← All articles

consultant

Workplace video surveillance: DPIA before any camera (Coccaglio)

Italy’s Garante fined the Comune di Coccaglio €6,000 for employee video surveillance without a credible DPIA and for disciplinary use of footage. In Luxembourg, a prior DPIA is almost always required when employees may be captured.

Excerpt — Italy’s Garante fined the Comune di Coccaglio €6,000 for employee video surveillance without a credible DPIA and for using footage for disciplinary purposes. Direct takeaway for Luxembourg: a prior, formal DPIA is triggered before any camera targeting workers.

The case

On 12 February 2026, the Italian data protection authority (Garante) sanctioned the Comune di Coccaglio for a camera system in and around a municipal warehouse targeting employees, used notably for disciplinary purposes, without an adequate DPIA and with insufficient information. The Garante found breaches of GDPR Articles 5(1)(a)-(b), 6(1)(c), 12(1), 13, 35 and 88, as well as labour rules, and set the fine at €6,000, with publication. Reference: Provvedimento of 12 February 2026 – Comune di Coccaglio, doc. web no. 10226611 (Garante). Full decision, esp. §§ 232–241 and 275–283: garanteprivacy.it.

Why does this matter immediately in Luxembourg? Because any setup likely to capture employees almost always triggers a prior DPIA and reinforced consultation and information duties. Luxembourg Labour Code Article L. 261‑1 adds, on top of the GDPR, a collective information duty towards the staff delegation and, where applicable, a prior opinion request to the CNPD within 15 days after that information. CNPD — Art. L. 261‑1.

Legal reasoning

  • DPIA trigger. GDPR Article 35(1) requires a DPIA where processing is likely to result in a high risk. WP29/EDPB Guidelines WP248 rev.01 list systematic monitoring of publicly accessible areas and surveillance of employees (vulnerable data subjects) as criteria; multiple criteria make the DPIA mandatory. WP248 rev.01 (endorsed version: EDPB).
  • Scope of video devices. EDPB Guidelines 3/2019 require an appropriate legal basis (often legitimate interests), strict proportionality (angles, break areas, audio, etc.), and visible, complete information. Guidelines 3/2019 and 2026 summary.
  • What the Garante found. No DPIA before deployment; a later undated and inconsistent DPIA (wrong legal bases); no effective DPO consultation (Art. 35(2)); disciplinary use without a clear basis; and breaches of lawfulness, transparency and minimisation (Art. 5). Fine: €6,000 with publication. Garante decision.
  • Luxembourg specifics. In addition to the GDPR (Arts. 5, 6, 13, 35 and 36 — prior consultation if a “residual high risk” remains), Labour Code Article L. 261‑1 mandates: (i) prior information of the staff delegation; (ii) individual information to employees; (iii) within 15 days, a possible prior opinion request to the CNPD (opinion within one month). CNPD — L. 261‑1 ; EUR‑Lex Arts. 35–36.

What this changes in practice

Who is exposed

All organisations planning cameras likely to capture employees (offices, counters, warehouses, workshops, break areas, utility vehicles with dashcams). Microphones, continuous capture of workstations, or disciplinary use heighten the risk.

Practices sanctionable without a DPIA

  • “Quickly” installing cameras to secure stock without a formal DPIA, without DPO consultation, and without two‑layer notices.
  • Extending purposes to discipline without a clear legal basis or necessity/balancing test.
  • Filming break/meal areas or recording audio continuously.
  • Keeping footage “just in case” beyond what is strictly necessary.

Minimal decision tree

  1. Legitimate, defined purpose? Security of persons/assets evidenced by incidents/risks; exclude day‑to‑day performance monitoring. Legal basis: legitimate interests (Art. 6(1)(f)), or a specific legal obligation where applicable. EDPB — legal bases.
  2. DPIA required? Yes if at least one strong criterion applies (systematic monitoring; employees as vulnerable; intrusive processing), all the more if criteria accumulate. EDPB — DPIA WP248.
  3. DPIA before rollout with DPO consulted (Art. 35(2)); if a “residual high risk” remains, consult the authority (Art. 36). EUR‑Lex Arts. 35–36.
  4. Internal controls: Article 30 record, camera policy, access control, justified retention, logging, and data subject rights handling.
  5. Luxembourg‑specific: inform the staff delegation; within 15 days, possible CNPD prior opinion; integrate the CNPD feedback before go‑live. CNPD — L. 261‑1.

Cross‑border alignment

  • Belgium: GDPR combined with the Camera Act/CBA no. 68; frequent enforcement. Belgian DPA — workplace video.
  • France: continuous capture of workstations and especially audio is rarely proportionate; sanctions are rising. CNIL — simplified sanctions 2026.
  • Germany/Spain: consistent application of WP248 and Guidelines 3/2019; same high‑risk and proportionality logic.

Frequent pitfalls

  1. Late, symbolic DPIA: undated, no mapping of areas, no abuse scenarios/mitigations (masking, privacy zones, audio off by default). Garante decision.
  2. Wrong legal basis: employee consent rarely valid; a legal obligation must be specific; otherwise rely on legitimate interests with a documented test. EDPB — legal bases.
  3. No DPO consultation: Article 35(2) requires DPO advice, and it must be recorded. Garante — Coccaglio.
  4. Unplanned disciplinary use: re‑using footage without a stated purpose or clear legal basis breaches Articles 5(1)(a)-(b).
  5. Forgetting local labour rules: ignoring Article L. 261‑1 weakens the setup regardless of GDPR substance. CNPD — L. 261‑1.

In short

Camera = prior DPIA when employees may be captured; DPO consulted; clear purposes; complete information; technical minimisation; and, in Luxembourg, strict compliance with Article L. 261‑1. Executives, DPOs and CISOs should require a robust DPIA before any purchase/installation.

To operationalise this, consider an external DPO mandate to ensure systematic DPIA reviews, align with our overview of key GDPR articles, and, for projects in Luxembourg, explore our CNPD compliance approach before you contact us for a fast scoping.

Official sources

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →