Privacy Trust

Protecting Privacy Build Trust
  • Contact Us
Data Breaches Industry Insight Privacy

CCTV Protects Your Estate. Good Governance Protects Your Residents.

CCTV helps an estate monitor incidents and support security operations. But when footage identifies people, it can also contain personal data. PDPC’s MCST 3615 case illustrates that identifiability matters: footage must be considered alongside other information available to the organisation.

For MCST councils and managing agents, our recommended approach is to treat CCTV governance as part of daily estate management. Residents, visitors, vendors and staff deserve care in how recordings are accessed, shared and retained.

At PrivacyTrust, our approach connects privacy protection with trust, risk assessment and employee training. Applied to CCTV, this means making the rules clear to everyone responsible for the system.

Five Questions Every MCST Should Ask

The following operational checks help translate data protection principles into everyday practice.

1. Who Can View the Footage?

List the roles that need access and the tasks they perform. Where the system supports it, separate permission to watch live feeds, replay recordings and export clips.

We recommend using individual accounts, reviewing permissions regularly and removing access when staff or vendors leave. Council membership should prompt a review of the person’s responsibilities and access needs.

These controls support the PDPA’s requirement for reasonable security arrangements against unauthorised access, disclosure and similar risks.

2. When Can Footage Be Shared?

Establish a process for requests from residents, authorities, insurers and other parties. Record the requester, purpose, relevant footage and decision before releasing a copy.

An individual may have a right to access their own personal data in CCTV footage, subject to applicable exceptions. PDPC’s MCST guidance cautions against limiting access only to law enforcement or investigations.

Where recordings also capture others, assess how their information should be protected, including whether masking is needed. A request for footage should receive a considered decision rather than an informal forward.

3. How Long Should Recordings Be Kept?

Document a retention schedule based on the purpose of recording and relevant business or legal needs. PDPC’s Retention Limitation Obligation requires organisations to stop retaining personal data when it is no longer needed for those purposes.

Our recommendation is to define routine deletion alongside a process for preserving relevant clips when an access request or incident requires attention. PDPC’s guidance illustrates the importance of locating requested footage before automatic overwriting.

Include exported copies and backups in the review.

4. Are Access Logs Reviewed?

Where logging is available, we recommend reviewing who viewed, downloaded or exported recordings. Assign an owner and a review frequency, and define how unusual activity will be investigated.

If the system cannot capture useful logs, document that limitation and assess other controls. An authorised viewing and export register may provide a practical interim measure.

5. Are Vendors and System Users Properly Controlled?

Document instructions for the managing agent, security provider and CCTV maintenance vendor. Clarify who can retrieve footage, approve exports and handle requests.

Review remote access, account ownership and access removal during handovers. In the MCST 3615 undertaking, corrective measures included documented instructions, vendor training and procedures for CCTV recording, retrieval and backup.

Our proposed approach connects estate security with clear responsibility for personal data.

A useful CCTV policy tells staff what to do when someone requests a clip. A useful access process explains who can approve it. A useful retention schedule explains what to delete and what may need preservation.

These practical recommendations reflect PrivacyTrust’s emphasis on identifying risks, supporting compliance and helping employees handle information responsibly.

Strengthen CCTV Governance with PrivacyTrust

PrivacyTrust offers DPO-as-a-Service, including assessment and support to implement data protection policies, procedures and controls.

Speak with PrivacyTrust about your estate’s CCTV practices and the support needed to strengthen everyday data protection.

Good access today. Greater privacy tomorrow.