Almost every business in Albania has cameras. Very few have the written decision that legitimises them.

That is not a formality. Instruction No. 03 of 30 April 2025 governs the processing of personal data by video surveillance systems. It was issued by the Commissioner under Arts. 82, 85 and 97 of Law 124/2024, it binds every public and private controller and processor in the territory of the Republic, and failure to apply it is a breach of the Law sanctioned under Art. 94. It repeals the 2010 instruction that preceded it.

Here is what it requires in practice.

Footage is personal data

Recordings held in a CCTV system are personal data provided an individual can be identified directly or indirectly from them. The instruction is specific about how: where the image or sound reveals distinguishing characteristics such as the face, physical features or voice, so that full identification becomes possible when combined with other available data.

The whole law therefore applies: lawful basis, security, retention, and the rights of data subjects under Arts. 12-21, the Albanian counterpart of GDPR Arts. 12-22. The instruction adds an explicit prohibition of its own: recordings containing personal data may not be distributed, except where the law provides for it.

Legitimate interest is narrower than people assume

The instruction states plainly that CCTV processing is a serious interference in an individual's private life, and that a controller may only process this data where it is lawful under Art. 7 of the Law. In practice that means either a legal obligation or the controller's legitimate interest, and it acknowledges something most guidance skates over: consent is rarely available here, because a controller cannot realistically identify everyone who will walk into the zone beforehand.

Where you rely on legitimate interest, four conditions have to hold together:

  • you have the right to decide who may enter and remain in the monitored area, meaning a right over the premises;
  • the use is justified by a specific need to protect the controller or third parties, such as the risk of theft or a threat to the physical or mental security of people inside the zone;
  • the purpose of recording is clearly specified and consistent with the controller's lawful interests, for example protecting property against theft;
  • the purpose cannot be achieved by any other means.

Note how specific that is. This is not legitimate interest at large. It is protection against theft or a security threat, with evidence that nothing less intrusive would have done the job. The instruction also requires, in every case, a guarantee that no less intrusive route to the same purpose existed.

Installation is prohibited in spaces used exclusively for private purposes: toilets, showers, changing rooms. Monitoring and transmitting recorded images in real time over the internet or electronic communications services, where people can easily be identified, is also prohibited. The camera wired to an app anyone with the link can watch is precisely the arrangement this rule forbids.

The written decision nobody has

This is the obligation almost no one meets. Before processing begins, the controller's decision-making body must adopt and document an internal act specifying:

  • the type and specifications of the cameras and their placement, consistent with the purpose for which they will be used;
  • the exact zones that will be under surveillance.

Positioning must be such that no camera captures images of areas that do not match the purpose of the surveillance. In other words, a camera installed to protect the till should not also cover the staff desks. Without that document there is no way to demonstrate either purpose or proportionality, and it is the easiest finding an inspector can make.

Access: restricted, logged, and confidential afterwards

The circle of people with access to recorded data must be kept as narrow as possible. Beyond that, the instruction requires that every access to the recorded data be documented, for the purpose of a possible later check. That means an access log: who viewed the footage, when, and why. If your system keeps no such trail, the obligation is not met.

Data recorded for risk prevention may not be used for other purposes, except where the law provides, for instance for important public interests such as fighting crime. And everyone with access is bound to confidentiality even after their employment ends.

Retention: 72 hours, or up to 30 days

Retention must not exceed the period necessary for the purpose. In general, recordings may be kept:

  • for 72 hours, which is the baseline where premises are continuously watched by a person;
  • for a longer period where the premises are not under continuous surveillance, but no more than 30 days, extendable over official holidays;
  • for longer only where a specific normative or regulatory act provides for it.

After the lawful retention period ends, the controller must take measures to delete the data. Deletion is not optional, and letting the system overwrite "when the disk fills up" is not a retention policy: the period has to be configured and enforced. Where a security incident has occurred, the data must be made available to the competent authorities.

One important and little-known exception. Where a data subject requests access to footage of themselves, that footage cannot be deleted after the controller receives the request. The request freezes the retention clock. An organisation that purges on its usual schedule after receiving a request has created a second problem on top of the first.

Residential buildings: 75% of residents

CCTV may be installed in residential buildings only with the approval of at least 75% of residents, in line with the legislation on managing co-ownership, and in the common areas only for the purpose of protecting the safety of people and property. Making images of residents and their activities available to third parties is prohibited, except where competent authorities require it.

Signage: the template already exists

Data subjects must be clearly informed of the existence and purpose of the system by a notice placed in the monitored zone. The controller is obliged to use the standard signage template approved by the Commissioner, which is annexed to the instruction itself. There is no reason to improvise one, and an improvised sign is a visible, photographable gap.

Access requests and third parties

Where someone asks to see footage in which they appear, and access is to be given by showing them the recorded material, the controller must take account of the data protection interests of third parties in the same material, making anonymisation of the video possible by obscuring their images.

In practice you need a workable way to blur other faces. Without it, the request is either refused without a proper basis or fulfilled by disclosing someone else's data. Both are breaches.

The checklist

  1. Does a written internal decision approving the system exist, with camera types, specifications, placement and the exact zones?
  2. Is the purpose specified, and do the cameras cover only what that purpose justifies?
  3. Are there cameras in exclusively private spaces?
  4. Is footage transmitted in real time over the internet where people can be identified?
  5. Is retention configured to 72 hours, or justified up to 30 days?
  6. Is every access to footage documented?
  7. Is the Commissioner's standard signage in place in the monitored zone?
  8. Can you anonymise third parties in response to an access request?
  9. For residential buildings: is there approval from 75% of residents?

If any of these is missing, it is not a problem for later. The instruction is in force, and non-compliance is sanctioned under Art. 94 of Law 124/2024.