Scope
Policy Statement
The Policy
- Principles
- Code of Practice
Related Policies
Related Guidance
Training Statement
Appendix 1
- Data Protection Legislation
Appendix 2
- The Guiding Principles of the Surveillance Camera Code of Practice
- Definitions
Policy Statement
This organisation is aware of its responsibilities in the use of CCTV equipment and of the need to ensure it is fully compliant with relevant legislative requirements. This policy sets out the use, and the safeguards in place covering the use, of any type of CCTV or surveillance equipment on any premises owned or leased by the company. Within the health and social care sector, the case of surveillance equipment has risen markedly in the last five years. There have also been case law judgements, in particular relation to privacy issues, which has led to the Code of Practice from the Information Commissioners’ Office (ICO,) issued in June 2015.
The Policy
Principles
Careful consideration needs to be given as to the reasoning behind the introduction of any type of surveillance system.
The general public needs to be aware of any covert usage.
Staff, where possible, should be included in discussions about the use of such systems.
Individual service users must be fully involved in decisions regarding the use of such equipment. Where they lack capacity, as defined by the Mental Capacity Act 2005, a best interest decision will be taken, following the guidance in the act.
Code of Practice
The first Code of Practice was introduced in 2000 and, since then, the use of CCTV has moved to a much more sophisticated system of digital and increasingly portable technology. Privacy has become an issue in the use of such systems, and the code aims to keep users of such systems on the right side of the law. The code provides good practise advice for those involved in operating CCTV and other surveillance camera devices that view or record individuals, e.g. vehicle registration using automatic number plate recognition (ANPR).
The Protection of Freedoms Act (POFA) has introduced a commissioner, the Surveillance Camera Commissioner, to promote the code. It is designed to help those who use surveillance cameras to collect personal data to stay within the law.
The terms ‘surveillance system(s)’, ‘CCTV’, and ‘information’ are used throughout the code for ease of reference. Information held by organisations that is about individuals is covered by data protection legislation; the guidance in the code will assist organisations to comply with these obligations.
This Code of Practice is consistent with the POFA code and there is a memorandum of understanding between the Information Commissioner and Surveillance Camera Commissioner. The code covers the use of surveillance systems that are used to monitor or record the activities of individuals or both. As such, they process individuals’ information – their personal data. Most uses of surveillance systems will therefore be covered by the Data Protection Act and the provisions of the code, whether the system is used by a multinational company to monitor entry of staff or visitors or a local newsagent recording information to help prevent crime.
The code also covers the use of camera-related surveillance equipment including:
- ANPR.
- Body worn video (BWV).
- Unmanned aerial systems (UAS).
- Other systems that capture information of identifiable individuals or information relating to individuals.
The code provides guidance on information governance, such as data retention and disposal.
It is important that the data controller of the organisation (Carly Fortune) is fully conversant with the Code of Practice and the principles set out below.
Related Policies
Adult Safeguarding
Confidentiality
Consent
Cyber Security
Data Protection Legislative Framework (GDPR)
Related Guidance
ICO CCTV:
https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/cctv/
Gov.UK: Surveillance camera code of practice:
https://www.gov.uk/government/publications/surveillance-camera-code-of-practice
CQC Using surveillance: information for service providers:
https://www.cqc.org.uk/guidance-providers/all-services/using-surveillance-information-service-providers
Training Statement
All staff responsible for data control receive training concerning CCTV.
All staff, during induction, are made aware of the organisation’s policies and procedures, all of which are used for training updates. All policies and procedures are reviewed and amended where necessary, and staff are made aware of any changes. Observations are undertaken to check skills and competencies. Various methods of training are used, including one to one, online, workbook, group meetings, and individual supervisions. External courses are sourced as required.
Date Reviewed: May 2021
Person responsible for updating this policy: Carly Fortune
Next Review Date: May 2022
Appendix 1
Data Protection Legislation
Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless:
- At least one of the conditions in Schedule 2 is met, and
- In the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.
- Personal data shall be obtained only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or those purposes.
- Personal data shall be adequate, relevant, and not excessive concerning the purpose or purposes for which they are processed.
- Personal data shall be accurate and, where necessary, kept up to date.
- Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
- Personal data shall be processed following the rights of data subjects under this act.
- Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and accidental loss, destruction of, or damage to personal data.
- Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects to the processing of personal data.
This is not a full explanation of the principles. For more general information, see the ICO’s Data Protection Act 1998 Legal Guidance, available on the ICO website:
www.ico.org.uk
Appendix 2
The Guiding Principles of the Surveillance Camera Code of Practice
System operators should adopt the following twelve guiding principles:
- The use of a surveillance camera system must always be for a specified purpose, which is in pursuit of a legitimate aim and necessary to meet an identified pressing need.
