VDAI (Lithuania) - 3R- 1876 (2.13-1.E)
| VDAI - 3R- 1876 (2.13-1.E) | |
|---|---|
| [[File:|center|250px]] | |
| Authority: | VDAI (Lithuania) |
| Jurisdiction: | Lithuania |
| Relevant Law: | Article 5(1)(a) GDPR Article 6(1)(f) GDPR Article 9(2) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 30.12.2025 |
| Published: | |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | 3R- 1876 (2.13-1.E) |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Lithuanian |
| Original Source: | VDAI (in LT) |
| Initial Contributor: | lde |
The DPA found that a hospital unlawfully carried out video surveillance and audio recording in several areas, including operating rooms. While video surveillance in general hospital areas could be justified by legitimate interests, monitoring in operating rooms and certain patient examination areas was deemed unlawful processing of health data.
English Summary
Facts
The controller is a public hospital operating a video surveillance system with 26 cameras installed across its premises, including entrances, corridors, patient admission areas, outpatient examination rooms, and three operating rooms. Most indoor cameras also recorded audio. The stated purposes of the surveillance were to ensure the safety of staff, patients and property and, in operating rooms, to ensure the smooth organisation of work.
Following a notification by a data subject, the State Data Protection Inspectorate (DPA) initiated an ex-officio investigation and carried out an on-site inspection. The inspection revealed that certain cameras partially covered patient examination areas and permanent employee workplaces. In operating rooms, cameras recorded areas close to operating tables and transmitted live video and audio to a workstation, although the controller could not clearly identify who had access to the live feed or whether recordings were stored.
The controller relied on legitimate interest under Article 6(1)(f) GDPR as the legal basis and had conducted a data protection impact assessment and a balancing test. It argued that data subjects were informed by signing hospital admission documents and that access to video and audio data was restricted. During the inspection, it was also found that video recordings were stored longer than the defined retention periods.
Holding
The DPA found that video surveillance in general areas of the hospital, such as entrances, corridors, and foyers, could in principle be based on the controller’s legitimate interest in ensuring safety, provided that camera views were appropriately limited. However, video surveillance in examination rooms, admission and emergency examination rooms, and geriatric care units was unlawful insofar as camera views covered patient examination areas or permanent employee workplaces, as this failed the balancing of interests required under Article 6(1)(f) GDPR.
The authority further held that video surveillance in operating rooms was unlawful. The controller failed to demonstrate that such surveillance was necessary to achieve the stated purpose of organising work efficiently, as less intrusive alternatives were available. Moreover, the rights and reasonable expectations of data subjects prevailed, given the particularly sensitive nature of operating rooms, where patients may be undressed and undergo invasive procedures. As a result, the processing did not meet the necessity or balancing requirements under Article 6(1)(f) GDPR.
Additionally, the authority found that the controller unlawfully processed special categories of personal data, including health data, as it failed to demonstrate the applicability of any exception under Article 9(2) GDPR. The same deficiencies applied to the audio recording carried out alongside video surveillance.
Accordingly, the authority concluded that the controller infringed Articles 5(1)(a), 6(1), 9(2), and related GDPR provisions and required the controller to bring its video and audio surveillance practices into compliance with data protection law.
Comment
In this decision, the DPA initiated proceedings to set an administrative fine against the controller. You can read the decision here.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.
ELECTRONIC DOCUMENT EXTRACT STATE DATA PROTECTION INSPECTORATE DECISION December 30, 2025 No. 3R- 1876 (2.13-1.E) Vilnius The State Data Protection Inspectorate (hereinafter referred to as the Inspectorate) received on 24-04-2025 a notification (Inspection reg. No. 1R-2619 (2.13 Mr)) from UAB „Šiaurės rytai“ (hereinafter referred to as the Notifier) regarding video surveillance carried out on the premises (including operating rooms) of the Public Institution Biržai Hospital (hereinafter referred to as the Hospital, the Person Under Inspection). By order No. 1T-44 (1.12.E) of the Director of the State Data Protection Inspectorate of 2025-05-05, the Director decided to initiate an investigation on his own initiative regarding a possible violation of the provisions of the GDPR1, in relation to the Hospital. The Inspectorate, having inspected the Hospital, stated: 1. Information provided to the Inspectorate The complainant indicated in the report that video surveillance is carried out in the Hospital premises (e.g., the reception area). He noted that at the last meeting of the district council it was reported that video surveillance is also carried out in the Hospital operating rooms, but patients undergoing surgery are not warned about video surveillance and have not signed any written consents. He noted that patients are usually brought into the operating room naked. He indicated that, according to witnesses, there have been cases where the Hospital director comments on what is happening in the operating room from home. He also indicated that it is unclear where and how the footage is used. The report raises the question of whether the video surveillance carried out in the Hospital operating room does not violate the laws regulating the protection of personal data. 2. Inspection carried out In accordance with the order of the Director of the Inspection No. 2R-2246 (2.14.E) dated 21-05-2025, an on-site inspection was carried out on 22-05-2025, i.e. the compliance of the video surveillance and audio recording carried out on the territory and premises of the Hospital (at the address Vilniaus g. 115, Biržai) with the requirements established in legal acts was checked. During the inspection of the Hospital carried out on 22-05-2025, in order to record the actual circumstances, the following actions were performed: 1) the observation fields of the Hospital's video surveillance cameras were checked and photographed; 2) the information boards located on the territory and premises of the Hospital, informing about the video surveillance and audio recording being carried out, were checked and photographed; 3) the actual storage duration of the video recordings recorded by the video surveillance cameras was checked; 4) an assessment of the change in the field of sound recording and video camera surveillance was carried out; 5) access to video and audio recordings recorded by video surveillance cameras was checked. 1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR). During the inspection, the Hospital's Personal Data Protection Officer (hereinafter referred to as the DPO) explained that 26 video surveillance cameras are operating on the territory and premises of the Hospital and submitted Annex 1 to the Rules for the Use of Video Surveillance Cameras and Video Data Processing of the Hospital, approved by order of 25 March 2025 - "List of video equipment for video surveillance of the territory and premises of the institution, establishing the terms for storing video data" (hereinafter referred to as the List). The Hospital DPO, when asked what the GDPR stipulates as the legal basis for the processing of personal data, based on which the Hospital conducts video surveillance and audio recording, indicated that the Hospital has conducted a data protection impact assessment (hereinafter referred to as the PDAA) and submitted the PDAA report of the Biržai Public Hospital on 03 February 2025. The Hospital DPO explained that data subjects are informed about the video surveillance and audio recording by means of information boards, in addition to the fact that files with the necessary documents are prepared (both for Hospital visitors and employees); data subjects can access files intended for Hospital visitors on the Hospital premises (in the posts and reception area), and the latter are familiarized with documents intended for employees upon signature. After the on-site inspection, the Inspected Person submitted additional explanations on 2025-06-17 (Inspection reg. No. 1R-3973 (2.13 Mr)). That is, he indicated that he was providing the Inspection with the following documents: 1) The rules for processing personal data of the Public Institution Biržai Hospital with annexes, approved by the Hospital Director's Order No. PVK-30 of 2024-06-18; 2) The description of the procedure for implementing the rights of data subjects when processing personal data in the Public Institution Biržai Hospital, approved by the Hospital Director's Order No. PVK-31 of 2024-06-18; 3) The description of the procedure for implementing the rights of data subjects when processing personal data in the information systems of the Public Institution Biržai Hospital, approved by the Hospital Director's Order No. PVK-32 of 2024-06-18; 4) The document “Information for patients on personal data processed in the Biržai Public Hospital” approved by the Hospital Director’s order No. PVK-42 of 2024-06-18; 5) Information notice on the processing of personal data of patients; 6) The test of the balance of legitimate interests regarding the video surveillance carried out in the Hospital together with audio recording of 2025-02-03; 7) The order of the Hospital Director on granting access to video data No. PVK-11 of 2025-03-27; 8) The undertaking of the authorized employees of the Hospital to maintain the confidentiality of data of 2025-03-27; 9) The Privacy Policy approved by the Hospital Director’s order No. PVK-35 of 2024-06-18; 10) The order of the Hospital Director of 2025-03-25 No. PVK-7 approved the Rules for the Use of Video Surveillance Cameras and Video Data Processing of the Public Institution Biržai Hospital with Annexes; 11) By order No. PVK-8 of the Hospital Director of 2025-03-25, the Description of the Procedure for Video and Audio Surveillance and Recording in the Provision of Personal Health Care Services and the Processing of Video and Audio Recording Data of the Public Institution Biržai Hospital with Annexes. It also indicated that during the inspection it was noticed that video data is stored longer than the established deadlines, therefore, by order of the Hospital Director, a