In this article
There's a camera over your till. Maybe one on the back door too, one on the floor, one that happens to catch the corridor to the toilet. Nobody in your restaurant has ever checked whether that's allowed — and the answer doesn't sit with whoever ran the cables, it sits with GDPR and a court that has already ruled on exactly this scenario.
A camera over the till is about the most common security measure in hospitality, and one of the least thought-through. You buy it for the same reason you buy a fire extinguisher: everyone has one, so you do too. The difference is a fire extinguisher doesn't process personal data on every staff member standing in front of it for eight hours a day.
This site already has extensive coverage of what theft and till discrepancies cost you, of burglary security, and of GDPR from the guest-data angle — reservations, email addresses, marketing consent. None of it covers the camera itself. And that's a genuinely different story from guest data: you can ask a guest for consent to a newsletter, but you can never get a staff member to "freely" consent to being filmed at their own workplace — the power imbalance between employer and employee makes that consent legally invalid under GDPR by definition. Workplace camera surveillance rests on a different lawful basis entirely, with its own rules.
That isn't a theoretical point. It's exactly the situation Europe's top human-rights court has already ruled on — a supermarket with hidden cameras above its tills, after a suspicion of theft. That ruling draws a line that's more relevant to a restaurant's till camera than any generic GDPR advice.
This article adds up seven numbers: how long a targeted camera operation held up in front of that court, how many legal purposes a workplace camera may serve, how long you may keep footage, why that same number can also work against you, where a camera may never point, what a real fine for excessive filming actually costs, and what a properly set-up system costs — including the parts nobody budgets for.
Why "we've got nothing to hide" isn't a legal basis
The reasoning most owners use sounds logical: the camera is there to stop theft, staff know it's there, so it's fine. The problem is "knowing it's there" isn't the same as a valid lawful basis, a documented purpose, a retention limit and proper notice — four separate requirements that each have to hold up on their own.
Camera surveillance of employees doesn't fall under the same loose rules as filming an empty car park or a warehouse with no staff in it. The moment a camera captures a working person, extra rules stack on top of GDPR: in Belgium that's Collective Labour Agreement 68 (CAO 68), with its own list of permitted purposes and a duty to inform the works council — or, failing that, the health-and-safety committee or your staff directly — before the camera is switched on.
The seven numbers below are each individually checkable — a European Court of Human Rights ruling, the text of CAO 68 itself, data-protection-authority guidance, and a real, documented fine. None of them is an educated guess, and the order follows the logic of an actual camera install: first the precedent that shows where the line sits, then the legal purposes, then retention, then the blind spot almost nobody sees, then the absolute no-go zones, then the fine, and finally what it costs to just do it right from the start.
The ultimate guide Every Digital & Data article, in one place GDPR, cybersecurity, POS systems and more — the overview. See the guideThe 7 numbers behind the camera over your till
Each number below marks a line the law draws — some give you more room than you thought, others less. Check your own setup with the tool further down instead of guessing.
1. 10 days — how long a targeted camera operation held up in front of Europe's top court
The leading European case on workplace cameras didn't happen in a restaurant, but the facts sit uncomfortably close to a till camera in hospitality. A store manager noticed stock losses and installed both visible and hidden cameras, aimed at the tills, for ten days. The footage showed cashiers not ringing up items, or letting colleagues take goods without paying; several employees were dismissed on the strength of it.
The case, López Ribalda and Others v. Spain, eventually reached the Grand Chamber of the European Court of Human Rights, which ruled in 2019 that the employees' privacy had not been violated — but for very specific reasons: the cameras were narrowly targeted at exactly where the suspicion lay (the tills, not the whole store), the operation was short (ten days, not months), and there was a concrete, documented loss behind it, not general suspicion.
That's the line your own till camera has to respect to be defensible: targeted, short where it's tied to a specific suspicion, and backed by a reason you can put on paper. A camera that runs permanently, films everything and never had a documented purpose is on the wrong side of the exact test this court itself drew.
2. 4 legal purposes, only 3 of which may film continuously
In Belgium, Collective Labour Agreement 68 (CAO 68) governs workplace camera surveillance specifically, on top of GDPR. It lists exactly four permitted purposes: the safety and health of employees, protecting company property, controlling the production process (machines), and controlling an individual employee's own work.
The detail that matters most is what does not apply to all four: continuous, permanent camera monitoring is only allowed for the first three purposes. Surveillance aimed at controlling one employee's individual work may only ever be temporary — never permanent. Most till cameras in hospitality are in practice running for exactly that fourth, most restricted purpose ("checking staff ring things up correctly") and simply stay on, year after year. On top of that, you have to inform the works council — or, failing that, the health-and-safety committee, or staff directly — about every aspect of the surveillance before it's switched on, not report it after the fact.
The same hardware, the same reason for hanging it — with a completely different risk profile.
The difference between these two bars isn't the camera — it's four choices that cost nothing: what it's aimed at, whether the purpose is on paper, whether staff were told in advance, and how long you keep the footage.
3. 30 days — the recommended maximum retention period for your footage
GDPR itself doesn't set a fixed number of days, but data-protection authorities across Europe send a consistent signal: don't keep footage longer than strictly necessary, and that generally lands around 30 days. France's CNIL is the most explicit about it: a few days is usually enough to investigate an incident, and retention shouldn't run past about a month — except when footage is needed for an ongoing disciplinary or criminal case, in which case it may be pulled from the general system and kept separately for the duration of that case.
