A Practical Privacy Assessment for Workplace Video Surveillance
Assess workplace video surveillance before deployment with documented necessity, proportionality, camera limits, access, retention and approval conditions.
Workplace cameras can support a legitimate safety, access or asset-protection purpose while continuously collecting information about employees who are simply doing their jobs. Employers should document the privacy decision before approving equipment.
A practical assessment asks four questions first: Is the proposed collection necessary? Will video address the documented problem? Is the privacy impact proportionate to the expected benefit? Could a less intrusive measure work? Approval should then depend on specific camera views, permitted uses, access roles, retention rules, safeguards, transparency and review dates.
This article provides a pre-deployment assessment framework. It is operational guidance, not legal advice. Privacy, employment, labour, human rights, sector-specific and collective-agreement obligations vary, so the organization should identify its governing context with qualified advisers.
1. Identify the governing context and decision owners
Start by recording the employer, workplace, employee groups, physical areas, proposed system owner and decision date. Determine which laws, contracts and policies may apply before evaluating the technology.
Canada’s federal, provincial and territorial privacy regulators noted in their 2023 resolution on employee privacy that workplace privacy protection is a patchwork. The resolution states that PIPEDA covers employees of federally regulated organizations, while Alberta, British Columbia and Quebec have provincial private-sector privacy laws that cover employees. It also identifies statutory gaps elsewhere in Canada. The resolution is a policy statement from regulators and does not determine the law for a particular employer.
Include these stakeholders in the assessment:
- the accountable business owner for the safety or security problem;
- privacy and legal advisers;
- human resources and labour relations;
- facilities and physical security;
- IT and cybersecurity;
- health and safety where the purpose involves worker protection;
- affected operations leaders; and
- union or employee representatives where required or useful.
Name one assessment owner and one approving executive. Record dissent, unresolved assumptions and approval conditions. A vendor proposal should inform camera feasibility, while the employer remains responsible for deciding why and how employee information will be handled.
2. Define the problem with evidence and boundaries
Write a narrow problem statement that can be tested. “Improve security” offers no boundary for collection or use. A useful statement identifies the event, location, consequence, existing controls and evidence gap.
For example:
Repeated unauthorized entry has occurred at the receiving personnel door after hours. Existing credential events show that the door opened but cannot establish whether tailgating occurred. The assessment will examine a fixed view limited to the doorway during the controlled access period.
Attach available evidence such as incident records, access events, safety reports, property damage, failed investigation notes and a current floor plan. Avoid collecting additional personal information merely to justify the project.
Define what falls outside scope. Exclusions may include routine productivity observation, attendance checking, breaks, union activity, medical information, audio, biometric identification, emotion analysis, face search and continuous live monitoring. Any future proposal to add one of those uses should trigger a new assessment and legal review.
The Office of the Privacy Commissioner of Canada’s 2014 employee video-surveillance investigation concerned a federal institution under the Privacy Act. Its context and legal framework differ from many workplaces. Its reasoning remains instructive: broad language about program integrity did not provide clear evidence that video was necessary for a wide range of employee conduct and performance purposes. The approved purpose must be precise enough to constrain actual use.
3. Apply necessity, effectiveness, proportionality and alternatives
Use a four-part test and require a written answer for each proposed surveillance zone. The OPC’s current privacy impact assessment overview presents necessity, effectiveness, proportionality and intrusiveness as core questions for privacy-invasive initiatives. That process is designed for federal institutions, but the questions form a disciplined assessment framework for other organizations.
| Test | Required assessment question | Evidence to retain |
|---|---|---|
| Necessity | Which personal information is directly required to address the defined problem? | Incident evidence, purpose and required observable event |
| Effectiveness | How will the proposed view improve prevention, response or investigation? | View test, workflow and measurable success criterion |
| Proportionality | Does the expected benefit justify the frequency, detail, identifiability and affected population? | Impact analysis, operating hours and exposure estimate |
| Less intrusive option | Can lighting, locks, barriers, staffing, access rules, supervision or a narrower sensor address the issue? | Alternatives considered, test results and reasons for rejection |
Score privacy impact using concrete factors:
- whether monitoring is continuous, scheduled or event-triggered;
- whether employees are identifiable and at what distance;
- whether the view captures workstations, screens, conversations or break activity;
- whether live viewing, recording, analytics or cross-system matching is enabled;
- the number and vulnerability of people affected;
- whether footage can influence discipline, performance, scheduling or employment; and
- the consequence of unauthorized access, disclosure or inaccurate inference.