commission was formed for the manual destruction of video data. It explained that data stored for too long was destroyed, and also indicated that it ensured that video data would be stored in the device only for the established deadline. The Hospital submitted the Hospital Director's order No. PVK-34 of 2025-05-23 "On the Formation of a Data Destruction Commission". After the inspection, the Information Technology Department of the Inspectorate prepared Inspection Report No. 4R-672 (2.14.E) on 2025-12-19 “Ensuring the requirements for video surveillance of the Public Institution Biržai Hospital” (hereinafter referred to as the Inspection Report). The inspection report assessed: 1) The surveillance fields of the hospital’s video surveillance cameras; 2) the possibility of changing the field monitored by video surveillance cameras; 3) Information signs located on the hospital’s territory and premises; 4) the actual storage duration of video and audio recordings captured by video surveillance cameras; 5) the possibility of accessing the video and audio recordings captured by video surveillance cameras and the video surveillance program was assessed. The inspection report made the following conclusions: First, during the inspection it was established that there are 26 video surveillance cameras operating in the territory and premises of the Hospital, the actual arrangement of which corresponds to the List submitted to the Hospital Inspection: 1) 8 video surveillance cameras operate in the outdoor area, which monitor the entrances to the Hospital premises, parking lots, electrical panel and solar power plant, waste collection site; 2) 1 video surveillance camera operates in the common room, which monitors the main entrance of the Hospital and the lobby near the stairs; 3) 4 video surveillance cameras operate in the Admission and Emergency Department, which monitor: (1) the entrance to the department, (2) the patient waiting room, (3) the patient admission and examination room of the Admission and Emergency Department (the field of view of this video surveillance camera has been adjusted - the patient examination area is covered by a filter), (4) the outpatient operating room (hereinafter referred to as the Outpatient Operating Room) (the entrance door and the part of the room next to the door, the video camera's field of view covers a small part of the patient examination area); 4) 1 video surveillance camera operates in the Supportive Treatment and Nursing Department, which monitors the main entrance and part of the corridor of this department; 5) 2 video surveillance cameras operate in the Internal Medicine Department 1, which monitor the entrance to this department, the corridor and the emergency exit; 6) 2 video surveillance cameras operate in the II Department of Internal Medicine, which monitor the entrance to this department, the lobby, the corridor and the emergency exit; 7) 2 video surveillance cameras operate in the Department of Surgery and Orthopedics Traumatology, which monitor the entrance to this department, the lobby, the corridor and the emergency exit; 8) 1 video surveillance camera operates in the consultation polyclinic, which monitors the entrance to this department and the corridor; 9) 1 video surveillance camera operates in the Geriatric Day Hospital, which monitors the reception and the corridor; 10) 3 video surveillance cameras operate in the operating rooms, i.e. one video surveillance camera operates in the surgical operating room, the purulent operating room and the traumatology operating room (hereinafter referred to as the Operating Rooms). After checking the field of view of the video camera in the surgical operating room, it was determined that the camera captures the image along the wall, i.e. a small part of the room near the wall, into which the work table and the employees located next to it enter; the operating table and/or the patient who was undergoing an operation at the time of the inspection did not enter the camera's field of observation. The video surveillance camera in the purulent operating room captures the wall, the space between the wall and the operating table, and the edge of the operating table also enters the field of observation of the video surveillance camera. The video surveillance camera in the trauma operating room captures the wall, the space between the wall and the operating table; the operating table does not enter the field of observation of the video camera. 11) 1 video surveillance camera operates in the basement, which monitors the basement corridor. Secondly, it was established that the fields of observation of all video surveillance cameras can be changed only physically. Thirdly, it was established that all video surveillance cameras installed in the Hospital premises perform audio recording. Audio recording is not performed by cameras installed outside2. Fourth, it was concluded that data subjects are informed by information signs before entering areas where video and audio recording is taking place. 2 The model of the outdoor video surveillance cameras is "Hikvision DS‑2CD2232‑I5. The cameras of this model do not have an audio recording function. Fifth, it was established that the image monitored by the video surveillance cameras located on the territory and premises of the Hospital (except for the Operating Rooms) is recorded, and the video recordings made are stored in two different video recording devices. The oldest saved video recordings in the first video recording device were dated 2025-05-03 (i.e. 20 calendar days old), and in the second video recording device the oldest saved video recordings were dated 2025-02-27 (i.e. almost 3 months old). Sixth, the video recordings recorded in the video recording devices are viewed only after entering a special room locked with a key, which can only be accessed by one authorized person. The computer workstation and the video recording device program are protected passwords, therefore the applied physical security measures are sufficient and ensure the physical security of the stored video recordings. It has also been established that remote access is not possible to monitor the video recordings captured by cameras (except for the Operating Room video cameras) (including connecting to a computer workstation, video recording device program or video surveillance cameras located in the room). Seventh, it has been established that the image monitored by the video surveillance cameras located in the Hospital's Operating Rooms is broadcast directly to a computer located in the Hospital's Operating Room reception. Persons may enter the Operating Room reception only with a pass card. The computer workstation of the Hospital's Operating Room reception employee is protected by a password, and the employee's account in the video surveillance program (through which the image and sound from the Operating Rooms are broadcast) is also protected by a password, therefore the applied physical security measures are sufficient and ensure the physical security of the video broadcast. Inspection The report stated that during the on-site inspection, the Hospital representatives could not indicate who has privileged access rights to the program, nor could they answer whether there is a video recording device for the cameras in the Operating Rooms (and if so, where it is located), therefore the Inspectorate employees were not given the opportunity to determine which persons have access to the program (i.e. live broadcast video), nor was there an opportunity to determine whether video recordings are made during video surveillance in the Operating Rooms. For this reason, after the on-site inspection, the Inspected Person was additionally contacted with instruction No. 2R-3401 (2.14 E) to provide additional information. The Inspected Person submitted a response to the Inspection's instruction on 07-08-2025 (Inspection reg. No. 1R-5255 (2.14 K)), however, the Inspectorate was not provided with evidence that would allow it to determine who actually has access to the program and whether the video recordings are actually or are not being made. For these reasons, the Inspectorate's employees were not given the opportunity to determine who has actual access to the program (i.e., live broadcast video and audio) and whether the image monitored in the Operations is not being recorded. 3. Applicable legal regulation The European Data Protection Board (hereinafter referred to as the EDPB) of 2020-01-29 Guidelines No. 3/2019 on the processing of personal data using video devices (hereinafter referred to as the Guidelines on video surveillance) in the preamble notes that the intensive use of video devices has an impact on citizens' behavior. These technologies can in fact limit the ability to move and use services anonymously, as well as generally limit the ability to remain undetected. The Guidelines on video surveillance also note that surveillance by video cameras is not necessary in itself in cases where there are other means to achieve the main purpose. Otherwise, dangerous changes in cultural norms may occur, which will lead to the fact that the abandonment of privacy will be recognised as a common starting point. The European Data Protection Board has indicated in its Guidelines on video surveillance that the specific purpose of the processing must be clearly stated before the data are used (Article 5(1)(b) GDPR). Video surveillance can be used for various purposes, such as helping to ensure the protection of property and other assets, life and physical integrity of persons, gathering evidence for civil claims, etc. These purposes of surveillance should be specified in written documents (Article 5(2) GDPR), and the specific purposes relating to each video surveillance camera used must be specified. The Guidelines on video surveillance emphasise that video surveillance has a significant impact on data protection and that video surveillance is therefore not necessary in itself where other means are available to achieve the main purpose. It should be noted that the GDPR does not lay down separate provisions exclusively for video surveillance and/or audio recording legal regulation, therefore, the video surveillance and/or audio recording must comply with the general provisions of the GDPR and the Law of the Republic of Lithuania on the Legal Protection of Personal Data (hereinafter referred to as the GDPR). Personal data processing is considered lawful when it complies with the provisions of the GDPR and the GDPR. Paragraph 39 of the GDPR preamble establishes that any processing of personal data should be lawful and fair. First of all, the processing of personal data must also be based on at least one of the conditions for lawful personal data processing provided for in Articles 6 and/or 