That number collides with how most systems are actually configured. An NVR or cloud recorder typically ships set to "record until the disk fills up", which in practice often means 60 to 180 days or more. Nobody actively changes that setting — which means your system, without anyone ever having looked at it, is probably already retaining months longer than it should.
4. 30 days — also the deadline to answer a request to see your own footage
This is the number that appears on no checklist, because it only becomes a problem the moment someone actually uses it. Under GDPR, anyone — a staff member, a guest — has the right to ask what footage of them exists, and you generally have one month to respond, counted from the day you receive the request.
The collision is obvious once you see it: if you delete footage after 30 days (the recommended maximum from the previous number) and you also have a full month to answer an access request, then a request submitted on day 29 of your retention window is filed well within the legal deadline to respond, while the footage itself may already be gone by the time you're due to reply. That's not a flaw in the rules — they're simply two limits that weren't written with each other in mind — but it means "we only keep 30 days, tidily" doesn't automatically protect you if someone asks quickly enough.
5. 0 — the number of toilets, changing rooms or staff break rooms a camera may ever cover
This is the one number on this list with no exception. Toilets, changing rooms, shower areas and staff break rooms are places with a heightened expectation of privacy, and no balancing test — however real the theft risk — makes a camera there lawful. That holds even if staff themselves ask for it, or if a camera "happens" to catch it because it sits near the corridor to the toilet.
In practice this is rarely a deliberate choice and almost always a framing problem: a camera meant for the kitchen entrance that's angled a little too wide and picks up the staff toilet door is just as much a violation as a camera deliberately aimed there. Check the framing of every camera in your venue, not just the purpose you originally installed it for.
6. 2% of turnover — a real fine for excessive staff filming, next to GDPR's 4% ceiling
The number that shows up everywhere in GDPR explainers is the ceiling: up to €20 million or 4% of worldwide annual turnover, whichever is higher. That figure is intimidating but not very informative for an independent restaurant — it's a cap for the most severe, most organised violations, not what an average owner actually risks.
The number that's actually relevant is smaller and more concrete: a French company was fined 2% of its turnover — around €20,000 in that case — for excessively filming employees without a valid legal basis. That's not a theoretical ceiling but a real, issued fine, of a size a small or mid-sized hospitality venue genuinely feels. It puts the GDPR maximum in perspective: the realistic exposure for a restaurant with a poorly set-up camera sits much closer to that French case than to the headline figures about multi-million-euro fines.
7. ±€2,300 — what a properly set-up camera system costs a small venue, compliance included
The hardware itself is usually the line owners do budget for: a system of four to six cameras (till, entrance, kitchen pass, back door), installed, typically runs somewhere between €1,500 and €2,500 for a small venue. What almost nobody budgets for is what sits alongside it: correct signage at every entrance and near the cameras themselves, the time to write a proper camera policy and formally inform staff (rather than assuming everyone already knows), configuring automatic deletion once the retention period passes, and, optionally, a short legal check of the whole setup.
The worked example below adds five line items up to a realistic total budget — plug in your own quotes with the tool further down once you have them.
Five line items from a realistic worked example — plug in your own quotes with the tool below.
Together: €2,300. The hardware sits at the top on purpose: it's the largest line, but the four beneath it are what actually decides whether the camera protects you or gets you fined.
Check your own camera setup
Fill in the five line items below with your own quotes once you have them — the starting values are the worked example from the text above.
Adjust the retention period and the two checkboxes to match how your camera is actually set up today — not how you think it should be — and see immediately where the risk sits.
Camera compliance check
Five cost lines, plus the two choices that decide your risk profile.
—
This is a check tool, not legal advice — the starting values are a realistic worked example, not a guarantee for your specific situation.
What this check tool doesn't do — deliberately: it doesn't calculate a probability of being fined in euros, because no reliable, per-venue figure for that exists. What it does do is add up every real cost line into one budget, and surface the three factors that determine your risk profile — independent of how much you spend on hardware.
Put the risk profile from this tool next to the seven numbers above, and you have the full, realistic picture of what a camera over your till requires — not just what's on the installer's invoice.
One camera, four choices that cost nothing
A camera over the till is a valid, often sensible decision — theft and till discrepancies are real, and a targeted, short-running operation tied to a concrete suspicion holds up legally well, as the case law shows. The problem is never the camera's presence itself, but the silent assumptions built around it: that "everyone already knows" counts as notice, that the factory retention setting is probably fine, and that a camera installed once for one reason keeps running for that same reason forever.
The order in which you tackle this isn't arbitrary: first check the framing (nothing near a toilet or break room is in shot), then put the purpose on paper and inform staff in writing, then actually set the retention period on the system itself instead of trusting the factory default, and only after all of that — if it all checks out — ask whether a legal review is worth it for your specific setup.
Use the check tool above to review your own setup before a complaint or inspection ever happens, and treat the four things that cost nothing (framing, a documented purpose, notice, retention) as priority one — those are exactly what separates the Spanish precedent that held up from the French case that drew a fine.