UK ICO Guidance on Video Surveillance including CCTV (2022)
Complying with the data protection principles – UK ICO Guidance on Video Surveillance including CCTV (2022)

UK ICO Guidance on Video Surveillance including CCTV (2022) P.12: P.12 Secure storage and viewing: restricted access, encryption or equivalents, secure cloud and transfers, monitors visible only to authorised staff

Recorded material should be stored to preserve confidentiality, integrity and availability, with access restricted to authorised people, encryption where possible (other measures where not), secure cloud storage with any international transfer addressed, and an audit trail where footage may become evidence. Live monitors should be visible only to operators and authorised people (hotel reception screens showing corridors positioned away from guests), and recordings viewed in a restricted area. Checks should cover restricted copying, network controls, secure delivery of disclosures, secure control and storage rooms, trained staff with sanctions for misuse and awareness that misuse can be an offence, and applying manufacturers' security updates.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

  • 7.4 Physical security monitoring
  • Art.32 Article 32 Security of processing

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Complying with the data protection principles – UK ICO Guidance on Video Surveillance including CCTV (2022)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.