Skip to content

GDPR · data protection in the systems we install

A camera records people. That has an owner, rules and time limits.

This page is not this website's privacy policy — that one is in the legal terms. This is the other thing, and it is the one that usually goes missing: how data is protected inside the video surveillance system we install at your site, and which part of that is down to you and not to us.

What this page covers and what the other one covers.

There are two data protection conversations and they get mixed up all the time. One is what this website does with your email address when you fill in the form: controller, legal basis, time limits and rights. That is a legal text, it is written out in full and it is not here.

The other is the one that matters when what you are buying is a system that records people: cameras producing images of workers, customers, suppliers and people walking down the street, stored on a drive in your building, viewable by a handful of people and claimable by anyone who appears in them. That is this one.

And the first thing to make clear is the thing that almost never gets made clear: most of that is down to you.

The privacy policy and cookies

Who is the controller and who is the processor.

When we install a system at your premises, you are the controller. We are the processor.

It looks like a lawyers' distinction and it is the one that decides who answers when a complaint arrives. The controller is whoever decides why recording happens, where the cameras go, how long footage is kept and who can look. You decide that, because it is your site, your risk and your operation. And if the Agencia Española de Protección de Datos —Spain's data protection authority— asks, it asks whoever decides.

We are the processor: we process those images on your behalf and only for what you have instructed. Installing, configuring, maintaining, and going in to look when there is a fault or a service visit. We cannot use your images for anything else, we cannot keep them on our side of our own accord, and we cannot bring a third party into the middle of it without you knowing and authorising it.

That doesn't hold up on goodwill: it is signed. The processing agreement is mandatory and states in writing what we may process, for how long, with what measures, which of our people have access, what happens to the data when it ends —it is returned or deleted, and evidenced— and what we do if we spot a problem. If a video surveillance supplier hasn't given you that contract, you are missing the document you would defend yourself with.

And in practice, what falls to you.

As you are the controller, these decisions are yours. We help you take them and we tell you when we think one is debatable, but we don't take them for you:

  • What each area is recorded for. A purpose written down, not "for security" in general.
  • What can be seen from each camera and what should not be seen.
  • How long the recording is kept, and that the system enforces it on its own.
  • Who has an account, and what each one can do: watch live, view recordings, export.
  • Who deals with a person asking for their own image, and how long it takes.
  • The signs, which are yours and are the first thing an inspection looks at.
  • The impact assessment when the case calls for one.

What we have in place at our end.

Because a processor whose own house isn't in order is no use to anyone.

Data protection impact assessments are carried out regularly: the exercise of sitting down to look at a processing operation and ask what could go wrong for the people affected and what is being done to stop it happening. When a project of yours needs one —and there are cases where it is mandatory— we know how it is done because we do it.

The record of processing activities is kept, which is the inventory of what data is processed, what for, on what basis, who has access, who it is disclosed to and how long it is retained. It is the first thing the supervisory authority asks for when it turns up, and it is also the only way of knowing what you have.

And Data Protection Officers are appointed in the group's organisations, which is the role that oversees all of this from the inside and that you can write to. We don't publish their name or a personal email address here: the contact details are given to anyone who asks, through the contact channel on this website, and that is the right route for exercising rights or for a compliance query.

The measures, audited by someone from outside.

Technical and organisational measures protect data against loss, alteration, unauthorised access or unlawful processing. That is what the regulation says, and written like that anyone will sign it. The difference is whether someone from outside has come to check.

Someone has. ISO/IEC 27001 certifies the information security management system, and ISO/IEC 27701 is about exactly this: privacy management, which is the extension of the previous one for the processing of personal data. With that, your IT department asks for the certificate and checks it, instead of sending us a forty-page questionnaire that somebody then has to assess.

The certificates, with their scope

Where a camera looks is a data protection decision.

Not just a technical one. And it is taken with a drill in your hand, which is the tricky part.

Data protection by design sounds like a document. In video surveillance it is something very physical: it is the height, the angle and the zoom of each camera. A camera that covers your front door and, along the way, thirty metres of public pavement is processing data about people who have nothing to do with you. Turned a few degrees, it stops doing that and still covers the door. That decision lasts as long as the installation does.

