GDPR And CCTV -what are the implications?

Whilst we would always recommend that you obtain specific advice relating to your own business in relation to complying with the forthcoming new Data protection regulations
Inspired CCTV
16/04/2018
Whilst we would always recommend that you obtain specific advice relating to your own business in relation to complying with the forthcoming new Data protection regulations here are the main categories we believe should be considered.By now all company directors and owners should be familiar with GDPR. It has moved from a niche and little understood issue to a very mainstream one, with general scaremongering giving way to a broad understanding within the business community about what needs to be done.But what about technology that may collect personal data in ways that are not exactly planned and deliberate? What about the sharing of data that is ad-hoc and specific to a situation? And that includes CCTV systems in particular.

The main focus of GDPR is that people will be given more explicit control over the use of their personal data. So, what if you capture the identity of people on CCTV? This must be affected by the GDPR rules. And it is

Policy

From our reading of the (very useful but not yet 100% complete) ICO guidelines, it is very clear that a ‘culture of privacy’ is intended within the legislation and by the ICO. Companies cannot rely on collecting data simply because they say they need it, or because they have a written assertion to that effect. All activity must be ‘reasonable’ in relation to a specific, legitimate purpose.

Signage

This falls under the ‘privacy information’ aspects of GDPR – discussed later, as part of the rights of individuals.

Broadly, it means that those subject to CCTV surveillance must be informed that CCTV is being recorded, as well as being told who controls it and how it is processed.

Clarity on who is the Data Controller

Are you a Controller or a Processor? What is the role of your partners and suppliers? Is there a shared understanding of the role of each party?

A Controller makes decisions on how to process data, whereas a Processor does work on behalf of a Controller.

You also need to make sure it is easy for the public (or staff etc) to be able to contact the Data Controller.

Responsibilities of a Data Controller are wide ranging but reasonably easy to understand. They include:

  • Only collecting what is necessary and being clear on which of the six lawful bases you are relying upon. (link to https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/)
    • Consent (which is freely and deliberately given and specific)
    • Contract (or steps taken in advance of entering into a contract)
    • Legal obligations
    • Vital interests (defined as the protection of life)
    • Public task (i.e. fulfilling a public interest or as a holder of public office)
    • Legitimate interest (which means your business interests) – but the extent to which you can rely on this is relative. It needs to be balanced against the need to protect the individual’s privacy)
  • Preventing breaches within your own activities. This includes policy, staff training etc.
  • Ensuring appropriate contract arrangements with any processors working on your behalf

Clearly with CCTV you are not often going to be relying on consent. So, you need to be clear on what the legal basis is. It may involve protecting your legitimate business interests by monitoring for threats, ensuring compliance with health and safety requirements or protecting the safety (even the life) of employees.

If a CCTV company does any processing for you – such as viewing, storing or otherwise accessing your footage, and this includes identifiable, living people, then they are obliged to log this and take care not to cause a breach. If they do cause a breach then they need to report this to the parties affected and the ICO.

Do you need a Data Protection Officer?

Not all businesses need to have a Data Protection Officer (DPO). The role goes beyond just somebody in-house who is responsible. It includes independence from those collecting and processing the data – although they can be an employee.

You must appoint a DPO if you are a public authority, or if you carry out certain types of processing activities. In relation to CCTV these might include the large scale processing of biometric data or monitoring of people generally – as part of your core activity. Or if you carry out large scale monitoring of criminal activity or hold large amounts of sensitive – now called ‘special category’ data.

The IPO specifies that ‘The DPO must be independent, an expert in data protection, adequately resourced, and report to the highest management level.

Duties to protect the personal data of living people

Archive footage

You must have procedures in place to protect such data. Any unauthorised access to archive footage that includes identifiable, living people will be classed as a data breach.

You must be able to identify if a breach has occurred. This means adequate security and access policy as a minimum.

IP addresses

Due to advances in technology and its widespread use, IP addresses can so easily be associated with individuals that there can be no question that these count as personal data. Indeed the GDPR specifically defines personal data as including IP addresses.

Biometrics

If your CCTV system is of a sophisticated variety and collects biometric data e.g. facial recognition or similar, then you have additional responsibilities due to this being categorised as ‘sensitive personal data’, now termed ‘special category’ data.

Criminal offences data

Rather than convictions only, criminal offence data includes allegations, proceedings or convictions. This could clearly include the results of CCTV footage and the way in which this is processed and shared. Rules around these are still being developed.

Rights of individuals

GDPR specifies eight rights of individuals. These are not new rights as such, but they are more clearly defined than may have previously been the case. Those rights are:

The right to be informed, the right of access, the right to rectification, erasure, restriction of processing, data portability, the right to object and rights related to automated decision making including profiling.

Some of these have specific implications relating to CCTV. Perhaps the most obvious is the use of biometric information as a method of profiling. If you are using sophisticated CCTV for security purposes then this could well apply to you.

How these rights relate to your particular CCTV application is complex and is likely to require specific legal advice. We would suggest being prepared though, for specific circumstances e.g. when a data subject objects to a form of processing or makes a request. These circumstances require the balancing of your legal basis for processing against the individual rights. And there are set timeframes for your response.

Needless to say, you would not be able to give a data subject access to their personal data in the form of footage if doing so would involve the sharing of the personal data of others. The guidance states: ‘The right to obtain a copy of information or to access personal data through a remotely accessed secure system should not adversely affect the rights and freedoms of others.’ https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/

Contracts

Various contracts may involve the setting up of a Data Processor relationship. Installation for example, if this gives access to footage or access to IP addresses or employee data. Or if you have an ongoing maintenance contract that may involve access to data or provides access to data remotely.

If any person or company is carrying out any form of monitoring of your footage: What is the basis for accessing the footage? What about storing it and processing it? IP addresses for the client’s system may be necessary for technical support. SO are they only accessible to those providing technical support? How do you limit access?

Do you archive the footage or does someone else archive it remotely?

What about filming employees? 

The legal basis here could well be legitimate interest rather than consent; and this may well be easier to rely upon. It would be impossible to manage if some office employees gave their consent and others didn’t. And to make it a condition of employment clearly does not represent consent that is freely given. You can still make it a condition of employment – you just have to be clear that consent is not the basis upon which you do so.

So is this just the next PPI?

Well, that depends upon whether or not businesses mostly get it right.

And in any case, the protection of your business from such risk is very much within your control.

Summary

The most important thing is not to ignore GDPR – it definitely applies to you.

Some simple steps you can take are:

Read the ICO website. Do your audit. Make sure CCTV is covered in your audit. Update your contracts. Update your policies. Get advice.