On 10 August 2026, the Office for Personal Data Protection (“UOOU”) issued Recommendation No. 01/2026 on CCTV systems installed on healthcare providers’ premises. The Recommendation follows up on the UOOU’s general Methodology for the Design and Operation of CCTV systems, whilst taking into account the specific characteristics of the healthcare environment, ranging from hospitals and polyclinics to individual doctor’s offices. We have summarised for you what is changing for operators of CCTV systems in the healthcare sector, where the new rules are stricter than the general Methodology, and where, conversely, they open up opportunities that were not previously available.
Why another Recommendation, and who is it aimed at?
In the past, the UOOU issued a general Methodology on the Design and Operation of CCTV Systems from the Perspective of the Processing and Protection of Personal Data (the “Methodology”), which applies to CCTV systems across all sectors, and subsequently issued a recommendation specifically for the education sector.[1] New Recommendation No. 01/2026 (the “Recommendation”) extends this approach to the healthcare sector, specifically for two groups of data controllers, namely smaller providers of outpatient care (general practitioners, dentists, gynaecologists, physiotherapists, etc.) and larger providers, including inpatient care (polyclinics, hospitals, university hospitals).
The UOOU’s conclusions are applicable to the processing of personal data in the healthcare sector in general; they are therefore also relevant, to an appropriate extent, to pharmacies and other entities providing healthcare or related services, even though the Recommendation does not expressly refer to them.
Purposes of the CCTV cameras and legal grounds for processing: four categories instead of the general phrase “protection of property”
The general Methodology essentially recognises two legitimate purposes of a CCTV system: the protection of property and the protection of the life and health of individuals; to ensure these, it most commonly relies in practice on the controller’s legitimate interests pursuant to Article 6(1)(f) of the GDPR. The Recommendation extends this framework for the healthcare sector to four purposes, two of which are entirely specific to the sector, and assigns a separate legal basis to each of them. This also includes an exception to the prohibition on processing special categories of personal data under Article 9 of the GDPR, where the camera records data relating to a person’s health condition.
In contrast to the general Methodology, the UOOU explicitly emphasises that in the healthcare sector, CCTV recording naturally involves the processing of data relating to health, i.e. a special category of personal data to which the GDPR applies stricter requirements. Providers must strike a balance between protecting property, health and life on the one hand, and the right of patients and staff to privacy and dignity on the other.
- Diagnostic purposes – the camera is used for the necessary examination of the patient and the conditions being monitored (e.g. assessment of mobility, sleep polygraphy, recording of surgical procedures) and the recording (once the purpose has been substantiated) becomes part of the medical records; the conceivable legal bases here are compliance with the obligation to maintain medical records (Article 6(1)(c) of the GDPR) in conjunction with the exemption for processing necessary for the purposes of medical diagnosis and the provision of healthcare services (Article 9(2)(h) of the GDPR);
- Monitoring purposes – real-time monitoring of patients, typically in anaesthesiology, resuscitation or intensive care units, during procedures involving ionising radiation, or in the case of patients subject to physical restraints; the legal basis is generally public interest (Article 6(1)(e) of the GDPR) in conjunction with the exemption for the provision of healthcare services (Article 9(2)(h) of the GDPR), and, in the event of a direct threat to the patient’s life, the protection of vital interests (Article 6(1)(d) in conjunction with Article 9(2)(c) of the GDPR);
- Protective purpose – traditional protection of property, health and life, with preventive, reactive and evidential functions, as also recognised in the general Methodology; the usual legal basis will be the controller’s legitimate interests (Article 6(1)(f) of the GDPR) with a mandatory balancing test; for providers categorised as critical infrastructure, compliance with a legal obligation may also be considered; and
- Educational purposes – transmitting or recording a procedure for the training of students and healthcare professionals; if the recording is made primarily for medical records, the controller’s legitimate interest applies to secondary use (with the patient having the right to object); if the recording is made exclusively for teaching purposes, the controller will have no option but to obtain the patient’s explicit consent, unless another suitable legal basis can be identified.
For providers, this effectively means that a blanket justification of “one purpose (and one basis) for all cameras on the premises” will not stand up to scrutiny. The purpose and legal basis must be assessed on a camera-by-camera basis, even within a single workplace; for example, the reception area, doctors’ offices, patient rooms, and the medicines storage are likely to have different justifications and settings.
