Disclosures to police or insurers not logged
Footage handed to the police or an insurer is a disclosure. GDPR and UK GDPR Art. 30 put the recipients in the record of processing and Art. 5 asks you to be able to show what you did; APP 6 sets when a disclosure for another purpose is open to you; for face matching in Illinois, BIPA 15(d) lists the only grounds for a disclosure. The held texts do not ask for a log of each request by that name, so the line is a question about how you would show it.
- When it is raised
- Raised when who can view names the police, law enforcement or an insurer, and the disclosures logged column is blank or no.
- The question
- Where is each disclosure recorded: what was handed over, to whom, when and on what request?
- For
- your privacy lead
- The column that settles it
- disclosures logged
- On the row
- a numbered delta and the words "disclosures" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
GDPR (the EU General Data Protection Regulation)
GDPR Art. 30Records of processing activitiesRecords of processing activities. Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.
GDPR Art. 5Principles relating to processing of personal dataPrinciples relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
UK GDPR
UK GDPR Art. 30Records of processing activitiesArticle 30 Records of processing activities. Each controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.
UK GDPR Art. 5Principles relating to processing of personal dataArticle 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
Australian Privacy Principles (APPs)
APP APP 6Use or disclosure of personal informationAPP 6 - Use or disclosure of personal information. Only use or disclose personal information for the purpose it was collected (primary purpose) or a permitted secondary purpose.
Illinois Biometric Information Privacy Act (BIPA)
BIPA s. 15(d)No disclosure, redisclosure or dissemination except on four groundsNo disclosure, redisclosure or dissemination except on four grounds. No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.