9 of the GDPR (depending on the category of personal data being processed). That is, in cases where special categories of data are also processed (e.g. health data relevant in the context of this inspection3), such processing of personal data must be based on Article 9(2) of the GDPR. Otherwise, the health data of the individual (patient) cannot be processed. Consequently, the processing of health data must comply with at least one of the conditions for lawful personal data processing provided for in Article 6(1) of the GDPR. the condition for lawful processing of personal data set out in Article 9(1)(a) of the GDPR, but also at least one of the exceptions to the prohibition on processing health data set out in Article 9(1)(a) of the GDPR. Secondly, personal data must be processed in accordance with the principles set out in Article 5(1)(a) to (f) of the GDPR. In other words, personal data must be processed in accordance with the principles of lawfulness, fairness and transparency, the principle of purpose limitation, the principle of data minimisation, the principle of accuracy, the principle of storage limitation and the principles of integrity and confidentiality. Compliance with the principles set out in Article 5(1)(a) to (f) of the GDPR entails certain obligations on the data controller. For example, the application of the principle of transparency set out in Article 5(1)(a) of the GDPR entails that data subjects should be clear about the purpose for which their personal data are being processed, how personal data relating to them are being processed and what personal data are being processed. data processing operations (collection, use, transfer, etc.) are carried out with them4. Thus, in accordance with the principle of transparency, data subjects must be provided with information about the processing of their personal data. It should be noted that Article 13(1) and (2) of the GDPR establish what information must be provided when personal data are collected from a data subject. Article 12(1) of the GDPR establishes that the data controller must take appropriate measures to provide the data subject with all the information referred to in Article 13 of the GDPR in a concise, transparent, intelligible and easily accessible form, in clear and plain language. The information is usually provided in writing or by other means, including, where necessary, in electronic form. Thus, the data controller (in this case, the Hospital) performing video surveillance and/or audio recording must provide the following information to individuals (before entering the premises or territory where the video surveillance and/or audio recording is being performed): 1) the fact of the video surveillance being carried out and / or audio recording; 2) the name and contact information of the data controller; 3) the purpose(s) of the personal data processing; 4) a reference to the source of information where more detailed information about the video surveillance being carried out can be obtained (i.e. Article 13(1) and (2) of the GDPR; 3 Article 4(15) of the GDPR establishes that health data means personal data relating to the physical or mental health of a natural person, including data on the provision of healthcare services, revealing information about the state of health of that person. 4 Point 60 of the preamble to the GDPR establishes that, in accordance with the principles of fair and transparent data processing, the data subject shall be informed of the data processing operation being carried out and its purposes. information specified in paragraphs 15-22 and 34 of the GDPR, the procedure for exercising the rights of data subjects set out in Articles 15-22 and 34 of the GDPR, etc.), for example, a reference to the website, a contact telephone number, etc. Article 5(1)(e) of the GDPR establishes the limitation of the storage period The principle of proportionality provides that personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Recital 39 of the GDPR establishes the obligation to ensure that the retention period of personal data is kept to a minimum. The European Data Protection Board points out in its Guidelines on video surveillance that “[t]he longer the retention period (in particular when it exceeds 72 hours), the more arguments need to be provided relating to the legitimacy of the purpose and the necessity of the retention. If the controller uses video surveillance not only to monitor its premises but also intends to retain the data, it must ensure that the retention of the data is actually necessary to achieve the purpose”5. This means that the controller must carefully assess what period of retention of the video recordings would be adequate and proportionate in its particular case. When choosing to store video recordings, it is necessary to both choose a specific term and be able to justify such a chosen term. The principle of integrity and confidentiality enshrined in Article 5(1)(f) of the GDPR means that personal data must be processed in such a way that appropriate technical or organisational measures ensure the security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. The implementation of this principle is linked to Article 32 of the GDPR, which requires that procedures must provide for the protection of video and audio recordings against accidental or unlawful destruction, alteration, disclosure and any other unlawful processing. The Inspectorate notes that, pursuant to Article 32(4) of the GDPR, the procedures must describe measures to ensure that any natural person under the control of the data controller who has access to the video and/or audio recordings does not become familiar with them. In addition, the procedures must specify the computer and software used to process the video and/or audio recordings, and, among other things, must specify how appropriate physical and logical access control to the video surveillance cameras and/or audio recording devices is ensured, e.g. locked premises, password storage, access by authorised persons, etc. The Inspectorate also notes that Article 35(1) of the GDPR provides that where the type of data processing, in particular when new technologies are used, and taking into account the nature, scope, context and purposes of the data processing, is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall, before processing the data, carry out an assessment of the impact of the envisaged data processing operations on the protection of personal data. It is noteworthy that point 6.2 of the list of data processing operations subject to the requirement to carry out a data protection impact assessment6 provides that a DPIA must be carried out in cases where personal data are processed in healthcare, social care, prison institutions and other institutions where services are provided to vulnerable persons. Point 10 of the aforementioned list also provides that a PDPA must be carried out in the event that the personal data of employees are processed for the purposes of monitoring or control: processing of personal video and/or audio data at the workplace and/or in the premises or territories of the data controller where its employees work; processing of personal data relating to the monitoring of employees’ communication, behaviour, location or movement. Thus, the data controller, before starting video surveillance and/or audio recording for health purposes, shall ensure that the data are kept in accordance with the following conditions: the owner of a small shop usually notices any vandalism on the same day. Therefore, a standard retention period of 24 hours is sufficient. However, weekends when the shop is closed or several public holidays may be a reason to set a longer retention period. 6 approved by Order No. 1T-35(1.12.E) of the Director of the State Data Protection Inspectorate of 14 March 2019. in a care facility and thus process the data of Hospital visitors and employees (vulnerable persons), must first carry out a PDAV. It should be noted that Article 5(2) of the GDPR provides that the data controller (in this case, the Hospital) is responsible for ensuring compliance with the GDPR and must be able to demonstrate that it is complied with (accountability principle). 4. Conclusions of the Inspectorate7: 4.1. Regarding the lawfulness of the video surveillance As mentioned above, the processing of personal data must first be based on at least one of the conditions for the lawful processing of personal data provided for in Articles 6 and/or 9 of the GDPR (depending on the category of personal data processed). In the case under consideration, the Inspected Person has submitted to the Inspectorate a PDAV report dated 2025-02-03 and a Balance of Interests Test dated 2025-02-03. The PDAV report states that the purpose of video surveillance and audio recording carried out in the Hospital's outdoor area and premises (except for the Operating Rooms) is the safety of Hospital visitors, employees and property, i.e. the aim is to ensure the safety of employees and Hospital visitors/patients, and to implement the prevention of physical and psychological violence. It is also stated that when conducting video surveillance, the Person Under Inspection has the opportunity to assess visitors entering the premises (whether they are not intoxicated, do not behave aggressively, do not bring in unauthorized items or do not take certain items away (in the event of theft), etc.), and also has the opportunity to identify patients leaving the Hospital premises without warning (thus ensuring the safety of patients). The PDAV report also establishes that three cameras are used for monitoring the Operating Rooms, i.e. three separate cameras monitor three Operating Rooms – the surgical operating room, the purulent operating room and the trauma operating room. It is stated that the purpose of video surveillance in the operating rooms is the smooth organization of the work of the Operating Room. Having assessed the objectives of video surveillance specified by the Hospital – the safety of persons and property and the smooth organization of work, it is concluded that the aim of protecting persons and property is to be considered a legitimate interest, therefore it is concluded that the Hospital carries out video surveillance on the basis of Article 6(1)(f) of the GDPR. It should be noted that the Hospital did not rely on any other conditions of lawfulness provided for in Article 6(1)(f) of the GDPR and/or the exceptions provided for in Article 9(2)(f) of the GDPR. According to Article 6(1)(f) of the GDPR, personal data may be lawfully processed when it is necessary to do so for the legitimate interests of the data controller or a third party, except in cases where such interests or fundamental rights and freedoms of the data subject which require the protection of personal data prevail over them, in particular where the data subject is a child. The Court of Justice of the European Union, interpreting Article 6(1)(f) of the GDPR, has established that the application of this provision provides for three cumulative conditions for the lawfulness of the processing of personal data: 1) the processing of personal data is necessary for the purposes of the legitimate interests pursued by the controller or a third party; 2) the processing of personal data is necessary for the purposes of the legitimate interests pursued; 3) the interests or freedoms and fundamental rights of the person whose data must be protected must not be overridden (judgment of 04 July 2023 in Meta platforms and others in case C-252/21; judgment of 17 June 2021 in Mircom International Content Management & Consulting (M.I.C.M.) Limited v. Telenet BVBA in case C-597/19). The requirement for the application of cumulative conditions means that if at least one of the cumulative conditions for the lawfulness of the processing of personal data is not established, the processing of personal data would be unlawful (decision of the Supreme Administrative Court of Lithuania of 29 November 2023 in administrative case No. eA-831-525/2023). Thus, in order to determine whether the video surveillance carried out by the Hospital is lawful, basing such processing of personal data on Article 6(1)(f) of the GDPR, it is necessary to assess all three of the aforementioned cumulative conditions. 