UK ICO Guidance on Video Surveillance including CCTV (2022)
Accountability – UK ICO Guidance on Video Surveillance including CCTV (2022)

UK ICO Guidance on Video Surveillance including CCTV (2022) A.1: A.1 Know who controls the system, agree joint and processor roles in writing, and set procedures, a named owner and regular audits

The organisation should establish who decides what gets recorded, what it is used for and who may receive it: that party is the controller and legally responsible. Joint decisions make joint controllers, each responsible, with responsibilities agreed transparently; processors need written contracts binding them to instructions with guarantees on security, storage and trained staff; shared services (a council-hosted server feeding a police control room, for example) need strict procedures and clarity on who controls which information when. The controller should define and communicate purposes to operators, document handling and disclosure procedures, give responsibility for them to a DPO or named person, and audit compliance regularly.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • Art.26 Article 26 Joint controllers
  • Art.28 Article 28 Processor

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Accountability – UK ICO Guidance on Video Surveillance including CCTV (2022)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.