A DPIA for CCTV is the structured assessment an organization carries out to decide whether video surveillance is justified, proportionate and adequately protected before cameras are installed or significantly changed. Cameras are among the most visible ways an organization collects personal data, and they capture everyone in view: staff, customers, visitors, passers-by and children.
This guide explains when a DPIA for CCTV is required, what it should contain, how to test necessity and proportionality, how to set retention and access rules, and when the regulator should be consulted.
When a DPIA for CCTV is required
Article 35 of the GDPR requires a data protection impact assessment where processing is likely to result in a high risk to individuals. Article 35(3)(c) specifically lists systematic monitoring of a publicly accessible area on a large scale. A shopping centre, a town centre scheme, a transport hub or a large retail site with cameras covering public spaces will usually fall within that provision. Many supervisory authorities also list video surveillance combined with other technologies, such as facial recognition or behavior analytics, on their published lists of processing that requires a DPIA.
Even where the trigger is not clear, a DPIA is good practice for workplace cameras, cameras covering areas with high privacy expectations, systems that record audio, and systems that use analytics or link footage to other data. Our guide to when a DPIA is required explains the criteria and the screening questions you can apply.
Sources to use for a DPIA for CCTV
The European Data Protection Board has published Guidelines 3/2019 on the processing of personal data through video devices. They cover lawfulness, transparency, retention, technical measures and the rights of individuals, and they are the most useful single reference for assessors in the EU. You can read them on the EDPB website. National regulators publish their own codes and checklists, which you should follow for the country where the cameras operate. For the general structure, see our overview of the DPIA.
Free DPIA template and tool
Does this processing need a DPIA, and what would it say?
Screen the processing against Article 35 and the nine WP248 criteria, describe it, test necessity and proportionality, rate the risks to the people concerned and record the DPO's advice and sign-off. Free, with findings and the Article 36 check.
What the DPIA for CCTV must contain
Article 35(7) sets the minimum content: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures envisaged to address those risks. For cameras, that translates into the following sections.
| Section | What to record for cameras |
|---|---|
| Description | Camera locations, fields of view, recording or live view, audio, analytics, who operates the system, who receives footage |
| Purpose | Specific problems such as theft, vandalism or safety incidents, with evidence of the problem |
| Lawful basis | Usually legitimate interests or, for public bodies, a task in the public interest |
| Necessity and proportionality | Alternatives considered, why cameras are needed, why each location is justified |
| Risks | Intrusion, chilling effect, misuse of footage, unauthorized access, function creep |
| Safeguards | Signage, retention limit, access controls, masking, audit trail, training |
| Consultation | Views of staff, unions, residents and the data protection officer |
| Outcome | Residual risk, approval, review date |
Necessity and proportionality for a DPIA for CCTV
This is the core of the assessment. Start with the problem. Record specific incidents, dates and losses rather than a general statement that security is important. Then ask whether less intrusive measures would work: better lighting, locks, staffing, access control, alarms or moving valuable items. If cameras remain justified, test each camera location separately. A camera covering a cash desk is easier to justify than one covering a staff rest area, and a camera pointed at a neighbor’s property is difficult to justify at all.
Consider the reasonable expectations of the people filmed. Employees have a legitimate expectation of privacy at work, and areas such as toilets, changing rooms and break areas should not be covered. Customers in a shop have a lower expectation in public sales areas but a higher one in fitting rooms. Balance these factors in your record. Our guide to legitimate interests examples shows how the balancing test works in practice, and it is closely related to this part of the assessment.
Technologies that raise the level of risk
Ordinary recording of fixed views is a lower-risk use than systems that analyze footage. Facial recognition, emotion analysis, behavior detection, license plate reading with watch lists and tracking of individuals across cameras increase the risk considerably. Biometric identification raises special category data issues under Article 9 and needs its own justification. Audio recording is particularly intrusive and is generally difficult to justify with cameras. If any of these features is proposed, assess them specifically and consider whether they can be excluded.
Retention, access and transparency
Set a fixed retention period and delete footage automatically at its end. The EDPB guidelines note that footage should in most cases be erased after a few days, and that periods beyond 72 hours need stronger justification. Longer retention for specific footage is acceptable when an incident has occurred and the material is kept for investigation. Record the reasons for your chosen period.
- Access. Limit who can view live and recorded footage, log every access and export, and review the logs.
- Disclosure. Define when footage is shared with police, insurers and others, and require a written request.
- Transparency. Put clear signs at the entrance to the monitored area and provide a fuller notice with the operator’s identity, purposes, legal basis, retention and contact details.
- Individual rights. Set a process for access requests, including blurring or masking third parties, and for objections.
- Security. Encrypt storage and transmission, change default credentials, patch devices and restrict network access.
Consultation and residual risk
Consult the data protection officer, and seek the views of the people affected where that is appropriate, such as staff representatives for workplace systems. Article 35(9) asks controllers to seek the views of data subjects or their representatives where appropriate. Our article on DPIA consultation with the DPO and data subjects explains how to do that. After adding safeguards, rate the residual risk. If it remains high and you cannot reduce it, Article 36 requires prior consultation with the supervisory authority before processing begins. See DPIA prior consultation and DPIA residual risk for the details.
A short worked example
A retail chain plans eight cameras in a store: two at the entrance, three over sales aisles, two at the cash desks and one in the stockroom. The assessment records shrinkage figures for the last two years and three incidents of staff-related theft in the stockroom. It finds the entrance and cash desk cameras well justified, accepts the aisle cameras with a narrower field of view that excludes the fitting room corridor, and moves the stockroom camera so that it covers the door and not the staff break table. It sets retention at seven days with automatic deletion, limits live viewing to the store manager and the security team, and adds signs at both entrances.
The record also notes that the manufacturer supports facial recognition and that the feature is disabled and locked in the configuration. Because each decision and reason is written down, the team can explain the design to staff representatives, to a customer who complains and to the regulator if it asks.
Keeping the assessment under review
Cameras change over time: locations are added, software is upgraded, analytics are switched on and footage is shared more widely. Set triggers that require the DPIA to be reviewed, and in any case review it at planned intervals. Keep a register of camera locations and the purpose of each, and check it against what is actually installed. Also review whether the original problem still exists. If crime has fallen or the risk has changed, a camera that was justified may no longer be.
Using a ready structure
To avoid building the record from scratch, the DPIA Report and Workbook provides a structured report with risk scoring and a working register that you can adapt for surveillance systems. You can also see a completed record in our DPIA example. Whichever format you use, complete the DPIA for CCTV before installing or changing cameras, and record the reasons for each camera you keep.
DPIA for CCTV FAQ
Do I always need a DPIA for CCTV?
Not always, but you need one where the monitoring is likely to be high risk, including systematic monitoring of a publicly accessible area on a large scale. It is good practice for workplace cameras and analytics too.
How long can CCTV footage be kept?
There is no fixed legal period. Regulators expect footage to be kept only as long as necessary, often a few days, and the EDPB says periods beyond 72 hours need stronger justification.
Can I record audio with CCTV?
Audio is much more intrusive than video and is generally hard to justify. If you think it is needed, assess it separately in the DPIA and consider whether it can be avoided.
Do I need signs?
Yes. People must be told that monitoring is taking place, by clear signs at the entrance to the area and by a fuller privacy notice available to them.
Who should approve the DPIA?
A senior manager with authority over the cameras should approve it after taking the advice of the data protection officer. If high residual risk remains, prior consultation with the regulator is required.