CCTV Privacy Law Mapper
Finding 14 of 18

Disclosures to police or insurers not logged

Footage handed to the police or an insurer is a disclosure. GDPR and UK GDPR Art. 30 put the recipients in the record of processing and Art. 5 asks you to be able to show what you did; APP 6 sets when a disclosure for another purpose is open to you; for face matching in Illinois, BIPA 15(d) lists the only grounds for a disclosure. The held texts do not ask for a log of each request by that name, so the line is a question about how you would show it.

When it is raised
Raised when who can view names the police, law enforcement or an insurer, and the disclosures logged column is blank or no.
The question
Where is each disclosure recorded: what was handed over, to whom, when and on what request?
For
your privacy lead
The column that settles it
disclosures logged
On the row
a numbered delta and the words "disclosures" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 30Records of processing activities

Records of processing activities. Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.

What a reviewer asks to see: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; Version history showing when each entry was last reviewed and by whom; Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well; The transfer entries with the third country identified and the safeguard documentation referenced; Where the fewer than 250 persons exemption is claimed, the assessment against all three disqualifying conditions
Where camera lists usually fall short: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since; Entries written at the level of a department or a system rather than a processing activity, which loses the purpose that everything else hangs off; Erasure time limits left blank throughout on the where possible qualifier, while a retention schedule exists elsewhere in the organisation; The small organisation exemption claimed on headcount alone, ignoring that regular non-occasional processing disqualifies it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 5Principles relating to processing of personal data

Principles relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where camera lists usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 30Records of processing activities

Article 30 Records of processing activities. Each controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.

What a reviewer asks to see: Record of processing activities covering every required field; Processor record per controller; Evidence of periodic review of the records
Where camera lists usually fall short: Records not updated as systems change; Small organisations claiming the exemption despite regular processing; Security measures described only generically
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 5Principles relating to processing of personal data

Article 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What a reviewer asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
Where camera lists usually fall short: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR, read 29 Sep 2026

Australian Privacy Principles (APPs)

APP APP 6Use or disclosure of personal information

APP 6 - Use or disclosure of personal information. Only use or disclose personal information for the purpose it was collected (primary purpose) or a permitted secondary purpose.

What a reviewer asks to see: Use/disclosure tied to primary or permitted purpose; Records of use and disclosure
Where camera lists usually fall short: Use/disclosure for unrelated purpose; No basis recorded
Source: Australian Privacy Principles (APPs), read 29 Sep 2026

Illinois Biometric Information Privacy Act (BIPA)

BIPA s. 15(d)No disclosure, redisclosure or dissemination except on four grounds

No disclosure, redisclosure or dissemination except on four grounds. No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.

What a reviewer asks to see: Register of every recipient of biometric data (vendors, processors, affiliates, cloud services) with the ground for each disclosure; Consents covering disclosure to named recipients; Legal, warrant or subpoena records for compelled disclosures
Where camera lists usually fall short: Templates sent to a timekeeping or access-control vendor with consent covering collection only; Sharing between affiliates treated as internal; No record of who has received biometric data
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026

See the specimen list run Map your own list