Cameras and employees: what the CNIL allows (and forbids)
Most workshops already have cameras. So the question is not “can we film?” but “what for, and within which limits?”. Here are the rules laid down by the CNIL — France's data protection authority — so that your cameras protect the company instead of exposing it. The same logic applies under the GDPR across the EU.
What is permitted: protecting property and people
The CNIL accepts video surveillance in companies for specific purposes: safety of property and people, protection of sensitive areas (stock, entrances, dangerous zones), identification of those responsible for theft or damage. Cameras may film entrances, circulation corridors, warehouses and hazard zones.
The guiding principle is proportionality: the system must fit the objective, and go no further.
What is forbidden: continuously monitoring employees
The red line is clear: a camera must not place an employee under permanent surveillance at their workstation. The following are prohibited in particular, except in very exceptional circumstances (handling cash or high-value items, for example):
- continuous framing of a workstation or of a particular employee;
- cameras in break areas, changing rooms, toilets;
- using the footage to assess employees' performance or behaviour;
- and, more generally, any biometric facial-recognition system applied to employees — considered disproportionate.
The obligations that come with any camera
Even for a legitimate system, several obligations apply:
- Individual information for employees (workplace rules, internal memo, contract addendum) and visible signs for anyone entering the field of view;
- Consultation of the works council (CSE) before installation;
- Entry in the GDPR processing record, with purpose, retention period and recipients;
- Limited retention of footage — the CNIL recommends not exceeding what is necessary, in practice a few days to one month at most;
- Restricted access to footage, reserved for authorised persons.
The question to ask: does my system produce data about people? If the answer is yes, the whole GDPR corpus applies — records, retention, access rights, security. If the system creates no personal data, compliance becomes radically simpler.
Why equipment detection changes the game
This is where Oneye's approach differs from conventional video surveillance. The system does not try to find out who is in the frame: it checks that a silhouette present in a hazard zone is wearing its hard hat, then destroys the analysis within a second. No image is recorded, no face is processed, no personal data is created.
The supervisor receives only a fact: “press zone, 2:02 pm, hard hat missing”. No name, no video to replay, no file on an employee. The system checks a safety rule — not people — and that is exactly the distinction the law draws.
This article presents the broad principles; it does not replace legal advice. The CNIL's practical guidance on video surveillance at work is available on cnil.fr.
Cameras that check equipment. Not people.
Oneye plugs into your existing cameras, alerts when PPE is missing, and never identifies anyone. Free for one camera.
Discover Oneye →