top of page
CCTV Policy

Last Updated: 8th January 2026

1. Purpose of the Policy

 

Creative Media Skills Institute (CMSI) uses Closed-Circuit Television (CCTV) systems to:

 

  • Protect staff, students, visitors, and contractors

  • Deter and detect crime (including theft of equipment)

  • Assist in the investigation of incidents

  • Safeguard Institute property and assets

  • Support health and safety obligations

This policy ensures CCTV is used lawfully, proportionately, transparently, and securely, in compliance with applicable data protection legislation.

 

2. Legal Framework

 

This policy is informed by and complies with:

 

  • UK General Data Protection Regulation (UK GDPR)

  • Data Protection Act 2018

  • Human Rights Act 1998

  • Information Commissioner’s Office (ICO) CCTV Code of Practice

 

CCTV footage that identifies individuals constitutes personal data and is processed accordingly.

 

3. Scope

 

This policy applies to:

 

  • All CCTV systems operated by CMSI

  • All staff, students, visitors, contractors, and members of the public who may be captured on CCTV

  • All locations where CMSI operates CCTV (including shared or leased premises)

 

4. Lawful Basis for Processing

 

CMSI processes CCTV data under the following lawful bases:

  • Legitimate interests – to prevent crime, protect property, and ensure safety

  • Public task – where applicable in delivering education and training services

 

CCTV is not operated on the basis of consent.

 

5. Data Protection Principles

 

CMSI ensures that CCTV data is:

 

  • Processed lawfully, fairly, and transparently

  • Collected for specified, explicit, and legitimate purposes

  • Adequate, relevant, and limited to what is necessary

  • Accurate and kept up to date

  • Retained only for as long as necessary

  • Stored and accessed securely

  • Processed in a manner that ensures accountability

 

6. Location of Cameras

 

Cameras are positioned to monitor areas such as:

 

  • Entrances and exits

  • Corridors and communal spaces

  • Areas containing valuable equipment

 

Cameras will not be installed in:

 

  • Toilets

  • Changing rooms

  • Private offices (unless exceptional and justified)

  • Areas where individuals have a heightened expectation of privacy

Cameras are positioned to avoid capturing areas beyond CMSI’s control where reasonably possible.

 

7. Transparency and Signage

 

CMSI ensures transparency by:

 

  • Displaying clear and visible CCTV signage at all entrances and monitored areas

  • Providing information about CCTV use in staff and student privacy notices

  • Making this CCTV Policy available upon request

 

Signage will state:

 

  • That CCTV is in operation

  • The purpose of CCTV use

  • The organisation responsible for the system

  • Contact details for further information

 

8. Access to CCTV Footage

 

Access to CCTV footage is:

  • Strictly limited to authorised personnel only

  • Granted on a need-to-know basis

  • Logged where technically possible

Authorised personnel may include:

  • Senior management

  • Designated security or facilities staff

  • Data Protection Officer (or nominee)

Footage will not be shared informally or used for purposes outside this policy.

 

9. Retention of CCTV Data

 

  • CCTV footage is retained for up to 30 days

  • Footage may be retained longer where:

  • An incident is under investigation

  • Footage is required for legal proceedings

  • A request has been made by law enforcement

 

Once no longer required, footage is securely deleted.

 

10. Disclosure of CCTV Footage

 

CCTV footage may be disclosed:

 

  • To law enforcement agencies for the prevention or detection of crime

  • Where required by law or court order

  • In response to a valid Subject Access Request (SAR)

 

All disclosures are documented and assessed for necessity and proportionality.

 

11. Subject Access Requests (SARs)

 

Individuals have the right to request access to CCTV footage that identifies them. CMSI will:

 

  • Respond within one calendar month

  • Verify the requester’s identity

  • Protect the privacy of third parties (e.g. blurring where required)

  • Refuse or restrict access where exemptions apply

 

Requests should be made in writing to: Valeria@cmsinstitute.co.uk
 

 

12. Data Security

 

CMSI implements appropriate technical and organisational measures including:

 

  • Secure storage systems

  • Password protection and access controls

  • Encrypted storage where available

  • Regular system reviews and updates

 

All staff with access to CCTV receive appropriate data protection training.

 

13. Use of Third-Party Contractors

 

Where external CCTV installers, maintenance providers, or storage services are used:

 

  • Data Processing Agreements are in place

  • Contractors act only on CMSI’s instructions

  • Contractors must comply with UK GDPR requirements

 

CMSI remains the Data Controller at all times.

 

14. Data Protection Impact Assessment (DPIA)

 

CMSI has conducted a Data Protection Impact Assessment (DPIA) to:

 

  • Assess privacy risks

  • Justify the use of CCTV

  • Identify mitigation measures

 

The DPIA is reviewed periodically and whenever significant changes are made to the CCTV system.

 

15. Complaints and Concerns

 

Any concerns regarding CCTV use should be raised with:

 

Valeria@cmsinstitute.co.uk

 

Individuals also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

 

16. Policy Review

 

This policy is reviewed:

 

  • Annually

  • When CCTV systems change

  • Following changes in legislation or ICO guidance

17. Contact

For questions or concerns regarding this policy, please contact:

CMS Institute (Creative Media Skills Group Ltd)
Pinewood Studios, Pinewood Road,
Buckinghamshire, SL0 0NH, United Kingdom
info@creative-media-skills.com
01753 656168

 

© CMS Institute / Creative Media Skills Group Ltd. All rights reserved.

bottom of page