THREAT BRIEFING · 10.09.2026 DEENFRES

Strategy & Governance

Important Guidelines for Video Conferencing Systems & Data Protection

By Tobias Massow · February 16, 2022 · 4 min read

Remote work and home offices are here to stay. Yet this shift to working from home inevitably brings security and data protection risks. This article provides you with essential guidelines for using data protection-compliant video conferencing systems in the home office.

During the coronavirus crisis, applications and software for online communication and flexible remote work gained significant importance.

While these tools appear smart and future-oriented, they also pose certain data protection risks that users should be aware of before deployment. One critical aspect is the work environment in which video conferences take place – especially at home in a home office setting.

Secure Your Home Office Workplace

The home office environment should ensure data confidentiality and availability just as in the office. Source: iStock /damircudic

Your home office setup should, in principle, guarantee the same level of data confidentiality and availability as in a traditional office. Family members or visitors should not be able to view your computer screen or access physical documents, preventing sensitive data from falling into unauthorized hands. You should also verify who has access to your work computer and proactively mitigate potential risks. To prevent eavesdropping, avoid holding conversations near open windows or during active video conferences.

The Bavarian State Office for Data Protection Supervision (BayLDA) also sees an urgent need for action due to the growing number of remote workstations. In response to the pandemic, it published a “Best Practice” checklist on home office work, which includes specific requirements for video conferencing solutions:

Checklist: Data Protection Regulations for Home Office Work

When selecting video conferencing tools to replace in-person meetings, certain requirements must be met (Checklist: Data Protection Regulations for Home Office):

msecure_checkliste

Checklist: Data Protection Regulations for Home Office (Source: own illustration)

Recordings and Screenshots

Exercise caution here as well. If parts of a video meeting are to be recorded or saved for later, all participants must be informed in advance. This follows from the data subject rights under the GDPR.

Recommendation: What You Should Keep in Mind

The data protection and IT security consultancy msecure recommends: Before installing and using any video conferencing solution, ensure you understand the relevant data protection aspects. Consider implementing employee training and awareness programs and, if in doubt, have your data protection officer review the software tool before use. For further detailed information on this topic, contact the experts at msecure.

 

Key Facts

GDPR Fines: European data protection authorities have imposed over 4.5 billion Euro in penalties to date.

Data Breaches: 83 percent of companies experience more than one data protection incident per year.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What is the difference between data protection and data security?

Data protection governs the lawful handling of personal data (legal basis, purpose limitation, data subject rights). Data security refers to the technical and organizational measures taken to protect all data against loss, manipulation, or unauthorized access.

Does every company need a data protection officer?

In Germany, a data protection officer is mandatory if at least 20 employees are regularly involved in the automated processing of personal data, or if special categories of data (e.g., health data) are processed.

What rights do individuals have under the GDPR?

The right to access, rectification, erasure, restriction of processing, data portability, and the right to object. Companies must respond to such requests within one month.

Related Articles

More from the MBF Media Network

cloudmagazinCloud as an enabler of digitalizationDigital ChiefsIT strategies for digital transformation

TL;DR

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH