CCTV Privacy Law Mapper
Finding 13 of 18

No owner, or no list of who can view

A camera with no owner has nobody to answer for it, and footage with no list of viewers has no access rule. With ISO/IEC 27001 in scope: an owner for every asset (A.5.9), access control rules (A.5.15), physical security monitoring (A.7.4) and the privacy requirements of law (A.5.34); GDPR and UK GDPR Art. 32 ask for security, including that people with access act only on instructions; APP 11 asks for reasonable security steps.

When it is raised
Raised on a camera whose owner column or who can view column is blank or none. A list with neither column gets one note for the whole register instead.
The question
Who owns this camera and its footage, and who may view it?
For
your privacy lead
The column that settles it
owner
On the row
a numbered delta and the words "no owner" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

ISO/IEC 27001 (information security management)

ISO/IEC 27001 A.5.9Inventory of information and other associated assets

Inventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.

What a reviewer asks to see: Statement of Applicability entry for control A.5.9, showing inclusion or justified exclusion, implementation status and the risks it treats; The asset inventories (information, hardware, software, virtual, facilities and others) with owner, classification and location fields populated; Reconciliation records between inventories and discovery tooling, or evidence that installs, changes and removals update the inventory automatically; A procedure for assigning ownership on creation or acquisition and reassigning it when owners leave or change role; Records of periodic classification and access restriction reviews carried out by asset owners
Where camera lists usually fall short: The inventory covers hardware only and omits information assets, cloud services and software components; Owners listed are people who have left or generic team names with no accountable individual; The inventory drifts from reality because no reconciliation or automated update exists; Disposed assets remain in the inventory, or live assets never entered it
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026
ISO/IEC 27001 A.5.15Access control

Access control. Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose (stated in ISO/IEC 27002:2022): ensures access to information and associated assets is authorized and unauthorized access is prevented. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.15.

What a reviewer asks to see: Statement of Applicability entry for control A.5.15, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements; Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification; Evidence of a default-deny design in firewall rules, application roles and cloud IAM policies; Separation of request, approval and administration functions in the access management workflow
Where camera lists usually fall short: The access control policy exists but is not reflected in actual system configurations; Default-allow rules persist in network or cloud environments; Non-human entities such as service accounts are left outside the access rules; Access rights are not aligned with classification, so sensitive data is broadly accessible
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026
ISO/IEC 27001 A.7.4Physical security monitoring

Physical security monitoring. Premises are to be watched continuously for unauthorized physical entry. Purpose (stated in ISO/IEC 27002:2022): detects and deters unauthorized physical access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 7.4.

What a reviewer asks to see: Statement of Applicability entry for control A.7.4, showing inclusion or justified exclusion, implementation status and the risks it treats; Coverage plans for CCTV and intruder detection over sensitive areas, external doors, accessible windows and unoccupied zones; Alarm and detector installation certificates to applicable standards and periodic test records, including battery-powered components; Monitoring logs or monitoring-provider reports showing alarms raised and responses; Access restrictions and hardening of CCTV and alarm systems, including protection of video feeds and remote management
Where camera lists usually fall short: CCTV records but nobody reviews footage or responds to alerts; Detectors are installed but never tested, with flat batteries unnoticed; Video systems are exposed on the network with default credentials; Video is retained longer than local law permits
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026
ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)

Privacy and protection of personal identifiable information (PII). The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.

What a reviewer asks to see: Statement of Applicability entry for control A.5.34, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific privacy and PII protection policy and its communication to relevant parties; Privacy procedures communicated to everyone who processes PII; Appointment of a privacy officer or equivalent with documented responsibilities; A record of processing or PII inventory mapping which laws apply to each processing activity
Where camera lists usually fall short: Privacy is treated as a legal matter only, with no link to security controls; No one is formally responsible for guiding staff and providers on PII handling; Cross-border transfers of PII occur without checking applicable restrictions; Privacy impact assessments are not performed for new processing
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026

GDPR (the EU General Data Protection Regulation)

GDPR Art. 32Security of processing

Security of processing. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.

What a reviewer asks to see: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome; The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out; Evidence the measures were reassessed after material change in processing, technology or threat
Where camera lists usually fall short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures; Backups taken and never restore tested, so the ability to restore in a timely manner is assumed rather than demonstrated; Article 32(1)(d) treated as satisfied by an annual perimeter penetration test, with the organisational measures never evaluated at all; Encryption stated as in place while key management, backup copies and third party copies sit outside its scope
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 32Security of processing

Article 32 Security of processing. Controllers and processors must implement technical and organisational measures ensuring security appropriate to the risk, taking into account the state of the art, costs, the nature and purposes of processing and the risks, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely way after an incident, and a process for regularly testing, assessing and evaluating the measures. The assessment must weigh the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Codes or certification may help demonstrate compliance, and anyone acting under the controller's or processor's authority must process data only on instructions.

What a reviewer asks to see: Risk assessment underpinning the chosen security measures; Encryption, access control, backup and restore evidence; Security testing and control effectiveness reviews
Where camera lists usually fall short: No periodic testing of controls; Restore capability never tested; Encryption absent on portable devices or data in transit
Source: UK GDPR, read 29 Sep 2026

Australian Privacy Principles (APPs)

APP APP 11Security of personal information

APP 11 - Security of personal information. Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.

What a reviewer asks to see: Information security controls for personal information; Destruction/de-identification of redundant PI
Where camera lists usually fall short: PI not secured; Redundant PI retained
Source: Australian Privacy Principles (APPs), read 29 Sep 2026

See the specimen list run Map your own list