CCTV Privacy Law Mapper
Finding 8 of 18

A third party can view or manage the footage, and no agreement is recorded

A monitoring company, a vendor cloud, a landlord or another group company that views or holds your footage is not a processor by default. It may be a processor (GDPR and UK GDPR Art. 28: a written contract with set terms), a joint controller (Art. 26: an arrangement allocating responsibilities), an independent controller or a recipient. The CCPA asks for a written contract with a service provider or contractor; for face matching in Illinois, BIPA 15(d) treats handing biometric data to a vendor as a disclosure that needs consent.

When it is raised
Raised when who can view names a vendor, monitoring or security company, landlord, integrator or other entity, or the footage is stored in a vendor cloud, and the processor terms column is blank or no.
The question
What is this party's role (processor, joint controller, independent controller or recipient), and which agreement governs it?
For
your privacy lead
The column that settles it
processor terms
On the row
a numbered delta and the words "third party role" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 28Processor

Processor. Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

What a reviewer asks to see: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
Where camera lists usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits; Sufficient guarantees evidenced only by the existence of the contract, with no assessment carried out before appointment; Sub-processor lists published by the processor and never actually reviewed, so the right to object is theoretical
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 26Joint controllers

Joint controllers. Where two or more controllers jointly determine the purposes and means of processing, determine their respective responsibilities for compliance in a transparent manner by an arrangement between them, unless those responsibilities are already determined by Union or Member State law, covering in particular the exercise of the data subject's rights and each party's duty to provide the Article 13 and 14 information. The arrangement may designate a contact point for data subjects. It must duly reflect the parties' respective roles and relationships towards data subjects, and its essence must be made available to the data subject. Irrespective of the terms of the arrangement, a data subject may exercise their rights in respect of and against each of the controllers.

What a reviewer asks to see: The joint controllership assessment identifying every relationship where purposes and means are jointly determined; The Article 26 arrangement for each, allocating responsibility for rights handling, transparency, security and breach response; The essence of the arrangement as published or otherwise made available to data subjects; Evidence the allocation reflects the real roles, such as which party holds the data and which faces the data subject; The operating process showing a rights request is honoured whichever joint controller receives it
Where camera lists usually fall short: A controller to processor agreement used where the relationship is in substance joint controllership; An arrangement signed but its essence never made available to data subjects, which is a separate obligation; Rights requests passed back and forth between joint controllers, when the data subject may exercise them against either; The allocation written to suit the commercial balance of power rather than the actual roles towards data subjects
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 28Processor

Article 28 Processor. A controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.

What a reviewer asks to see: Article 28 compliant processing agreements for every processor; Sub-processor list with authorisation and change notices; Processor due diligence and audit records
Where camera lists usually fall short: Processors engaged on standard terms lacking the Article 28(3) clauses; Sub-processors added without notice; No evidence data were deleted or returned at contract end
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 26Joint controllers

Article 26 Joint controllers. Joint controllers must determine their respective responsibilities, in particular for data subject rights and the information duties, by an arrangement that reflects their roles and relationships, may designate a contact point, and must make the essence of the arrangement available to data subjects, who may exercise their rights against each of them.

What a reviewer asks to see: Joint controller arrangement allocating responsibilities; Published summary of the arrangement
Where camera lists usually fall short: Joint control unrecognised, so no arrangement exists; Arrangement silent on who answers rights requests
Source: UK GDPR, read 29 Sep 2026

California Consumer Privacy Act (CCPA, as amended by the CPRA)

CCPA s. 1798.100(d)Contractual Requirements for Third Parties, Service Providers, and Contractors

Contractual Requirements for Third Parties, Service Providers, and Contractors. A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.

What a reviewer asks to see: Service provider/contractor agreements containing all required CCPA clauses; Third party data sharing agreements; Vendor inventory classifying each recipient (service provider, contractor, third party); Audit/inspection records; Subcontractor flow-down clauses
Where camera lists usually fall short: Legacy vendor contracts missing CPRA-required clauses; No classification of recipient role; No audit rights exercised; Combining-data prohibitions absent
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

Illinois Biometric Information Privacy Act (BIPA)

BIPA s. 15(d)No disclosure, redisclosure or dissemination except on four grounds

No disclosure, redisclosure or dissemination except on four grounds. No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.

What a reviewer asks to see: Register of every recipient of biometric data (vendors, processors, affiliates, cloud services) with the ground for each disclosure; Consents covering disclosure to named recipients; Legal, warrant or subpoena records for compelled disclosures
Where camera lists usually fall short: Templates sent to a timekeeping or access-control vendor with consent covering collection only; Sharing between affiliates treated as internal; No record of who has received biometric data
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026

See the specimen list run Map your own list