CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?
Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.
Verified fact — In Luxembourg, the CNPD sets a retention period of 8 days in principle for CCTV footage, with a documented exception up to 30 days. In France, the CNIL states that “as a rule, a few days are enough,” while tolerating “in principle” a period not exceeding one month.
Compliance goal: operationalize the GDPR storage limitation principle under Article 5(1)(e), aligned with the employment context (Luxembourg Labor Code L. 261‑1) and EDPB Guidelines 3/2019.
The case
On 5 April 2024, the CNPD updated its page on storage limitation for video surveillance: “images may be kept in principle for up to 8 days,” with a reasoned exception up to 30 days; beyond that, retention is “generally disproportionate.” The CNPD even cites a sanction decision (14FR/2021, 12 May 2021). Sources: CNPD – Storage limitation ; CNPD – Video surveillance guidelines.
In France, the CNIL recalls that “as a rule, a few days are enough,” while also indicating “in principle, retention should not exceed one month,” subject to proportionality and, where public roads are filmed, a prefectural authorization. Sources: CNIL – How to implement video systems? ; CNIL – Video protection ; CNIL – Workplace CCTV.
The EDPB Guidelines 3/2019 (v2.0, 29 January 2020) stress minimization/limitation: “in most cases, data should be erased after a few days,” supporting a cautious approach. Sources: EDPB – Guidelines 3/2019 ; French version (PDF).
Legal reasoning
- Legal basis and employment context (LU): systems targeting employees fall under Labor Code L. 261‑1 and must rely on a GDPR Article 6(1) legal basis (often legitimate interests, Art. 6(1)(f)), with collective and individual information; the staff delegation may seek prior CNPD advice within 15 days. Source: CNPD – Article L. 261‑1.
- Storage limitation principle: Article 5(1)(e) GDPR requires not keeping data longer than necessary. The CNPD operationalizes this: 8 days in principle; 30 days exceptionally with justification recorded in the register (Art. 30 GDPR). Beyond that, retention is “generally disproportionate.” Sources: CNPD – Storage limitation ; GDPR – EUR‑Lex.
- DPIA: under Article 35 GDPR and EDPB 3/2019, CCTV may trigger a DPIA; in France, the CNIL mandates one for “systematic monitoring on a large scale of a publicly accessible area.” Sources: CNIL – Video protection ; EDPB – Guidelines 3/2019.
The gap lies less in legal bases than in how storage limitation is implemented: CNPD publishes a strict benchmark (8 days, 30 days exceptionally), while CNIL maintains a generic upper cap (up to one month) and still notes that “a few days are enough” in general.
What this changes in practice
- Luxembourg: a “30 days by default” policy will be hard to defend. Default to 8 days, with an exception duly reasoned (e.g., high loss incidence, internal investigation needs, long weekends) and recorded in the Art. 30 register and any DPIA. Source: CNPD – Storage limitation. For governance, an external DPO mandate can help set policy and controls.
- France: for sites open to the public, one month is a ceiling, not a right: document why “a few days” are insufficient; where a prefectural authorization applies, the order specifies the retention period. Sources: CNIL – How to implement… ; CNIL – Video protection.
- Multi‑country: adopt the strictest default (8 days) EU‑wide, with local, justified exceptions. This aligns with Article 5(1)(e) GDPR and avoids an unmanageable patchwork. For local expertise, see GDPR Luxembourg.
- Demonstrating compliance: implement automatic deletion, access/extraction logs, and a “legal hold” procedure in case of an incident, as both CNPD and CNIL recommend.
Common pitfalls
- Keeping 30 days “because the DVR allows it.” Without a necessity/balancing test (EDPB 3/2019) and written justification, you are exposed. Sources: CNPD – Storage limitation ; EDPB – Guidelines 3/2019.
- Ignoring Luxembourg’s L. 261‑1 framework. Installing cameras targeting employees without proper collective notice, the CNPD advice window, and Articles 12‑13 GDPR information is non‑compliant. Source: CNPD – Article L. 261‑1.
- No automated deletion or internal instructions. Without scheduled purges, access logs, and documented extractions, proportionality is not demonstrated. Sources: CNPD – Storage limitation ; CNIL – Video protection.
- Copy‑pasting a France policy to Luxembourg (or vice versa). The CNPD/CNIL divergence requires local annexes and per‑site VMS/DVR settings. Sources: CNPD – Storage limitation ; CNIL – How to implement….
- Skipping the DPIA for extensive monitoring. The CNIL requires a DPIA for systematic large‑scale monitoring of public areas; the EDPB provides criteria. Sources: CNIL – Video protection ; EDPB – Guidelines 3/2019.
To structure your register, calibrate retention, and automate purges, support from a certified DPO can speed up compliance.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →