maxrebo Posted March 14, 2024 Posted March 14, 2024 I'm just looking for a bit of guidance on the correct procedures for staff\External users viewing the schools CCTV. In my previous school our Data manager (and GDPR Bod) brough into place a CCTV policy where staff had to fill out forms and only certain staff were allowed to view and request this. At my current school its a bit of a free for all, any one requests it and we sometimes have to do around 10 a day. Can people share their procedures (if you're lucky enough to have to manage this) and direct me to any official guidance on any GDPR regulations on sharing\viewing this Data? Thanks in advance.
Rob_D Posted March 14, 2024 Posted March 14, 2024 For us CCTV is managed by the site manager (or, in their absence, the second most senior member of the site team). Pupil support can request to be shown footage (for example, if they want to see which student came out just after the toilet vape alarm went off). But this would be done by them going to the site office. Only SLT can request footage be removed from the system (for example, to be shared with the police or shown to parents). This is done through a restricted file share with the understanding that the data will only be removed from that share with specific consent. The one time we've actually had to send footage to the police, it was done by the DPO through a sharepoint link with anti-forwarding policies in place. The ICO website is your best bet for finding specific guidelines. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/cctv-and-video-surveillance/guidance-on-video-surveillance-including-cctv/ But generally speaking GDPR guidance would be to make sure that any data shared from the system is limited (as much as possible) to what is required to meet a specific goal, and you need to have processes and agreements in place to limit any further sharing of this information. And ideally you should have documentation to prove that. I hope some of this is helpful for you. 1
PotNoodleTech Posted March 14, 2024 Posted March 14, 2024 Basically the short answer is - you should be sticking two whatever your CCTV policy states.
ITGURU Posted March 17, 2024 Posted March 17, 2024 Pastoral director and Head have full live and playback with couple other staff live only along with IT with full access who do majority of requests. Staff complete a form, we have log of requests by whom where and what and any exported footage/ police incident. Ensures we have full audit log from request to export if needed.
Aprice Posted March 17, 2024 Posted March 17, 2024 One of our sites believes that they aren't allowed to use live view or would need some sort of licence for this. Does anyone know about this or is it something someone's just misunderstood?
ITGURU Posted March 17, 2024 Posted March 17, 2024 One of our sites believes that they aren't allowed to use live view or would need some sort of licence for this. Does anyone know about this or is it something someone's just misunderstood?A license is only needed if monitoring a business or local authority CCTV system covering public areas i.e remote monitoring Centre or station
Rob_D Posted March 18, 2024 Posted March 18, 2024 Of course a GDPR risk assessment should be carried out before the installation of any "live view" screens (or export stations). "Live view" would be pretty low risk but you should still document why and how your restricting access to just what's necessary.
jmak Posted March 18, 2024 Posted March 18, 2024 A license is only needed if monitoring a business or local authority CCTV system covering public areas i.e remote monitoring Centre or stationSo the licence isn't required because they're monitoring a private space? Does it matter that the are likely to be members of the public in that area?
NegativeKillDeath Posted March 18, 2024 Posted March 18, 2024 You don't need a SIA licence if you are employed in house. Find out if you need an SIA licence - GOV.UK (http://www.gov.uk)
KK20 Posted March 19, 2024 Posted March 19, 2024 (edited) do whatever the policy says. If you do not have a policy then get your senior leadership to create one. Otherwise if it is a free for all and you are unhappy then bring it up with your school data controller. We restrict, only the SLT, site manager, me (since I have admin access), safeguarding DSL have access. There is a manual activity log for data extraction that is filled in, there isnt one for viewing. Edited March 19, 2024 by KK20 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now