Suitable for councils and other organisations using surveillance and CCTV systems.
14 August 2018
CCTV cameras have become a part of our everyday lives, we go about our business largely unaware of them. They can serve as a valuable tool for security, crime prevention and detection.
However, capturing a person’s movements on camera is intrusive, and, as you’d expect, subject to strict data protection and human rights laws.
Those laws say that organisations have to think through the privacy implications carefully before implementing any type of CCTV or surveillance system.
And while there are many areas of concern around surveillance, one particular issue we are currently dealing with is the rise of CCTV cameras in taxis.
Councils across the UK have installed the cameras in licensed taxis as a way to combat crime, and to protect drivers and vulnerable passengers.
But we have discovered that many of these CCTV systems are activated whenever a vehicle is running. They operate continuously, including when the taxi is being used privately by the driver.
That means it’s switched on when drivers are picking up their children from school, taking the family shopping or heading off on holiday driving to another part of the country. Taxi drivers, like all of us, have a right to privacy. And that right is enshrined in law.
The law states that the processing of personal data should be necessary for its purpose and proportionate. So where a taxi is being used by a driver for their own private or domestic purpose, continuous recording is likely to be unlawful, unfair and excessive under data protection legislation and in breach of Article 8 of the Human Rights Act 1998.
It’s not just continuous recording that raises concerns. There’s also the question of who controls the processing of this data. In most circumstances a council which instructs systems to be installed should be responsible for the data. It’s the council which is the data controller, not an individual taxi driver. Councils need to make sure they understand this part of the law.
Before introducing any new CCTV or surveillance system, councils need to stop, think and check that they’ve taken the appropriate mitigating actions to minimise the risk of the loss or misuse of personal data captured by CCTV. The ICO has powers to stop the processing of personal data and to take action against any organisation breaking the law.
With this in mind we’ve put together three key points for councils:
You need to go back to the start of your project and consider the problem you are seeking to address and whether a CCTV system would be a necessary, justified and effective solution.
Take into account whether other, potentially less intrusive solutions exist that can achieve the same aim, as well as the effect that each aspect of the CCTV system may have on individuals, and whether their use is a proportionate response to the problem identified.
Conduct a Data Protection Impact Assessment (DPIA)
Data protection law has changed – new legislation states that Data Protection Impact Assessments (DPIAs) must be carried out prior to the roll-out of any intrusive surveillance system – CCTV in taxis is likely to be one of these systems. You need to be able to demonstrate you have conducted a DPIA to the ICO. There’s more information on DPIAs on our website.
If you decide that a CCTV system is required, then a ‘privacy by design’ approach should be considered when making decisions about which equipment to purchase. You should identify which equipment is the most appropriate to meet the need and purposes it is required for.
It’s a guide to how you should be running your system, plus it highlights particular problem areas and the fact that your CCTV system needs to be registered with the ICO.
We’ll be continuing our work in this area offering councils advice and guidance where necessary.
Elizabeth Denham was appointed UK Information Commissioner on 15 July 2016, having previously held the position of Information and Privacy Commissioner for British Columbia, Canada.