Set a stop condition. If the problem lacks evidence, the camera cannot meet the stated objective, a less intrusive control is reasonably effective, or the proposed view creates excessive collateral monitoring, pause the project and redesign it.
4. Map every information flow and camera view
Create a camera-purpose schedule and a data-flow diagram before installation. Follow the information from lens to deletion.
For every camera, record:
- camera ID, location and accountable owner;
- exact purpose and prohibited uses;
- fixed field of view, focal length and privacy masks;
- operating schedule and recording triggers;
- audio, analytics, tracking and PTZ status;
- people, work areas and neighbouring property incidentally captured;
- recorder or cloud destination and data location;
- integrations with access, alarm, HR or operational systems;
- live-view, playback, export and administration roles;
- retention, preservation and secure disposal rules; and
- next review date.
Conduct an on-site view test with normal furniture, doors, lighting and work activity. Capture a commissioning still that proves the approved boundary without retaining unnecessary employee imagery. Compare it with the signed drawing.
Prefer physical composition over broad digital collection. Change the mount, lens or aim to exclude desks, break areas, adjacent property and computer screens. Use privacy masks as a documented additional control. Disable microphones and unapproved analytics at the device and recorder. Remove unused PTZ presets and vendor remote access.
The OPC’s private-sector overt video guidance recommends a defined business reason, less intrusive alternatives, limited viewing range, notice, restricted access, secure storage, deletion and periodic evaluation. The guidance expressly excludes employee surveillance, so it should be used as a source of design questions and not as a complete workplace compliance answer.
5. Separate security use from employee evaluation
Write a purpose and use matrix that tells managers what they may do with live and recorded video.
| Proposed use | Assessment treatment |
|---|---|
| Verify an alarm at the assessed door | Define responder, view, time window and escalation |
| Investigate a documented access incident | Require case number, approver, limited search window and audit record |
| Preserve footage for a safety or legal matter | Define authority, custodian, hold date and review date |
| Browse recordings for general misconduct | Prohibit unless a separately authorized process and legal basis apply |
| Measure pace, attendance or performance | Treat as a new purpose requiring fresh assessment and legal review |
| Add face search, behaviour analytics or audio | Stop and conduct a new assessment before activation |
The OPC investigation cited above distinguished operational video use from broad performance monitoring and emphasized policies, scenarios and purpose limits. Build those limits into roles and software. A written prohibition is stronger when ordinary supervisors lack unrestricted playback and export rights.
Define an exception process for serious incidents. It should identify who can authorize review, the threshold, search limits, employee or union notification where applicable, audit requirements and how decisions will be documented. Emergency access should produce a reviewable log.
6. Meet Ontario transparency duties and communicate clearly
Part XI.1 of Ontario’s Employment Standards Act, 2000 addresses written policies on electronic monitoring. Ontario’s current electronic monitoring policy guide explains that employers with at least 25 Ontario employees on January 1 must have a written policy in place before March 1 for that year. The policy must state whether electronic monitoring occurs and, when it does, describe how, when and for which purposes information may be used. The employer must provide copies within prescribed timeframes and retain required former policies for three years after they cease to be effective.
The same provincial guide states that these ESA provisions create transparency requirements and do not create new employee privacy rights. Compliance with the policy requirement therefore does not complete the privacy assessment or authorize a particular surveillance practice.
Prepare communication at three levels:
- Employee policy: monitoring methods, circumstances, purposes, contacts and required ESA content.