4.1.1. Regarding the condition relating to the pursuit of a legitimate interest (first condition), the Article 29 Data Protection Working Party, established on the basis of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, in its Opinion No. 06/2014 of 9 April 2014 on the concept of legitimate interests of the controller under Article 7 of Directive 95/46/EC (hereinafter referred to as the Opinion on legitimate interests), has clarified that interest is the general need of the controller to process the data or the benefits of the processing for the controller or the potential benefits for society. In accordance with the EDPB Guidelines on video surveillance, the legitimate interests of the controller or a third party may be of a legal, economic or intangible nature. It is noted that a legitimate interest must be real and relevant (i.e. it cannot be a fictitious or hypothetical interest). According to the Opinion on legitimate interests, an interest can be considered legitimate if the data controller can pursue it without violating data protection and other legal acts. In other words, a legitimate interest must be acceptable according to the law. In the case under consideration, the Person Under Review indicated that video surveillance is carried out in the Hospital premises (except for the Operating Rooms) in the interest of ensuring the safety of persons and property, and video surveillance in the Hospital's Operating Rooms is carried out in order to ensure the smooth organization of work and provide services more efficiently. It is accepted that both the aim of ensuring a safe and appropriate environment for the Hospital's visitors/patients and employees and the aim of properly and efficiently organizing work in the Operating Rooms are realistic and legitimate. Taking this into account, it is accepted that the Hospital, when carrying out video surveillance, pursues a legitimate interest, therefore the video surveillance carried out meets the first condition necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR. 4.1.2. Regarding the condition relating to the necessity of processing personal data (second condition) According to recital 39 of the GDPR, personal data should only be processed if the purpose of the processing of personal data cannot reasonably be achieved by other means. The Opinion on legitimate interests states that “[i]n applying this balancing test, it is important to first consider, on the one hand, the nature and origin of the legitimate interests and whether the processing is necessary for the pursuit of those interests”. Thus, if the controller decides that the processing of personal data is necessary for the pursuit of the relevant legitimate purpose, he should also ensure that the purpose of the processing is achieved by applying the least intrusive means for the privacy of data subjects. It should be noted that the Hospital submitted a Balance of Interest Test to the Inspectorate on 2025-02-03, which indicated that the Hospital determined that such processing of personal data (video surveillance) is the only way to achieve the objectives pursued. It was noted that the processing of personal data (video surveillance) will achieve the goal of ensuring the safety of visitors and employees of the Hospital, the security of property, and public order. It is stated that it is not possible to effectively achieve the set goal in any other way. It was noted that no other alternatives for achieving the set goals were considered. The Inspectorate, having assessed the assessment submitted by the Inspected Person, concludes that in order to ensure the safety of persons and property (public order) in the territory and premises of the Hospital (except for the Operating Rooms), video surveillance is one of the necessary measures, therefore the video surveillance carried out in these premises complies with the second condition, the necessary processing of personal data based on Article 6, Paragraph 1, Point f of the GDPR. According to the explanations provided by the Inspected Person, video surveillance in the Hospital's Operating Rooms is carried out in order to ensure the smooth organization of the work of the Operating Room and more efficient provision of services. During the on-site inspection, the Hospital representatives explained that the employee working in the Operating Room reception, by observing the image broadcast directly from the Operating Rooms, can more quickly determine when the operation is being completed/finished and can more quickly organize the management of the Operating Rooms, the preparation of another patient for the operation, etc. It should be noted that the presented Balance of Interest test does not assess whether video surveillance in the Hospital's Operating Rooms is the only and most effective way to achieve the aforementioned objective. During the inspection, the Inspected Person did not provide the Inspectorate with any explanations as to why work in the Operating Rooms cannot be properly organised not by means of video surveillance, but by applying other measures that are less restrictive of the privacy of data subjects (patients) (e.g. by notifying the responsible employee about the end of the operation by telephone or in other ways). Taking into account the above, it is concluded that the Inspected Person has not proven that in order to ensure the smooth organisation of work in the Operating Rooms, video surveillance is the only and necessary means to achieve this objective. Thus, video surveillance in the Hospital's Operating Rooms does not meet the second condition necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR. 4.1.3. Concerning the condition of primacy of conflicting rights and interests (third condition) According to the Guidelines on video surveillance, in cases where video surveillance is necessary to protect the legitimate interests of the data controller (i.e. when the first two cumulative conditions are met), the video surveillance system may be put into operation only if there are no overriding interests of the data subject or fundamental rights and freedoms of the data controller or a third party. The data controller must assess: 1) the extent to which the surveillance affects the interests, fundamental rights and freedoms of individuals and 2) whether the rights of the data subject are infringed or adversely affect them. In other words, it is necessary to balance the legitimate interests of the data controller or a third party with the legitimate interests of the data subjects. According to the Guidelines on Video Surveillance, it is necessary to take into account the reasonable expectations of the data subject at the time when his or her personal data are processed. The Guidelines on Video Surveillance state that in the context of video surveillance, the decisive criterion should be whether an objective third party could reasonably expect and conclude that he or she will be monitored in the specific situation. For example, an employee usually does not expect to be monitored by his or her employer at the workplace. Furthermore, one cannot expect to be monitored <...> in examination and treatment rooms. Data subjects can reasonably expect that there will be no surveillance by video cameras in such places. Data subjects can also expect that they will not be monitored in places that are publicly accessible, in particular where those places are commonly used for treatment, rehabilitation and leisure activities. In this case, the interests or rights and freedoms of the data subject will often override the legitimate interests of the data controller. In the Balance of Interests test submitted to the Inspectorate on 2025-02-03, the Inspectorate has indicated only that data subjects are informed about the processing of personal data, and video data is accessible only to a very limited number of persons. In the Balance of Interests test, the Inspectorate has indicated that video data is processed only for the purpose of ensuring the security of persons and property, and that monitoring data subjects in service premises to ensure the protection of persons and property is common practice. It is also indicated that the video surveillance carried out has only a positive impact on data subjects, since using video data, conflict situations are resolved, violations (e.g. theft) are identified, the safety of Hospital employees and visitors is ensured, and physical and psychological violence is prevented. It is also stated that the video surveillance carried out does not have any negative impact on data subjects, since the video data is not provided to anyone, there is no constant review of the recordings, the video recordings are stored only to the extent necessary to achieve the objectives, and no video recordings are made at all in the Hospital Operating Rooms. It is noted that a negative impact on data subjects could arise only in the event of a personal data breach. It should be noted that the EDPB Guidelines No. 1/2024 of 2024-10-08 on the processing of personal data based on Article 6(1)(f) of the GDPR (hereinafter referred to as the Guidelines on Legitimate Interest) state that the data controller must assess its legitimate interests and the legitimate interests of data subjects and third parties. This balancing test