CCTV Privacy Law Mapper
Workplace cameras

Workplace CCTV laws in the UK, the EU and Australia

Cameras that watch staff at work raise questions a customer-facing camera does not: break rooms, changing rooms and toilets, analytics that may infer emotion, face matching of staff, and the works council.

The findings that turn on staff

Workplace CCTV laws in the UK

UK GDPR applies to every camera at a UK site: a basis for each purpose (Art. 6), fairness and data minimisation (Art. 5), notice (Art. 13), and an assessment where the processing is likely to result in a high risk (Art. 35). The ICO guidance on video surveillance is named, not quoted.

Workplace CCTV laws in Australia

The APPs apply where the Privacy Act applies to you. The employee records exemption, Privacy Act (Cth), section 7B(3), is named, not quoted: it does not reach customers or visitors, so a camera that captures them as well as staff raises finding 18 as a question. Queensland's Invasion of Privacy Act (Qld) 1971 is named for audio. The state acts do most of the workplace work and are named, not quoted: Workplace Surveillance Act (NSW) 2005, Workplace Privacy Act (ACT) 2011 and Surveillance Devices Act (Vic) 1999.

Workplace CCTV in the EU and Germany

The EU AI Act reaches workplace cameras through their analytics: Art. 5 on emotion recognition in the workplace, Art. 26 on a deployer of a high-risk system informing workers and their representatives. In Germany Works Constitution Act, section 87(1)(6) gives the works council its say, named, not quoted.

The clauses

GDPR Art. 5Principles relating to processing of personal data

Principles relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where camera lists usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
UK GDPR Art. 5Principles relating to processing of personal data

Article 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What a reviewer asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
Where camera lists usually fall short: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR, read 29 Sep 2026
APP APP 3Collection of solicited personal information

APP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.

What a reviewer asks to see: Justification of necessity for collection; Lawful and fair collection methods; Heightened protection for sensitive information
Where camera lists usually fall short: Over-collection; Unlawful/unfair collection; Sensitive info collected without consent
Source: Australian Privacy Principles (APPs), read 29 Sep 2026
CCPA s. 1798.100(c)Data minimisation, necessity and proportionality

Data Minimisation, Necessity and Proportionality. A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.

What a reviewer asks to see: Record of processing showing, per data element, the purpose it was collected for; Documented necessity and proportionality assessment for each collection purpose; Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds; Compatibility analysis for any secondary use, referencing the context of collection; Approval record showing a new use was assessed before it went live
Where camera lists usually fall short: A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose; Necessity assessed once at launch and never revisited as the product changed; Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner; Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected; Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
EU AI Act Art. 5The practices listed in Article 5

Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education, biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).

What a reviewer asks to see: Pre-deployment screening against the Art.5 prohibition list; Documented assessment that the system does not fall under a prohibited category
Where camera lists usually fall short: Deploying an Art.5-prohibited practice; Treating exceptions as routine basis
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systems

Transparency obligations for providers and deployers of certain AI systems. Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interacting with AI, label synthetic content in a machine-readable format, and disclose deepfakes and AI-generated public-interest text (subject to free-expression and artistic exceptions).

What a reviewer asks to see: User-facing AI-interaction notification; Machine-readable labelling of synthetic content; Deepfake/AI-text disclosure
Where camera lists usually fall short: No disclosure that the user is interacting with AI; Synthetic content not machine-readably labelled
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 26Obligations of deployers of high-risk AI systems

Obligations of deployers of high-risk AI systems. Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What a reviewer asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
Where camera lists usually fall short: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 6Classification rules for high-risk AI systems

Classification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.

What a reviewer asks to see: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation; A trigger that re-runs classification when Annex III is amended or the intended purpose changes; Registration of the not-high-risk conclusion in the EU database as required by Art.49(2)
Where camera lists usually fall short: Classification decided once at design time and never revisited when the intended purpose broadened; The Art.6(3) derogation relied on without the documented assessment that is the condition of using it; A profiling system routed through the derogation, which the Regulation forecloses; Only Annex III considered, so a safety component falling under Annex I legislation is missed
Source: EU AI Act, read 29 Sep 2026

See the specimen list run Map your own list