- Zone notice: clear notice before entry into the monitored area, with purpose and contact route appropriate to context.
- Manager procedure: permitted uses, approval thresholds, search steps, disclosure, preservation, complaints and escalation.
Consult affected employees or representatives early enough to change the design. Ask which work activities, screens, rest areas or personal information the proposed view may capture. Record the response and resulting mitigation.
7. Set access, retention, disclosure and safeguards
Choose retention from the documented workflow. Identify how long a relevant incident can remain undiscovered, who can preserve a clip, how holds are reviewed and when protected copies are deleted. Configure automatic deletion and test it. Storage capacity alone is not a retention purpose.
Use role separation:
- responders may receive limited live alarm views;
- investigators may search recordings for approved cases;
- custodians may export under a documented request;
- administrators may configure systems without routine investigative authority; and
- auditors may review logs without unrestricted footage access.
Require unique identities, strong authentication, least privilege, encryption where supported, protected equipment, network controls, configuration backup and reviewable logs. Exports need case identifiers, approval, recipient verification, secure transfer and a deletion date.
Vendor terms should address remote support, personnel access, subcontractors, hosting location, breach notification, return or deletion, audit evidence and termination. Confirm whether vendor staff can view footage by default and disable unnecessary access.
Ontario public institutions should consult the IPC’s video-surveillance guidelines and their privacy coordinator. The IPC says parts of that public-sector guidance are under review following 2026 legislative changes, with additional amendments taking effect on specified later dates. Private employers should not present public-sector guidance as their governing statute.
8. Approve conditions, test controls and schedule review
The assessment should end with one of four outcomes: approved, approved with conditions, redesign required or rejected. Conditions need an owner and due date.
Before activation, test:
- every field of view against the signed drawing;
- privacy masks through day, night and door-position changes;
- audio and unapproved analytics disabled at all layers;
- role permissions for live view, playback, export and administration;
- login, playback, export and deletion logging;
- automatic routine deletion and controlled preservation;
- signs, employee communications and enquiry routing;
- vendor remote-access controls;
- camera tamper and system health alerts; and
- the incident workflow using a fictional case.
Approve a pilot when effectiveness or impact remains uncertain. Define duration, success measures, complaint route, data handling and shutdown date. Delete pilot footage according to the approved rule and return for sign-off before permanent operation.
Review the assessment after incidents, complaints, camera movement, renovation, analytics changes, vendor changes, new integrations or a proposed new use. Also set a periodic date to ask whether the original problem persists and whether a less intrusive control can now meet the need.
Workplace video privacy assessment checklist
Do not approve deployment until the record contains:
- governing context and legal review owner;
- evidence-based problem statement and defined exclusions;
- necessity, effectiveness, proportionality and alternatives analysis;
- signed camera schedule, floor plan and data-flow map;
- permitted and prohibited use matrix;
- employee policy, notices and consultation record;
- role-based access and case approval process;
- retention, preservation, disclosure and disposal rules;
- security and vendor controls;
- acceptance tests, deficiencies and closure evidence; and
- named review triggers, owner and date.
This assessment should inform the technical scope for commercial security cameras and connect to the organization’s broader Ontario video-surveillance privacy program. The practical goal is a camera design whose purpose, boundaries and operation can be explained before installation and verified throughout its life.
Frequently Asked Questions
Yes. Document the problem, evidence, legal context, necessity, effectiveness, proportionality, alternatives, camera views, uses, access, retention, safeguards and review conditions before equipment is approved.
The Employment Standards Act requirement is a transparency obligation for covered employers. Ontario's guide states that it does not create new employee privacy rights. Employers should assess all applicable privacy, employment, labour, human rights and other legal obligations separately.
That would be a new or expanded purpose with significant employment and privacy implications. Define permitted and prohibited uses before deployment, restrict access technically, and require a fresh legal and privacy review before any purpose changes.
Choose the shortest period that supports the documented incident-discovery and response process, subject to applicable legal duties. Configure automatic deletion, controlled preservation and final disposal, then test that those controls work.


