The short answer
Use Data Protection Day on 28 January 2027 as the fixed annual date for a structured privacy sweep of your cameras, AI and guest data. Work through 12 checks: lawful basis per camera, private zones, audio, signage, retention and access rights, AI risk classification, biometrics, guest records, processors, incidents and staff training. Run the full checklist once a year and lighter spot checks quarterly.
Key takeaways
- Data Protection Day falls on 28 January every year (the anniversary of Convention 108, signed in 1981) and is a reliable anchor for an annual privacy audit at hotels, resorts and event venues.
- Each camera needs a specific, documented purpose; a generic label such as "for your safety" is not enough under EDPB guidance, and legitimate interest rather than consent is usually the working basis for ordinary CCTV.
- Cameras should not cover genuinely private areas (guest rooms, toilets, changing rooms), audio recording is hard to justify and should normally stay off, and layered signs plus a privacy notice are expected.
- Footage should be kept no longer than needed and overwritten or deleted automatically; if monitoring is high-risk (staff monitoring, vulnerable people), a data protection impact assessment is expected before rollout.
- Plain recording usually sits outside the EU AI Act's high-risk regime, but face recognition is high-risk biometric processing; standalone Annex III high-risk obligations are expected to apply from 2 December 2027 after the AI "Omnibus" delay, subject to final adoption.
- This article gives general EU/UK guidance, not legal advice; requirements vary by country and by the exact camera and AI configuration.
Why 28 January and how to run the checklist
Data Protection Day has been marked on 28 January since 2006, when the Council of Europe's Committee of Ministers chose the date to recall the anniversary of Convention 108, signed on 28 January 1981. For a venue operator that hosts guests, the date is a practical annual anchor: block out the last week of January for a full privacy sweep rather than trying to fix everything on the day itself.
A calendar format keeps the audit honest. Sector practice and regulator guidance agree that privacy is about how the system actually runs, not just a policy file. The Information Commissioner's Office (UK) and the European Data Protection Board's guidance on video devices both emphasise documented purposes, visible signage, restricted retention and controlled access.
Jurisdiction matters: this article explains the EU GDPR / UK GDPR approach and notes where EU AI Act deadlines sit as of early 2027. It is general information to support self-audit, not legal advice for your specific venue.
- January: full 12-point sweep.
- Quarterly: spot checks on cameras, access and retention.
- Immediately: log any incident or guest complaint.
Cameras: purpose, lawful basis and layout
Start with the purpose for every camera and write it down. The EDPB guidance on video devices warns that a purpose as vague as "for your safety" is not specific enough; identify what each camera is there to protect — guests, staff, property, entry control — and make sure the technical setup matches that purpose.
For most ordinary CCTV in a venue, the realistic lawful basis under the GDPR is legitimate interest rather than consent, because asking every guest to consent before entering is impractical. But the interest must be balanced against privacy expectations: cameras belong in entrances, exits, corridors, car parks, reception and event floors, not in guest rooms, toilets, changing rooms or other genuinely private areas. If a private area truly needs coverage (for example repeated serious incidents), document the strong justification and tell people clearly.
Audio is a separate decision. Many cameras can record sound, but that does not mean they should. Recording conversations is highly intrusive and usually hard to justify on a lawful basis; where audio genuinely helps, keep it switchable and rare rather than continuous, and disclose it.
- Build a register: where each camera is, what it captures and why.
- Remove or mask coverage of genuinely private zones.
- Verify signs are visible before a person enters the recorded area.
Transparency, access rights and retention
Transparency should be layered. A clear sign at the entrance tells people they are being recorded and how to ask questions, while the fuller detail — lawful basis, retention period, who has access, who footage is shared with — sits in the privacy notice that people can reach without entering the monitored zone. Regulator guidance recommends making this available both digitally and on paper.
Data subjects have rights over footage that identifies them, most commonly the right of access. Your system must be able to retrieve stored footage and to redact or blur third parties before disclosure. If use of CCTV creates high risk — for example staff monitoring or recording vulnerable people — you should carry out a data protection impact assessment before going live, and if the risk cannot be reduced you may need to consult your supervisory authority.
Retention should be short and defined. In many countries a few days to a few weeks is enough for typical security purposes; keep it only as long as needed, enable automatic overwrite, and protect the archive with passwords and role-based access. Footage held too long or leaked is a personal data breach in the making.
