Is your CCTV system GDPR compliant?
Written by staff reporter
Organisations are at risk of breaching the GDPR because they’re failing to realise that the new regulations cover their CCTV systems and the visual data they collect. These are the words of Andrew Charlesworth, reader in IT Law at the University of Bristol, and come just over six months before the GDPR becomes law.
Charlesworth says that because CCTV systems have been lightly regulated until now, there is a danger that users will not understand their obligations under the new legislation. New IP-based systems can expose operators to significant data protection and privacy risks, but he uses a recent court case to show how data protection legislation applies to all CCTV systems which record and store visual data, both public and private.
Charlesworth cites a dispute earlier this year between two householders in Scotland where one recorded and stored data covering the other’s private property and from which they could be identified. This resulted in damages of more than £17,000 for distress caused – and the court was not asked to consider whether data was kept appropriately secure and met other data protection requirements, which would also be considerations for data controllers running CCTV systems. Potential fines under the GDPR are much greater, up to €20m or 4% of turnover, whichever is higher.
As there is no compulsory registration process it is difficult to get an accurate estimate of the number of CCTV cameras in the UK. In 2015 the British Security Industry Association said there were between four and six million cameras. Research from Cloudview suggests there are currently around 8.2 million cameras, all of which will need to comply with the GDPR.
“Changing technology created the need for the GDPR, altering both the data protection environment and public perceptions of what constitutes acceptable data processing,” Charlesworth explains. “From May all CCTV operators will have to be proactive in assessing, improving and ‘evergreening’ their compliance efforts – tickbox compliance will no longer be sufficient. However, GDPR provides a significant opportunity to enhance the industry’s public image as a valued and trusted service, rather than an unaccountable and privacy invasive ‘eye in the sky’.
“There are already precedents for fining CCTV users who breach existing data protection legislation,” comments James Wickes, CEO of Cloudview. “Users need to assess their CCTV systems alongside the rest of their IT, and remember that the law applies to everything from a single camera monitoring the entrance to their office or home to a larger system used in a business, housing or public spaces.
“The good news is that the GDPR gives CCTV users an opportunity to tackle what is often a negative image and take the lead in demonstrating accountability and privacy protection. They can also use new technologies such as cloud, which enable them to meet the new regulations while improving data accessibility and security.”