One co-owner opposes the six surveillance cameras in his residence's shared courtyard and garage. However, a large majority of the co-owners vote to keep them. The Litigation Chamber of the Data Protection Authority ruled on May 11, 2026 (No. 100/2026) that such a majority decision is not sufficient: without a reasoned balancing of interests per camera, any processing remains unlawful.
The facts
The case revolves around Residence [II], an apartment complex in which six surveillance cameras are focused on the common courtyard and the entrance to the underground garage. The images are stored with an external processor and accessed via a smartphone application by the software provider. The complex was erected by a builder-company (Y2 NV), in conjunction with an adjacent apartment block (Residence [I]) erected by a related company (Z1 NV).
The complaint nods to an earlier decision. In decision 36/2020 of July 9, 2020, the Litigation Chamber had imposed a permanent injunction on Z1 SA for the cameras directed at Residence [I] and a temporary injunction for the cameras that monitored both residences, until both co-owners' associations (hereafter, COAs) would jointly decide. The plaintiff, a co-owner of Residence [II], noted that the cameras remained active and therefore filed a new complaint in May 2023.
At the Special General Meeting of September 23, 2020, the COA of Residence [II] had formally assumed responsibility for the camera surveillance from the building owner and decided by 851 votes out of 914 to retain the cameras. That same day, a new syndic was appointed. For the Inspectorate, it is established that the COA of Residence [II] acted as data controller from the end of September 2020. As of September 22, 2023 - after the start of the inspection investigation - the cameras were turned off, but physically remained in place.
At the hearing, it appears that the majority of residents continue to insist on camera surveillance. At the December 13, 2023 general meeting, the use is again approved, but the syndic leaves the cameras inactive because of the plaintiff's continued dissent.
The decision
The Litigation Chamber first notes that only the COA can be held liable as a data controller for the period from September 23, 2020. On that date, the building owner-company has transferred all authority for the purpose and means of camera surveillance to the COA and cannot be considered a data controller within the meaning of art. 4, 7) General Data Protection Regulation (GDPR). The complaint against the builder is dismissed.
On the merits, the Litigation Chamber finds a series of violations under the COA. Central is the lack of a valid legal basis. Consent within the meaning of Art. 6(1)(a) GDPR in conjunction with Art. 4, 11) GDPR is ruled out: the basic deed of the complex stipulates that each owner or user must “respect” the camera surveillance and give his consent to the privacy notices. Such an obligation does not meet the requirement of free consent, since the resident has no real choice. Nor do the internal order regulations, which merely inform residents that the building is equipped with camera surveillance, constitute consent.
The Litigation Chamber clarifies that the COA can only invoke legitimate interest (Art. 6(1)(f) GDPR), and that this requires for each individual camera an express balancing of interests according to the cumulative criteria elaborated by the ECJ in Rīgas satiksme and in TK / Asociaţia de Proprietari bloc M5A-ScaraA. Only when that consideration per camera turns out to be positive can it be retained - provided that the other GDPR obligations are also met (information obligation, facilitation of data subjects' rights, conclusion of a processing agreement).
The COA is also sanctioned for ignoring a request for access to the complainant's camera images (Art. 12(2) in conjunction with Art. 15 GDPR and Art. 12 Camera Law). That the requested images possibly showed third parties instead of the complainant does not relieve the controller of its obligation to respond in a timely and reasoned manner.
In addition, a violation of Art. 28(3) GDPR is found due to the absence of a processing agreement with the software supplier hosting the images. For the violation of art. 31 GDPR (inadequate cooperation with the Inspectorate), a dismissal of charges is pronounced, given the exceptional complexity of the file (successive syndics, two COAs and two building owners).
The outcome is an order to bring the processing into compliance with Art. 6(1) GDPR within three months by conducting an interest balancing exercise on a camera-by-camera basis, a reprimand for the breaches found, and a dismissal against the building owner.
Legal analysis and interpretation
Consent via basic deed: not a valid legal basis
The Litigation Chamber draws out a principle it has defended before: in a forced co-ownership, consent can never serve as a valid legal basis for camera surveillance. The reasoning relies on Art. 4, 11) GDPR: a consent that is attached to the acquisition of an apartment as a condition - via a clause in the basic deed - does not meet the requirement of freedom. After all, the resident has no real choice: if he does not accept the privacy regime, then he cannot live in the building.
This vision is consistent with the Guidelines 05/2020 on consent of the European Data Protection Board, which identifies freedom as a core element of consent. A majority decision of the general meeting does not change this. The GDPR has no collective consent for processing operations that do affect the minority. Those who vote against cameras - and even those who vote blank - are not bound by the consent route.
The legal reasoning is rigorous but consistent. The practical implications are far-reaching. A clause in the basic deed phrased as “consent with camera surveillance” is legally without merit. Anyone finding such a clause in a basic deed or by-laws might as well assume that it has no merit.
Balance of interests per camera, not per system
A second finding is methodologically significant: the Litigation Chamber requires a balancing of interests on a camera-by-camera basis. It is not enough to rule in the abstract that a surveillance system as a whole is justified. For each of the six cameras individually, the three cumulative conditions of Rīgas satiksme must be weighed: a legitimate purpose, the necessity of the processing, and the balance in relation to the fundamental rights of data subjects.