- Document retention periods and switch on automatic overwrite.
- Test that footage can be retrieved, redacted and securely shared.
- Check whether a DPIA was (or should be) completed.
AI and analytics: where the regulation is heading
Not every camera feature is "AI" in the regulatory sense. Simple recording is not high-risk under the EU AI Act, and even lighter analytics — anonymous people counting, occupancy heatmaps, object detection — is generally less intrusive. The EDPB's analysis already distinguishes between low-intrusion counting algorithms and complex biometric techniques, and regulators expect you to treat them differently.
The picture changes when a system recognises faces or otherwise identifies and classifies individuals. Under the GDPR, biometric recognition through video normally needs explicit consent or a clear legal basis plus a DPIA; the AI Act lists biometric identification as a high-risk area, and some uses are prohibited outright, such as emotion recognition in the workplace. If your vendor has quietly enabled face recognition or attribute classification, that is a material change to your processing.
On timing: the original August 2026 application date for standalone high-risk systems listed in Annex III was postponed by the EU's AI "Omnibus" simplification, with obligations now expected to apply from 2 December 2027. As of the drafting of this article that change was agreed in trilogue but not yet fully enacted, so confirm the current status before relying on it. The practical point is unchanged: document the intended purpose of any AI module and check whether it pushes the system toward high-risk classification and who is accountable for that decision.
- List which AI functions your camera vendor has switched on.
- Keep anonymous statistics separate from identity-based processing.
- For face recognition, secure explicit consent, a DPIA and clear documentation.
- Re-check the AI Act timeline, as schedules are still being settled.
Guest data: registration, minimisation and processors
A hotel, resort or event venue holds a lot of guest data: name and contact details from bookings, identity or passport data required for registration, payment card details, dietary and accessibility notes, and CCTV footage. The guiding principle is collection minimisation — gather only what you actually need for the booking, the stay, payment and any legally required registration, and drop optional fields that serve no purpose.
Check every disclosure to third parties: property management and booking systems, Wi-Fi and loyalty providers, payment processors, cleaning and security contractors, and authorities where registration law requires it. Each transfer needs a lawful basis and, where the recipient is a separate controller or processor, a contract. Review your processor agreements at least annually and confirm where data is hosted.
Access control is where governance is won or lost. Staff at reception and security handle passport scans and archive footage; role-based permissions, audit logs and a clear owner for the CCTV system reduce both insider misuse and accidental exposure. When a guest asks what you hold, you should be able to produce a clear picture of the data you have and where it flows.
- Map every guest data set and its lawful basis.
- Verify each processor contract (PMS, Wi-Fi, payment, security).
- Set role-based access and audit logs for guest records and footage.
Governance: incidents, training and the annual calendar
Close the audit with the organisational layer: name a person accountable for data protection, keep a register of cameras and their purposes, and run a log of subject requests and incidents. Define who may release footage — to a guest, an insurer or law enforcement — and under what conditions.
Build a response process before you need it: where a guest sends a data subject request, who handles it, how third parties in footage get redacted, how a breach is assessed and whether the supervisory authority must be notified. Train front-of-house and security staff so they know what they may show or share, and update the training as systems and law change.
The calendar turns all of this into routine: a full sweep around Data Protection Day each January, quarterly spot checks, an annual review of vendor contracts, and updates whenever you add a camera, an AI module or a new way of handling guest data. That is how a one-day observance becomes a working habit rather than a poster campaign.
- Confirm who is accountable and maintain an incident log.
- Keep privacy notices and processor contracts current.
- Deliver staff training at least once a year.
Put it into practice
Data Protection Day 2027: 12-Point Camera, AI & Guest-Data Checklist
Print or copy this into a working document and run the full cycle once a year around 28 January, marking each item as OK / action needed / needs legal advice. Repeat items 1, 4, 7 and 10 quarterly as spot checks.
- 1. Camera register: each camera has a location, field of view and a specific documented purpose.
- 2. No camera covers guest rooms, toilets, changing rooms or other genuinely private zones; surplus coverage is masked.
- 3. Layered notice in place: visible signs before entering the area plus a privacy notice with lawful basis, retention and contacts.
- 4. Retention limits set and automatic overwrite enabled; archive access is password-protected and role-based.
