GDPR & workplace CCTV: What employers need to know?

The General Data Protection Regulation (GDPR) extends beyond written records of personal data. The rules of the UK GDPR are also applicable to video surveillance that might include personally identifiable images and footage. It is mandatory to comply with the UK GDPR, as loss or unlawful distribution of personal information can result in heavy fines.

In this article, learn how to ensure CCTV is GDPR compliant, as well as the risks associated with setting up CCTV monitoring at your workplace.

What is GDPR-compliant CCTV?

GDPR compliance in CCTV is the process of ensuring that your CCTV system complies with the UK GDPR. The UK GDPR requires transparency about how organisations handle personal data and requires consent from users before collecting their personal information. To comply with UK GDPR, you must also make sure your CCTV system meets these basic requirements:

  • It has a clear purpose statement describing why it is being used by the organisation (i.e., safety and security purposes).
  • The footage from cameras should only be retrieved if there is suspicion that an individual may have committed an offence (i.e. if it matches existing video footage from other sources).
  • Any footage collected must be stored securely so that it cannot be accessed by unauthorised individuals or third parties without consent from those individuals (i.e., via a password or biometric identifier).
 

Why might workplace CCTV monitoring be useful for your organisation?

The need for CCTV monitoring depends on each organisation. If you have storage units containing valuable items and sensitive information, CCTV may be useful in monitoring access and maintaining a log of activities around these areas. Other organisations may choose to only install CCTV following previous security incidents.

The monitoring of employees through video surveillance isn't required by the GDPR. It is left to the discretion of the data controller (your organisation) to identify a need for CCTV and reach a decision.

How can you ensure your CCTV is GDPR Compliant?

When we think about personal information, our first thought is often written documentation, such as banking details and forms of identification. However, images and videos can also contain personally identifiable information, and this is where CCTV is concerned when navigating the GDPR.

To ensure compliance, it is important to consider the following when using and distributing CCTV footage:

  • Maintain transparency around how/why CCTV is used

The GDPR is rooted in transparency, and you are required to inform people that they are under surveillance using visible signs. Signs should also include the following details:

  1. Why this data is being collected/its purpose, for example: “CCTV currently in operation to ensure public safety”
  2. Contact details of the data protection officer (DPO)
  3. Information about your organisation (data controller)
  4. Means to access other details upon request (via QR code, for example)
  • Aim to collect minimal data 

Article 5(1)(c) of the GDPR stipulates that data collection should be “adequate, relevant and limited to what is necessary” in line with its stated purpose. Be sure to regularly review your CCTV practices and delete unnecessary footage.

  • Ensure access to footage is limited to certain individuals

Only those who need access to surveillance footage should be allowed access, i.e. those in management roles and others who require this data to perform their duties. To facilitate this, cloud-based systems can be used to securely store CCTV footage in an encrypted format that can be accessed by those with permission.

  • Conduct a data protection impact assessment (DPIA)

Before you set up your CCTV cameras and begin surveillance, you should identify and minimise any potential data processing risks. Gather this information through a DPIA - learn more about carrying out a DPIA and download a DPIA template here.

A DPIA should be conducted whenever CCTV equipment is newly installed or moved. 

  • Comply with reasonable access requests

Individuals should be allowed access to CCTV footage that concerns them. These requests can be formal or informal, and you are expected to respond to requests within one month. The requested footage should be provided in a secure and easily accessible way, with the identities of other subjects blurred to ensure their privacy.

When done effectively, CCTV can be a valuable tool in maintaining workplace security and protecting the confidentiality, availability and integrity of sensitive information. However, there are a few risks you should consider before choosing to install CCTV. 

Why is a GDPR compliance audit essential? Watch our webinar to understand how to prepare for your next GDPR audit and learn practical tips and insights.

What are the risks associated with workplace CCTV monitoring?

Though not inherently risky, there are a few things you should aim to avoid before choosing to install CCTV at your workplace:

  • Breach of employee-employer trust

Monitoring workplace activities may damage your relationship with your employees, so it is very important that they are informed of any and all CCTV devices. Uninformed/non-consensual surveillance may result in complaints and staffing issues.

  • GDPR infringement

If the collected data isn’t properly protected, your organisation might be in violation of the GDPR and incur heavy fines. This could damage your organisation’s reputation and put it at great financial risk.

  • Human Rights Act violation

Ensure that the means of surveillance is not overly intrusive so as to not violate the privacy of your employees. Such violations can result in legal action.

 

What is the penalty for non-compliance?

The ICO takes data privacy violations very seriously, and this extends to poor CCTV practices. GDPR violations can result in fines amounting to €20 million or 4% of an organisation’s annual global turnover – whichever is greater. However, it is unlikely that CCTV malpractice will result in fines of such a scale.

Nevertheless, be sure to maintain GDPR compliance when carrying out CCTV monitoring by regulating its use and distribution.

