← All articles

consultant

CNPD vs CNIL: 8 days or 1 month to retain workplace CCTV footage?

Facts: CNPD sets 8 days in principle (30 days exceptionally), while CNIL tolerates up to one month. Key point: align video retention with GDPR Art. 5(1)(e) and Luxembourg Labor Code L. 261‑1.

Verified fact — In Luxembourg, the CNPD sets a retention period of 8 days in principle for CCTV footage, with a documented exception up to 30 days. In France, the CNIL states that “as a rule, a few days are enough,” while tolerating “in principle” a period not exceeding one month.

Compliance goal: operationalize the GDPR storage limitation principle under Article 5(1)(e), aligned with the employment context (Luxembourg Labor Code L. 261‑1) and EDPB Guidelines 3/2019.

The case

On 5 April 2024, the CNPD updated its page on storage limitation for video surveillance: “images may be kept in principle for up to 8 days,” with a reasoned exception up to 30 days; beyond that, retention is “generally disproportionate.” The CNPD even cites a sanction decision (14FR/2021, 12 May 2021). Sources: CNPD – Storage limitation ; CNPD – Video surveillance guidelines.

In France, the CNIL recalls that “as a rule, a few days are enough,” while also indicating “in principle, retention should not exceed one month,” subject to proportionality and, where public roads are filmed, a prefectural authorization. Sources: CNIL – How to implement video systems? ; CNIL – Video protection ; CNIL – Workplace CCTV.

The EDPB Guidelines 3/2019 (v2.0, 29 January 2020) stress minimization/limitation: “in most cases, data should be erased after a few days,” supporting a cautious approach. Sources: EDPB – Guidelines 3/2019 ; French version (PDF).

Legal reasoning

  • Legal basis and employment context (LU): systems targeting employees fall under Labor Code L. 261‑1 and must rely on a GDPR Article 6(1) legal basis (often legitimate interests, Art. 6(1)(f)), with collective and individual information; the staff delegation may seek prior CNPD advice within 15 days. Source: CNPD – Article L. 261‑1.
  • Storage limitation principle: Article 5(1)(e) GDPR requires not keeping data longer than necessary. The CNPD operationalizes this: 8 days in principle; 30 days exceptionally with justification recorded in the register (Art. 30 GDPR). Beyond that, retention is “generally disproportionate.” Sources: CNPD – Storage limitation ; GDPR – EUR‑Lex.
  • DPIA: under Article 35 GDPR and EDPB 3/2019, CCTV may trigger a DPIA; in France, the CNIL mandates one for “systematic monitoring on a large scale of a publicly accessible area.” Sources: CNIL – Video protection ; EDPB – Guidelines 3/2019.

The gap lies less in legal bases than in how storage limitation is implemented: CNPD publishes a strict benchmark (8 days, 30 days exceptionally), while CNIL maintains a generic upper cap (up to one month) and still notes that “a few days are enough” in general.

What this changes in practice

  • Luxembourg: a “30 days by default” policy will be hard to defend. Default to 8 days, with an exception duly reasoned (e.g., high loss incidence, internal investigation needs, long weekends) and recorded in the Art. 30 register and any DPIA. Source: CNPD – Storage limitation. For governance, an external DPO mandate can help set policy and controls.
  • France: for sites open to the public, one month is a ceiling, not a right: document why “a few days” are insufficient; where a prefectural authorization applies, the order specifies the retention period. Sources: CNIL – How to implement… ; CNIL – Video protection.
  • Multi‑country: adopt the strictest default (8 days) EU‑wide, with local, justified exceptions. This aligns with Article 5(1)(e) GDPR and avoids an unmanageable patchwork. For local expertise, see GDPR Luxembourg.
  • Demonstrating compliance: implement automatic deletion, access/extraction logs, and a “legal hold” procedure in case of an incident, as both CNPD and CNIL recommend.

Common pitfalls

  1. Keeping 30 days “because the DVR allows it.” Without a necessity/balancing test (EDPB 3/2019) and written justification, you are exposed. Sources: CNPD – Storage limitation ; EDPB – Guidelines 3/2019.
  2. Ignoring Luxembourg’s L. 261‑1 framework. Installing cameras targeting employees without proper collective notice, the CNPD advice window, and Articles 12‑13 GDPR information is non‑compliant. Source: CNPD – Article L. 261‑1.
  3. No automated deletion or internal instructions. Without scheduled purges, access logs, and documented extractions, proportionality is not demonstrated. Sources: CNPD – Storage limitation ; CNIL – Video protection.
  4. Copy‑pasting a France policy to Luxembourg (or vice versa). The CNPD/CNIL divergence requires local annexes and per‑site VMS/DVR settings. Sources: CNPD – Storage limitation ; CNIL – How to implement….
  5. Skipping the DPIA for extensive monitoring. The CNIL requires a DPIA for systematic large‑scale monitoring of public areas; the EDPB provides criteria. Sources: CNIL – Video protection ; EDPB – Guidelines 3/2019.

To structure your register, calibrate retention, and automate purges, support from a certified DPO can speed up compliance.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →