A camera in the lobby feels like a small decision. You buy a unit, point it at the door, put up a sign, and move on. But the moment that camera records someone you can recognize, you're processing personal data, and GDPR holds surveillance to the same standard as any other sensitive activity you run.

Workplace monitoring is one of the easiest ways for a growing company to drift out of compliance without noticing. The cameras work, the footage saves, and nobody asks the hard questions until an employee complains or a regulator gets in touch. This guide covers what GDPR actually asks of you when you monitor employees and visitors, and how to run surveillance as a documented process in OptiTech instead of a blind spot.

When monitoring becomes personal data processing

Surveillance is easy to underestimate because it doesn't look like a record. But any recording of an identifiable person is personal data, and that covers far more than the cameras at your entrance. Access logs that capture who badged in and when, GPS tracking in company vehicles, email and network monitoring, and video with audio all process personal data about your people and your visitors.

Each of those is a processing activity in its own right, with its own purpose and its own risks. Treating "the CCTV system" as a single line item hides the fact that a camera over the till, a camera in the car park, and a keystroke logger on a shared workstation raise very different questions. The first step is naming each one honestly.

Find a lawful basis that holds

Every surveillance activity needs a lawful basis, and for monitoring that basis is usually legitimate interest. You have a genuine reason, like protecting property or staff safety, that a reasonable person would accept. But legitimate interest isn't a free pass. You have to run a balancing test that weighs your reason against the intrusion on the people you're recording, and you have to write it down.

Consent almost never works here, and legal obligation only applies in narrow cases. So the balancing test carries the weight. If you can't explain, on paper, why your interest outweighs the privacy of the people in frame, you don't have a lawful basis yet.

Consent has to be freely given, and an employee can't freely refuse the boss who signs their paycheck. Data protection authorities across the Nordics treat employee consent as rarely valid for exactly this reason. That leaves legitimate interest, backed by a documented balancing test, as the realistic basis for monitoring staff. The imbalance of power is the whole point, so your justification has to be strong enough to stand without the employee's agreement.

Proportionality is the test you can't skip

Proportionality asks a blunt question: is this the least intrusive way to achieve your goal? Cameras belong where the risk actually lives, at entrances, near cash handling, or over high-value stock. They don't belong in break rooms, changing areas, or toilets, and continuous recording is harder to justify than targeted, time-limited monitoring.

For each camera and system, you should be able to say what it's for, why a less intrusive option won't do, and what area it covers. If you can't answer those questions, the camera probably shouldn't be there.

Covert monitoring is almost never lawful

Secretly recording employees is one of the fastest ways to turn a compliance gap into a serious violation. Outside rare, well-documented investigations of specific wrongdoing, hidden cameras and silent monitoring fail the transparency test on their own. Assume monitoring must be visible and disclosed unless a lawyer tells you otherwise in writing.

Be transparent, and mean it

People have a right to know they're being recorded before they walk into the frame. That means clear signage at every entrance to a monitored area, placed before the camera's field of view, not tucked away where nobody reads it. The sign should say who's recording, why, and where to find more detail.

Employees deserve more than a sign. They need a written monitoring policy that explains what you collect, why, how long you keep it, who can see it, and what rights they have. In the Nordics, that transparency usually has to be paired with consultation before you switch anything on, which brings us to the local context.

Run a DPIA before the cameras go live

Systematic monitoring of a publicly accessible area on a large scale is one of the clearest triggers for a data protection impact assessment under Article 35. In practice, most meaningful surveillance needs a DPIA, and the point is to do it before you install anything, not after a complaint.

A good DPIA for surveillance describes the system, the personal data it captures, the necessity and proportionality of the monitoring, the risks to the people recorded, and the measures you'll take to reduce those risks. It's not a formality. It's the document that proves you thought this through, and it's the first thing an auditor or regulator will ask to see.

Retention: footage and logs both run on a clock

Footage you keep forever is footage you have to defend forever. Set a retention period that matches your purpose, usually days rather than months, and delete recordings automatically when it expires. If you need to hold specific footage for an incident, record why and for how long, so the exception is deliberate rather than accidental.

Retention applies to more than the video. The access logs that record who viewed footage, exported it, or changed a camera's settings are personal data too, and they deserve their own retention rule. Being able to show who watched what, and when, is often what separates a well-run system from a liability.

Nordic sensitivities around employee monitoring

Nordic workplaces run on a high level of trust, and the law reflects it. In Sweden, monitoring that affects employees typically requires negotiation with the relevant union under the co-determination rules before you introduce it. Works councils and similar bodies play the same role elsewhere in the region. Skipping that step isn't just a labor issue, it undermines the transparency and fairness your lawful basis depends on.

The cultural expectation is that monitoring is visible, limited, and justified. Recording audio, tracking employees outside working hours, or monitoring personal communications all sit far over the line for most Nordic employers. When in doubt, assume your people expect less surveillance than the law's outer limit allows, and design for that.

Document your surveillance in OptiTech

All of this only protects you if you can prove it, and that's where a program beats a pile of documents. In the OptiTech Console, you record each surveillance system as a processing activity: its purpose, its lawful basis and balancing test, the locations and cameras involved, the retention period, and who receives the footage.

The DPIA attaches directly to that activity as evidence, linked to the controls it supports, so the assessment doesn't rot in a shared drive. When a customer's security review or a regulator asks how you handle monitoring, the answer is already assembled. Your trust center can even show the relevant posture to buyers without anyone emailing your team, so the work you did to stay lawful also helps you close deals.

Getting started

You don't have to fix everything at once. A realistic first pass looks like this:

  1. Inventory every camera and monitoring system, including access logs, vehicle tracking, and network monitoring.
  2. Assign a lawful basis to each one and write the balancing test that supports it.
  3. Run a DPIA for any high-risk surveillance and attach it as evidence.
  4. Set retention periods and signage, and consult employees or their union before you start.
  5. Record it all as a processing activity in OptiTech and publish your posture to your trust center.

Surveillance done right is quiet, limited, and documented. Build the records once, keep them current, and both your employees and your auditors get the same honest answer about what you watch and why.

Ready to make your monitoring provable instead of risky? Book a demo and see how OptiTech turns surveillance processing and its DPIA into living evidence.