CCTV and Chinese cameras cast a shadow over the EU’s enlargement into the Balkans
The contract launched by Huawei in Serbia in 2019 aims to develop a ‘leading Safe City’. European investigations have not yet resolved the issues surrounding potential data leaks. Shortcomings in privacy management have also come to light in Montenegro, North Macedonia and Albania. This issue is having an impact on the political process of rapprochement. Italia may request further audits
Key points
Data processing, CCTV cameras, facial recognition systems and Chinese contracts in the Balkans. These are all factors against which to assess EU enlargement. Serbia is the most advanced and well-documented case: Huawei has launched a ‘Safe City’ project for Belgrade and potentially for the whole country, whilst the European Commission continues to raise concerns about the lack of safeguards regarding the use of biometrics. For Italia, this is not a peripheral issue. It concerns the Adriatic, European infrastructure, police cooperation, logistics corridors and the credibility of enlargement.
Belgrade has contracts with Huawei
In January 2019, a Huawei publication stated that the Serbian Ministry of the Interior intended to develop a ‘leading Safe City’ scheme covering Belgrade and, in the long term, the whole country. An integrated platform involves more than just the purchase of cameras: it can include sensors, networks, servers, storage systems, control software, facial recognition, number plate recognition, movement analysis, maintenance and links to public databases. It is the integration, not the optical device itself, that transforms video surveillance into strategic infrastructure. What has actually been implemented may be less transparent than what was originally planned. On 8 November 2023, the European Commission reported that, following negative opinions from the Serbian Commissioner for Information of Public Interest and Data Protection on the Ministry of the Interior’s impact assessment, Belgrade had stated that it had suspended the processing of biometric data pending the establishment of a legal basis. On 30 October 2024, Brussels noted that the legal basis had not yet been established and that it was necessary to verify whether Serbia had processed personal data using facial recognition. The report of 4 November 2025 then assessed Serbian legislation as being only largely aligned with the GDPR and the European Directive on the processing of data by police authorities, difficult to enforce and still lacking in terms of sanctions. There is no evidence that Beijing receives Serbian biometric data. However, there is already a serious institutional problem: Europe does not yet have a comprehensive public overview of the systems that have been installed, are active or are in use. A CCTV camera records an anonymous face. An algorithm transforms it into a biometric vector. A database assigns it a possible identity. Correlation between multiple cameras reconstructs the person’s movements. The link with number plates, documents, police records or border crossings ultimately transforms a presence in public space into a personal history that can be queried.
The vulnerability stems from camera maintenance
The most sensitive issue is maintenance. These systems rely on firmware updates, licence renewals, digital certificates, archive optimisation and technical interventions. Support accounts may have higher privileges than those of police officers. If the supplier retains exclusive control over updates, recovery keys or proprietary formats, the state formally owns the system but does not have full control over its continuity. Huawei’s 2025 annual report states that the group has assessed the cyber and privacy risks of over 4,000 suppliers and holds more than 890 security and data protection certifications. These are significant indicators of corporate governance, but they do not certify the configuration of a specific Balkan operations centre. The security claimed by the group and that verified at the individual facility remain two distinct levels.
Street protests
The protests that began in Serbia following the collapse of the bus shelter at Novi Sad station on 1 November 2024, which claimed the lives of 16 people, have turned into a nationwide campaign for transparency and accountability. In August 2025, United Nations experts reported allegations of intimidation, assaults and surveillance targeting the student movement. These are allegations that require investigation; they are neither verdicts nor accusations levelled at the Huawei platform. In 2026, the Parliamentary Assembly of the Council of Europe expressed concern over revelations regarding the surveillance of Serbian journalists and activists, calling for effective investigations and accountability. EU Regulation 2024/1689, published on 12 July 2024, governs both real-time remote biometric identification and post-event biometric identification. The AI Act considers real-time recognition in public spaces for policing purposes to be particularly intrusive and permits it only subject to strict conditions and exceptions. Most of the provisions came into force on 2 August 2026, following the phased introduction of certain provisions from February and August 2025. On 24 July 2026, the EU also introduced specific codes to identify biometric systems subject to the AI Act, including remote identification. The second pillar is supply chain security. On 13 February 2026, the NIS Cooperation Group — comprising Member States, the Commission and ENISA — adopted the ICT Supply Chain Security Toolbox: assessment of critical suppliers, multi-vendor strategies and reduction of dependencies on high-risk operators. For candidate countries, video surveillance thus becomes a condition of accession. It will not be enough to simply adopt laws that are formally in line with EU requirements: it will be necessary to demonstrate which modules are installed, which databases are connected, who controls updates, and whether the system can operate without the original supplier.
Serbia is the best-documented case, but not the only vulnerable environment. In 2025, the Commission noted that Montenegro’s data protection legislation was not yet aligned with EU standards; that in North Macedonia, there remained a low level of awareness and insufficient IT safeguards within public bodies; and that in Albania, the Total Information Management System continued to present security and data protection vulnerabilities. Candidate countries set to integrate progressively into the European area could connect infrastructure that is not fully verifiable to border systems, digital identity, judicial cooperation and information exchange. Enlargement without technical convergence would bring vulnerabilities as well as new members.

