Video surveillance is one of the most widely used tools by physical retail to protect premises against theft, vandalism and other incidents. It is also one of the areas where the AEPD (the Spanish Data Protection Authority) has intervened most frequently: poorly oriented cameras, indefinite retention of recordings, absence of signage or covert purposes other than security.
This guide sets out how a shop can install and operate a video surveillance system with full safeguards under the GDPR (Regulation (EU) 2016/679), art. 22 LOPDGDD (Spain's Organic Law 3/2018) and the public criteria of the Spanish Data Protection Authority.
Legitimate purpose: the foundation of the system
The first requirement of a video surveillance system in a shop is that its purpose is clear and well-defined. Art. 22 LOPDGDD authorises the processing of images for the purpose of preserving the safety of persons and goods, as well as their premises. That is the typical purpose of a shop: protection against theft, robbery, damage or assault.
The usual legal basis is the controller's legitimate interest (art. 6(1)(f) GDPR), not the customer's consent. There is no need to ask permission of whoever enters the shop: it is enough to comply with the duty of information through signage and the available extended information.
Different purposes require different bases and, in some cases, are directly inadmissible:
| Purpose | Legal basis | Viability |
|---|---|---|
| Safety of persons and goods | Legitimate interest (6(1)(f)) + art. 22 LOPDGDD | Allowed with signage |
| Workforce monitoring of employees | Art. 20.3 Spanish Workers' Statute + art. 89 LOPDGDD | Requires express information to the worker |
| Customer behaviour analysis (heatmap, counting) | Legitimate interest or consent, depending on solution | Subject to analysis and specific additional information |
| Audio recording on the floor | Strict restrictions | Only in exceptional and justified cases |
| Publication on the shop's social media or website | Express consent of those recorded | Inadmissible without consent |
Areas where you can and cannot point cameras
The guiding criterion is minimisation: the system captures only what is strictly necessary for the safety purpose. In practice:
- Allowed areas: accesses, shop windows from the inside, checkout line, retail aisles, display areas, internal warehouse, own loading dock, shop's private car park.
- Prohibited areas: toilets, changing rooms and staff break areas. Privacy prevails absolutely.
- Public highway: the shop may not record the street, save for the strip strictly necessary to monitor access to the premises. Capturing the full pavement, passers-by or the façade of the neighbouring shop is not permissible.
- Adjoining premises and entrances: cameras may not point at others' accesses, shop windows of adjacent shops or neighbouring homes. Where technically feasible, privacy masks in the system software are used to mask out those areas.
- Checkout line: allowed, but it is advisable to orient the camera to capture the transaction and the customer's space, without pointing the lens directly at the POS monitor or the keypad where sensitive codes are entered.
Information signage and extended information
The duty to inform (art. 13 GDPR) is met in video surveillance at two levels. First, through the information sign visible at each access to the surveilled area, following the indicative model published by the AEPD. Minimum content:
- Camera pictogram and mention of "surveilled area".
- Identity of the controller (shop trade name and CIF).
- Purpose: security.
- Legal basis: legitimate interest.
- Reference to the exercise of rights and the address or enabled channel.
- Reference to the extended information (URL, counter, leaflet).
Second, the extended information with all the elements of art. 13 GDPR: identity and contact of the controller, DPO where applicable, detailed purposes and legal basis, recipients (law enforcement where applicable), retention periods, rights and route to exercise them, and the right to lodge a complaint with the AEPD. This information is made genuinely available: extended notice at the counter, leaflet, QR code to a URL or printed on request.
Retention period: one month
Art. 22.3 LOPDGDD is categorical: images are retained for a maximum of one month from capture. They may only be retained for longer when they must evidence acts against the integrity of persons, goods or premises, in which case the images are delivered to the competent authority within a maximum of 72 hours of becoming aware of the incident.
Operational implications:
- The DVR/NVR is configured with an automatic overwrite cycle respecting the one-month period.
- Retaining recordings "just in case" beyond that period is not permissible.
- When an incident occurs, the relevant clip is extracted, delivered to law enforcement or reserved for the judicial proceedings, and the rest continues its normal cycle.
