UK ICO Guidance on Video Surveillance including CCTV (2022)
Accountability – UK ICO Guidance on Video Surveillance including CCTV (2022)

UK ICO Guidance on Video Surveillance including CCTV (2022) A.4: A.4 DPIA before surveillance likely to be high risk (most cases), evidence-based, with alternatives considered; consult the ICO if high risk remains

A DPIA is a legal requirement before processing likely to result in high risk, which covers most video surveillance, including large-scale systematic monitoring of publicly accessible places. It must set out what the processing is, its scope, context and purposes, weigh necessity and proportionality and the compliance measures, identify and rate the risks to people, and set out further measures to reduce them; a decision not to do one must be documented and justified. The organisation should consider lawfulness and transparency, whether the system is necessary and proportionate and actually solves the problem on reliable evidence, and less intrusive alternatives; if high residual risk remains it must consult the ICO and not proceed until it has. Failing to do a required DPIA is itself an infringement.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • Art.35 Article 35 Data protection impact assessment
  • Art.36 Article 36 Prior consultation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Accountability – UK ICO Guidance on Video Surveillance including CCTV (2022)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.