SIA CCTV Legal Framework for CCTV 2 — Questions and Answers
Question 1: Which piece of legislation enshrines the right to privacy in UK law and must be balanced against surveillance camera operations?
- The Data Protection Act 2018
- The Human Rights Act 1998 (incorporating Article 8 of the ECHR — the right to respect for private and family life) (Correct answer)
- The Freedom of Information Act 2000
- The Police and Criminal Evidence Act 1984
Correct answer: The Human Rights Act 1998 (incorporating Article 8 of the ECHR — the right to respect for private and family life)
The Human Rights Act 1998 incorporates the European Convention on Human Rights into UK law. Article 8 ECHR protects the right to respect for private and family life, home, and correspondence. CCTV surveillance must be proportionate and legally justified to avoid breaching this right.
Question 2: Under the Data Protection Act 2018, which principle requires that CCTV images should only be used for the purpose for which they were collected?
- Data minimisation
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
The purpose limitation principle (UK GDPR Article 5(1)(b)) requires that personal data collected for specified, explicit, and legitimate purposes must not be processed in a manner incompatible with those purposes. CCTV footage collected for security cannot be freely used for unrelated purposes.
Question 3: What is a 'Data Protection Impact Assessment' (DPIA) and when is one required for CCTV systems?
- An annual review of CCTV camera positions conducted by the local authority
- A systematic assessment of the privacy risks of a data processing activity, required where processing is likely to result in a high risk to individuals, including CCTV in public areas (Correct answer)
- A quarterly audit of footage retention compliance
- A technical assessment of CCTV image quality carried out by the ICO
Correct answer: A systematic assessment of the privacy risks of a data processing activity, required where processing is likely to result in a high risk to individuals, including CCTV in public areas
A DPIA (required under UK GDPR Article 35) is a process to identify and minimise privacy risks. For CCTV, a DPIA is typically required for systematic monitoring of publicly accessible areas, covert surveillance, or where the scale of monitoring could have significant impact on individuals.
Question 4: The Protection of Freedoms Act 2012 established the Surveillance Camera Commissioner. What is the Commissioner's role?
- To prosecute organisations that misuse CCTV footage
- To encourage compliance with the Surveillance Camera Code of Practice by relevant authorities, provide guidance, and review how the Code is working (Correct answer)
- To issue SIA licences to CCTV operators
- To approve all CCTV installations before they can be used
Correct answer: To encourage compliance with the Surveillance Camera Code of Practice by relevant authorities, provide guidance, and review how the Code is working
The Surveillance Camera Commissioner (established under the Protection of Freedoms Act 2012) encourages compliance with the Surveillance Camera Code of Practice among relevant authorities, reviews its operation, and provides guidance. The role is advisory and regulatory rather than prosecutorial.
Question 5: Under the UK GDPR, how should a CCTV system operator notify individuals that they are being recorded?
- No notification is required — surveillance is inherently expected
- Through clear and visible signage indicating that CCTV is in operation, the purpose, and the identity of the data controller (Correct answer)
- Only by posting a notice on the organisation's website
- By providing written notice to each individual before they enter the surveilled area
Correct answer: Through clear and visible signage indicating that CCTV is in operation, the purpose, and the identity of the data controller
UK GDPR requires data controllers to provide privacy information to data subjects. For CCTV, this is typically done through prominent, clear signage at entry points indicating that CCTV is in use, the purpose, and how to find out more (including the data controller's identity and contact details).
Question 6: If a CCTV operator receives a Subject Access Request for footage, but providing it would reveal the identity of third parties, what should they do?
- Refuse the request entirely on privacy grounds
- Redact or blur the images of third parties before providing the footage to the requester, unless redaction is not possible (Correct answer)
- Provide the footage unedited as the requester's right takes priority
- Wait until the footage has been automatically deleted before responding
Correct answer: Redact or blur the images of third parties before providing the footage to the requester, unless redaction is not possible
When responding to a SAR involving footage showing third parties, the operator should redact or blur images of those third parties to protect their privacy before providing the footage, unless redaction would make the footage meaningless or is technically impossible — in which case refusing disclosure of certain footage may be appropriate.
Which piece of legislation enshrines the right to privacy in UK law and must be balanced against surveillance camera operations?