Conclusion

Video surveillance can contain personally identifiable images and, therefore, should not be ignored when reviewing your organisation’s handling of personal information. Complying with the GDPR protects your organisation from the unauthorised dissemination of sensitive information, data breaches and incurring heavy fines. 

Learn more about maintaining GDPR compliance within your organisation and how our experts and platform can support you in this journey.

 
GDPR Audit checklist 212x234 UK GDPR Audit checklist 800x600 MOBILE UK

GDPR Audit Checklist

Understand if your CCTV system is GDPR compliant with our GDPR audit checklist.

Download now!

About the author

DataGuard Privacy Experts DataGuard Privacy Experts
DataGuard Privacy Experts

Dive into the world of data protection, compliance, ethics, and data security with hands-on advice and actionable opinions from our certified Data Protection Officers and Privacy Consultants from Germany, the UK, and Austria. Coming from a wide range of backgrounds like business, legal, tech, or marketing, our specialists share the latest news and solutions to current challenges, as well as their takes on recent judgements and legal decisions with you. Their aim? Enable you to make the right decisions and keep your business safe, build trust, and grow revenue while remaining compliant with current privacy laws. What makes our specialists qualified? These are some of the certifications of our privacy experts: Certified Information Privacy Professional/Europe (IAPP), Certified Information Privacy Manager (IAPP) Information Security, Certified Information Privacy Technologist (IAPP), Certified Practitioner in Data Protection (BCS), Certified Data Protection Officer (TÜV), Fellow of Information Privacy (IAPP), Certified EU General Data Protection Regulation Practitioner (IBITGQ), Data Protection Officer & Europrivacy Auditor, Practitionier Certificate in Data Protection, PC.dp. (GDPR)

Explore more articles

Contact Sales

See what DataGuard can do for you.

Find out how our Privacy, InfoSec and Compliance solutions can help you boost trust, reduce risks and drive revenue.

  • 100% success in ISO 27001 audits to date 
  • 40% total cost of ownership (TCO) reduction
  • A scalable easy-to-use web-based platform
  • Actionable business advice from in-house experts

Trusted by customers

Canon  Logo Contact Hyatt Logo Contact Holiday Inn  Logo Contact Unicef  Logo Contact Veganz Logo Contact Burger King  Logo Contact First Group Logo Contact TOCA Social Logo Contact Arri Logo Contact K Line  Logo Contact

Get to know DataGuard

Simplify compliance

  • External data protection officer
  • Audit of your privacy status-quo
  • Ongoing GDPR support from a industry experts
  • Automate repetitive privacy tasks
  • Priority support during breaches and emergencies
  • Get a defensible GDPR position - fast!

Trusted by customers

Canon  Logo Contact Hyatt Logo Contact Holiday Inn  Logo Contact Unicef  Logo Contact Veganz Logo Contact Burger King  Logo Contact First Group Logo Contact TOCA Social Logo Contact Arri Logo Contact K Line  Logo Contact

Get to know DataGuard

Simplify compliance

  • Continuous support on your journey towards the certifications on ISO 27001 and TISAX®️, as well as NIS2 Compliance.
  • Benefit from 1:1 consulting
  • Set up an easy-to-use ISMS with our Info-Sec platform
  • Automatically generate mandatory policies
Certified-Icon

100% success in ISO 27001 audits to date

 

 

TISAX® is a registered trademark of the ENX Association. DataGuard is not affiliated with the ENX Association. We provide consultation and support for the assessment on TISAX® only. The ENX Association does not take any responsibility for any content shown on DataGuard's website.

Trusted by customers

Canon  Logo Contact Hyatt Logo Contact Holiday Inn  Logo Contact Unicef  Logo Contact Veganz Logo Contact Burger King  Logo Contact First Group Logo Contact TOCA Social Logo Contact Arri Logo Contact K Line  Logo Contact

Get to know DataGuard

Simplify compliance

  • Proactive support
  • Create essential documents and policies
  • Staff compliance training
  • Advice from industry experts

Trusted by customers

Canon  Logo Contact Hyatt Logo Contact Holiday Inn  Logo Contact Unicef  Logo Contact Veganz Logo Contact Burger King  Logo Contact First Group Logo Contact TOCA Social Logo Contact Arri Logo Contact K Line  Logo Contact

Get to know DataGuard

Simplify compliance

  • Comply with the EU Whistleblowing Directive
  • Centralised digital whistleblowing system
  • Fast implementation
  • Guidance from compliance experts
  • Transparent reporting

Trusted by customers

Canon  Logo Contact Hyatt Logo Contact Holiday Inn  Logo Contact Unicef  Logo Contact Veganz Logo Contact Burger King  Logo Contact First Group Logo Contact TOCA Social Logo Contact Arri Logo Contact K Line  Logo Contact

Let's talk