The general Methodology does not recommend consent as a legal basis for the use of CCTV cameras but allows for it as a last resort where the group of persons being monitored can be clearly defined. The Recommendation elaborates on this conclusion in the context of healthcare: in the doctor–patient relationship (as in the employer–employee relationship), there is an imbalance of power which makes it difficult to meet the requirement for free consent. This is not a new conclusion, but rather a useful clarification for contexts where this issue is often underestimated in practice. If the controller nevertheless chooses opts for consent, the refusal to give such consent must never be a ground for refusing to provide healthcare services and must be strictly distinguished from consent to the provision of healthcare services in accordance with the Healthcare Services Act. The same conclusion regarding the problematic nature of consent in unequal relationships has, in fact, been repeatedly confirmed recently by supervisory authorities in other areas of health data processing, such as clinical trials of medicinal products.[2]
Balancing test: general procedure, supplemented by a map of high-risk areas within the healthcare facility
The methodology of the balancing test remains unchanged as a general framework. An added benefit for the healthcare sector is the categorisation of spaces according to the degree of interference with privacy, which helps to assess the criterion of necessity:
- Minor interference – the perimeter of the site, car parks with no legible number plates, areas without authorised movement of persons (emergency exits, storerooms, roof);
- Medium-level interference – entrances to the facility, entrance halls, storage areas for medicinal products and medical devices, car parks with surveillance of individuals and number plates;
- High-level interference – ward corridors, reception areas, waiting rooms, communal cafeterias; and
- Very high-level interference – individual patient rooms, doctors’ offices and examination rooms, toilets and bathrooms, nurses’ stations, doctors’ rooms, staff changing rooms, hospital chapels, and cameras with biometric recognition or audio recording.
The UOOU also expressly points out that in places such as toilets, consultation rooms where intimate examinations are carried out, or staff background facilities, a positive outcome of the balancing test will be practically unattainable, as the extent of the interference with the rights of patients and staff generally outweighs the controller’s interests.
Record retention period: the same indicative timeframe, with more nuanced differentiation based on the size of the provider
The general Methodology stipulates that for CCTV recordings made for security purposes, a retention period of up to 72 hours should be sufficient in most cases, whilst any longer period must be substantiated. The Recommendation adopts this indicative framework for the healthcare sector, but expressly distinguishes between small and large providers:
- In the case of small providers (typically outpatient clinics), which may temporarily suspend operations due to holidays or illness, an extension of the retention period to one to two weeks may be considered in justified cases; and
- For large providers operating 24/7, on the other hand, a shorter period of a few days should generally suffice. It will be difficult to justify a longer retention period in hospitals where staff are on duty around the clock. An exception may be made for specific premises which the provider is unable to monitor on a daily basis (e.g. an external warehouse for materials or documentation), where the retention period may be appropriately longer.
The retention period for diagnostic records included in medical records is determined by the relevant provisions of the Health Services Act and the Decree on Medical Records.
If an incident is detected, a copy of a part of the recording evidencing relevant facts may be retained for the purposes of an investigation by the competent authorities or for the purposes of an insurance claim, until the investigation by the relevant authorities has been concluded. The relevant part of the record must be extracted and stored separately, whilst the remaining records continue to be automatically overwritten in accordance with the specified retention period.
Duty to provide information and the rights of data subjects
The Recommendation adopts the two-level information model (information signs at the entrance to the monitored area and detailed second-level information in accordance with Article 13 of the GDPR) from the general Methodology without any change. A distinctive feature of the healthcare sector is the emphasis on providing detailed information in a suitable form, taking into account the specific group of patients. The UOOU expressly warns against two common mistakes: (i) “bundling” information on the processing of personal data in the patient information with the consent to the provision of healthcare services and other rights, which fails to meet the GDPR’s requirement for separate and comprehensible information, and (ii) choosing a form of information that does not reflect the actual capabilities of the target group of patients (e.g. providing information exclusively via the website of a provider specialising in care for the elderly).
The Recommendation further points out that access to, correction or deletion of the recording in the case of diagnostic records is governed by the rules on the maintenance of medical documentation, whilst for other purposes, the standard rights of data subjects under the GDPR apply, as set out in the general Methodology (the right of access, rectification, erasure, restriction of processing, and objection).
Other practical aspects: the Labour Code, cybersecurity, cloud computing, and advanced camera features
The Recommendation expressly states that the operation of a CCTV system must comply with Section 316(2) of the Labour Code, which prohibits subjecting employees to surveillance without a serious reason arising from the specific nature of the work. That provision is mandatory; it cannot be derogated from, even with the employee’s consent. The enforcement practice of labour inspectorates is, in fact, even more restrictive than the Recommendation suggests: inspectors repeatedly impose sanctions not only for cameras in staff background facilities (changing rooms, kitchenettes, nurse stations), but also for cameras in standard workplaces, such as offices, open-plan areas or reception areas, where employees carry out their normal work duties.
