Employee Handbook
Policy 18: CCTV POLICY
1. POLICY STATEMENT
Simplyfruit (Ire) Limited is committed to the safety of all its employees and customers and has invested in the security of its buildings and facilities. There is a Closed-Circuit Television (CCTV) Surveillance System for the main purposes of preventing and detecting crime and for the safety and security of our premises, employees and customers.
The purpose of this policy is to regulate the management, operation and the usage of CCTV system at the Simplyfruit (Ire) Limited.
As the CCTV system is based around digital technology there is the need to treat information confidentially and that it will be processed in accordance with the Data Protection Act 1998 and GDPR regulations. The persons ultimately responsible for data protection are the Directors.
The system comprises of a number of fixed cameras located both internally and externally on the Simplyfruit (Ire) Limited sites. All cameras may be monitored and are only available for use by the Directors.
2. SCOPE
This policy applies to all employees and workers. It also applies to contractors and/or subcontractors who may be working on the company premises.
3. OBJECTIVES
The objectives of the CCTV system are to:
- Protect the company buildings and its assets to ensure that they are kept free from intrusion, vandalism, damage or disruption.
- Provide increased personal safety for employees, workers, contractors, subcontractors or customers and reduce fear of crime, physical abuse or intimidation.
- Assist in the identification, apprehending and prosecuting offenders found on the company site.
- Protect members of the public and private property.
- Assist in the usage and management of the building on a day to day basis.
4. COMPANY INTENT
The company will comply with the Data Protection Act 1998, whether it be information, recordings and downloads which may be related to the CCTV system.
Cameras will be used to monitor activities within the Simplyfruit (Ire) Limited premises, our parking and other areas to identify criminal activity either occurring, anticipated or perceived and with the purpose of ensuring the safety and wellbeing of employees, workers, visitors, contractors and subcontractors.
Unless an immediate response is required to events employees must not direct cameras at an individual, their property or a group of individuals without authorisation from a Director or their designated authority.
Materials or knowledge secured as a result of the CCTV system will not be used for any commercial purpose. Downloads will only be released to the relevant authorities, with authorisation from a Director or their designated authority.
The CCTV system has been planned, designed and installed to try to ensure that the CCTV system will give the maximum effectiveness and efficiency, but it is not possible to guarantee that the CCTV system will cover or detect every incident taking place in the areas covered by the cameras.
CCTV images which evidence any behaviour which cannot reasonably be ignored may be used for disciplinary purposes.
Warning signs, as required by the Information Commissioner’s Code of Practice shall be placed at all access routes and other appropriate areas covered by the company CCTV.
5. OPERATION OF THE SYSTEM
The system will be administered and managed by a Director in accordance with the principles and intent outlined in this policy.
The day-to-day management will be the responsibility of a Director and the service provider.
The CCTV System will be operated 24 hours a day throughout the whole year.
Camera surveillance may be maintained at all times for monitoring purposes.
Should it be decided that images be retained for any reason, including the release to a third party (including the PSNI) under the exemptions contained within the relevant sections, at the appropriate time, of the Data Protection Act 1998 and/or GDPR regulations or retained for any reason for which the system is registered with the Information Commissioner, copies of such images may be transferred to an appropriate computer file.
Unless required for any other reasons contained in the appropriate sections of the Data Protection Act 1998, recorded images will be retained for no longer than required for the purpose for which they were originally obtained.
Outside of normal company working hours the system will connect to a Director or their designated authority in the event of a security alarm being activated.
ACCESS TO RECORDING BY THIRD PARTIES
Recordings may be reviewed by the PSNI. The company will need to give permission to do so through a Director or their designated authority. This will normally be in relation to criminal activities or other activities for which there is deemed to be a valid and justifiable reason.
A record will be maintained of the release of downloads to the police or other authorised parties. A register will be maintained for this purpose and will be retained and securely stored by a Director or his designated authority.
The viewing of downloads by the PSNI will be recorded in writing and in the register. Requests by the PSNI can only be actioned in accordance with the relevant section of the Data Protection Act 1998.
Should a download be required as evidence; a copy may be released to the PSNI in accordance with the procedures described in this policy. Downloads will only be released to the PSNI on the clear understanding that the disc or other means of transfer remain the property of the company.
The disc or other means of transfer and the information contained on it are to be treated in accordance with this policy. The company retains the right to refuse permission for the PSNI to pass to any other person the disc or other means of transfer or any or all of the information contained therein.