The three places where this is broken almost every time are always the same. The public highway: only what is essential around the entrance may be captured, and the rest is cropped or masked. The neighbour's property: their door, their window and their garden are not your site. And the workstation: a camera pointed permanently at one particular desk is not security surveillance, it is monitoring of employees, and that has different rules, different prior information and a different conversation with the works council.

There are also areas where no camera goes, and it is not a matter of opinion: changing rooms, toilets, canteens and rest areas. If one appears there on the drawing, the drawing is wrong.

All of this is decided during the design stage, while it is still free, and it is written down: what each camera covers, what is deliberately left out and which areas of the image are masked. The masks are checked against the real image and not against the drawing, and they are checked again at maintenance: a camera someone repositioned to get a better view of the loading bay may have taken the agreed field of view with it.

How long the video is kept.

Less than people think. And the drive is bought for the retention period, not the other way round.

Video surveillance images are deleted within a maximum of one month from capture, except for those that have to be kept to evidence acts against people, property or premises — and those are kept precisely so they can be handed to whoever has to investigate them. The Spanish data protection act says so, and it is not a recommendation.

The right order, then, is to fix first how long has to be kept and calculate the storage afterwards. The opposite happens very often: a generous drive is bought, the system ends up keeping three months because there is room and nobody configured it to delete. That is a silent breach, one nobody finds out about until somebody asks. On what we maintain, automatic deletion is part of the configuration we hand over and part of the inspection report.

And it works the other way round too. A system that keeps seven days because the drive won't take more is a system that doesn't do what it was bought for: incidents are discovered late, and the recording from the day that mattered no longer exists.

Someone is going to ask for their own image. The system has to be able to give it to them.

And if it can't, the problem isn't the right: it is the system.

Anyone who has been recorded can request access to their images, ask for them to be erased when there is no longer a reason to keep them, object to the processing or lodge a complaint with the supervisory authority. That isn't negotiable and there is a deadline for replying, counted in weeks and not in months.

It looks easy until you have to do it. A request comes in saying "I was in your building on the 14th, in the morning". You have to locate that stretch on the right camera, check that the person is who they say they are, extract the images they appear in and hand them over without revealing the other people in the same frame, who have rights too. And keep a record.

A system that only lets you look back camera by camera, without searching properly by date and time, without exporting a specific clip and without logging who exported what, turns every request into an afternoon's work and a poor answer. Locating, clipping, anonymising third parties and exporting with a log is a data protection requirement, and you look at it when choosing the system and not when the first letter arrives.

The signs. The easiest thing to comply with and the most often broken.

Layered information: the sign is the first layer, and there has to be a second.

Before entering an area under video surveillance, people have to know that it is. The sign goes on the perimeter, visible before you go in, not on the wall at the end of the corridor. And it has to say four things: that the area is under video surveillance, who the controller is, why recording happens, and where the rest of the information can be consulted and rights exercised.

That is the first layer. The second is the full detail: legal basis, retention periods, recipients, transfers if there are any, and how to complain. It has to be genuinely available —at reception, on the intranet, at a web address— and not just mentioned.

The typical failure isn't having no signs: it is having the previous supplier's, with a company name that is no longer the controller, or having them at three of the five entrances. It is the cheapest check there is and the first one an inspection makes, so it goes on the maintenance round.

Biometrics: not the default answer for opening a door.

Fingerprints and faces are special category data. That changes everything around them.

When a physical trait is used to identify a person, the data stops being a card number and becomes a special category: processing prohibited as a general rule, and only possible if it fits one of the exceptions in the regulation. It isn't solved with a consent tick-box in the employment contract, because between employer and employee that consent is unlikely to be freely given — if the alternative is not being able to come in to work, there is no choice.

What it requires: a reinforced legal basis that stands up in writing, a prior impact assessment, justification of why a less intrusive measure isn't enough, specific information to the people affected and stronger security measures, because a compromised fingerprint can't be changed like a password.

