Video surveillance and GDPR – we provide a template for the privacy notice

11 March 2026

For the data controller – who is on the other side – the important question is how to use monitoring in compliance with the law. The European Data Protection Board (EDPB) has issued Guidelines 3/2019 on the processing of personal data through video devices, i.e., in the context of video surveillance, to organize knowledge on this matter.

The document clearly and transparently outlines numerous recommendations regarding the purpose and manner of capturing images of individuals in public spaces. However, is it truly worthwhile to uncritically rely on the guidance proposed by the EDPB? Below, we present an analysis of the guidelines and the most interesting elements thereof. 

When is monitoring not subject to GDPR?

Not every act of recording images via a camera will be subject to the regime of personal data protection regulations. The key criterion determining this circumstance is the so-called household use criterion. Although the guidelines do not explicitly define what exactly should be understood by this term, they do provide examples indicating when an exemption from GDPR will apply.

 

Sample Privacy Notice

We provide a sample privacy notice that meets the requirements set forth by both the regulations and the latest EDPB guidelines.

The first of the exemplary situations cited by the EDPB is the use of a parking camera in a vehicle. However, the condition for effective exemption is that the device does not collect images that allow for the identification of natural persons, including the license plates of other vehicles. Another example is video surveillance of a private garden—of course, only if the camera does not cover public spaces outside the private property. The above aligns with existing practices and leaves little room for doubt.

In Germany, up until 2023, at least 10 fines of up to 1000 euros have been imposed on private individuals for the use of dash cameras.

In 2020, the Austrian supervisory authority imposed a financial penalty of 2,200 euros on a private individual who used CCTV monitoring in their home. The monitoring covered areas designated for the general use of residents of a multi-family housing complex, namely: parking lots, sidewalks, courtyards, gardens, and access roads to the housing complex; furthermore, the monitoring included the garden areas of a neighboring property. Therefore, the video monitoring was not limited to areas under the exclusive control of that individual.

Where NOT to use monitoring?

Equally important is the issue raised by the authors of the guidelines regarding the identification of places where monitoring should be excluded. According to EROD, areas such as gardens, medical and treatment rooms, sanitary facilities, saunas, public benches, parks, cinemas, and fitness rooms should not be monitored. The proposed list may seem puzzling or even debatable, particularly due to the inclusion of park areas, where the need for control and maintenance of order is generally greater than in other facilities.

DPO Function - it is well communicated

It is worth mentioning that the Polish Labor Code also provides for the prohibition of monitoring sanitary rooms, changing rooms, canteens, and smoking areas, although this is permissible under certain exceptions. Non-compliance with these requirements has already been the subject of a penalty imposed by the Polish DPA on one of the large retail chains that installed a hidden camera in its warehouse to detect a thief stealing alcohol.

EROD also emphasizes that the use of image recording methods for the purpose of securing property should only be permitted within its boundaries. However, it indicates the likelihood of situations where such limited supervision is insufficient for effective protection of the data controller's area. In such cases, they should consider physical and technical measures, such as obscuring or pixelating the image in parts that extend beyond the necessary scope for them.

The Polish DPA has already issued decisions regarding the monitoring of public spaces by private individuals, which should not be monitored by them, although no financial penalties have been imposed in this regard: decision of May 30, 2022 and decision of October 21, 2025. In contrast, the Spanish supervisory authority imposes fines of up to 300-5000 euros on private individuals in such situations (a fine of 5000 euros was imposed on an individual who installed monitoring in their home within a residential complex, which also covered a public swimming pool).

Furthermore, in light of the recommendations presented in the guidelines, the data controller should first consider whether the video surveillance they intend to use is actually necessary to ensure safety in the area under their supervision. The EDPB indicates that a data controller whose aim is to prevent crime and protect property may, instead of installing a video surveillance system, take alternative security measures, such as fencing the property, deploying security patrols, providing better lighting, installing security features on windows and doors, or applying coatings or films against graffiti. According to the guidelines, these measures may prove sufficient and equally effective as video surveillance, which can then be avoided.

Legal grounds for processing data from surveillance

Next, attention should be drawn to the position taken by the EDPB, according to which each ground from Article 6(1) of the GDPR may constitute a legal basis for processing data from video surveillance.

