It is not enough to deploy a high-performing technology — you must be able to prove it is necessary, proportionate and lawful.
More and more organisations are investing in surveillance technologies to increase their level of control, security and operational efficiency. However, when these solutions are deployed without a rigorous GDPR analysis, they can quickly become a major source of legal, financial and reputational risk.
A recent case investigated by the National Supervisory Authority for Personal Data Processing demonstrates how easily one can move from the intention of "protection" to serious breaches of the rights of the data subjects. And the costs do not mean only fines, but also the loss of employee trust, internal tensions and public exposure.
Following a complaint filed by an employee, the authority identified several serious shortcomings in the way personal data was processed in the workplace. Among the issues found were:
The result was predictable: financial sanctions, corrective measures and a finding of the breach of essential GDPR principles, such as lawfulness, data minimisation and transparency.
This example shows one simple thing: it is not enough to deploy a high-performing technology. You must be able to prove that its use is necessary, proportionate and perfectly justified from a legal standpoint.
In the absence of these elements, any monitoring solution can become a compliance vulnerability.
The fact that a solution exists on the market and is accessible does not automatically mean it is also justified. In the case analysed, the use of body-cams was considered excessive, because less intrusive alternatives existed.
Many employers treat the privacy notice as a formality. In reality, it must clearly explain:
Any data processing must have a solid legal basis. Without it, even the recording of meetings or access to images/audio can become unlawful.
Transmitting data to third parties, without a well-defined legal basis, is one of the most serious failings and one of the most costly from a GDPR risk perspective.
Organisations that want to avoid sanctions must not merely react after an incident. They must build prevention before deployment.
The first question is not "Can we deploy this technology?", but "Is it truly necessary?". If a less invasive alternative exists, that one must be evaluated as a priority.
For high-risk technologies, the data protection impact assessment is not optional. It is one of the most important tools through which you can demonstrate accountability and compliance.
Legitimate interest, legal obligation or another applicable basis — the legal ground must be correctly established, documented and substantiated.
The data subjects must be informed in a clear, accessible and complete manner. A vague or incomplete notice does not protect the company.
Collect only what is strictly necessary. More technology does not automatically mean more safety, but it can certainly mean more risk.
Access, storage, deletion, security and use of recordings must be regulated internally, in a concrete way, not just in theory.
Compliance is not resolved through documents alone. The people who use the technology must know exactly what they are and are not allowed to do.
Companies that treat GDPR as part of their business strategy, rather than as a bureaucratic obligation, are the ones that significantly reduce the risks.
An effective approach means:
This unpleasant situation shows very clearly that technology deployed without a solid GDPR foundation can quickly generate sanctions, internal deadlocks and reputational damage.
In a business environment where digitalisation is advancing rapidly, compliance is no longer an "extra". It is an essential condition for sound, sustainable and safe decisions.
Companies that invest early in analysis, documentation and prevention do not just avoid fines. They protect their reputation, their relationship with employees and their ability to grow without unnecessary risks.
If your organisation uses or intends to deploy surveillance solutions, the right time for a GDPR analysis is not after a complaint or an inspection, but before deployment.
Surveillance is lawful only if it is necessary, proportionate and has a clear legal basis (usually legitimate interest or a legal obligation). The mere fact that a technology is available on the market is not enough: the employer must prove that the purpose cannot be achieved through a less intrusive measure. In the case investigated by ANSPDCP, the use of a body-cam was considered excessive precisely because less invasive alternatives existed.
Yes. For high-risk technologies, the data protection impact assessment (DPIA) is not optional. Systematic monitoring of employees or of publicly accessible areas usually falls into this category. The DPIA is one of the most important tools through which you can demonstrate accountability and compliance before deployment, not after a complaint or an inspection.
Yes. Transparency is mandatory. The privacy notice must be clear, accessible and complete, and must explain the purpose of the processing, how the recordings are used, the storage period and the rights of the data subjects. A vague or incomplete notice does not protect the company. In the ANSPDCP case, the lack of clear information and the audio-video recording without complying with transparency obligations were among the sanctioned shortcomings.
Proportionality means that the surveillance measure must be balanced against the purpose pursued and must collect only the data that is strictly necessary. The first question is not Can we deploy this technology?, but Is it truly necessary? If a less invasive alternative exists, that one must be evaluated as a priority. More technology does not automatically mean more safety, but it can certainly mean more risk.
We carry out the necessity and proportionality analysis and the DPIA before deployment, so you avoid sanctions.