Organisations operating CCTV or ANPR should understand why the system is required, what information is being collected, who is authorised to access it and how long information should be retained. Access to recorded video, registration data and associated metadata should be appropriately controlled and secured.
Where required, clear signage and privacy information should tell people that CCTV or ANPR is in use, identify the organisation responsible for the system and explain how further information can be obtained.
System design should also consider secure user access, recording and retention settings, export of evidence, information requests, maintenance access and the protection of data when engineers or authorised third parties need to work on the system.
The organisation operating the system is responsible for determining its own legal and data protection requirements. Current guidance is available from the Information Commissioner's Office at ico.org.uk.
The ICO also publishes specific guidance and self-assessment material for organisations using surveillance systems. Videcom can help customers consider practical security, access, retention and system-management requirements as part of CCTV and ANPR design and maintenance.
