CCTV Privacy Law Mapper
Finding 11 of 18

Camera covering a staff-only private area

A break room, a changing room or a toilet is where people expect not to be watched. GDPR and UK GDPR Art. 5 (fairness) is where the question starts; the NSW Workplace Surveillance Act and the ACT Workplace Privacy Act name these places for sites there. These cameras are listed at the top of the register.

When it is raised
Raised on every camera whose coverage reads as a break room, changing room or toilet, where a regime or a named law is placed at the site.
The question
Why does a camera cover this area, and can it be moved or switched off?
For
your lawyer
The column that settles it
the analytics or coverage column
On the row
a numbered delta and the words "private area" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 5Principles relating to processing of personal data

Principles relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where camera lists usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 5Principles relating to processing of personal data

Article 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What a reviewer asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
Where camera lists usually fall short: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR, read 29 Sep 2026

Australian Privacy Principles (APPs)

APP APP 3Collection of solicited personal information

APP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.

What a reviewer asks to see: Justification of necessity for collection; Lawful and fair collection methods; Heightened protection for sensitive information
Where camera lists usually fall short: Over-collection; Unlawful/unfair collection; Sensitive info collected without consent
Source: Australian Privacy Principles (APPs), read 29 Sep 2026

California Consumer Privacy Act (CCPA, as amended by the CPRA)

CCPA s. 1798.100(c)Data minimisation, necessity and proportionality

Data Minimisation, Necessity and Proportionality. A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.

What a reviewer asks to see: Record of processing showing, per data element, the purpose it was collected for; Documented necessity and proportionality assessment for each collection purpose; Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds; Compatibility analysis for any secondary use, referencing the context of collection; Approval record showing a new use was assessed before it went live
Where camera lists usually fall short: A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose; Necessity assessed once at launch and never revisited as the product changed; Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner; Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected; Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

Named, not quoted

See the specimen list run Map your own list