Monitoring at Self-Service Checkouts and GDPR – Boundaries of Legality

21 August 2025

Did you know that when you shop in a store and use a self-checkout, you are increasingly… being watched? Cameras above the self-checkout stations are not only a means of detecting fraud attempts but also a tool for analyzing your behavior and optimizing the operation of the checkouts. Is this compliant with the GDPR? How long are the recordings stored, and can you object to this? In this article, we examine how "smart" cameras work, what data they collect, and how stores should process this data in accordance with the regulations.

Why are there cameras at self-checkout counters?

Cameras installed at self-checkout counters primarily serve to enhance the security of transactions. Their main task is to detect errors during product scanning – both unintentional mistakes and those resulting from deliberate attempts at fraud. Stores, aiming to protect their property and minimize losses, increasingly turn to solutions based on monitoring and image analysis.

The second significant reason for using cameras is the desire to optimize the shopping process. Analyzing recordings allows for the identification of moments when customers encounter difficulties – whether with the checkout process or with scanning products themselves. Based on this, stores can implement improvements both in the checkout interface and in the organization of the surrounding space.

How do the cameras work?

Cameras installed above self-checkout counters work in conjunction with advanced real-time image analysis software. They are typically positioned above the checkout station in such a way as to cover both the customer and the entire operational area – including the scanner, scale, shopping basket, and the area for placing scanned products.

The system utilizing artificial intelligence analyzes the image from the camera and is capable of detecting various types of events – it recognizes products, tracks the movement of the customer's hands, and determines their position relative to the checkout. This enables, among other things, verification of whether each product has been correctly scanned and placed in the appropriate location.

In the event of detecting irregularities, the system can generate an alert. This provides the customer with an opportunity to correct the mistake or signals the need for employee intervention. Importantly, these devices do not make any decisions automatically – they serve only as a tool to support the transaction verification process.

What does the GDPR say about this?

Monitoring at self-checkout counters involves the processing of personal data and thus falls under the provisions of the GDPR. Although in theory, the cameras might not record the customer's face, in practice, it is difficult to speak of anonymity – especially since most stores already operate standard monitoring that encompasses the entire environment, including the silhouettes and behavior of customers.

Like any data processing, recording at self-checkout counters must comply with the fundamental principles of the GDPR. This particularly concerns the principles of purpose limitation, data minimization, storage limitation, as well as ensuring integrity and confidentiality.

Purpose limitation means that before initiating monitoring, the purpose for which the recordings will be used must be clearly defined. In addition to the primary function of preventing possible fraud – which requires prior notification to customers – the purpose may include, for example, securing evidence for potential reporting of an offense or crime to the police.

Data minimization, on the other hand, requires limiting the scope of recorded information – not only in terms of quantity but also the quality of the image. Excessively high camera resolution may lead to the unintended disclosure of excessive data, such as the contents of a handbag or the payment card details of a customer.

DPO Function - it translates well

Data retention limitation principle means that recordings from cameras should only be stored for the period necessary to achieve the specified purpose. If no incident occurred while using the self-service checkout, such as an attempted fraud or violation of store regulations, the video recording should be deleted as soon as possible. Minimizing this period reduces the risk of unauthorized access, breach of confidentiality, or data leakage.

The justification for such an approach is confirmed by cases of abuse. There have been instances where store employees used monitoring recordings for personal purposes, such as posting images of customers on social media. This constitutes a serious violation of the right to privacy.

For this reason, the confidentiality principle takes on particular significance. Access to materials from cameras should be restricted solely to authorized individuals – preferably representatives of management or the security department. Additionally, it is recommended to implement access controls to the recordings, for example, by requiring login to the system, which allows the data controller to continuously monitor who accessed the recorded data and when.

Automated decisions? Only with human involvement

In the context of self-service checkouts, it is also worth noting the provisions of Article 22 of the GDPR concerning automated decision-making. A person whose data is being processed should not be subject to a decision based solely on automated processing – including profiling – if it may have legal effects on them or similarly significantly affect their situation. This means that the monitoring system cannot, among other things, independently make decisions to restrict a customer's rights.