The most commonly applied provisions are Article 6(1)(f) GDPR (legitimate interest of the data controller) and Article 6(1)(e) GDPR (necessity of performing a task carried out in the public interest or in the exercise of official authority). If national law imposes a requirement for video surveillance, Article 6(1)(c) GDPR will apply. Consent of the data subject can only be used as a legal basis in exceptional situations. Furthermore, Article 9(2)(d) GDPR may serve as a basis for processing by a data controller implementing video monitoring solely based on the justification of absolute necessity to safeguard the vital interests of the individual and proving that the individual is physically or legally incapable of giving consent to the processing of their personal data.

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to fulfill the role of Data Protection Officer. We invite you!
CHOOSE A DATE
It is worth mentioning examples through which the EDPB clarifies the justification for applying bases related to the processing of special categories of personal data.

  • A video recording showing a data subject wearing glasses or in a wheelchair is not considered as such to be processing of special categories of personal data.
  • From photographs depicting identifiable individuals participating in a protest, strike, or demonstration, one can infer political opinions. This situation implies the application of Article 9 GDPR.
  • Monitoring directed at a church is generally not covered by Article 9 GDPR. However, the data controller must conduct a particularly careful assessment of the legitimate interest of such surveillance in accordance with Article 6(1)(f) GDPR, taking into account the nature of the data and the risk of capturing sensitive data.
  • Relying on Article 9(2)(c) GDPR is justified in the case of the necessity to provide assistance to an unconscious person whose life is in danger by the hospital emergency team.

In the positions presented above, EROD shows some inconsistency regarding whether the image from monitoring contains personal data of special categories. When we see a Black person, we also "see" their personal data in the form of race. When we see a person using a wheelchair, we also "see" their personal data regarding health status. When we see that someone is present at an anti-abortion march, we also "see" that person's personal data in the form of their worldview. However, these are data that the entity using monitoring does not "want" to process, has no intention of collecting, even though they de facto appear in the monitoring image. Therefore, we cannot state that the owner of the monitoring recording is a data controller of someone's race/health/worldview.

What about biometrics?

Recording images of natural persons is increasingly associated with the use of images in the context of biometrics. According to the position presented by EROD, a data controller installing a video surveillance system with facial recognition capabilities, for example, at the entrance to a concert hall, cannot limit itself to this option. It is obliged to provide individuals entering the premises it manages with a clearly separate entrance that does not require the use of biometric devices.

It should be noted that tools allowing for the use of biometrics must be installed by the data controller in a manner that prevents the system from capturing individuals who have not previously given their consent.

The use of biometric data from monitoring was the subject of a decision by the Swedish supervisory authority in 2019. A school in Skellefteå used facial recognition technology to monitor student attendance. Although processing data for attendance monitoring is generally possible, doing so using facial recognition is disproportionate to the purpose. Given that biometric data was processed, Article 9 of the GDPR applied. According to the Swedish supervisory authority, consent could be used as a legal basis for processing, as students and their guardians could not freely decide whether they wanted to be monitored for attendance. Additionally, the authority stated that the school could not invoke any other exception to the prohibition on processing biometric data, as mentioned in Article 9(2) of the GDPR.

How long can recordings be stored?

A critical issue related to the use of video surveillance is the period during which the data controller may store recordings obtained in this manner. Unfortunately, neither the provisions on personal data protection nor the guidelines explicitly define this term. The EDPB, in relation to this matter, again relies on practical examples. In this context, it has been indicated that in a small store, where theft or other types of violations can be easily noted, a 24-hour storage period is sufficient. Factors that may justify extending this period include holidays or other non-trading days. In the event of damage being detected, the intention to take legal action against the perpetrator may also constitute a basis for retaining the recording for a longer time.

Referring generally to other cases of video surveillance application, the EDPB states that as a rule, recordings should be deleted after a few days, preferably automatically. This is another thesis that may provoke controversy. So far, a certain standard of storing recordings for about 30 days, and even up to 3 months, has been adopted in practice by data controllers, which significantly deviates from the current recommendations of the EDPB.

Do you also prefer prevention over treatment?

In turn, in the document “Guidelines of the President of the Polish Data Protection Authority on the use of video surveillance” issued in 2018, the Polish DPA indicated that “this period should rather be counted in weeks than in months,” without specifying in detail what period would be most appropriate.

