6(1) of the GDPR is met. These grounds are generally equal in standing. Therefore, to demonstrate the legality of personal data processing, the consent of the data subject is not always required; one can invoke another ground listed in Article 6(1) of the GDPR. The most commonly used legal bases for data processing during video conferences include:

  • performance of a contract (Article 6(1)(b) of the GDPR) – if the processing of data is necessary for the performance of a contract to which the user is a party, or to take steps at the request of the data subject prior to entering into a contract,
  • consent (Article 6(1)(a) of the GDPR) – if the participants of the video conference have given their explicit and voluntary consent to the processing of their personal data, including for the purpose of recording sessions or for another purpose related to the video conference,

GDPR. Support is useful!

  • legitimate interest of the data controller (Art. 6(1)(f) GDPR) – in some cases, the processing of personal data during video conferences may be necessary for the purposes arising from the legitimate interest of the data controller or a third party, provided that it does not infringe upon the fundamental rights and freedoms of the participants (this interest must be balanced against the rights and interests of the participants),
  • compliance with a legal obligation (Art. 6(1)(c) GDPR) – sometimes, the processing of data may be required to fulfill a legal obligation imposed on the data controller.

Relying on the basis from Art. 6(1)(b) GDPR can be considered, for example, in the case of processing employee data. This particularly applies to those individuals who conduct training, conferences, or other public appearances in their daily work, as well as employees who participate in business meetings remotely. However, when the processing of images in conjunction with ordinary data occurs for purposes other than those covered by the employment relationship, it may be appropriate to consider the application of the consent basis from Art. 6(1)(a) GDPR. Although the EDPB, in its guidelines 05/2020 on consent, takes a skeptical view of this basis due to the subordination of the employment relationship and the risk of lack of voluntariness of consent, this does not mean that employers can never rely on consent as a lawful basis for processing. As an example, the EDPB points out a situation where, during the filming of parts of the office, employees who do not wish to be recorded can work in other rooms at that time. Conversely, the legitimate interest of the video conferencing solution provider is particularly limited when the provider processes data regarding the use of video conferencing systems to achieve its own benefits, such as improving the quality of services provided. This is especially relevant in the case of Software as a Service (SaaS) models or software delivery by the provider.

It should be emphasized that the data controller bears the responsibility for assessing the legal basis for data processing each time. Therefore, as the organizer of the video conference, they should have a clearly defined legal basis for data processing, inform participants about it at the beginning of the meeting, and ensure that data processing is carried out in accordance with the principles outlined in Article 5 of the GDPR. This particularly concerns limiting access to personal data, securely storing it, as well as not retaining it for longer than necessary. It is therefore valuable for the data controller to establish procedures that specify the timeframe and method for deleting information containing personal data, as well as the principles for reviewing processed data.

Transfer of data to third countries with a lower level of data protection

The topic of possible transfer of personal data from video conferences outside the EU and EEA, particularly to the USA, where key business players such as Microsoft (which operates the Teams application) are headquartered, returns like a boomerang. In most cases, cloud services offered by American providers rely on standard contractual clauses aimed at securing data (with the exception of companies listed based on the recent decision of the European Commission regarding the Data Privacy Framework). However, it is worth noting that even if most data processing operations take place in Europe, access from parent companies located in third countries cannot be completely ruled out.

GDPR Tools
Working with good GDPR tools is not work!
Applications, calculators, GDPR snapshots - everything that can help you manage your personal data protection system.
SEE MORE
Regarding the public sector, there are doubts about the necessity of such data processing that may be subject to transfer to third countries. In the case of video conferences, which are also used in the public domain, it is essential to ensure additional safeguards to guarantee a level of data protection compliant with European requirements before transferring them to a third country.

German supervisory authorities emphasize that the currently implemented safeguards, such as encryption during transmission or on data carriers, are insufficient for video conferencing systems. As a result, the use of cloud services offered by international providers is often non-compliant with applicable law. Therefore, data controllers utilizing video conferencing should thoroughly verify whether the solutions offered provide adequate safeguards for personal data, especially in the case of transfers outside the EU and EEA. Representatives of German data authorities advise against using offerings from global corporations and recommend opting for European solutions that are based on appropriately secured agreements or organizing video conferencing systems independently. However, such solutions may be problematic and costly for data controllers.

Summary

The growing popularity of widely available video conferencing platforms may pose a significant threat to the security of participants' personal data. Proper data management and adherence to the principle of data minimization are crucial actions for privacy protection. Organizations should carefully review contracts with providers to ensure compliance with GDPR and appropriate data safeguards. It is important to familiarize oneself with the provider's privacy policy before the video conference and obtain users' consent for the processing of personal data. Managing participants' data, paying attention to connection security, and using official application websites are essential steps in maintaining data security.

A major challenge is the transfer of personal data to third countries with a lower level of data protection. Organizations should choose European solutions or thoroughly analyze the safeguards offered by global corporations. Ensuring the security of personal data during video conferences helps minimize the risk of privacy breaches for participants and builds trust in business relationships. At the same time, it is important to pay attention to the development of legal frameworks to adapt to rapidly evolving technology.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.