SIA CCTV Data Protection (UK GDPR) 2 — Questions and Answers
Question 1: What is a 'data breach' in the context of CCTV operations?
- When a camera stops recording
- When personal data is accidentally or unlawfully accessed, disclosed, altered, or destroyed (Correct answer)
- When footage quality is poor
- When a camera is vandalised
Correct answer: When personal data is accidentally or unlawfully accessed, disclosed, altered, or destroyed
A data breach is a security incident where personal data is accessed, disclosed, altered or destroyed without authorisation. For CCTV, this could include footage being viewed by unauthorised people or leaked online.
Question 2: How quickly must a data breach involving CCTV footage be reported to the ICO if it poses a risk to individuals?
- 24 hours
- 72 hours (Correct answer)
- 7 days
- 30 days
Correct answer: 72 hours
Under UK GDPR, data breaches that pose a risk to individuals must be reported to the ICO within 72 hours of the organisation becoming aware of the breach.
Question 3: What is the purpose of a 'privacy impact assessment' for a CCTV system?
- To calculate the cost of the system
- To identify and minimise the privacy risks associated with the CCTV system (Correct answer)
- To test whether the cameras work properly
- To determine how many cameras are needed
Correct answer: To identify and minimise the privacy risks associated with the CCTV system
A privacy impact assessment (also called DPIA) helps identify and minimise privacy risks before the system is deployed, ensuring it is necessary, proportionate, and compliant with data protection law.
Question 4: If CCTV footage is to be shared with the police, what must the operator ensure?
- The footage is edited first
- There is a lawful basis for the disclosure and it is documented (Correct answer)
- The footage is only shared verbally
- No documentation is needed for police requests
Correct answer: There is a lawful basis for the disclosure and it is documented
Any disclosure of CCTV footage must have a lawful basis and be documented. Operators should record what was shared, with whom, when, and the reason for the disclosure.
Question 5: What principle of UK GDPR requires that CCTV footage be kept accurate and up to date?
- Purpose limitation
- Data minimisation
- Accuracy (Correct answer)
- Storage limitation
Correct answer: Accuracy
The accuracy principle requires that personal data be accurate and, where necessary, kept up to date. For CCTV, this means ensuring cameras have correct time stamps and dates.
Question 6: Under UK GDPR, what does 'data minimisation' mean for CCTV operators?
- Using the cheapest cameras available
- Only collecting footage that is adequate, relevant, and limited to what is necessary (Correct answer)
- Recording for the shortest possible time
- Having the minimum number of operators
Correct answer: Only collecting footage that is adequate, relevant, and limited to what is necessary
Data minimisation means collecting only the personal data needed for the specified purpose — not filming areas that are unnecessary, not recording audio when it is not needed, and not keeping more footage than required.
What is a 'data breach' in the context of CCTV operations?