Jump to content

Recommended Posts

Posted
I was wondering if anyone has any info on the length of time you should keep CCTV recordings in relation to GDPR? Only seem to find reference to it being a 'reasonable' amount of time.
Posted
We've had no specific guidance, but all 3 of our systems store for 90 days unless there is a specific incident. In the case of an incident the relevant footage is backed up (to DVD in the case of one system) and kept until we are satisfied the incident is dealt with, which we *have* received guidance is 'reasonable'.
Posted

Generally 30 days seems to be the accepted norm. (edit: or it seems from above: 90)

 

ICO Guidance:

"retention should reflect the organisation’s purposes for recording information. The retention period should be informed by the purpose for which the information is collected and how long it is needed to achieve this purpose. It should not be kept for longer than is necessary, and should be the shortest period necessary to serve your own purpose. This should not be determined simply by the storage capacity of a system."

 

No reason to suspect that it would be any different under GDPR.

Posted
I was wondering if anyone has any info on the length of time you should keep CCTV recordings in relation to GDPR? Only seem to find reference to it being a 'reasonable' amount of time.

 

There's no set amount of time you need to set to be magically GDPR compliant just as there's no set-GDPRcompliant -yes powershell command for windows server 2016 because the exact time isn't important. What matters is that you have a policy that states you're keeping the CCTV data for a set amount of time consistent with reasonable use for your needs, processing it carefully, etc. and then complying with that policy.

Posted
We had a recommendation from somewhere (cant remember where but not related to GDPR) that specified 2 weeks, anything more you would need to explain why - for example if the CCTV was installed as a deterrent to vandalism / behavior why would you need it longer that 2 weeks as the issue would have already been reported inside those 2 weeks.
Posted
It looks like we all differ, I vaguely remember reading something that mentioned 28 days so that's what we've gone with. I imagine as long as your CCTV policy reflects the period of time and justification for doing so, it will be OK - most of these data retention's seem to be open to interpretation and are only as a guide more so than actual fact.
Posted
We're 28 days. I guess it's down to individual school preference although if your CCTV Policy/documentation states that you ONLY keep it for 28 days then you must ensure that footage older than 28 days removed or you are in breech of your own policy which would be an issue under GDPR.
Posted
Our concern would be summer holidays. If something occurred say the day after school closed it might need to be more like 5-6 weeks to see what happened.

 

This is how we justify keeping ours for "up to" four months in our policy. Something may happen at the beginning of the holiday that we don't see for a long time.

Posted
Our concern would be summer holidays. If something occurred say the day after school closed it might need to be more like 5-6 weeks to see what happened.

 

That was kind of what I was wondering for holiday periods. I thought maybe 60 days retention to cover this period but was not sure if there was a set amount of time we could hold this for. At the moment we don't appear to have a CCTV policy and no one here(admin) seems to have any idea on the retention time. It seems the pvr records up to 6 months as default and that is just what it was left at. I thought it was a good time to address this with the GDPR coming in.

Posted
Our concern would be summer holidays. If something occurred say the day after school closed it might need to be more like 5-6 weeks to see what happened.

 

I guess it depends on that something. Someone breaking in overnight, well your site manager is going to notice well before September. A fight in the corridor on the last day - if a parent waits until September to raise it then the old fashioned investigation methods will need to be employed, I'm sure they could find a way to raise it earlier.

It's perfectly acceptable for you to respond saying due to our retention policy this data no longer exists. Like many other areas of data protection, you make a judgement call based on risk and legislation and you document your decision and review annually and if the situation changes.

 

For the record - we overwrite after 28 days, unless ceased by the police.

Posted
Generally 30 days seems to be the accepted norm. (edit: or it seems from above: 90)

 

ICO Guidance:

"retention should reflect the organisation’s purposes for recording information. The retention period should be informed by the purpose for which the information is collected and how long it is needed to achieve this purpose. It should not be kept for longer than is necessary, and should be the shortest period necessary to serve your own purpose. This should not be determined simply by the storage capacity of a system."

 

No reason to suspect that it would be any different under GDPR.

 

Can you cite that ICO guidance? I might need a conversation with someone here....

Posted

We do a rolling ~50 days on the basis that stuff that happens/is noticed in term time (~1100 people on site) gets reported promptly, but stuff that happens over the Xmas (complete shutdown) or summer holidays (~5-10 people) may not get noticed for a while unless it sets off an alarm.

 

Not to mention the lag between "we should check the CCTV footage" and "let's ask someone who can check the CCTV footage to do that".

Posted
I've spoken to our site manager who is actually responsible for our CCTV. Apparently we run 90 days because we used to run 30 and an incident occurred well before the summer holidays which was considered trivial at the time and not viewed, medical complications arose, the the child in question changed their story and suddenly social workers, the hospital and the council's H&S department were involved and we had no CCTV to back up what actually happened. 90 days was what was chosen at the time to see us well clear of the holidays. 60 days would proabably do, but 90 was what was chosen.
  • Thanks 1
Posted
As with most other data retention, it often comes down to how long you can justify it, and @Oaktech 's post seems a good reason to extend it. My concern is we keep things here until they get overwritten, but according to the quote from the ICO above, that isn't sufficient justification for the duration (which varies, as our cameras records for different durations at different times of year, because they're motion-activated)
Posted

Shouldn't really matter as long as you've good reason to keep it for X amount of time but it shouldn't be long at all. 2 weeks should be more than sufficient.

So, you need that reason to keep it; that would typically depend on how long it takes for an issue to be reported. Usually that's security & safeguarding, so those issues should generally be either immediate or within 24 hours. So should something happen on Friday and it doesn't get to the CCTV controller until Monday, that's 4 days in total. Then the relevant footage generally would be extracted/exported and kept elsewhere. The rest of that recording is then effectively junk.

 

In a nutshell, and in an ideal world it would be unnecessary to keep CCTV footage for longer than a week. 2 weeks would allow for discrepancies and single-week holidays, and that's where I'd draw my policy around.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...