Data Protection & AI

Video surveillance in Austria: What you need to consider from a data protection perspective

A guide to the legal requirements for video surveillance in Österreich. Information on GDPR and Austrian Data Protection Act (DSG) compliance, data subject rights, and practical implementation.

The installation and operation of video surveillance systems raise complex legal questions in Austria. Since the GDPR came into force and the amendment of the Austrian Data Protection Act, operators of surveillance cameras must comply with a dense web of regulations. Here, we examine the legal framework and provide practical guidance on legally compliant implementation.

Video surveillance data protection

Table of Contents

The legal framework of video surveillance

In the private sphere, an important distinction applies first of all: recordings in the purely private or familial sphere are fundamentally exempt from data protection regulations, but this exception does not apply if public space is also captured. This is the case, for example, when a security camera also films the sidewalk in front of a private property.

The Three Pillars of Privacy-Compliant Video Surveillance

The first pillar is the legitimate purpose. This must be concretely defined and comprehensible. Classic examples are the protection of property against theft or vandalism, or personal security. The purpose must be determined (and ideally also documented) before the surveillance system is installed.

The second pillar is the legal basis. In practice, video surveillance is usually based on the operator's „legitimate interest“ – e.g., securing evidence in the event of criminal offenses. This interest and the rights of the data subjects (i.e., those recorded) must be carefully weighed against each other. Factors such as the intensity of the intrusion, the number of people affected, and the necessity of the surveillance play a role here.

The third pillar is compliance with data protection regulations during the operation of video surveillance. This primarily includes ensuring data security (protection of data against unauthorized access) and safeguarding the rights of data subjects. These comprise the right to information, access, erasure, and objection. Transparency is particularly important: data subjects must be able to clearly recognize that they are under video surveillance before entering the monitored area.

Specific requirements of the Austrian Data Protection Act (DSG)

The Federal Act on Data Protection (DSG) specifies the general requirements of the GDPR and establishes additional requirements. The DSG provides for scenarios in which video surveillance is generally permissible and, on the other hand, certain forms of video surveillance that are generally impermissible. For example, privately used properties may generally be video-monitored provided that only as much of the public space is captured as is strictly necessary to achieve the purpose of the surveillance.

However, the legislature has also drawn clear boundaries: for example, the surveillance of the most private sphere of life is taboo. This affects, for example, changing rooms, toilets, or wellness areas. Targeted surveillance of employees in the workplace is also prohibited.

Finally, the DSG stipulates from a technical perspective that recordings must be tamper-proof. Every access to the data must be logged. The storage period is fundamentally limited to 72 hours. Longer retention is only permissible in exceptional cases if a specific incident justifies it, such as for securing evidence after a break-in.

Practical implementation of legally compliant video surveillance

The implementation of data protection-compliant video surveillance therefore requires careful planning. It is recommended to create detailed documentation even before commissioning, which describes the purpose of the surveillance, the areas captured, and the technical security measures. The signage must be placed in such a way that it can be noticed before entering the monitored area.

If business premises are monitored by video, corresponding documentation must exist in any case. In addition, concrete organizational measures must be implemented within the company and clear responsibilities defined: Who is allowed to access the recordings? How is deletion after 72 hours ensured? How are requests for information handled?

These questions should be answered in a procedural documentation. For larger systems, a data protection impact assessment may also be required.

Conclusion

Therefore, the commissioning of a video surveillance system should be well thought out. Those affected by unlawful video surveillance can file a complaint against it and under certain circumstances even claim damages. For further information and individual consultation, please contact Matija Pfefferkorn and Roman Taudes at the phone number 01 3912345 or by email office@atb.law available.

More articles

EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note
Picture of Stefan Knotzer
Stefan Knotzer
Laptop is losing data

Data Breach: The Devil Never Sleeps

What Austrian companies can learn from the incident at a major US law firm
Picture of Stefan Knotzer
Stefan Knotzer