Spanish Data Protection Agency Updates Video Surveillance Guide

In February 2025, the Spanish Data Protection Agency (AEPD) published an updated version of its Guide on the Use of Video Cameras for Security and Other Purposes. This edition replaces the 2019 version and, while both share the same structure, the content has been significantly enriched. The 2025 guide aligns even more closely with the principles of the General Data Protection Regulation (GDPR) and adapts its recommendations to technological and social developments, addressing both data controllers in businesses and organisations such as property owners’ associations and public administrations.

RGPD

One of the key focuses of this edition is the concept of proactive responsibility. It is no longer sufficient to comply with regulations; organisations must now be able to demonstrate their compliance. In this regard, the guide also provides detailed guidance on handling image processing in complex scenarios, such as the use of drones, onboard cameras, dashcams in vehicles, and systems with advanced functions such as facial recognition.

To facilitate understanding of these updates, the AEPD has expanded the number of practical case examples and adapted the language to better reflect everyday contexts.

Beyond Security: Privacy, Rights, and Responsibilities

The document does not solely address technical aspects but also calls attention to the ethical considerations of video surveillance. New sections delve into increasingly common environments, such as communal swimming pools, school playgrounds, digital peepholes, and smart intercom systems. In all these cases, the guide highlights the importance of applying the principle of data minimisation and avoiding excessive or unjustified image capture.

Another notable aspect is the handling of images in contexts unrelated to security. For instance, recordings in educational centres or public events are analysed from the perspective of legitimate interest and respect for privacy. The guide also clarifies that the term “erasure” should now be used instead of “cancellation” when referring to the deletion of images and reinforces the legal limits on how long recordings may be retained—setting a standard period of one month unless justified exceptions apply. While the distinction between recording and live viewing remains, the guide reminds us that even without image storage, data processing may still take place.

Practical Recommendations for Data Controllers

Among the most useful recommendations for those managing video surveillance systems are conducting impact assessments, formalising contracts with data processors, and reviewing technical security measures.

The guide provides further details on when appointing a Data Protection Officer (DPO) is mandatory, how to maintain an activity register, and when a security breach must be reported within the 72-hour deadline.

Finally, the section on the sharing of images with third parties has been expanded, covering both judicial requests and requests from individuals with a legitimate interest. The guide emphasises that all such actions must be properly documented and carried out in a proportional manner, minimising shared data and ensuring the rights of all parties involved are respected.

While the update does not alter the legal foundations, it strengthens the clear, current, and responsible application of these principles at a time when recording is easier than ever—but knowing how to do it properly is more essential than ever.

The full guide can be downloaded here: guia-videovigilancia.pdf

All information related to video surveillance can be accessed here: Videovigilancia | AEPD