Workplace CCTV laws in the UK, the EU and Australia
Cameras that watch staff at work raise questions a customer-facing camera does not: break rooms, changing rooms and toilets, analytics that may infer emotion, face matching of staff, and the works council.
The findings that turn on staff
- 11 Camera covering a staff-only private areaRaised on every camera whose coverage reads as a break room, changing room or toilet, where a regime or a named law is placed at the site.
- 17 Workplace surveillance law named for this siteRaised on every camera where staff are present (or the coverage could not be read) at a site in Germany, New South Wales or the ACT.
- 18 Employee records exemption: does it reach this footage?Raised on a camera at an Australian site where staff are present and you said the Privacy Act applies to you (or you are not sure).
- 2 Behaviour or emotion alerts over an area where staff work, at an EU siteRaised on a camera at an EU site whose analytics read as behaviour or emotion alerts and whose coverage has staff present (or could not be read).
- 12 High-risk AI use in an EU workplaceRaised on a face matching camera at an EU site where staff are present (or the coverage could not be read).
- 1 Face matching or face recognition: biometric identificationRaised on every camera whose analytics read as face matching or face recognition, where a regime or a named law is placed at the site. Face detection or blurring never raises it.
- 15 Covert cameraRaised on a camera whose covert column reads yes, at any site; with no clause or named law for the site it reads as a question with none.
Workplace CCTV laws in the UK
UK GDPR applies to every camera at a UK site: a basis for each purpose (Art. 6), fairness and data minimisation (Art. 5), notice (Art. 13), and an assessment where the processing is likely to result in a high risk (Art. 35). The ICO guidance on video surveillance is named, not quoted.
Workplace CCTV laws in Australia
The APPs apply where the Privacy Act applies to you. The employee records exemption, Privacy Act (Cth), section 7B(3), is named, not quoted: it does not reach customers or visitors, so a camera that captures them as well as staff raises finding 18 as a question. Queensland's Invasion of Privacy Act (Qld) 1971 is named for audio. The state acts do most of the workplace work and are named, not quoted: Workplace Surveillance Act (NSW) 2005, Workplace Privacy Act (ACT) 2011 and Surveillance Devices Act (Vic) 1999.
Workplace CCTV in the EU and Germany
The EU AI Act reaches workplace cameras through their analytics: Art. 5 on emotion recognition in the workplace, Art. 26 on a deployer of a high-risk system informing workers and their representatives. In Germany Works Constitution Act, section 87(1)(6) gives the works council its say, named, not quoted.
The clauses
GDPR Art. 5Principles relating to processing of personal dataPrinciples relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
UK GDPR Art. 5Principles relating to processing of personal dataArticle 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
APP APP 3Collection of solicited personal informationAPP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.
CCPA s. 1798.100(c)Data minimisation, necessity and proportionalityData Minimisation, Necessity and Proportionality. A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.
EU AI Act Art. 5The practices listed in Article 5Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education, biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systemsTransparency obligations for providers and deployers of certain AI systems. Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interacting with AI, label synthetic content in a machine-readable format, and disclose deepfakes and AI-generated public-interest text (subject to free-expression and artistic exceptions).
EU AI Act Art. 26Obligations of deployers of high-risk AI systemsObligations of deployers of high-risk AI systems. Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.
EU AI Act Art. 6Classification rules for high-risk AI systemsClassification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.