must be carried out in each case where the processing of personal data is based on Article 6(1)(f) of the GDPR, and must be carried out before the processing of personal data begins. This means that it is necessary to balance the conflicting interests of the data controller and the data subjects. In accordance with the Guidelines on legitimate interest, the balancing of interests test must address: 1) the interests, fundamental rights and freedoms of the data subjects; 2) the impact of the data processing on the data subjects, including the nature of the personal data processed, the context of the processing and any other consequences of the processing; 3) the reasonable expectations of the data subjects; 4) a final assessment of the balance of the conflicting rights and interests, including an assessment of the possibility of taking other measures that are less restrictive of the privacy of individuals. Having assessed the Balancing of Interest Test carried out by the Subject, it can be seen that it does not actually address how data subjects could react to the processing of their personal data (video surveillance) in specific Hospital premises (including Operating Rooms). In addition, the Balance of Interests test assessed the compatibility of the interests of the data controller (Hospital) and data subjects formally and abstractly. Among other things, the Balance of Interests test is limited to only one of the legitimate interests of the Inspected Person relevant in the case under consideration - ensuring security. However, the Inspected Person did not fully assess his interest in effectively organizing work in the Operating Rooms and the legitimate interests of the data subjects (patients and employees). The Inspectorate, taking into account the above, as well as having assessed the information collected during the inspection, concludes that when conducting video surveillance in the general use Hospital territory and premises, such as the perimeter of the Hospital field, entrances to the Hospital premises, corridors and lobbies of the Hospital departments, video surveillance carried out in pursuit of the legitimate interest of the Hospital to ensure the security of persons and property does not unduly restrict the rights and legitimate interests of the data subjects. The specified areas and premises usually have a constant movement of people, therefore, it is in these zones of the Hospital that incidents related to the safety of people and/or property can most often occur. The Inspectorate also notes that the video surveillance carried out in the premises of the Hospital, such as: 1) Outpatient operating room, 2) Reception and emergency department patient reception and examination room and 3) Geriatric day hospital department, is not per se excessively restrictive of the rights and legitimate interests of data subjects, if the field of surveillance of the video cameras does not include the patient examination area and the permanent workplaces of the employees. In the case under consideration, it was established during the inspection that: 1) part of the patient examination table falls within the field of surveillance of the video camera located in the Outpatient operating room of the Hospital; 2) the field of surveillance of the video camera located in the patient reception and examination room of the Reception and emergency department includes the permanent workplaces of the employees; 3) the field of view of the video camera recording the reception of the Geriatric Day Inpatient Department includes the employee's permanent workplace. Having assessed these circumstances, it can be concluded that although video surveillance can be carried out in the aforementioned premises, the field of view must be strictly limited so that it does not include the patient examination area and the permanent workplaces of the employees. Otherwise, the privacy of the data subjects (patients and employees of the Hospital) is excessively violated. Taking into account the above, the Inspectorate concludes that the video surveillance carried out in the Hospital premises: 1) The Outpatient Operating Room, 2) Room 11 of the Reception and Emergency Department for the reception and examination of patients, and 3) the Geriatric Day Hospital does not comply with the third condition necessary to justify the processing of personal data on the basis of Article 6(1)(f) of the GDPR, since the field of view of the video surveillance cameras includes part of the patient examination area and the employees' permanent workplaces. The Inspectorate, having also assessed the information collected during the inspection, also concludes that conducting video surveillance in the Hospital's Operating Rooms (surgical operating room, purulent operating room and trauma operating room) in order to achieve the legitimate interest of the Hospital in effectively organizing work in the operating rooms is excessively restrictive of the rights and legitimate interests of data subjects (both patients and employees). Although it was established during the inspection that the operating table is not within the field of view of the video cameras in the Operating Rooms, the cameras in the Operating Rooms capture the space next to the operating table, therefore it is most likely that a patient being brought to or taken from the operation could be captured. It should be noted that the operating room is by its nature a particularly sensitive space, where invasive procedures are performed on patients, during which complete or partial body exposure is possible, therefore the expectation of privacy in such an environment is extremely high. According to the Inspectorate, the right of data subjects (patients) to privacy in the case under consideration undoubtedly outweighs the interest of the Hospital in organizing work more efficiently. Thus, video surveillance in the Hospital's operating rooms does not meet the third condition necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR. The Inspectorate also notes that even when video cameras partially record places such as the patient examination table (in the outpatient operating room) and the operating tables and the close space around them, health data is also processed, therefore the processing of such personal data must be based on at least one of the exceptions to the prohibition on processing health data set out in Article 9(2)(a)-(j) of the GDPR. In the case under consideration, the Inspected Person did not prove that at least one exception to the prohibition on processing special categories of data provided for in Article 9(2)(a) of the GDPR exists in the case under consideration. Summarizing the above assessment of the Inspectorate, the following conclusions are drawn: First, video surveillance in the Hospital's Outpatient Operating Room, to the extent that part of the patient examination area falls within the field of view of the video cameras, does not meet one of the three cumulative conditions – the reconciliation of legitimate interests, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5(1)(a) of the GDPR and Article 6(1) of the GDPR. In addition, since the Hospital has not proven that the processing of health data in the case under consideration is justified by at least one of the exceptions provided for in Article 9(2) of the GDPR, it is concluded that video surveillance in the Hospital's Outpatient Operating Room, to the extent that part of the patient examination area falls within the field of view of the video cameras, is carried out unlawfully, in violation of Article 9(2) of the GDPR. Secondly, video surveillance in the patient reception and examination room of the Hospital's Admission and Emergency Department and the Geriatric Day Hospital, to the extent that the permanent workplaces of employees fall within the field of surveillance of video cameras, does not meet one of the three cumulative conditions - reconciliation of legitimate interests, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5, paragraph 1, point a, of the GDPR, and Article 6, paragraph 1, of the GDPR. Thirdly, video surveillance in the Hospital's Operating Rooms does not meet two of the three cumulative conditions - necessity and reconciliation of legitimate interests, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5, paragraph 1, point a, of the GDPR, and Article 6, paragraph 1, of the GDPR. In addition, since the Hospital has not proven that the processing of health data in the case under consideration is based on at least one of the exceptions provided for in Article 9(2) of the GDPR, it is concluded that the video surveillance in the Hospital's Operating Rooms is carried out unlawfully, also in violation of Article 9(2) of the GDPR. 4.2. Regarding the lawfulness of the audio recording, the processing of personal data (i.e. each of its operations) must be based on at least one condition for the lawful processing of personal data provided for in Articles 6 and/or 9 of the GDPR (depending on the category of personal data being processed). In the case under consideration, it was established during the inspection that the video surveillance cameras installed in the Hospital's premises also record audio. Audio recording is not performed by cameras installed outdoors. The inspected person bases both the video and audio recording on Article 6(1)(f) of the GDPR. Therefore, in order to determine whether the Hospital's audio recording is lawful, in order to base such personal data processing on Article 6(1)(f) of the GDPR, it is necessary to assess all three aforementioned cumulative conditions. 