Kamery a kamerové systémy bez pokut v roce 2025

Key takeaways
Why are cameras both a risk and an opportunity for your company?
However, their installation and operation represent a significant invasion of privacy and are therefore subject to strict legal regulation. This clash of two legitimate interests – the protection of property and the protection of privacy – is at the heart of the entire issue.
The basic legal framework is the General Data Protection Regulation, known as GDPR, and the Czech Act on the Processing of Personal Data. These regulations stipulate that you must have a valid legal basis for monitoring individuals with a camera. In the vast majority of corporate scenarios, this basis will be the so-called legitimate interest of the controller (i.e., your company) in protecting property or security.
However, it is crucial to understand that a legitimate interest is not an automatic right to install cameras anywhere and in any way. You must be able to demonstrate, justify, and defend this interest, proving that it genuinely outweighs the right to privacy of the monitored individuals.
Furthermore, the principle of purpose limitation applies: a camera installed to prevent theft at the entrance cannot, without further justification, be used, for example, to monitor employees' work ethic.
Properly setting up a camera system is therefore not just a technical matter for the IT department or a security agency. It is a strategic decision with direct legal, financial, and reputational impacts that requires a comprehensive approach. The lawyers at ARROWS daily help clients find the right balance between protecting their interests and fulfilling their legal obligations, thereby minimizing their legal and financial risks.
New Rules of the Game: What the DPA's Guidelines Brought and What to Expect in 2025?
The year 2024 brought a fundamental change in the field of camera systems. On February 8, 2024, the Office for Personal Data Protection (ÚOOÚ) issued new, comprehensive guidelines that replace all previous recommendations and respond to the evolution of practice and technology since the introduction of GDPR.
Although the guidelines are not law, they are essentially the manual by which the ÚOOÚ will proceed during inspections. Ignoring them is therefore a high-stakes gamble.
The most significant new feature is that the guidelines explicitly apply to camera systems in online mode, i.e., without making a recording. The mere real-time transmission of images of identifiable persons is considered the processing of personal data, with all the obligations that arise from GDPR.
The time when some operators could believe that GDPR did not apply to them simply by watching a monitor without recording is definitively over.
These new rules essentially mean the end of "plausible deniability." By also providing sample documents, such as a balancing test or information signs, the ÚOOÚ is making it clear what it expects from companies.
[CONTACT_BANNER]Insufficient or missing documentation is no longer an excusable mistake but a clear violation of the rules. The burden of proof has completely shifted to the operator, who must be able to document the legitimacy and lawfulness of their system even before it is launched.
This shift makes expert legal advice not a luxury, but an absolute necessity for any company that is serious about protecting its assets and complying with the law. The lawyers at ARROWS have already analyzed these new guidelines and implemented their requirements into practice for their clients, which include more than 150 joint-stock companies and 250 limited liability companies.
Step 1: Do you have a compelling reason? How to pass the balancing test
The cornerstone of any legal camera system operated on the basis of a legitimate interest is the so-called balancing test. This is not a mere formality, but a key document in which you must carefully and convincingly justify why your interest in monitoring is stronger than the right to privacy of employees, customers, or visitors. You must conduct and document this test before installing the cameras.
According to the ÚOOÚ guidelines, the balancing test has four basic steps:
1. Real threat criterion: You must describe and document that your company is facing a real and objective danger. A subjective feeling of "what if" is not enough. It is ideal to rely on concrete data – records of past thefts or vandalism, police crime statistics for the area, or documented incidents.
2. Necessity criterion: At this stage, you must consider whether the stated goal can be achieved by other, less invasive means. You need to justify why, for example, better locks, bars, an alarm, more frequent security patrols, or just installing dummy cameras are not sufficient.
3. Suitability criterion: Here you analyze whether the proposed camera system is actually a suitable and effective solution to the problem. You assess, for example, whether the chosen location and quality of the cameras will allow for the identification of the perpetrator, and you also consider the cost-benefit ratio.
4. Proportionality criterion: In the final step, you make the final consideration. You weigh your legitimate interest (e.g., protecting valuable equipment) against the degree of intrusion into the privacy of the data subjects. The conclusion must be that your interest clearly prevails.
A well-prepared balancing test is not just a bureaucratic necessity for a potential inspection from the ÚOOÚ. It also acts as a strategic legal shield. In the event of any dispute – whether with an employee who feels unjustly monitored or with a customer – this document is key evidence that your company acted reasonably, transparently, and in accordance with the law.
ARROWS specializes in preparing balancing tests that will stand up to scrutiny. It's not just about filling out a template, but about creating an argumentatively strong document that will truly protect your company.
Step 2: Correct setup and operation – key obligations in practice
Successfully conducting a balancing test is just the beginning. The operation of the camera system itself must meet other strict requirements.