Applications received from external bodies e.g. solicitors to view or for the release of downloads will be referred to a Director or their designated authority. In such circumstances a Director or their designated authority will normally release downloads where there is satisfactory evidence produced showing that they are required for legal proceedings, a subject access request, or in response to a Court Order. In such circumstances the company reserve the right to charge a small charge.
BREACHES OF THE POLICY (INCLUDING BREACHES OF SECURITY)
Any breaches of the Company Policy will be investigated in accordance with the company Disciplinary Policy which may lead to disciplinary action up to and including dismissal.
Access to and disclosure of images will be restricted and carefully controlled, not only to ensure that the rights of individuals are preserved but also to ensure that the chain of evidence remains intact should the images be required for evidential purposes.
Access to recorded images will be restricted to a Director or their designated authority and those employees who may require access, following consent of a Director in order to achieve the purposes of using the equipment.
Requests by person(s) outside the company (other than the PSNI) for viewing or obtaining recordings will be assessed on a case by case basis by a Director or their designated authority and access will only be granted where it is consistent with the obligations placed on the company by the Data Protection Act 1998.
All requests for access will be recorded detailing the date and time at which access was allowed/or disclosure made; the reason for the access/disclosure; the extent of the information accessed/disclosed; name of the employee(s) providing access.
If access to images is denied to an employee or third party (including the PSNI) a Director or their designated authority will clearly record the reasons why and this information will be logged.
Where a PSNI officer requests access to CCTV images either by viewing such data or requesting a copy of the data, the requisite form must be completed and signed.
Requests for access to images by the PSNI will not normally be denied and can be made without the authority of a Director or their designated authority provided they are accompanied by a written request signed by a PSNI officer, who must indicate that the images are required for the purposes of a specific crime enquiry.
COVERT MONITORING
The current operating system is an open CCTV system. Covert monitoring will only be considered in exceptional circumstances and as a final measure. The use of covert monitoring will be subject to the completion of an impact assessment, in accordance with the ICO’s Data Protection, Employment Codes of Practice and approval of a Director or their designated authority. The assessment of the impact should be undertaken by the manager appointed to investigate the alleged misconduct.
Circumstances where covert monitoring may be considered, but not exclusive to include:
- Where there are grounds for suspecting criminal activity.
- Gross misconduct in accordance with the disciplinary policy and procedure or other malpractice.
- Where notifying the individuals about the monitoring would or is likely to prejudice its prevention or detection.
Where covert monitoring is approved, it must be strictly targeted at obtaining evidence within a set timeframe and must cease once the investigation is complete.
Images recorded of individuals not under suspicion must be deleted.
ASSESSMENT OF THE SCHEME AND CCTV USAGE POLICY
The company reserve the right to carry out random operating checks. In such circumstances these will be carried out by approved persons referred to throughout this document.
COMPLAINTS
Any complaints about the company’s CCTV system should be addressed to a Director or their designated authority
Complaints will be investigated in accordance with Section 9 of this policy.
ACCESS BY THE DATA SUBJECT
The Data Protection Act and GDPR regulations provide Data Subjects (individuals to whom “personal data” relate) with a right to data held about themselves, including those obtained by CCTV.
Requests for Data Subject Access should be made in writing to a Director or their designated authority.
For requests by an individual to view data about themselves the following information should be supplied:
- Specific information about dates, times and location of incident is required. The company will respond to a data subject access request "without undue delay" and within one month at the latest, although the company reserve the right to extend this time period by two further months where necessary, taking into account the complexity and number of requests.
- The company may charge a fee for providing information in response to a data subject access request, only if the request is "manifestly unfounded or excessive", in particular because it is repetitive, or it can refuse to act on the request.
- Where the company is unable to comply with the subject access request without disclosing the information relating to another individual who can be identified from that information, it is not obliged to comply with that request unless the individual has consented to the disclosure or it is reasonable, in the circumstances, to comply without the consent of the individual.
- Where the data subject makes a request by electronic means, the information "shall be provided by electronic means where possible", unless the data subject requests otherwise.
13. PUBLIC INFORMATION
Copies of this policy will be made available to the public, by making a request to a Director or their
designated authority.
14. SYSTEM MAINTENANCE AND MONITORING
The system will be maintained in accordance with the Data Protection Act and GDPR regulations 2018.