This refines existing case law. In TK v. Asociaţia de Proprietari bloc M5A-ScaraA - which the Litigation Chamber explicitly cites - the ECJ ruled that camera surveillance in the common parts of an apartment building can be compatible with the GDPR, as long as a balancing of interests is done on a situation-by-situation basis. The Litigation Chamber now clarifies that this may not be handled “per building” or “per system,” but must be done separately per camera.
The difference is not a detail. A camera imaging the driveway to the parking garage is relatively easy to justify - traffic safety and preventing vehicle break-ins are legitimate goals, and alternatives (smart lighting, badge systems) have their limits. A camera in a community courtyard, on the other hand, requires a much more complicated balancing act: what is the reasonable expectation of privacy of someone relaxing or playing with children there? The Litigation Chamber is forcing the COA to bring that nuance explicitly into the record.
The presence of inactive cameras
A striking consideration is that the Litigation Chamber already considers the mere presence of inactive cameras to be a violation of the right to privacy (Art. 8 ECHR). The cameras have been off since September 2023, but they are still there. For the Litigation Chamber, this is insufficient: as long as the resident has no control over whether or not the system is functioning, the threat of reactivation remains.
This reasoning is dogmatically defensible on the right but deserves critical comment. A chilling effect can occur when the visible presence of a camera makes the resident assume that he is being filmed. Yet it is striking that the Litigation Chamber goes further here than the GDPR strictly requires: that regulation only applies to the processing of personal data, and an inactive camera by definition does not process any data. The reliance on Article 8 ECHR suggests that the Litigation Chamber wants to enforce a sense of freedom of surveillance that is broader than the actual processing act.
The practical consequence remains clear: do not use the cooling-off period after a dispute to leave cameras hanging “just in case.” If they are disposed of permanently, dismantle the housing as well. If they are retained, include a reasoned balancing of interests in the COA file.
Specifically, what does this mean?
For syndics and COA directors. The message is twofold. Delete in any new basic deed the clause requiring co-owners to “agree” to camera surveillance - that clause does not hold up before the Data Protection Authority. For ongoing cases, this means that the general meeting cannot suffice with a majority decision to enable cameras. A written balancing of interests must be prepared for each camera, addressing the security purpose, necessity (are there less intrusive alternatives such as smart lighting, badge systems or intrusion detection?) and the reasonable privacy expectations of residents. That consideration is best kept as an appendix to the minute book and reviewed annually. Failure to do so leads directly to violations of Articles 5 and 24 GDPR, even with an unchanged camera plan. The broader framework of the Camera Act - reporting to the police, register of imaging activities, pictogram at entrances, retention period of up to one month and the right of access of filmed persons - we already discussed in detail in our contribution on surveillance cameras in the common parts of an apartment building.
For co-owners with questions. A co-owner who does not agree to camera surveillance has a strong weapon in his hands. A majority decision of the COA is not sufficient to install or keep cameras operational without the syndic being able to submit a balance of interests for each camera. Failing that, a complaint to the Data Protection Authority is a low-threshold, no-cost avenue to enforce compliance. In addition, there is an autonomous right to acces the images on which one may have been filmed (Art. 12 Camera Law in conjunction with Art. 15 GDPR); the syndic cannot leave such a request unanswered, even if he believes that the images essentially show third parties.
For building owners and developers. The role of building owner ends once the COA is established and the syndic is given formal access to the monitoring system. Until then, the building owner must assume responsibility himself. Avoid boilerplate provisions in the basic deed that seek to establish “once and for all” permission for camera surveillance - these create an appearance of security that proves to be legally worthless to the future COA. Better to hand over a “GDPR-compliance camera surveillance” file upon completion, with the balancing of interests for each camera, pictogram plans and a draft processing agreement with the camera system vendor.
Frequently asked questions (FAQ)
May the general assembly of an apartment block decide to install surveillance cameras?
A majority decision of the general assembly is not in itself a valid legal basis for the processing of personal data via surveillance cameras. The COA must invoke the legitimate interest of Art. 6(1)(f) GDPR and make a substantiated balancing of interests for each camera. Only then can the cameras be installed or retained, provided that the other GDPR obligations (information obligation, register of processing activities, processing agreement, reporting to the police) are also complied with.
Does a clause in the basic deed suffice as permission for camera surveillance?
No. A clause requiring every buyer to agree to camera surveillance does not meet the requirement of free consent in Art. 4, 11) GDPR. The occupant has no real choice, since accepting the basic deed is a condition for becoming an owner. Such clauses are legally without value as a legal basis.
Who is the data controller for security cameras in a new building complex?
Initially, it is the building owner or developer who installs and operates the cameras. From the moment the COA is established and the trustee is given formal access to the system, responsibility passes to the COA. From that date, all GDPR obligations must be fulfilled by the COA, even if it was not a party to any previous decision by the Data Protection Authority.
Conclusion
This decision confirms and refines an established line: in a forced co-ownership, camera surveillance can only rest on the legitimate interest, and then only if a reasoned consideration has been made for each camera. A majority decision of the general meeting or a clause in the basic deed is not enough. Anyone working with a camera system as a syndic, COA administrator or builder would be well advised to put their case on this basis - failing which, even inactive cameras pose an enforcement risk.