4.2.1 Regarding the condition related to the pursuit of a legitimate interest (first condition) In the case under consideration, the Balance of Interest Test submitted by the Inspected Person states that audio is also recorded when conducting video surveillance in the Hospital. Based on the information submitted to the Inspectorate, the Inspected Person performs audio recording for the same purposes and in order to implement the same interests that it seeks to implement when conducting video surveillance: i.e., the Hospital, by recording audio in the premises (except for the Operating Rooms), seeks to implement the interest in ensuring the safety of persons and property, as well as the prevention of psychological violence, and the Hospital's audio broadcasting in the Operating Rooms is carried out in order to ensure smooth work organization and more efficient provision of services. It is agreed that both the aim of ensuring a safe and appropriate environment for the Hospital's visitors/patients and employees, and the aim of properly and efficiently organising work in the Operating Rooms are realistic and legitimate. Taking this into account, it is agreed that the Hospital, by carrying out the audio recording, pursues a legitimate interest, therefore the audio recording carried out complies with the first condition, the necessary processing of personal data, based on Article 6(1)(f) of the GDPR. 4.2.2 Regarding the condition related to the necessity to process personal data (second condition) It should be noted that according to Article 6(1)(f) of the GDPR, the processing of personal data is considered necessary only if the specified purpose cannot be achieved by other, less restrictive means of the rights of data subjects. It should be noted that the Balance of Interests test submitted by the Hospital shows that the processing of personal data - video surveillance and audio recording - was assessed together. Audio recording, as a separate personal data processing operation, is not assessed in the Balance of Interests test and is mentioned only formally. In the case under consideration, the Balance of Interests test submitted by the Inspected Person states that such personal data processing is the only way to achieve the objectives pursued. The Inspected Person did not provide a more detailed explanation of why audio recording on the premises of the Hospital is a necessary measure to ensure the safety of persons and property and the efficient organization of work during the inspection. According to the Inspectorate's assessment, audio recording on the premises of the Hospital, in order to ensure the safety of persons and property, is not the only and necessary measure to achieve this objective. Both the physical and emotional/psychological safety of the Hospital's employees and visitors can be ensured by using other measures (e.g., such as employee training, alarm buttons and physical protection in case of danger, etc.). In addition, video surveillance in the Hospital premises, applied in conjunction with other security measures, should be considered a sufficiently effective way to ensure security and/or resolve conflicts. It should be noted that audio recording by itself cannot prevent incidents. The person under inspection did not explain or provide any objective evidence from which it could be concluded that cases of violence (including psychological) occur in the Hospital premises to such an extent that it would be necessary to take such privacy-restricting measures as audio recording. It should also be noted that the person under inspection did not justify in any way why audio recording in the Hospital's Operating Rooms is a necessary means of organizing work. Taking into account the above, it is concluded that the person under inspection did not prove that in order to ensure the safety of the Hospital's employees and visitors, as well as to ensure the smooth organization of the work of the Operating Rooms, audio recording is the only and necessary means to achieve this goal. Thus, Sound recording carried out in hospital premises (including operating theatres) does not meet the second condition, necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR. 4.2.3. Regarding the condition of the primacy of conflicting rights and interests (third condition) As already mentioned, the data controller, when basing the processing of personal data on Article 6(1)(f) of the GDPR, must assess, among other things: 1) to what extent the processing of personal data affects the interests, fundamental rights and freedoms of individuals and 2) whether the rights of the data subject are infringed or have adverse consequences in relation to them. In other words, it is necessary to balance the legitimate interests of the data controller or a third party with the legitimate interests of the data subjects. The opinion on legitimate interest states that it is important to consider whether the status of the data controller, its relationship with the data subject or the nature of the service provided [...] may give rise to a legitimate expectation of greater confidentiality and stricter restrictions on further use of the data. The opinion on legitimate interest also states that it is important to take into account the status of the data controller and the data subject, i.e. whether the data subject is a child or belongs to another vulnerable group in society (such as, for example, people with mental health problems, asylum seekers or the elderly) who need special protection. It is also necessary to take into account whether the data subject is an employee, student or patient and whether the relationship between the data subject and the data controller is characterised by other inequalities. It is important to assess the impact of the actual processing of data on specific individuals. The opinion on legitimate interests also noted that the balancing criterion is not intended to prevent the data subject from experiencing any negative impact – it aims to avoid a disproportionately large impact. The Balance of Interests test submitted by the inspected person to the Inspectorate on 2025-02-03 did not assess whether the audio recording carried out for the purpose of security and efficient work organisation does not infringe the legitimate interests of the data subjects – the Hospital visitors, patients and employees. In the case under consideration, it is necessary to assess the fact that the data controller is the Hospital, and the data subjects are the Hospital visitors/patients and employees, who are considered to be more vulnerable in the context of this relationship. Private conversations between Hospital visitors/patients and employees usually take place in hospital premises, such as ward corridors, lobbies, etc., therefore it is obvious that data subjects have a legitimate expectation that their private conversations will not be recorded. It is also necessary to note that conversations between Hospital visitors and patients may, among other things, include conversations related to their health status, etc., which would mean that health data are recorded and recorded, which, according to Article 9 of the GDPR, are considered to be special categories of data, the lawfulness of the processing of which must be justified not only by the provisions of Article 6 of the GDPR, but also by the provisions of Article 9 of the GDPR. According to the Inspectorate, in the case under consideration, the right to privacy of data subjects (Hospital visitors/patients and employees) prevails over the Hospital's interest in ensuring security and organizing work more efficiently. Thus, audio recording on the Hospital premises also does not meet the third condition necessary for the processing of personal data based on Article 6(1)(f) of the GDPR. In addition, the Hospital did not base the processing of personal data (audio recording) on any of the conditions provided for in Article 9(2) of the GDPR, i.e. has not proven that in the case under consideration there is an exception to the prohibition on processing health data provided for in Article 9(1) of the GDPR. Summarizing the above assessment of the Inspectorate, it is concluded that the audio recording in the premises of the Hospital does not meet two of the three cumulative conditions – necessity and legitimate interests , and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5(1)(a) of the GDPR, Article 6(1) of the GDPR and Article 9(2) of the GDPR. 4.3. Regarding the duration of storage of video and audio recordings The Guidelines on video surveillance state that personal data may not be stored for longer than is necessary to achieve the purposes for which the personal data are processed (Article 5(1)(c) and (e) of the GDPR). The Guidelines on video surveillance also state that the storage period must be clearly defined and set separately for each specific purpose. It is the data controller, taking into account the principles of necessity and proportionality, who must define the retention period and prove compliance with the GDPR provisions. During the on-site inspection, it was established that the image monitored by the video surveillance cameras located on the territory and premises of the Hospital (except for the Operating Rooms) is recorded, and the video recordings made are stored on two different video recording devices. After checking the oldest saved recordings, it was established that the dates of the oldest saved video recordings on the first video recording device were 2025-05-03 (i.e. 20 calendar days), and on the second video recording device, the dates of the oldest saved video recordings were 2025-02-27 (i.e. almost 3 months). The video recordings recorded on the first and second video recording devices are viewed only on devices located in a specially designated room, and remote access to the devices is not possible. In the case under consideration, the Inspected Person submitted to the Inspection relevant documents for the inspection. For example, from the Information for Patients on Personal Data Processed at the Biržai Public Hospital, approved by the Hospital Director's Order No. PVK-42 of 2024-06-18, paragraph 4.9, it can be seen that the established storage period for video data is 14 days. Meanwhile, the PDAV report submitted to the Inspection on 2025-02-03 provides that the storage period for video records is 14 days, except for video records made in the admission and emergency departments; video records made in this department are stored for 30 days. It is indicated that these terms are based on the aim of identifying events related to the security of visitors, employees, documents and property. It is also indicated that after the storage period for records expires, older video records are automatically deleted from the video recording device, and new records are recorded in the vacated space; backup copies of video recordings are not made. It can be seen from paragraph 22 of the Description of the Procedure for Video and Audio Monitoring and Recording in the Provision of Personal Health Care Services and for the Management of Video and Audio Recording Data of the Public Institution Biržai Hospital, approved by the Hospital Director's Order No. PVK-8 of 25 March 2025, that video and/or audio data are stored in the storage for 1 month from the date of their recording. From the above, it is obvious that the Inspected Person has not established a specific and clearly defined storage period for video and audio recordings, i.e. in one place a storage period of 14 days is provided, in another place a storage period of 30 days. In addition, after the inspection, the Hospital provided additional explanations (Inspection Reg. No. 1R-3973 (2.13 Mr)), in which it acknowledged that the video recordings were actually stored for much longer than 30 days8. For this reason, a commission was established by order of the Hospital Director for the manual destruction of video data. 8 I.e., during the on-site inspection on 2025-05-22, it was determined that the oldest saved video recording on the video recording device was recorded on 2025-02-27. The Inspected Person explained that the data stored for an excessive period of time has been deleted, and also indicated that it is currently ensured that the video recordings are stored on the devices for no longer than the specified period. Summarizing the above, the Inspectorate concludes that the Inspected Person has not fulfilled its obligation to accurately determine the storage period(s) of video and audio recordings. In addition, the video and audio recordings were actually stored for an obviously excessive period of time (i.e., the video and audio recordings were actually stored for almost 3 months). Taking this into account, it is concluded that the Inspected Person violated the principle of limitation of the storage period established in Article 5(1)(e) of the GDPR by these actions. 