CCTV in School Toilets is a GDPR and Privacy Red Line

Bulgarian news have reported the installation of cameras in school toilets in Sofia, Bulgaria.* This post examines the failure to conduct a mandatory Data Protection Impact Assessment (DPIA). Had one been carried out, it would likely have identified unacceptable risks and prevented both the resulting publicity and regulatory scrutiny. This post does not assume the guilt or otherwise of anyone involved.

I rarely have an absolute opinion on data protection matters because answers are often context-driven. But when I read the news that CCTV was installed in school toilets in Sofia, Bulgaria, I knew that would be a no from a data protection perspective.

@mclee on Unsplash

Why This Case Matters for All Schools

It is worth noting that this case would be following the EU GDPR as Bulgaria is an EU country (plus other applicable national data laws), but the key principles still stand.

  • Legal: schools are high-risk environments for data protection because they involve children.

    In this case, we have teenagers between 13-18 years of age.

  • Factual: toilets are among the most privacy-sensitive spaces.

    At the time of writing, the investigation isn’t clear on whether the cameras were pointing at the sinks and/or the cubicles.

  • Governance: personal devices at work create risks you as the controller can’t control but can be responsible for.

    It has been established that the camera footage fed straight into the Head Master’s laptop, which was also transferred to his personal phone via an app.

It is argued that the CCTV was needed to monitor undesirable behaviour and prevent smoking. The Head Master is reported to not have had any knowledge of the CCTV cameras up until the news came out. Lack of knowledge, however, does not reduce controller responsibility. There is also reporting suggesting that some files have been deleted.

Whatever the motivations, this case sits at the extreme end of surveillance and is a useful example of what not to do under the GDPR.

It sets up a discussion around lawfulness, proportionality, and safeguarding vs privacy; a discussion which could have been had via a DPIA.

A DPIA for CCTV in Toilers is Mandatory

An easy fix would have been to do a DPIA on the appropriateness of CCTV in toilets, however, there is no mention of this having been done. The likely outcome of it if completed correctly would have looked something like this:

Mandatory because we have:

  • Systematic monitoring

  • Vulnerable data subjects (children)

  • High-risk processing

  • Highly intrusive location.

Likely outcomes:

  • Unacceptable risk despite the intended purpose. The school could find an alternative less intrusive way to achieve the goal or would have to have quantitative evidence of undesirable behaviour and / or smoking.

  • Consultation with the parents and the supervisory authority would be required.

  • Processing should not commence.

Read on for more considerations to keep in mind.

Children’s Data Warrants Heightened Protection

CCTV footage is personal if individuals are identifiable. In toilets, footage may reveal:

  • Physical characteristics

  • Health-related information

  • Sexual development (especially for children).

This may elevate the processing into special category data, even if unintentionally, and is an addition to intrusive processing which raises the GDPR bar very high.

Additionally:

  • Children merit specific protection, particularly in surveillance contexts.

  • Schools are expected to meet a higher standard of care, not a lower one.

Any processing involving children must consider:

  • Best interests of the child

  • Power imbalance

  • Inability to give meaningful consent.

Even if we assume parental consent is needed for the younger children, it’s questionable that consent should be the lawful basis for this.

What Could the Lawful Basis for CCTV in Toilets Be?

Consent is not possible because:

  • Unlikely to be freely given in a school setting

  • Impossible to refuse without consequences

  • Cannot achieve goals if consent not given.

There is very likely a law to say smoking must be prohibited and that school management is responsible for dealing with bullying. However, it is unlikely that any law requires CCTV monitoring in this way, therefore legal obligation is a weak lawful basis.

If the school claimed legitimate interests, they (eg safety) may very well be legitimate, but the balancing test would fail on the fact that children have higher expectations of privacy here and the processing cannot be justified.

Public task is a possibility, but it still requires necessity and proportionality, neither of which is justified. Technical possibility is not the same as legal permissibility under the GDPR.

In summary, there is no defensible appropriate lawful basis for this type of CCTV on the facts (not general CCTV).

How Do You Avoid “Function Creep”?

There is a big failure here to protect against function creep.

There is still running investigation into motives and who shared what with whom, but the main failing here is that the footage (allegedly) fed straight to the Head Master’s personal devices.

As such, there is a high risk of unauthorised and unchecked secondary use, including:

  • Reviewing footage

  • Sharing with third parties

  • Further sharing on personal devices

  • Retention beyond necessity and original purpose.

Consequences and Risks for Schools

School have a hard task of balancing safeguarding and surveillance. It’s a fine line that, if crossed, can undermine safeguarding by creating opportunities for misuse and risks psychological harm.

The Bulgarian authorities are still investigating this case but generally speaking, schools / controllers in this position should be ready to face:

  • Regulatory enforcement action or at least attention

  • Criminal liability under local law

  • Civil claims from parents and their children

  • Loss of staff

  • Loss of trust in educational institutions.

Practical Takeaways

  • Recognise that certain spaces are effectively off-limits for surveillance.

    Toilets and other spaces associated with bodily privacy sit at the extreme end of intrusion. In practice, no amount of transparency, signage, or consultation is likely to make CCTV in such spaces lawful.

  • Use a DPIA as a decision-making tool, not a paperwork exercise.

    A properly conducted assessment should be capable of stopping a project, not just documenting it. Where risks to children’s dignity and psychological wellbeing cannot be mitigated, the correct outcome is not to proceed.

  • Involve data protection expertise at the earliest stage.

    CCTV decisions should never be treated as facilities or safeguarding matters alone. Data Protection Officers or advisers must be involved before any procurement, installation, or testing takes place.

  • Do not rely on consent to legitimise intrusive monitoring.

    In school environments, consent is rarely freely given and is particularly inappropriate where pupils have no realistic ability to refuse without consequence.

  • Ensure senior leadership oversight of all high-risk processing.

    Claims that leadership was unaware of surveillance measures point to governance failures, not reduced responsibility. Controllers are accountable for decisions made within their institutions.

  • Explore and evidence less intrusive alternatives first.

    Safeguarding and behaviour concerns must be addressed through measures that respect privacy and dignity, such as supervision policies, environmental design changes, or educational interventions.

The GDPR does not prevent safeguarding, but it does require that it is done lawfully and with a thorough consideration of the person whose data is being used.

* https://bntnews.bg/news/kameri-v-toaletnite-na-stolichno-uchilishte-zadarzhan-e-direktorat-1370014news.html, accessed 20 December 2025.

Previous
Previous

Employee Departures: Mind the Confidentiality Gap

Next
Next

The Empathy Trapper: AI Should Not Be Your Therapist