PONOPT FIELD NOTES · Privacy и governance

Who Viewed the Footage? Access Controls, Audit Logs and Periodic Review

Who may open recorded camera footage, what a dependable audit log should capture, and how often to review access — a practical governance checklist for surveillance operators.

Let only named staff with a documented need open live or archived video, each on a unique least-privilege, role-based account that is never shared. Record every view, search, export and permission change in a tamper-evident audit log, and review that log on a fixed schedule — for example monthly spot checks and an annual governance report. These three controls, access, logs and review, are what regulators from New Zealand's Privacy Commissioner to the UK's ICO expect an accountable operator to demonstrate.

Key takeaways

  • Access follows least privilege and need-to-know: unique named accounts per person, scoped to specific cameras, functions and time windows, with no shared logins.
  • Audit logs should capture not just logins but live viewing, archive searches and exports, plus permission changes and failed attempts, in a tamper-evident system.
  • Logs only protect you if they are actually read on schedule — monthly spot checks and an annual governance report, with anomalies investigated promptly.
  • Manage the full user lifecycle: revoke access immediately on role change or departure and re-certify entitlements periodically.
  • Exports and external disclosures need separate logging with basis, approval, redaction of third parties and chain-of-custody fields.
  • Requirements vary by jurisdiction; this is general information, not legal advice for any specific country.

Why knowing who opened the footage matters

Recorded video almost always contains personal data — people in the frame can be identified. That is why regulators across jurisdictions, from the EU's GDPR and the UK's ICO to New Zealand's Privacy Commissioner, reason from the same starting point: access to recordings must be justified and traceable. The operative question is not who formally has a right, but who actually opened the archive, what they searched, what they exported and on what basis.

Without that record an organisation can neither demonstrate lawful processing, respond to a complaint or an access request, nor notice misuse early. Guidance documents therefore keep returning to the same chain: the purpose of the cameras, who manages the system, who may view footage, how access is controlled, and how long video is kept. This is a governance principle that exists independently of any single regulation.

The practical consequence is that access control, audit logging and review operate as one circuit. Well-configured permissions protect little if nobody reads the logs, and careful log review cannot save you if entitlements were handed out too broadly.

  • Name the roles that genuinely need viewing: security, HR during an incident investigation, the system owner, maintenance staff.
  • State in policy that casual or curiosity-driven viewing is prohibited even where technically possible.

Access: named accounts and least privilege

The foundation of control is least privilege. Access is granted not by job title in general but for a concrete task: one person needs live view of their own cameras, another needs archive search, a third needs export. Rights over cameras, functions and time windows are assigned separately rather than as one blanket administrator package for everyone.

Every person should have a unique, named account with multi-factor authentication where the platform supports it. Shared logins destroy the entire chain of evidence because the log can no longer tell you who acted. Granting rights should be reserved to an authorised administrator, and the act of granting or changing rights should itself be recorded in a separate log.

Access is tied to the employee lifecycle: on transfer to another role, permissions are revisited; on departure they are revoked immediately rather than at the end of the month. Periodically entitlements are re-certified — for example quarterly or annually a manager confirms who keeps access and why.

One nuance is that limits also apply to technical accounts. Maintenance contractors may receive access only for the duration of the work and under supervision, a point that large operators set out explicitly in their own regulations.

  • Issue rights from a matrix of camera plus function plus time, never global VMS access.
  • Every account has an owner; service and temporary access expires automatically.

What a dependable audit log captures

A useful audit log records, per camera and across the system: who (the account identifier), when (precise time), what (live view, archive search, opening a specific clip, export, download), from which device or address, and with what result. To these are added permission changes, user additions and removals, and failed logins.

Exports and transfers of footage are recorded separately with extra fields: the basis (an event, incident or case number), who approved it, to whom it was sent, and a file name or hash for integrity checks. This level of detail lets an operator reconstruct the chain if a recording is later disputed.

The log must be protected from retrospective alteration: the right to read logs is separated from the right to administer cameras, and the actions of system administrators are logged too. Retention of logs is set by policy and law — university-grade regulations, for instance, commonly keep access and export logs for at least one year.

  • Record the outcome of each action: successful login, denial, or an error when opening a file.
  • Keep the log append-only so ordinary users and camera administrators cannot silently edit it.

Reviewing the logs on a schedule

A log earns its keep only when it is read. A sensible model is layered: operational checks at the control-room level, regular sample reviews (say monthly), and an annual summary report to leadership covering volumes of requests and exports, the number of exceptions, and improvement actions. This structure appears in the regulations of large operators, and its logic transfers to almost any system.

During a review you look for: whether every login and view matches a documented need, whether access still belongs to people who use the system or who have left, whether any export happened without approval, and whether any disclosure went unlogged. Each anomaly is chased immediately — the account owner is asked to explain and the resolution is recorded.

Cadence scales with risk: sensitive zones warrant more frequent checks, lightly trafficked areas can run less often. The important thing is that review is assigned, documented and owned by named individuals rather than left to 'we will look when something happens'.

  • Designate who reviews the logs and write down the frequency.
  • Retain review results and a register of anomalies found and closed.

