MkII Posted February 16, 2018 Posted February 16, 2018 Can I check with everyone who does retrieval of data from CCTV, do you make sure you have a log of who is authorised to make the request, the request itself (including justification), and who any data is subsequently shared with *as a minimum*?Can you quote the rules on that please? We don't and I want to show evidence why we should. Thanks.
rom1984 Posted February 17, 2018 Posted February 17, 2018 Can you quote the rules on that please? We don't and I want to show evidence why we should. Thanks. This is the ICO's guidance on CCTV, section 5.1 covers the administration of the CCTV system. https://ico.org.uk/media/for-organisations/documents/1542/cctv-code-of-practice.pdf In terms of the actual GDPR, the "rules" so to speak are in Article 5 (f) "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures" How you interpret "appropriate security" is obviously up to each separate organisation and will be different every time. However, if there is a breach the ICO will ask you to show what security measures you had in place to protect the data. I'd personally think that some kind of log of who is authorised to make the request would be seen as "appropriate security". Your DPO/SLT/Governors/Network Manager should always be able to satisfy themselves that they have put in appropriate security measures to protect any system the processes personal data. The ICO will then balance what security measures you have put in place against the breach (looking at things like what the data was, how sensitive it was, the damages to the invidual, what you could have done to prevent it etc.) As a starting point the ICO would look at basic ICT security principles, so Integrity, Availability, Confidentiality and Privacy of the data. This will be the starting point and you should be able to show that you have addressed each of these for all of your systems the process personal data. The one thing that I would say, is that personal data of children is thought of as very important within the ICO and what ever procedure you do put in place, the ICO would take into consideration that the data is of children when balancing the weight of the breach. 2
jenatddm Posted February 17, 2018 Posted February 17, 2018 (edited) Hi Everyone can you please give me your opinion on CCTV at my current school we have had the CCTV on in our office for the last 5 years however now a new deputy has started and said that we should have this removed as it is inappropriate for us have cctv that shows children continually on show, he said it should be removed under safeguarding. As far as I’m aware most schools have CCTV on display be it in the ICT support office or some other office! We have all taken it a little personal, it is like saying we do not trust you and we think you may be inappropriately watching children all day! Your opinions would be much appreciated Rather than an ad-hoc decison, what does your privacy / data protection impact assessment say? If you've not done one, then you could, as if you were considering buying it for the first time. As part of that you balance necessity and proportionality, against infringements of rights and freedoms. Then you have a decsion which can be accounted for and as needed under GDPR (and current DPA 1998) Not every school is the same. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-impact-assessments/ Edited February 19, 2018 by MkII fixed quote tags (because it irked m'k?)
crc-ict Posted February 19, 2018 Posted February 19, 2018 We use CCTV too. However, it is only accessed to view footage of incidents. Doesn't it all come down to what you are actually using the CCTV for? ie. whether it is intended as a preventative tool to help prevent incidents, or just a tool to help apportion guilt once something has happened? This would need to be defined in your policy and what the justification is for having the system. Personally, I think monitoring is important - surely CCTV it is more valuable (for example) if it enables an intruder to be seen and tackled before they do something, rather than just enabling you to identify the perpetrator after some harm or crime has been done? 1
jenatddm Posted February 20, 2018 Posted February 20, 2018 I have been trying to get SLT to treat the use of CCTV more seriously with respect to data protection etc. For whatever reason, they don't seem interested. We have no log of who requests footage, who views footage, or the reason why it is being viewed. I have tried to raise awareness of data security time and time again, but I seem to be getting nowhere. Perhaps setting out the bare minimum of the ICO guidance as others set out in this thread and the risks to data and reputation might help > British councils hit by nearly 100million cyber-attacks | Daily Mail Online Would more guidance specific to schools be helpful on this?
TMBS Posted February 26, 2018 Posted February 26, 2018 Can you not just keep the monitor switched off unless you need to playback any footage?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now