Where to place cameras and what to avoid?
The basic principle is data minimization. This means you should only monitor the space that is strictly necessary to achieve the stated purpose. A camera protecting the entrance to a building should not capture the entire street or the windows of the opposite house. The shot must be limited to the necessary minimum.
There are also areas where monitoring is completely prohibited, with very few exceptions. These are primarily places where people reasonably expect a high degree of privacy, such as toilets, showers, changing rooms, or employee break rooms.
How long can you store recordings?
The retention period for recordings must be proportionate to the purpose. The ÚOOÚ recommends a maximum of 72 hours to one week as a standard and usually easily defensible period. This timeframe is generally sufficient to detect any incident (theft, vandalism) and secure the recording for further action.
Any longer retention period must be specially and compellingly justified. The technical capacity of the recording device cannot be the reason. A reason could be, for example, the extended absence of a responsible person during holidays or the specific nature of the operation, but you must always be able to defend it.
What do I need to do to meet the documentation obligation?
GDPR abolished the previous obligation to register camera systems with the ÚOOÚ. Instead, however, it introduced an obligation for every controller to maintain so-called Records of Processing Activities under Article 30 of the GDPR.
For a camera system, this document must contain at least the identification of your company, the purpose of monitoring, a description of the monitored persons (e.g., employees, customers), a description of the data (video recording), any recipients (e.g., police, insurance company), the retention period, and a description of the technical and organizational security measures.
ARROWS provides a complete service in creating internal policies for camera operation, which precisely define these operational details and serve as a key basis for any inspection. We also offer expert training for employees who work with the system, including a certificate.
Step 3: An information duty that actually works
People entering a monitored area must be aware of it before they enter. They must have the opportunity to decide whether or not to be monitored. Fulfilling this information obligation is best handled in practice using a so-called two-layer approach.
The first layer is an information sign, which must be visibly placed at all entrances to the monitored area. A small camera pictogram is not enough. According to the ÚOOÚ guidelines, it should contain:
A clear camera pictogram.
Text: “This area is monitored by a camera system”.
Identification and contact details of the controller (your company).
A brief statement of the purpose (e.g., “Protection of property and persons”).
A link to the second layer of information (e.g., “More information at www.yourcompany.com/gdpr” or “at the reception”).
The second layer is a detailed information document that must be easily accessible (for example, on the mentioned website or upon request at the reception). This document must contain all the information required by Article 13 of the GDPR, including all the rights of data subjects (the right of access to the recording, the right to erasure, the right to lodge a complaint with the ÚOOÚ, etc.).
ARROWS prepares complete information packages for clients, from the wording of the signs to detailed personal data protection policies, which are understandable to laypeople and legally sound.
The most common mistakes and how to avoid them
The following table summarizes the most common offenses companies commit when operating cameras and shows how they can be prevented.
Possible problems | How ARROWS helps (consultation@arws.cz) |
Missing or formal balancing test → Unlawful processing, fine from the ÚOOÚ in the range of hundreds of thousands to millions of CZK, indefensible system during an inspection. | Preparation of a robust balancing test that details the legitimate interest and will stand up to inspection. |
Improper camera placement (e.g., filming public spaces, neighbors' privacy, employee break areas) → Invasion of privacy, lawsuits for protection of personal rights, fines from the ÚOOÚ and the Labour Inspectorate. | Legal consultation and review of the camera system project to ensure compliance with the principle of minimization. |
Excessively long record retention period → Violation of GDPR, increased risk of data leakage, fine from the ÚOOÚ for non-compliance with the storage limitation principle. | Preparation of an internal policy that sets and justifies a reasonable retention period for recordings. |
Insufficient information duty (missing or incomplete signs) → Non-transparent processing, fine from the ÚOOÚ, complaints from data subjects. | Preparation of complete documentation to fulfill the information duty (signs, detailed information). |
Missing records of processing activities → Violation of Art. 30 GDPR, inability to demonstrate compliance during an inspection, fine. | Creation of the legally required records of processing activities for the camera system. |
Inadequate security of the system and records → Risk of data leakage, hacker attack, misuse of records. High fines and reputational damage. | Legal consultation on setting up technical and organizational measures and reviewing contracts with IT/security service providers. |
Unregulated relationship with the supplier/security agency → Joint liability for GDPR violations if a proper data processing agreement is not in place. | Preparation or review of data processing agreements according to Art. 28 GDPR. |
Special cases: Cameras in the workplace and international aspects
In addition to the basic rules, there are also specific situations that require increased attention and often a different approach.
Monitoring your employees? Beware of the Labour Code
Monitoring employees is one of the most sensitive areas. It is subject to a dual legal regime – in addition to GDPR, the Labour Code also applies. Section 316 of the Labour Code states that an employer may only interfere with an employee's privacy in the workplace if there is a "serious reason based on the special nature of the employer's activity".
