GDPR and CCTV surveillance — what the security guard needs to know
Signage, storage periods and who is allowed to view the recordings
Camera surveillance is taking up more and more of security work — from the control room's screen wall to individual cameras above an entrance. But because recordings are personal data, the area is subject to both TV surveillance law and data protection rules (GDPR). As a guard, you are often the one who operates the system in practice, and therefore you must know the most important rules — not just the technical buttons.
§Marking is not optional
If TV surveillance is conducted of places or premises to which there is general access, or of workplaces, there is according to the TV surveillance law a requirement for clear signage so people can see they are being monitored before they move into the area. Additionally there is the general notification requirement in article 14 of the data protection regulation, which means that the person being monitored should generally also be able to find out who is responsible for the surveillance and what the purpose is. As a security guard you must be able to refer to this information if a visitor asks.
§30-day rule — and the exceptions
According to the Data Authority's guidelines on CCTV surveillance, recordings must as a rule be deleted no later than 30 days after they are made. There are important exceptions: recordings can be retained longer if necessary due to a reported criminal act, a specific dispute or crime prevention purposes. If storage is necessary due to a dispute, the person the dispute concerns must be notified within the 30-day period and can request a copy of the recording. As a security guard, it is therefore important to know when an incident should be marked for longer retention before the recording is automatically overwritten or deleted.
§Who may see the recordings?
Recordings from CCTV must be stored safely so they can only be accessed by people who have a work-related need for it — typically via access control, password protection and in some cases multi-factor login. In practice this means that as a guard you cannot just show recordings to curious colleagues or outsiders, no matter how innocent it seems. Access to recordings must follow the same professional discipline as access to physical keys.
- 01Check that signage is visible and updated where cameras are set up
- 02Know the procedure for 'locking' a recording at a specific incident.
- 03Never give access to recordings to people without work-related need.
- 04Note in your incident report if a recording is saved or issued and to whom.
§Why it is part of your professional skills
Many think about GDPR as something management or the IT department handles. But because the guard is often the one who in practice operates the cameras stores clips and delivers recordings to the police you are part of the chain that must follow the rules. A guard who knows the framework protects both the rights of those being monitored and their workplace from a complaint to the Data Protection Authority.
“The camera sees everything — but the rules determine how long what it sees can be stored, and who may see it afterwards.”