Body-worn video is a powerful tool: it protects staff, provides reliable evidence, and strengthens trust. But without a clear policy, it can become a liability. This blog outlines practical steps to ensure compliance with the GDPR and beyond.
Step 0: Establish Your Legal Basis and Transparency
Under GDPR, your legal grounds may include:
- Legal obligation or statutory duty – e.g., in law enforcement or regulatory enforcement.
- Legitimate interests – such as protecting staff or preventing theft (requires Legitimate Interests Assessment).
- Vital interests – safeguarding individuals in emergencies.
Consent is usually not practical. Transparency through signage, briefings, and privacy notices is essential.
Step 1: Define Your Legal Framework
Clarify:
- Minimum/maximum retention periods
- Sector-specific obligations
- Who can authorise extended retention
Conduct and review a DPIA that documents safeguards: deletion schedules, access controls, redaction, breach response, and stakeholder engagement.
Step 2: Set Retention Periods That Fit Reality
- Routine footage: 14–30 days
- Incident-related footage: 6–12 months
- Evidential footage: Until all proceedings are concluded
Apply automated deletion rules to reduce human error.
Step 3: Control Access and Preserve Chain of Custody
- Role-Based Access Control (RBAC): Limit access based on role and purpose
- Audit logs: Track viewing, editing, exporting
- Chain of custody: Maintain authenticity with logs and hashes
- Encryption: Protect in transit and at rest
Step 4: Build a Redaction Workflow
- Blur/mask faces, plates, addresses
- Mute sensitive audio
- Log all redactions
This is critical for GDPR compliance, especially Article 15(4).
Step 5: Address the Rights of Individuals and Accountability
- Right of access: Respond in 1 month (2 for complex)
- Right to erasure: May apply in specific cases
- Right to object: Must be assessed case by case
Appoint a DPO or responsible officer. Train staff. Involve stakeholders.
Step 6: Processors and International Transfers
Sign GDPR-compliant Article 28 processor agreements and include sub-processors and audit rights. For transfers outside the EEA, use Standard Contractual Clauses (SCCs) and conduct risk assessments.
Step 7: Review, Audit, and Document
Regularly review your policy to reflect new laws, technology, and operational lessons. Include breach protocols and documentation for accountability.
Turning Bodycams into a Tool of Trust and Compliance
A clear policy ensures lawful use, secure handling, and public trust. ZEPCAM provides secure, compliant systems and expert guidance to support you every step of the way.
📌 Frequently Asked Questions (FAQ)
- 1. How long can body-worn video be retained?
- Under GDPR, only as long as necessary. Routine footage is often deleted after 14–30 days; evidential material is retained until legal processes are complete.
- 2. What is a chain of custody?
- It’s a documented trail showing how footage is handled, including timestamps, access logs, and hashes to verify authenticity.
- 3. How should subject access requests be handled?
- Organisations must respond within one month (or two for complex cases), redacting third-party data before disclosure.
- 4. What happens in the event of a data breach?
- A breach must be assessed and logged. If it poses a high risk, notify authorities within 72 hours and inform affected individuals.
- 5. What security measures are required?
- Encryption (in transit and at rest), RBAC, export controls, hashing for verification, and regular testing are all best practices.