This is a significantly stricter condition than the general legitimate interest under GDPR. The reason could be, for example, protection against theft in a jewelry store or ensuring safety in a chemical plant, but it would be difficult to justify in a regular office. Violation of these rules carries a fine not only from the ÚOOÚ, but also from the State Labour Inspection Office, up to CZK 1,000,000.
Storing data in the cloud or have branches abroad?
Using cloud storage for camera recordings, especially if the servers are located outside the European Union, constitutes a cross-border transfer of personal data and requires additional legal safeguards.
Similarly, if your company has branches in other EU countries, you must take into account that although GDPR applies everywhere, its application and national specifics may differ. For example, Germany has stricter rules for monitoring public spaces (§ 4 BDSG), and in Austria, a maximum retention period of 72 hours is considered standard.
This international "legal mosaic" poses a significant risk for companies with international operations. Thanks to our ARROWS International network, built over ten years, we handle cases with an international element daily and ensure that our clients comply not only with Czech but also with local requirements in Poland, Slovakia, Germany, and other countries.
Advanced risks for larger companies and international corporations
For larger companies and corporations with more complex operations, other, more serious risks emerge that require an expert approach.
Possible problems | How ARROWS helps (consultation@arws.cz) |
Unlawful monitoring of employees (without meeting the conditions of the Labour Code) → Fine from the Labour Inspectorate (up to 1 million CZK), fine from the ÚOOÚ, labour disputes, damage to employer's reputation. | Legal opinions on assessing the legality of employee monitoring and preparation of internal policies in compliance with both GDPR and the Labour Code. |
Failure to conduct a Data Protection Impact Assessment (DPIA) for high-risk systems → Mandatory for large-scale monitoring (e.g., shopping centers, transport). Violation of Art. 35 GDPR, high fine. | Preparation of a complete DPIA that systematically analyzes and minimizes risks to the rights of data subjects. |
Storing records in a non-EU cloud without proper safeguards → Unlawful transfer of personal data to third countries, violation of Chapter V of GDPR, high fines. | Review of contracts with cloud service providers and securing appropriate legal instruments (e.g., SCCs) with the support of the ARROWS International network. |
Using cameras with advanced features (biometrics, facial recognition) → Processing of special categories of personal data, which is prohibited with few exceptions. Extremely high risk and penalties. | Urgent legal consultation to assess legality and immediately implement corrective measures to prevent sanctions. |
Ignoring requests from data subjects (e.g., for a copy of a recording) → Violation of data subject rights (Art. 15 GDPR), complaints to the ÚOOÚ, fines for inaction. | Implementation of internal processes for handling requests and representation in communication with data subjects and authorities. |
Sharing records with unauthorized third parties (e.g., posting on social media) → Gross violation of GDPR, possible criminal consequences, lawsuits for protection of personal rights. | Expert training for management and employees on the rules for handling records and managing security incidents. |
When the worst happens: An inspection from the authorities and how to defend yourself
An inspection from the ÚOOÚ or the Labour Inspectorate can happen at any time, often based on a tip from a disgruntled employee, customer, or even a competitor. The first thing inspectors will ask for is complete documentation – the balancing test, records of processing activities, internal policies, and proof of fulfilling the information duty.
In such a situation, preparedness is absolutely key. If you have all your documentation in order, professionally prepared, and corresponding to reality, the inspection often becomes a mere formality. If the documentation is missing or insufficient, you open the door to lengthy proceedings and significant penalties.
With complete and high-quality documentation from ARROWS, an inspection is a mere formality. Should a problem still arise, we provide full representation before administrative authorities and defend our clients' rights at every stage of the proceedings.
Why handle cameras with ARROWS?
As this article shows, the legislation concerning camera systems is complex, dynamic, and hides significant risks. Professional legal advice in this area is not an expense, but an investment in the security and stability of your business.
ARROWS offers comprehensive services that cover all aspects of operating camera systems:
From drafting internal policies, through preparing complete documentation that will protect you from fines, to legal consultations, preparing and reviewing contracts with suppliers, representing you before authorities, and providing expert training for your employees.
Our experience is based on long-term cooperation with more than 150 joint-stock companies, 250 LLCs, and 51 municipalities and regions. We know what works in practice and what to watch out for.
Thanks to the ARROWS International network, we are also able to effectively handle complex cases with a cross-border dimension. What's more, we are happy to connect our clients if we see interesting business opportunities, and we are always ready to listen to your business ideas.
Don't wait for an inspection and a fine. Contact us today and arrange a no-obligation consultation. Our team of experts is ready to assess your situation and propose a solution that will give you peace of mind.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.


