Services ▾
Weak currents and networks
Weak currents and networks
Certified and documented voice-data networks. View category →
Fire safety
Fire safety
Authorized IGSU · ISU approval and authorization. View category →
Cybersecurity
Cybersecurity
ISO/IEC 27001 certificate. View category →
IT Service and Outsourcing
IT Service and Outsourcing
Your IT department, outsourced — support, servers, M365, backup. View category →
HVAC maintenance
HVAC maintenance
Scheduled checks and interventions for air conditioning. View category →
Corporate Sales and SEAP
Corporate Sales and SEAP
IT equipment and security, including through SEAP. View category →
BlogContact
Blog Fire Safety

Video surveillance and GDPR in 2026: the complete rules for businesses

Complete guide on installing and using CCTV systems in compliance with GDPR and Romanian legislation

Video surveillance has become one of the most effective methods of protecting people, assets and a company's activities. At the same time, surveillance cameras process personal data, which means that any CCTV system must be implemented and operated in compliance with the General Data Protection Regulation (GDPR).

In 2026, authorities are paying increasing attention to how businesses use video surveillance. Fines can reach millions of euros for serious violations, but most problems can be avoided with proper system design and management.

In this article we explain all the essential rules that any company needs to know.

What does GDPR say about video surveillance?

GDPR does not prohibit the use of video cameras.

However, the regulation requires that any image processing that allows the identification of a person must comply with data protection principles.

These principles are:

  • legality;
  • transparency;
  • limitation of purpose;
  • data minimization;
  • accuracy;
  • limitation of the storage period;
  • data security;
  • operator's responsibility.

In short, a company can only install video cameras if there is a legitimate purpose and it can demonstrate that the surveillance is necessary and proportionate.

In what situations is video surveillance permitted?

The most common legitimate purposes are:

  • protection of assets;
  • theft prevention;
  • employee security;
  • access control;
  • vandalism prevention;
  • protection of confidential information;
  • security of critical objectives;
  • compliance with legal obligations regarding security.

In many situations, the legal basis used is legitimate interest of the operator.

However, this must be documented through an analysis that demonstrates that the company's interest prevails over the impact on privacy.

Is legitimate interest analysis mandatory?

Yes.

For most CCTV systems used in private environments, the operator must document:

  • the purpose of the installation;
  • existing risks;
  • the need for cameras;
  • the existence of less intrusive measures;
  • the impact on people.

This document is one of the first requested in the event of an ANSPDCP inspection.

Is a DPIA required?

In certain situations, yes.

O Data Protection Impact Assessment (DPIA) is recommended or mandatory when:

  • there is systematic monitoring on a large scale;
  • smart cameras are used;
  • there is facial recognition;
  • areas accessible to the public are permanently monitored;
  • the system uses artificial intelligence;
  • there is continuous monitoring of employees.

Where can cameras NOT be installed?

There are areas where video surveillance is normally prohibited:

  • toilets;
  • changing rooms;
  • changing cabins;
  • showers;
  • rest rooms;
  • other spaces where there is a high expectation of privacy.

Monitoring such spaces can lead to severe sanctions.

Can employees be supervised?

Yes, but only under certain conditions.

Permanent monitoring of employees must be justified by objective reasons and must respect the principle of proportionality.

It is not recommended to use the cameras for:

  • continuous performance evaluation;
  • excessive control;
  • permanent surveillance without justification.

Employees must be clearly informed about:

  • the existence of cameras;
  • the purpose of monitoring;
  • storage period;
  • their rights;
  • the operator's contact details.

Is it mandatory to inform people?

Yes.

Anyone must know before entering a monitored area that images are being recorded.

This is achieved by:

  • CCTV icon;
  • information about the operator;
  • the purpose of the processing;
  • how to obtain complete information regarding GDPR.

The full policy can be accessed via:

  • website;
  • QR code;
  • reception;
  • internal regulations.

How long can records be kept?

The GDPR does not establish a fixed period.

The operator should only retain images for as long as necessary.