And there is almost always a less intrusive measure that solves the real problem. If what you want is for the card not to be lent out, there is card plus PIN. If what you want is to know who opened it, there is an access log with image verification, which records but doesn't create a biometric database. If what you want is a car park barrier, there are number plates. Biometrics is the answer when the risk justifies it —a critical area, an entrance that cannot fail— and then you build it with all of the above done.

So when someone asks for a fingerprint reader on the main door, the first thing is to ask what problem is underneath. Sometimes it is biometrics. Quite often it is something else, cheaper and with half the paperwork.

Counting people is not identifying people.

And that difference is what decides whether a project is simple or needs a great deal more.

There are two things that go by the same name —"video analytics"— and in data protection terms they are nothing alike. One is measuring: how many people go down this corridor, how long the loading bay has been occupied, how long the queue is. The system needs to see an outline in order to count it and doesn't need to know who it was, so the result is a number and not a person.

The other is identifying: linking an image to a specific identity. It needs a different legal basis and, if it goes by physical traits, it is biometrics with everything that drags along. Mixing the two in the same sentence is the mistake that turns an occupancy-measuring project into three months of conversation with the works council.

The rule we apply: if the function can be met with a number, it is built so that a number comes out. And for almost everything that gets asked for —occupancy, queues, dwell times, use of protective equipment, vehicle counting— it can be.

And there is one more piece that changes the conversation: where the image is analysed. IRIS Neural, the system from Infinity Neural —one of the companies in this group—, processes the video inside the installation itself: there is no need to send the images to a third party's cloud to understand what is going on. It removes no obligation, it is still processing with its controller, but it takes off the table the hardest thing to justify: who else has access to your images and where they are.

IRIS Neural, the system that processes on site

Who can look, and keeping a record of it.

Most video incidents are not attacks. They are internal access that nobody logged.

At a normal site, the images can be seen by rather more people than you thought: the security shift, the plant manager, the IT person who set up the server, the support supplier and the generic user whose password half the workforce knows. That last one is the real problem.

What is set up instead: named users that are not shared, permissions by area and by function —some people need to watch live and don't need to be able to export—, and a log of who has looked at what and who has taken a file out and when. That log is what turns a suspicion into a fact, and it is what an audit asks for.

And our access, the processor's, works the same way: with identified users, only for what has been contracted, and leaving a trail. It is reasonable for you to require it by contract, and it is in the processing agreement.

And where the video physically is.

The drive that holds the recordings is somewhere. If that somewhere is an open cabinet in a corridor, the most sophisticated software measure is worth nothing. That is why the location, the cabinet lock and who holds the key are part of the measures, and they are written down.

And where there is a backup or remote access, it is stated where it is and with what safeguards. An international transfer has to be identified and covered by one of the mechanisms the regulation allows: it isn't enough for the supplier to be well known. The simplest way of not having that conversation is for the video not to leave your premises.

And if there is a breach.

Seventy-two hours. The clock starts when you find out, not when you understand it.

A breach isn't only someone getting in from outside. It is also a drive going missing, a video sent to the wrong person or a user accessing what they shouldn't have. The controller has to notify the supervisory authority without undue delay and, at the latest, within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to individuals. And where the risk is high, tell them too.

Seventy-two hours is very little time to improvise: you need to know in advance who decides, who drafts and where the logs are that let you tell what happened. It is a half-page procedure that nobody writes until the day they need it.

Our part is in the contract: if we detect something in what we manage, we tell you without delay —because the one who notifies the authority is you— and we give you what we have: what happened, when, what data and which people may be affected and what has been done to contain it. The access logs we were talking about earlier are what make it possible to answer that in hours rather than weeks.

In short.

You are the controller and we are the processor, with a contract that governs it. The field of view of each camera is decided and written down. The retention period is configured so that it takes care of itself. And there are three lines that are not crossed without written justification: no recording where recording isn't allowed, no processing biometrics because it is convenient, and no saying that a system identifies when what it does is count.

Get started

Got a specific question?

If you are building a system and you don't know which side a decision falls on —a field of view, a retention period, a fingerprint reader— ask. And if what you need is the Data Protection Officer's contact details, ask here and you will be given them.