In connection with the above, it is worth mentioning that according to the content of the guidelines, at the request of a third party, it is permissible to provide them with the recording held by the data controller. However, the condition is that the purpose of using the video aligns with the purpose of the surveillance in question. This concerns a situation where, for example, in a parking lot (which is covered by video surveillance aimed at ensuring safety), our car has been scratched, and we want to verify how the damage occurred in order to take any further steps related to it. However, it is not acceptable to share a similar recording with the intention of posting it, for example, on an online entertainment platform.

Note: According to the GDPR, the processing of data (including the sharing of data from surveillance) is permissible when, among other things, it is necessary for the purposes arising from the legitimate interests pursued by the data controller or by a third party. A third party may be a person who, although not visible in the recording, can demonstrate a legitimate interest in obtaining a recording that contains images of individuals other than themselves. A classic example of such a situation is a request for the release of a recording by a person who left their car in a parking lot and it was damaged during their absence.

Information Obligation – not only in graphic form

Considering that the image of a natural person undoubtedly constitutes their personal data, the entity acting as the data controller has an information obligation as provided in Article 13 of the GDPR. Given the specificity of this type of data and its collection, the EDPB distinguishes two layers of the privacy notice relating to this matter. In light of the guidelines, part of the information should be presented on the warning sign informing about the fact of monitoring (the first layer), while further mandatory details may be provided through other means (the second layer). The first layer (warning sign) should essentially convey the most important information – detailed data regarding the purposes of processing, the identity of the data controller and how to contact them, the rights of the data subjects, and the most significant consequences of processing – as well as include a mention of the Data Protection Officer (if appointed in the organization). It is also required to refer to the second layer of the information obligation and indicate where and how the privacy notice can be found. The location allowing individuals to access its full content should be easily accessible to the data subjects, e.g., at an information point, reception, or cash desk.

Importantly, according to the guidelines, stating in the privacy notice that video surveillance is based solely on the purpose of “security” is not sufficiently detailed and contradicts the principle of transparency established by the GDPR. Undoubtedly, such a position will hinder data controllers in properly fulfilling their information obligation.

A good example of how to understand the layered approach to information provision is the decision of the Italian supervisory authority issued in 2023. It concerned the fulfillment of the information obligation in the context of video surveillance used at a waste collection point. The authority accused the data controller of:

  • Inadequate and unclear information boards (first layer): The warning sign about cameras was located directly on the waste container, surrounded by other signs. This location made the message poorly visible and did not allow residents to be aware of the surveillance before entering the camera's field of view.
  • Misleading purposes of processing: The information sign and the information on the website vaguely referred to “security reasons,” “public safety,” or “protection against vandalism and theft.” In reality, the main purpose of the cameras was to document administrative offenses related to improper waste disposal, which should have been clearly communicated.
  • Lack of reference to the full privacy notice: The boards placed near the waste bins did not contain information on where to find the full, second layer of the information obligation (e.g., by referring to the website). The complete privacy policy was published online with significant delay.
  • Concealment of information about the extension of the retention period: When the municipality decided to extend the retention period of recordings from 7 to 15 days, it did not update the information notices, which meant that the recorded individuals were unaware of this change.
  • Obstructing access to information and false declarations: On newer signs, the municipality included information about an alleged "automatic data deletion mechanism," which did not actually exist. Furthermore, it forced citizens to physically visit the information point of the office to access the full privacy notice, which unjustifiably hindered the exercise of the rights of the individuals concerned.
 

Template of the privacy notice – monitored object

We provide a template of the privacy notice that meets the requirements set forth by both the regulations and the latest EDPB guidelines.

The mandatory elements of the first layer of the information obligation indicated by the EDPB may make it seem quite challenging to fulfill. To assist in navigating the construction of a privacy notice compliant with personal data protection regulations (from both a substantive and graphical perspective), we have prepared a template that meets the requirements set forth by both the regulations and the EDPB guidelines specifically for you.

When using our proposed privacy notice, please remember that it is a template that must be appropriately adapted to each factual situation. The elements requiring particular verification are: the basis and purpose of processing, the retention period of recordings, and the designation of the area covered by monitoring.

Regardless of the essence of the considerations undertaken, it is worth noting that the guidelines are currently in the consultation phase – the EDPB is accepting comments on them until September 9, 2019. We encourage you to familiarize yourself with the content of guidelines 3/2019, which can be found on the Polish DPA's website at: https://www.uodo.gov.pl/pl/138/1100 (accessed: August 26, 2019).

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.