In practice, the most common periods are:

  • 15 days;
  • 30 days;
  • 45 days;
  • 60 days in justified situations.

Longer periods must be motivated and documented.

If there is an incident, relevant images can be retained until the investigation is complete.

Who can access the images?

Access must be strictly limited.

They can usually access:

  • system administrator;
  • security personnel;
  • company management;
  • persons authorized through internal procedures.

It is recommended:

  • individual authentication;
  • access logging;
  • complex passwords;
  • multifactor authentication;
  • encryption of communications;
  • secure backup.

Can cameras with artificial intelligence be installed?

Yes, but the operator's responsibility increases considerably.

Functions such as:

  • facial recognition;
  • behavioral analysis;
  • tracking people;
  • automatic classification;
  • automatic identification;

may require additional data protection assessments and should also be considered in the light of the European legislation on artificial intelligence (AI Act), where applicable.

What documents does a company need to have?

A properly implemented CCTV system should be accompanied by:

  • video surveillance policy;
  • register of processing activities;
  • analysis of legitimate interest;
  • DPIA (if required);
  • procedure regarding access to images;
  • the procedure for deleting records;
  • retention policy;
  • informing the persons concerned;
  • agreements with processors (for example, companies that provide maintenance or hosting of the system, if they process data on behalf of the operator).

What fines can there be?

Depending on the severity of the violation, GDPR allows for significant sanctions.

The most common reasons for sanctions are:

  • lack of information for people;
  • excessive retention of images;
  • cameras installed in unauthorized areas;
  • unauthorized access to images;
  • lack of security measures;
  • lack of GDPR documentation.

In addition to financial sanctions, the authority may order the modification or even suspension of the surveillance system until the non-compliances are remedied.

Recommendations for companies

Before installing a CCTV system it is recommended to:

  • consider whether supervision is really necessary;
  • design the system to capture only the relevant areas;
  • avoid filming the public domain when it is not necessary;
  • establish a justified retention period;
  • implement GDPR policies and procedures;
  • secure equipment against unauthorized access;
  • perform periodic technical reviews and compliance audits.

A modern system of video surveillance must combine physical security with the protection of personal data. Compliance with GDPR is not only a legal obligation, but also an element that contributes to the trust of employees, customers and partners in the way the company manages information.

How GreenSoft can help you

GreenSoft designs, installs and maintains professional video surveillance systems for companies, public institutions, industrial units and critical infrastructures. Our solutions are designed to meet both technical and security requirements, as well as data protection obligations.

We offer:

  • consultancy for choosing the optimal system architecture;
  • design and installation carried out by authorized personnel;
  • configuring security measures for access to records;
  • preventive and corrective maintenance;
  • support for the implementation of good practices regarding the use of CCTV systems in accordance with legal requirements.

If you are planning to implement or upgrade a video surveillance system, the GreenSoft team can help you find the right solution for your organization's needs.

Did you like the article? Share:
GreenSoft Service

You need GDPR compliant CCTV systems in Constanta? Request a quote →

We discuss your project, without initial costs

Free technical advice and quote within 3–5 business days.

ANRE · IGSU · IGPRreply on the same business day
Talk to a specialist
Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton
Bentel Security
Teledata
NSC Sicherheitstechnik
FireClass
Fire Eater
Hilti
Promat
TOA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno
VIGI
Dahua Technology
Novus
DSC
Paradox
Ajax Systems
Rosslare Security
YLI
KaDe
Dell
Seagate
TP-Link
Omada
HP
EnGenius
3M
Fortinet
Grandstream
Panasonic
Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton
Bentel Security
Teledata
NSC Sicherheitstechnik
FireClass
Fire Eater
Hilti
Promat
TOA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno
VIGI
Dahua Technology
Novus
DSC
Paradox
Ajax Systems
Rosslare Security
YLI
KaDe
Dell
Seagate
TP-Link
Omada
HP
EnGenius
3M
Fortinet
Grandstream
Panasonic