- 5. Footage can be retrieved, third parties redacted, and access/disclosure requests answered within the required time.
- 6. A data protection impact assessment exists (or is justified as unnecessary) for high-risk monitoring such as staff or vulnerable-person coverage.
- 7. Audio recording is off unless genuinely justified, and is disclosed where used.
- 8. AI functions are inventoried: plain recording, anonymous analytics and identity-based processing are separated and documented.
- 9. Face recognition or biometric classification, if any, has explicit consent or another clear basis plus a DPIA; prohibited uses (e.g. workplace emotion recognition) are absent.
- 10. Each third-party transfer (PMS, Wi-Fi, payment, security, authorities) has a lawful basis and a written agreement.
- 11. Guest data sets are mapped and minimised; role-based access and audit logs cover records and footage.
- 12. Someone is accountable, an incident and request log is maintained, and staff were trained within the last 12 months.
Questions people ask
Do I need consent to run CCTV over guests in the EU or UK?
Usually not for ordinary CCTV. Under the GDPR/UK GDPR the realistic basis is typically legitimate interest, because obtaining genuine, freely given consent from every person who enters is impractical, and consent implies a choice that a guest effectively does not have. What you must do instead is document the specific purpose, ensure the coverage is proportionate (no genuinely private areas), provide clear signage and a privacy notice, keep footage no longer than needed, and control access. If you add biometric recognition such as face identification, explicit consent or another clear basis plus a data protection impact assessment is normally required.
Is my camera 'AI' and subject to the EU AI Act?
Merely recording video is not an AI system under the EU AI Act. The AI Act targets software that analyses data with machine-learning or logic-based techniques. Light features such as anonymous people counting or object detection are generally lower risk, but facial or biometric recognition and behavioural analytics sit closer to high-risk categories, and some uses are prohibited, for example emotion recognition in the workplace. Standalone high-risk systems listed in Annex III were expected to face obligations from 2 August 2026, but the EU's AI 'Omnibus' postponed that to 2 December 2027; confirm the final adopted status before relying on it.
How long can I keep CCTV footage of guests?
There is no single EU-wide period; the GDPR's storage limitation principle says you may keep footage only as long as needed for the stated purpose. For typical venue security a few days to a few weeks is commonly sufficient, and national laws may set specific limits. The safest approach is a short, documented retention period with automatic overwrite, extended only when an incident or investigation genuinely requires it. Whatever period you choose, it should appear in your privacy notice and be enforced by the system rather than left to staff memory.
A guest asked for footage they appear in. What do I do?
Treat it as a data subject access request. Because footage usually shows other identifiable people, you should not hand over the raw recording as-is. Retrieve the relevant clip, redact or blur the faces of third parties, and provide only the portion concerning the requesting guest. Keep a log of the request and the response. If the footage is also needed by law enforcement or insurers, handle that through a defined internal process and, when in doubt, seek legal advice, as procedures differ by jurisdiction.
When do I need a data protection impact assessment (DPIA) for cameras?
A DPIA is expected when processing is likely to result in high risk to individuals. For video surveillance that often means monitoring staff, recording vulnerable people (for example in care or children's settings), large-scale systematic monitoring, or combining footage with biometric identification. EDPB guidance indicates that a DPIA helps you reduce risk before rollout. If you complete one and find a high risk you cannot mitigate, you may be required to consult your supervisory authority before going live. For simple entrance and corridor security with short retention, a full DPIA may not be required, but you should document that reasoning.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Establishment of the Council of Europe Data Protection DayUrząd Ochrony Danych Osobowych (Polish data protection authority)
- CCTV for your organisation: things you need to doInformation Commissioner's Office (ICO), UK
- EDPB Adopts Guidelines on Data Processing Through Video DevicesHunton Andrews Kurth Privacy Blog
- High-Risk AI Systems under the AI Act: Timeline Extensions and Initial ClarificationsSKW Schwarz Rechtsanwälte
- Retningslinjer for bruk av kameraovervåking (EDPB video guidelines summary)Datatilsynet (Norwegian data protection authority)
- Обработка персональных данных в отеле по ФЗ-152ЮристОтель (uristhotel.ru)
- Что писать в уведомлении, если используется видеонаблюдениеIC-TECH