4.4. Regarding access control According to Article 5(1)(f) of the GDPR, personal data must be processed in such a way that, by applying appropriate technical or organisational measures, appropriate security of personal data is ensured, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (principle of integrity and confidentiality). The guidelines on video surveillance state that in the context of video surveillance, security aspects include the confidentiality, integrity and availability of the system and data. That is, the security of the video and audio recording system includes: 1) the physical security of all system components and 2) access control to the video surveillance system, while data security includes the prevention of data loss or manipulation. Access rights were checked and assessed during the on-site inspection. During the on-site inspection, it was established that the image monitored by the video surveillance cameras located on the territory and premises of the Hospital (except for the Operating Rooms) is recorded, and the video recordings made are stored on two different video recording devices. The video recordings recorded on the first and second video recording devices are viewed only on devices located in a specially designated room, and remote access to the devices is not possible. Only an authorized person [DATA NOT PUBLISHED], who has signed a pledge to maintain the confidentiality of the data, may enter the said room and connect to the video recording device. Taking this into account, it is concluded that the security of the video and audio recordings made on the territory and premises of the Hospital (except for the Operating Rooms) is sufficiently ensured, i.e. sufficient access control is ensured. However, during the On-Site Inspection, it was established that the image captured by the video surveillance cameras located in the Hospital's Operating Rooms is transmitted directly to the computer of an authorized employee ([DATA NOT PUBLISHED]). The computer workstation of the authorized employee ([DATA NOT PUBLISHED]) is protected by a password, and the employee's account in the video surveillance program, through which the image and sound from the Operating Rooms are transmitted, is also protected by a password. The aforementioned employee uses only ordinary user rights in the video surveillance program, therefore she does not have the ability to save video recordings. The inspection report concluded that physical access to the authorized employee's computer workstation is sufficiently ensured. However, the Inspection Report indicated that during the on-site inspection, the Hospital representatives could not indicate who has privileged access rights to the program, nor could they answer whether there is a video recording device for the cameras in the Operating Rooms (and if so, in which location), therefore, the Inspectorate employees were not given the opportunity to determine which persons have access to the program (i.e. live broadcast video and audio), nor was it possible to determine whether video recordings are made during video surveillance in the Operating Rooms. For this reason, after the on-site inspection, the Inspected Person was additionally contacted with instruction No. 2R-3401 (2.14 E) to provide additional information: 1) to indicate who has privileged access rights to the program through which the images captured by the three video surveillance cameras in the Operating Rooms are monitored and to perform its software and technical maintenance. Also indicate what rights a user with privileged access rights has in this program (e.g. to make video recordings, view the oldest video recordings, etc.), if not, provide supporting evidence; 2) indicate whether a video recording device (NVR / DVR) is used, in which video recordings from video cameras located in the operating rooms are stored. If so, provide the system connection logs of this video recording device (NVR / DVR). Also indicate whether the video recording device (NVR / DVR) used has a remote access function, provide supporting evidence and the model of the video recording device used; 3) indicate whether the device on which the video surveillance program9 is installed can be connected remotely. If so, indicate how the device is connected and who can connect; 4) indicate whether a service agreement has been concluded with third parties for the maintenance or administration of the video surveillance system. If so, provide copies of the service agreement and data processing agreement. The inspected person submitted a response to the Inspectorate's instruction (Inspection reg. No. 1R-5255 (2.14 K)) on 2025-08-07, in which it stated that: 1) privileged access rights to the program through which the images captured by the three video cameras in the Operating Rooms are monitored are held by an authorized employee [DATA NOT PUBLISHED], who is responsible for the software and technical maintenance of the video equipment and their preparation for use; 2) the video recording device is not used, and video data from the video surveillance cameras in the Operating Rooms are not recorded and are not stored. The image can only be viewed in real time by the aforementioned authorized employee ([DATA NOT PUBLISHED]); 3) there is no possibility of remotely connecting to the device containing the program through which the images of the three video cameras in the Operating Rooms are monitored; 4) a service agreement with third parties for the maintenance and administration of the video surveillance system has not been concluded. Together with the response to the Inspectorate's order, the Inspected Person did not submit any annexes - evidence substantiating the statements made in the response. Thus, together with the response to the order, the Inspectorate was not provided with any evidence that would allow it to determine who has actual access to the program and whether video recordings are actually being made. For these reasons, the Inspectorate's employees were not given the opportunity to determine who has actual access to the program (i.e. live broadcast video and audio) and whether the image monitored in the Operations Room is not being recorded. It should be noted that the Inspectorate has the right to receive free of charge from data controllers and data processors, state and municipal institutions and bodies, other legal and natural persons all necessary information, copies and transcripts of documents, copies of data, as well as to familiarize itself with all data and documents necessary for performing the tasks and functions of the supervisory authority (Article 12, Part 2, Item 1 of the Act on the Protection of Personal Data). Legal and natural persons must comply with the requirements of the supervisory authority, promptly provide information and (or) explanations, copies and transcripts of documents, copies of data, and provide access to all data and (or) equipment related to the processing of personal data, and documents necessary for the performance of the functions of the supervisory authority (Article 14 of the GDPR). In accordance with Article 5(2) of the GDPR, the accountability principle consists of two parts - the responsibility of the data controller to ensure compliance of its activities with the requirements of the GDPR and the ability of the data controller to prove that compliance to the supervisory authority (Supreme Administrative Court of Lithuania, 2021-07-02 ruling in administrative case No. eA-745-261/2021). The data controller is responsible for compliance with the principles related to the processing of personal data established in Article 5(1) of the GDPR and must be able to prove it. The data controller must prove that the personal data could have been processed and that the principles relating to the processing of personal data set out in Article 5(1) of the GDPR (i.e. the principle of lawfulness, fairness and transparency; the principle of purpose limitation; the principle of data minimisation; the principle of accuracy; the principle of storage limitation; the principle of integrity and confidentiality) were not violated as a result. This means that the data controller 9 Name of the program used "Avtech CMS LITE" has the obligation to provide sufficient supporting evidence (decision of the Supreme Administrative Court of Lithuania of 2020-07-08 in administrative case No. eA-2837-968/2020; ruling of 2021-03-31 in administrative case No. eA-2229-968/2021; ruling of 2021-07-02 in administrative case No. eA- 745-261/2021). According to Article 31 of the GDPR, the controller and the processor must cooperate with the supervisory authority at its request in carrying out the tasks assigned to it. This provision is mandatory and not subject to exceptions. Article 57 of the GDPR defines the tasks of the Inspectorate, including monitoring the application of the GDPR, collecting information and conducting investigations. Article 58(1)(a) of the GDPR establishes that the supervisory authority has the power to order the controller and the processor and, where applicable, the controller's or processor's representative, to provide all information necessary for its tasks. Taking into account the aforementioned provisions of the GDPR, the Inspectorate, when carrying out an on-site inspection of the Hospital, i.e. in carrying out the task set out in Article 57(1)(a) of the GDPR, ordered the Inspection to provide the information necessary for the performance of the task (Article 58(1) of the GDPR), however, the Inspected person did not provide the requested information during the on-site inspection (i.e. indicated that he did not know this information), and responded to the written instruction of the Inspection only formally and incompletely, without providing any evidence. Based on the information set out above, the Inspection decides that the Inspected person, being