Complete guide on installing and using CCTV systems in compliance with GDPR and Romanian legislation
Video surveillance has become one of the most effective methods of protecting people, assets and a company's activities. At the same time, surveillance cameras process personal data, which means that any CCTV system must be implemented and operated in compliance with the General Data Protection Regulation (GDPR).
In 2026, authorities are paying increasing attention to how businesses use video surveillance. Fines can reach millions of euros for serious violations, but most problems can be avoided with proper system design and management.
In this article we explain all the essential rules that any company needs to know.
What does GDPR say about video surveillance?
GDPR does not prohibit the use of video cameras.
However, the regulation requires that any image processing that allows the identification of a person must comply with data protection principles.
These principles are:
- legality;
- transparency;
- limitation of purpose;
- data minimization;
- accuracy;
- limitation of the storage period;
- data security;
- operator's responsibility.
In short, a company can only install video cameras if there is a legitimate purpose and it can demonstrate that the surveillance is necessary and proportionate.
In what situations is video surveillance permitted?
The most common legitimate purposes are:
- protection of assets;
- theft prevention;
- employee security;
- access control;
- vandalism prevention;
- protection of confidential information;
- security of critical objectives;
- compliance with legal obligations regarding security.
In many situations, the legal basis used is legitimate interest of the operator.
However, this must be documented through an analysis that demonstrates that the company's interest prevails over the impact on privacy.
Is legitimate interest analysis mandatory?
Yes.
For most CCTV systems used in private environments, the operator must document:
- the purpose of the installation;
- existing risks;
- the need for cameras;
- the existence of less intrusive measures;
- the impact on people.
This document is one of the first requested in the event of an ANSPDCP inspection.
Is a DPIA required?
In certain situations, yes.
O Data Protection Impact Assessment (DPIA) is recommended or mandatory when:
- there is systematic monitoring on a large scale;
- smart cameras are used;
- there is facial recognition;
- areas accessible to the public are permanently monitored;
- the system uses artificial intelligence;
- there is continuous monitoring of employees.
Where can cameras NOT be installed?
There are areas where video surveillance is normally prohibited:
- toilets;
- changing rooms;
- changing cabins;
- showers;
- rest rooms;
- other spaces where there is a high expectation of privacy.
Monitoring such spaces can lead to severe sanctions.
Can employees be supervised?
Yes, but only under certain conditions.
Permanent monitoring of employees must be justified by objective reasons and must respect the principle of proportionality.
It is not recommended to use the cameras for:
- continuous performance evaluation;
- excessive control;
- permanent surveillance without justification.
Employees must be clearly informed about:
- the existence of cameras;
- the purpose of monitoring;
- storage period;
- their rights;
- the operator's contact details.
Is it mandatory to inform people?
Yes.
Anyone must know before entering a monitored area that images are being recorded.
This is achieved by:
- CCTV icon;
- information about the operator;
- the purpose of the processing;
- how to obtain complete information regarding GDPR.
The full policy can be accessed via:
- website;
- QR code;
- reception;
- internal regulations.
How long can records be kept?
The GDPR does not establish a fixed period.
The operator should only retain images for as long as necessary.
In practice, the most common periods are:
- 15 days;
- 30 days;
- 45 days;
- 60 days in justified situations.
Longer periods must be motivated and documented.
If there is an incident, relevant images can be retained until the investigation is complete.
Who can access the images?
Access must be strictly limited.
They can usually access:
- system administrator;
- security personnel;
- company management;
- persons authorized through internal procedures.
It is recommended:
- individual authentication;
- access logging;
- complex passwords;
- multifactor authentication;
- encryption of communications;
- secure backup.
Can cameras with artificial intelligence be installed?
Yes, but the operator's responsibility increases considerably.
Functions such as:
- facial recognition;
- behavioral analysis;
- tracking people;
- automatic classification;
- automatic identification;
may require additional data protection assessments and should also be considered in the light of the European legislation on artificial intelligence (AI Act), where applicable.
What documents does a company need to have?
A properly implemented CCTV system should be accompanied by:
- video surveillance policy;
- register of processing activities;
- analysis of legitimate interest;
- DPIA (if required);
- procedure regarding access to images;
- the procedure for deleting records;
- retention policy;
- informing the persons concerned;
- agreements with processors (for example, companies that provide maintenance or hosting of the system, if they process data on behalf of the operator).
What fines can there be?
Depending on the severity of the violation, GDPR allows for significant sanctions.
The most common reasons for sanctions are:
- lack of information for people;
- excessive retention of images;
- cameras installed in unauthorized areas;
- unauthorized access to images;
- lack of security measures;
- lack of GDPR documentation.
In addition to financial sanctions, the authority may order the modification or even suspension of the surveillance system until the non-compliances are remedied.
Recommendations for companies
Before installing a CCTV system it is recommended to:
- consider whether supervision is really necessary;
- design the system to capture only the relevant areas;
- avoid filming the public domain when it is not necessary;
- establish a justified retention period;
- implement GDPR policies and procedures;
- secure equipment against unauthorized access;
- perform periodic technical reviews and compliance audits.
A modern system of video surveillance must combine physical security with the protection of personal data. Compliance with GDPR is not only a legal obligation, but also an element that contributes to the trust of employees, customers and partners in the way the company manages information.
How GreenSoft can help you
GreenSoft designs, installs and maintains professional video surveillance systems for companies, public institutions, industrial units and critical infrastructures. Our solutions are designed to meet both technical and security requirements, as well as data protection obligations.
We offer:
- consultancy for choosing the optimal system architecture;
- design and installation carried out by authorized personnel;
- configuring security measures for access to records;
- preventive and corrective maintenance;
- support for the implementation of good practices regarding the use of CCTV systems in accordance with legal requirements.
If you are planning to implement or upgrade a video surveillance system, the GreenSoft team can help you find the right solution for your organization's needs.
You need GDPR compliant CCTV systems in Constanta? Request a quote →









































