Italian Research Institute Fined for Unlawful Video Surveillance of Employees
The National Institute of Meteorological Research failed to meet basic GDPR obligations by deploying workplace video surveillance without properly informing employees and third parties of its existence or purpose. Compounding the violation, the institute expanded and relocated cameras without conducting a mandatory Data Protection Impact Assessment (DPIA), a critical safeguard required when processing activities pose high risks to individuals' rights. This case highlights how physical security measures are not exempt from data protection law and must follow the same compliance lifecycle as digital data processing. Organizations that treat surveillance as a purely operational decision—rather than a legal and privacy matter—expose themselves to regulatory fines and reputational harm.
Tactical Insight
Immediate actions
- Conduct a full audit of all existing surveillance systems to verify that proper employee and visitor notifications are displayed and documented.
- Halt any planned expansion or relocation of cameras until a DPIA has been formally completed and approved.
Long-term improvements
- Embed DPIA requirements into the project approval workflow for any new data processing activity, including physical surveillance installations.
- Establish a Privacy by Design policy that mandates legal and DPO review before deploying any monitoring technology in the workplace.
- Maintain an up-to-date Record of Processing Activities (RoPA) that includes all surveillance systems, their locations, purposes, and legal bases.
Governance & Training
- Train HR, facilities, and IT teams on GDPR obligations specific to employee monitoring so compliance is understood across departments.
- Assign clear ownership to the Data Protection Officer (DPO) to review and sign off on all surveillance-related changes before implementation.