informed in advance of the intended on-site inspection and having the obligation to implement the accountability principle established in Article 5(2) of the GDPR, should have been able to provide the information necessary for the inspection related to the security of the personal data processed and access to the video surveillance system. In addition, the Inspected person was obliged to respond in full to the instruction given by the Inspection after the inspection and to provide evidence confirming the indicated circumstances. In the case under consideration, the Inspected Person submitted a formal response to the Inspectorate's order, but did not provide the Inspectorate with all the requested information. That is, the response did not indicate and explain what rights a user with privileged access rights has in the program used (e.g. whether he can make video recordings, view the oldest video recordings, etc.) and did not provide evidence from which the Inspectorate could draw conclusions about the aforementioned circumstances. Taking this into account, it is concluded that the Inspected Person did not cooperate sufficiently with the Inspectorate, thus failing to comply with the Inspectorate's orders to provide all the information necessary to perform its tasks (Article 58(1)(a) of the GDPR). In accordance with the most relevant case law of the Supreme Administrative Court of Lithuania, the accountability principle established in Article 5(2) of the GDPR consists of two cumulative conditions, i.e. the data controller must not only comply with the GDPR, but also be able to prove it. The data controller's non-cooperation and inability to eliminate reasonable doubts regarding the processing of personal data shall be to the detriment of the data controller (the Supreme Administrative Court of Lithuania of 17 December 2025 in administrative case No. eA-704-629/2025). It should be noted that the EDPB has noted in the Guidelines on video surveillance that data controllers, when developing their video surveillance policies and procedures, must consider, among other things, who is responsible for the management and operation of the video surveillance system, and must also provide for who has access to the video recordings and for what purposes. Consequently, the data controller has an obligation to know who has access to the video surveillance system and the video and/or audio recordings made. In addition, by Resolution of the Government of the Republic of Lithuania of 6 November 2024 No. 945 “On the Implementation of the Law of the Republic of Lithuania on Cybersecurity” approved by the Cybersecurity Requirements (hereinafter referred to as the Cybersecurity Requirements) in paragraph 66 states that a list of persons granted administrator rights to access networks and information systems must be approved. Taking this into account, the data controller must ensure that a list of persons granted privileged access rights to networks and information systems is drawn up. In the case under consideration, the Inspectorate has been provided with the Hospital Director’s Order No. PVK-11 of 27 March 2025 (hereinafter referred to as the Order). The Order provides that the right to access the Hospital’s video surveillance camera recording device is granted to the employee [DATA NOT PUBLISHED]. Meanwhile, the right to access the video data recorded in the Hospital’s Operating Rooms is granted to the employee [DATA NOT PUBLISHED]. Thus, it is obvious that the right of access to the video data recorded in the Hospital's Operating Rooms is granted by the Order to only one employee [DATA NOT PUBLISHED]. However, during the on-site inspection, the representatives of the Inspected Person (DPO and the Hospital Director) stated that they did not know who in the program (which is used to monitor the Hospital's Operating Rooms) has privileged access rights (administrator rights) and whether the video recording device of the cameras located in the Operating Rooms is used. The Inspected Person does not have an approved list of persons who have been granted administrator rights in the video surveillance program, as required by the Description of Cybersecurity Requirements. In addition, according to the explanations provided by the Inspected Person in writing on 07-08-2025 (Inspection reg. No. 1R-5255 (2.14 K), it can be seen that the actual privileged access rights (administrator rights) to the video surveillance program used in the Hospital's Operating Rooms are not held by the employee authorized by the Order [DATA NOT PUBLISHED], but by another employee [DATA NOT PUBLISHED], who is not granted the right to access the video data recorded in the Hospital's Operating Rooms by the Order. Having assessed the above, the Inspection concludes that access control to the video and audio broadcasting carried out in the Hospital's Operating Rooms was not properly ensured. The Inspected Person, when carrying out video surveillance and audio recording, especially when doing so in the Hospital's Operating Rooms - extremely sensitive premises where high confidentiality is expected, unequivocally had and must know which specific persons have access to the program and what actions in the program, these persons can perform. Taking into account the above, the Inspectorate concludes that the Inspected Person violated the principle of integrity and confidentiality established in Article 5(1)(f) of the GDPR. 5. Regarding sanctions, point 129 of the preamble to the GDPR provides that each measure applied by the supervisory authority must be appropriate, necessary and proportionate to ensure compliance with this Regulation, taking into account the circumstances of each specific case. When deciding on the imposition of sanctions on the Inspected Person, the Inspectorate takes into account that: 1) The Inspected Person carried out video surveillance in the Hospital Operating Rooms unlawfully, in violation of the principle of legality established in Article 5(1)(a) of the GDPR, Article 6(1) of the GDPR and Article 9(2) of the GDPR; 2) The person being inspected unlawfully conducted video surveillance in the Hospital's Outpatient Operating Room, where part of the patient examination area falls within the field of view of the video cameras, in violation of the principle of legality established in Article 5(1)(a) of the GDPR, Article 6(1)(a) of the GDPR and Article 9(2) of the GDPR; 3) The person being inspected unlawfully conducted video surveillance in the Hospital's premises - in the patient admission and examination room of the Admission and Emergency Department and the Geriatric Day Hospital, where the permanent workplaces of employees fall within the field of view of the video cameras, in violation of the principle of legality established in Article 5(1)(a) of the GDPR and Article 6(1)(a) of the GDPR; 4) The person under inspection carried out the audio recording in the Hospital premises unlawfully, in violation of the principle of lawfulness established in Article 5(1)(a) of the GDPR, Article 6(1)(b) of the GDPR and Article 9(2) of the GDPR; 5) The person under inspection, by not setting a specific and clearly defined data retention period, stored the video and audio recordings for an unreasonably long period, in violation of the principle of limitation of the storage period established in Article 5(1)(e) of the GDPR; 6) The person under inspection improperly ensured access control to the video surveillance program (used in the Hospital's Operating Rooms), thus violating the principle of integrity and confidentiality established in Article 5(1)(f) of the GDPR; 7) The person under inspection insufficiently cooperated with the Inspectorate, i.e. failed to comply with the Inspectorate's instructions to provide the information necessary to perform its tasks, thereby violating Article 58(1)(a) of the GDPR. Due to these violations, the Inspectorate decides to initiate the procedure for imposing an administrative fine on the Inspected Person. The Inspected Person, in accordance with Article 58(2)(d) of the GDPR, is also given instructions: 1) to cease the unlawful video surveillance (broadcasting) and audio broadcasting in the Hospital's Operating Rooms; 2) to cease the unlawful audio recording in the Hospital's premises; 3) to establish the exact term(s) for storing the video recordings; 4) to take technical measures to ensure that during video surveillance in the premises (the Outpatient Operating Room, the Reception and Emergency Department's patient reception and examination room and the Geriatric Day Hospital Department), the field of surveillance of the video cameras does not include the patient examination and permanent workplaces of the employees. The Inspectorate, in accordance with Article 22(1)(2) of the Act on the Protection of Personal Data, Article 58(2)(d) and (i) of the GDPR, decides: 1. To initiate administrative fine proceedings against the Inspected Person for violation of the principle of legality established in Article 5(1)(a) of the GDPR, Article 6(1) of the GDPR and Article 9(2) of the GDPR, violation of the principle of limitation of the storage period established in Article 5(1)(e) of the GDPR, violation of the principle of integrity and confidentiality established in Article 5(1)(f) of the GDPR and improper cooperation with the Inspectorate by not providing the requested information in accordance with Article 58(1)(a) of the GDPR. 2. To issue instructions to the Inspected Person10: 2.1. to terminate the unlawful video surveillance in the Hospital Operating Rooms; 2.2. to terminate the illegal audio recording in the Hospital premises; 2.3. to precisely determine the term/terms for storing video recordings and ensure that they are adhered to; 2.4. to take technical measures to ensure that during video surveillance in the premises (Outpatient operating room, Reception and Emergency Department patient reception and examination room and Geriatric Day Hospital ward), the field of surveillance of video cameras does not include the patient examination and permanent workplace of employees. This decision, in accordance with the procedure established by the Law on Administrative Procedure of the Republic of Lithuania may be appealed to the Regional Administrative Court (address: Žygimantų g. 2, Vilnius) within one month from the date of its delivery. Director Dijana Šinkūnienė 10 The instructions must be implemented no later than 2026-01-14. The Inspectorate has the right to conduct a repeated inspection at any time, as well as to assess the same circumstances upon receipt of a complaint or report. If, during the re-inspection, following a complaint or notification, it is determined that the instructions provided in this decision have not been implemented, the sanctions established in the GDPR will be applied.



