CCTV Policy
Last Updated: 8th January 2026
1. Purpose of the Policy
Creative Media Skills Institute (CMSI) uses Closed-Circuit Television (CCTV) systems to:
-
Protect staff, students, visitors, and contractors
-
Deter and detect crime (including theft of equipment)
-
Assist in the investigation of incidents
-
Safeguard Institute property and assets
-
Support health and safety obligations
This policy ensures CCTV is used lawfully, proportionately, transparently, and securely, in compliance with applicable data protection legislation.
2. Legal Framework
This policy is informed by and complies with:
-
UK General Data Protection Regulation (UK GDPR)
-
Data Protection Act 2018
-
Human Rights Act 1998
-
Information Commissioner’s Office (ICO) CCTV Code of Practice
CCTV footage that identifies individuals constitutes personal data and is processed accordingly.
3. Scope
This policy applies to:
-
All CCTV systems operated by CMSI
-
All staff, students, visitors, contractors, and members of the public who may be captured on CCTV
-
All locations where CMSI operates CCTV (including shared or leased premises)
4. Lawful Basis for Processing
CMSI processes CCTV data under the following lawful bases:
-
Legitimate interests – to prevent crime, protect property, and ensure safety
-
Public task – where applicable in delivering education and training services
CCTV is not operated on the basis of consent.
5. Data Protection Principles
CMSI ensures that CCTV data is:
-
Processed lawfully, fairly, and transparently
-
Collected for specified, explicit, and legitimate purposes
-
Adequate, relevant, and limited to what is necessary
-
Accurate and kept up to date
-
Retained only for as long as necessary
-
Stored and accessed securely
-
Processed in a manner that ensures accountability
6. Location of Cameras
Cameras are positioned to monitor areas such as:
-
Entrances and exits
-
Corridors and communal spaces
-
Areas containing valuable equipment
Cameras will not be installed in:
-
Toilets
-
Changing rooms
-
Private offices (unless exceptional and justified)
-
Areas where individuals have a heightened expectation of privacy
Cameras are positioned to avoid capturing areas beyond CMSI’s control where reasonably possible.
7. Transparency and Signage
CMSI ensures transparency by:
-
Displaying clear and visible CCTV signage at all entrances and monitored areas
-
Providing information about CCTV use in staff and student privacy notices
-
Making this CCTV Policy available upon request
Signage will state:
-
That CCTV is in operation
-
The purpose of CCTV use
-
The organisation responsible for the system
-
Contact details for further information
8. Access to CCTV Footage
Access to CCTV footage is:
-
Strictly limited to authorised personnel only
-
Granted on a need-to-know basis
-
Logged where technically possible
Authorised personnel may include:
-
Senior management
-
Designated security or facilities staff
-
Data Protection Officer (or nominee)
Footage will not be shared informally or used for purposes outside this policy.
9. Retention of CCTV Data
-
CCTV footage is retained for up to 30 days
-
Footage may be retained longer where:
-
An incident is under investigation
-
Footage is required for legal proceedings
-
A request has been made by law enforcement
Once no longer required, footage is securely deleted.
10. Disclosure of CCTV Footage
CCTV footage may be disclosed:
-
To law enforcement agencies for the prevention or detection of crime
-
Where required by law or court order
-
In response to a valid Subject Access Request (SAR)
All disclosures are documented and assessed for necessity and proportionality.
11. Subject Access Requests (SARs)
Individuals have the right to request access to CCTV footage that identifies them. CMSI will:
-
Respond within one calendar month
-
Verify the requester’s identity
-
Protect the privacy of third parties (e.g. blurring where required)
-
Refuse or restrict access where exemptions apply
Requests should be made in writing to: Valeria@cmsinstitute.co.uk
12. Data Security
CMSI implements appropriate technical and organisational measures including:
-
Secure storage systems
-
Password protection and access controls
-
Encrypted storage where available
-
Regular system reviews and updates
All staff with access to CCTV receive appropriate data protection training.
13. Use of Third-Party Contractors
Where external CCTV installers, maintenance providers, or storage services are used:
-
Data Processing Agreements are in place
-
Contractors act only on CMSI’s instructions
-
Contractors must comply with UK GDPR requirements
CMSI remains the Data Controller at all times.
14. Data Protection Impact Assessment (DPIA)
CMSI has conducted a Data Protection Impact Assessment (DPIA) to:
-
Assess privacy risks
-
Justify the use of CCTV
-
Identify mitigation measures
The DPIA is reviewed periodically and whenever significant changes are made to the CCTV system.
15. Complaints and Concerns
Any concerns regarding CCTV use should be raised with:
Individuals also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
16. Policy Review
This policy is reviewed:
-
Annually
-
When CCTV systems change
-
Following changes in legislation or ICO guidance
17. Contact
For questions or concerns regarding this policy, please contact:
CMS Institute (Creative Media Skills Group Ltd)
Pinewood Studios, Pinewood Road,
Buckinghamshire, SL0 0NH, United Kingdom
info@creative-media-skills.com
01753 656168
© CMS Institute / Creative Media Skills Group Ltd. All rights reserved.