- The use of a surveillance camera system must take into account its effect on individuals and their privacy, with regular reviews to ensure its use remains justified.
- There must be as much transparency in the use of surveillance camera systems as possible, including a published contact point for access to information and complaints.
- There must be clear responsibility and accountability for all surveillance camera system activities, including images and information collected, held and used.
- Clear rules, policies and procedures must be in place before a surveillance camera system is used, and these must be communicated to all who need to comply with them.
- No more images and information should be stored than that which is strictly required for the stated purpose of a surveillance camera system, and such images and information should be deleted once their purposes have been discharged.
- Access to retained images and information should be restricted, and there must be clearly defined rules on who can gain access and for what purpose such access is granted. The disclosure of images and information should only take place when it is necessary for such a purpose or law enforcement purposes.
- Surveillance camera system operators should consider any approved operational, technical, and competency standards relevant to a system and its purpose and work to meet and maintain those standards.
- Surveillance camera system images and information should be subject to appropriate security measures to safeguard against unauthorised access and use.
- There should be effective review and audit mechanisms to ensure legal requirements, policies, and standards are complied with in practice, and regular reports should be published.
- When the use of a surveillance camera system is in pursuit of a legitimate aim and there is a pressing need for its use, it should then be used in the most effective way to support public safety and law enforcement to process images and information of evidential value.
- Any information used to support a surveillance camera system that compares against a reference database for matching purposes should be accurate and kept up to date.
In communal areas, we consult with those where the fitting of such cameras may impact their privacy.
In bedroom areas, consent, as defined by the Mental Capacity Act 2005, is sought, as this setting is covered by the handling of sensitive personal data under the Data Protection Act 2018.
We are aware of the Care Quality Commission guidance of the use of CCTV in a social care setting and we have adopted the checklist contained in the Code of Practice, which will be reviewed annually.
Definitions
Surveillance. The monitoring of a place, person, or group or ongoing activity to gather information.
Overt surveillance. Where the individual being monitored would reasonably be aware of the surveillance occurring, e.g. visible CCTV cameras with clear signage that they are in use.
Covert surveillance. Where the individual being monitored would not be reasonably aware of the surveillance occurring, e.g. the use of hidden audio recording devices for a time-limited and specific purpose.
Surveillance systems. The technology or equipment used to store or process the information gathered. Advances in technology mean it encompasses CCTV, Wi-Fi cameras, audio recording, radio frequency identification (RFID), smartphone apps etc.
This policy excludes the use of medical devices or treatment that gathers information; any use of technology with the knowledge and explicit consent of the patient, e.g. filming a surgical procedure; or any communication system controlled by the person using it, e.g. webcams, alarm buttons etc.
These would not be considered as surveillance, but issues of privacy still need to be considered.
Privacy. In its broadest sense, is the right of the individual to be left alone. Intrusion into privacy can include the collection of information through surveillance or monitoring of how people act in public or private spaces.
It is therefore important that all factors are taken into consideration and recorded before the decision to undertake any form of surveillance is authorised.
A privacy impact assessment (PIA), where appropriate, must be completed, following the guidance issued by the ICO. Using the following screening questions will assist in determining whether a PIA is necessary. Yes, as the answer to any of the questions, will indicate that a PIA would be a useful exercise.
- Will the surveillance involve the collection of new information about individuals?
- Will the surveillance compel individuals to provide information about themselves?
- Would such information be disclosed to organisations or people who previously had routine access to it?
- Would such information be used in a way it is not currently used?
- Will the surveillance result in us making decisions or taking action against the individuals in ways that can have a significant impact on them?
- Would the surveillance require you to contact individuals in ways that they may find intrusive?
If a PIA is deemed necessary, then complete the following six steps.
Step One: Identify the need for a PIA
- Explain what the project aims to achieve and what the benefits will be to the organisation, to individuals and other parties.
- Links to other relevant documents related to the project, e.g. a project proposal, will be helpful.
- Summarise why the need for a PIA was identified (this can draw on your answers to the screening questions).
Step Two: Describe the information flows
The collection, use and deletion of personal data should be described here. It may also be useful to refer to a flow diagram or another way of explaining data flows. You should also say how many individuals are likely to be affected by the project.
Consultation requirements:
- Explain what practical steps you will take to ensure that you identify and address privacy risks.
- Who should be consulted, internally and externally?
- How will you carry out the consultation? You should link this to the relevant stages of your project management process.
- Consultation can be used at any stage of the PIA process
Step Three: Identify the privacy and related risks
Identify the key privacy risks and the associated compliance and corporate risks.
Larger-scale PIAs might record this information on a more formal risk register.
Step three can be used to help identify the compliance risks related to the Data Protection Act.