- USB or external disk copies relating to a specific incident are kept with appropriate traceability until resolution of the proceedings.
"Video surveillance in a shop is assessed with three very specific questions: what is captured, how long it is kept and who accesses it. If the three answers are reasonable and written down, the system operates normally. When any of the three has been decided by the installer's intuition, problems tend to follow."
Mario P. Talamillo · Managing Partner, Certix®
Access to recordings and custody
Access to the system must be restricted to persons with direct security or management functions: shop owner, store manager and, where applicable, contracted security company. It is not acceptable for the DVR viewer to be open in a shared office area, nor for any employee to be able to review recordings at will.
Good practices:
- Individual password for each user with access to the system.
- Access logging (log of views and exports) when the equipment supports it.
- Equipment physically secured (closed room or cabinet, not in plain sight of the public).
- Where the security company or installer accesses remotely, art. 28 GDPR contract (processor) with all the elements of paragraph 3.
- Periodic review of who retains access (departed staff with valid permissions is a common cause of incidents).
Connected cameras and cloud provider
When the video surveillance system stores in the cloud (IP cameras with recording on the manufacturer's or integrator's service), the service provider is a processor and an art. 28 GDPR contract is required. Points to verify:
- Location of the storage servers and, where applicable, international transfer with an appropriate instrument (Data Privacy Framework where applicable, standard contractual clauses where appropriate).
- Provider security measures (encryption in transit and at rest, access control, audits).
- Procedure for returning recordings on service termination, before any destruction.
- Retention period configuration in line with the one-month legal limit.
- Sub-processors notified and authorised.
Registration in the RoPA and documentation
Video surveillance processing must be entered in the shop's Record of Processing Activities (art. 30 GDPR), with its purpose, legal basis, categories of data, recipients (law enforcement where applicable, judicial authority), retention period and general description of security measures.
Usual associated documentation:
- Floor plan of the premises with location and orientation of each camera.
- Signage delivered and installed at each access.
- Available extended information (art. 13 GDPR text).
- Art. 28 GDPR contract with the installer/maintainer and the cloud provider.
- Incident management protocol (image extraction, delivery to authorities, breach notification template if any).
- Documented retention period configuration of the system.
Minimum video surveillance checklist for retail
- Declared purpose: safety of persons, goods and premises.
- Cameras oriented to allowed areas; zero capture of public highway or adjoining premises (save for the minimum essential strip).
- Information sign at each access following the AEPD model.
- Art. 13 GDPR extended information available and accessible.
- DVR/NVR overwrite cycle configured to one month maximum.
- System access with individual users and view logging where applicable.
- Art. 28 GDPR contracts with installer, maintainer and cloud provider.
- Processing entered in the RoPA and documented incident protocol.
- If there are cameras in the work area, express information to staff (art. 89 LOPDGDD).
Frequently asked questions
Can a shop install video surveillance cameras without permission from the AEPD?
Yes. No prior authorisation is required. Compliance with art. 22 LOPDGDD is required: security purpose, appropriate areas, signage, extended information, one-month maximum retention and registration of the processing in the RoPA.
Where can and cannot a shop install cameras?
Allowed in accesses, shop windows from the inside, checkout line, aisles, warehouse and own loading docks. Prohibited in toilets, changing rooms and break areas. The public highway is only captured in the strip essential to monitor access. Adjoining premises and neighbouring homes may not be pointed at.
How long can the shop retain recordings?
The maximum is one month (art. 22.3 LOPDGDD). If images must evidence an incident, they are delivered to the competent authority within 72 hours of becoming aware. Retaining recordings beyond a month for other purposes is not permissible.
What video surveillance signage must the shop display?
The AEPD model sign at each access, with pictogram, controller identity, purpose, legal basis, exercise of rights and reference to extended information. The art. 13 GDPR extended information is made available at the counter, leaflet or URL.
This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.
Want to review your shop's video surveillance without surprises?
At Certix we assign you a compliance expert specialised in the retail sector. No commercial intermediaries, no generic templates.
Talk to an expert