For example, it would be unacceptable to automatically block a customer's access to self-service checkouts if they have previously been identified (e.g., through a loyalty card) and the system detected "irregularities." Such decisions must always be subject to human verification.

Managing Compliance with AI

Should the customer have a choice?

In data protection doctrine, there are voices advocating that customers should have the option to use self-service checkouts without being monitored. This position is supported by the French supervisory authority – CNIL, which advocates for the possibility of users independently disabling the camera during the scanning of products. In practice, the alternative to a monitored self-service checkout is usually a traditional checkout operated by a staff member – however, according to CNIL, this option may not necessarily be sufficient.

Although this approach stems from a concern for privacy protection, it seems somewhat too stringent – especially since monitoring typically covers the entire store, regardless of the method of purchase. The difference, therefore, lies more in the "degree of visibility" of the customer rather than the mere presence of cameras.

CNIL also points out another significant right of the customer – the right to object to the use of their data for the purpose of improving technological systems. In practice, this means that a person using a self-service checkout should be able to decide whether their data can be processed for the further development of algorithms. It is recommended that an appropriate checkbox appears on the checkout screen, e.g., with the message: "I object to the use of my data for the purpose of improving and training the algorithm."

Information obligation – when and how to fulfill it?

According to the GDPR, the customer should be informed about the processing of their personal data, before they start using the self-service checkout. This information should be made available in a clear and understandable manner, preferably at the entrance to the store, e.g., in the form of a poster or information board. However, this is not enough.

The cash register itself should also be appropriately marked, for example, using a pictogram or text message. The most transparent solution would be to implement an information window on the cash register screen, which would appear before the scanning of purchases begins. This allows the data controller to demonstrate that the information obligation has been effectively fulfilled for each customer, which is crucial from the perspective of the so-called accountability principle.

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to perform the role of Data Protection Officer. We invite you!
CHOOSE A DATE
A good complement to such actions may also be the placement of a QR code. This enables quick access to the full content of the privacy notice – regardless of whether it is displayed on the screen or, for example, affixed in a visible location near the cash register.

The content of the information provided is regulated by Article 13 of the GDPR. Therefore, a person monitored at the self-service cash register should be informed, among other things, about:

  • the identity of the data controller (the store) and its contact details, and if appointed – also the details of the Data Protection Officer,
  • the purposes of data processing and the legal basis (protection of the store against abuse, analysis of cash register operation for improvement purposes, legal basis: Article 6(1)(f) GDPR, i.e., the legitimate interest of the store),
  • the recipients of personal data or categories of recipients, if they exist (e.g., IT company, security agency), as well as the transfer of data outside the EU (e.g., when the IT company, as a data recipient, is based outside the EU),
  • the period for which personal data will be stored, and when this is not possible – the criteria for determining that period (the easiest would be to align this period with the retention period of other monitoring data and establish it, for example, at a maximum of 1 month),
  • the right to request from the data controller or store access to personal data (i.e., footage from the camera at the checkout), their rectification (which is practically impossible – it is not possible to rectify monitoring footage), deletion, or restriction of processing (limited to mere storage) or the right to object to processing (e.g., in cases where the customer does not want the footage from cameras installed at self-service checkouts to be used for the purpose of improving checkout operations),
  • the right to lodge a complaint with the President of the Polish Data Protection Authority,
  • automated decision-making, including profiling – if such actions are taken based on data obtained from monitoring self-service checkouts.

Summary

Cameras installed at self-service checkouts – similar to monitoring in other parts of the store – primarily serve a protective function. They aim to secure the property and interests of the store, as well as to assist in detecting irregularities and streamlining the purchasing process.

Although monitoring at self-service checkouts involves an intrusion into customers' privacy, it is difficult to challenge the existence of a real and justified interest on the part of the data controller. However, it remains crucial that the implementation of such monitoring is carried out in compliance with the principles of the GDPR – particularly transparency, data minimization, purpose limitation, and ensuring an appropriate level of data protection.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.