The Recommendation briefly mentions that for large data controllers, Act No. 264/2025 Sb. on cybersecurity, as well as related legislation, also applies in relation to the security of CCTV systems. However, this marginal mention should not be underestimated. The Cybersecurity Act imposes extensive obligations on regulated entities in the areas of risk management, incident detection, access control and network security, all of which apply in full to CCTV infrastructure connected to the provider’s data network. Certain functions of a CCTV system (transmission encryption, logging of access to recordings, tamper detection) may therefore not merely be recommendations set out in the Methodology, but direct legal duties arising from cybersecurity regulation.
The Recommendation now also addresses the issue of where CCTV recordings are stored. For diagnostic and monitoring recordings, it is recommended that they be stored locally with the controller and made accessible only to authorised persons. If a service provider opts for a cloud-based solution, they should, in particular, verify the country in which the recordings are stored, the appropriate level of personal data protection in that country, and the adequacy of the technical and organisational measures ensuring the secure transfer of data. The cloud computing catalogue on the Digital Information Agency’s website may serve as a useful guide when selecting a cloud service provider; the individual services listed there have undergone an ex ante assessment in terms of security requirements for public authorities. For large service providers that are subject to cybersecurity regulations, the choice of a cloud-based solution will also be closely linked to the requirements of Act No. 264/2025 Sb.
Also worth noting is the approach the Recommendation takes to advanced CCTV system features. The general Methodology is sceptical about those features, assuming that in most cases a balancing test will demonstrate that there are no grounds for, for example, making an audio recording. However, the Recommendation for the healthcare sector suggest that the “turn everything off” rule may not apply in this environment. For diagnostic purposes, it expressly permits the use not only of visual but also of audio recordings, where this is necessary for assessing the patient’s condition. For protective purposes, it allows the deployment of algorithms to detect hazardous events (e.g. firearms, shouting, explosions). In the case of large providers categorised as critical infrastructure, the Recommendation does not rule out the use of CCTV systems utilising artificial intelligence or biometrics, although in such cases the controller will also be subject to the obligations set out in the Artificial Intelligence Act. The key point is that the use of advanced features must always be justified by a specific purpose and necessity.
If not everything is quite perfect, or if you are not fully compliant, we suggest:
- Going through the CCTV system camera by camera and for each one verify whether it has a defined purpose, a corresponding legal basis under Article 6 of the GDPR and (if it captures health data) an exception under Article 9 of the GDPR;
- If the CCTV system has been in operation for some time, it is also worth checking whether the CCTV system layout plan is up to date, or whether new cameras have been connected (or any existing ones disconnected);
- Where the use of CCTV relies on the patient’s consent, consider switching to a more appropriate legal basis, particularly in doctors’ offices and in wards providing direct patient care;
- Carrying out or updating a balancing test for protective cameras, particularly in areas where there is a high level of interference with privacy;
- Checking the record retention period according to the size and operational activity of the facility, distinguishing it from the retention periods for medical records, and establishing a procedure for isolating records in the event of an emergency;
- Verifying that the cameras in the workplace also comply with Section 316 of the Labour Code, not only in staff areas but also in consultation rooms and corridors;
- For large providers, assessing the compliance of the CCTV system’s technical measures with the requirements of the Cybersecurity Act, including any cloud-based storage; and
- Updating information signs and detailed information on processing, reviewing records of processing activities, and involving a data protection officer if one has been appointed.
Conclusion
Recommendation No. 01/2026 does not represent a radical change. The general provisions of the GDPR and the UOOU’s Methodology on CCTV continue to apply without change. What the Recommendation does offer is a useful practical guide for environments where large amounts of health-related data are processed on a daily basis: the classification of camera purposes into four categories, each with its own legal basis; clearer language on the unsuitability of consent in the healthcare sector; an easy to navigate map of high-risk areas for the balancing test; and the grading of data retention periods according to the size of the healthcare provider.
What to watch out for: Section 316 of the Labour Code and the Cybersecurity Act are mentioned in the Recommendation in only a few paragraphs. However, it is precisely these two acts that are crucial for large providers, and failure to comply with them can lead to problems not only with the UOOU, but also with the labour inspectorates and the National Cyber and Information Security Agency (NUKIB). The review of the CCTV system should therefore cover all three regulatory levels at once.
We suggest that healthcare providers of all sizes read the Recommendation carefully and compare its conclusions with their existing internal documentation on CCTV systems. The Havel & Partners team will be happy to assist you.
- [1] – For the general Methodology, see: New recommendations for operating video surveillance systems have been released. Available at https://en.havelpartners.blog/new-recommendations-for-operating-video-surveillance-systems-have-been-released-do-you-adhere-to-them.
- [2] – For a more detailed discussion of the issue of consent as a legal basis in the context of clinical research, see: Patient consent in research and treatment: When is it not sufficient and what can be used instead? Available at https://en.havelpartners.blog/patient-consent-in-research-and-treatment-when-is-it-not-sufficient-and-what-can-be-used-instead.