Disclosure, exports and people asking for their own footage

Alongside internal control sit external requests: police, insurers, and individuals asking for recordings in which they appear. In some jurisdictions the right of a person to obtain footage of themselves is statutory — in New Zealand, for example, Privacy Act principle 6 obliges an agency to respond, and deleting footage after a request is made can be an offence.

When releasing clips to third parties the rule is minimum and relevant: first preserve the clip so auto-overwrite cannot erase it, verify the requester actually appears, and edit the video to hide other people by cropping or blurring. Refusing outright simply because third parties are present is treated in many jurisdictions as too rigid and unlawful.

Every external release is logged: who asked, on what authority, what was provided, to whom, in what form, and when. Files travel through protected channels and copies or viewings are provided only to the authorised person after approval.

  • On receiving a request about someone's own footage, immediately suspend auto-deletion of the clip.
  • Keep a disclosure log that is distinct from the internal viewing log.

Common failure points and the limits of control

Systems most often fail on the mundane: a shared password at the monitor station, contractor administrator access with no expiry, logs that nobody reads, and exports made without recording a basis. A second recurring mistake is storing logs for less time than an investigation needs, or inside the same system the camera administrator can edit.

It is worth being clear about limits. Access control does not prove a person should have seen a frame — it shows what happened and lets you ask the question. Legal requirements differ by country, and this article is general information rather than legal advice for any specific jurisdiction.

Finally, there are technical constraints: some actions may not be logged until the platform is configured, and editing of recordings should be done with tools that are not trivial to bypass. Where such functions are missing, plan for them at the next system upgrade.

  • Verify that logging is switched on for every action, including permission changes and exports.
  • Budget for the redaction capability (blurring) needed before footage can be given to third parties.

CCTV access, audit-log and periodic-review checklist

A ready-to-run checklist for a monthly or quarterly governance review of a video-surveillance system. Mark status per item, save results, and turn anything not yet done into an owned task with an owner and a deadline.

  1. Approved role list exists stating who genuinely needs live and recorded access, with reasons.
  2. Each person has a unique named account; no shared logins or blanket access for everyone.
  3. Permissions are least-privilege: specific cameras, functions (live/search/export) and time windows.
  4. Granting, changing and revoking rights is done only by an authorised administrator and logged.
  5. Access is revoked immediately on departure or role change; temporary and contractor access has an expiry.
  6. Audit logging is enabled for views, searches, exports, permission changes and failed logins.
  7. Logs are protected from editing and deletion; log-read rights are separated from camera administration.
  8. Log retention period is set in policy and meets legal expectations (for example at least one year).
  9. Regular scheduled log review is carried out; anomalies are investigated and documented.
  10. Periodic re-certification of rights confirms every access is still needed and owned.
  11. Exports and external disclosures are logged with basis, approval and a file identifier or hash.
  12. Procedure exists for individuals' requests for their own footage, covering preservation and redaction of third parties.

Questions people ask

Who should be allowed to view recorded CCTV footage?

Only named staff with a documented operational need: typically security and safety personnel, plus HR or management investigating a specific incident. Access follows least privilege — scoped to roles, particular cameras and functions — and is granted on unique named accounts rather than a shared login. Maintenance staff and contractors should receive access only for the duration of the work and under supervision.

How long should audit and access logs be kept?

The period is set by your own policy and applicable law; there is no single number. As a reference point, larger operators commonly retain access and export logs for at least one year so there is enough history for investigations and access requests. What matters more than the exact figure is that the period is written down, the log is protected from tampering, and a legal hold overrides normal deletion.

How often should CCTV access permissions be reviewed?

A common model is periodic re-certification — quarterly or annually — where a manager confirms who keeps access and why, complemented by immediate revocation when someone leaves or changes role. Frequency rises in sensitive areas and high-turnover teams. The key is that review is scheduled, documented and owned by a named person rather than performed once and forgotten.

What should we do when someone requests footage that shows both them and other people?

First preserve the clip so automatic overwriting cannot destroy it. Then verify the requester actually appears in the footage and aim to release an edited version: crop so only the requester remains, or blur the other people. In several jurisdictions, refusing solely because third parties appear is considered too rigid. Record every release in a separate disclosure log.

Do we need separate logs for viewing and for exporting footage?

Yes, that is best practice. Internal views and searches go into the general activity log, while exports and transfers carry extra fields: the basis (event or incident number), who approved, to whom the file went, and a filename or hash for integrity. Separating the two lets you reconstruct the chain of custody and respond if the authenticity of a recording is challenged.

What is the risk of never reviewing the audit logs?

If nobody reads the logs, misuse tends to surface only after an incident or complaint, when it is already hard to prove who viewed what. The organisation also cannot demonstrate to a regulator that it controls the personal data it processes. The presence of a log is not protection in itself — regular review, investigation of anomalies and documented results are what create accountability.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. Responding to access requests for CCTV footageOffice of the Privacy Commissioner (New Zealand)
  2. Security Camera ProceduresUniversity of Arizona Office of Public Safety
  3. CCTV and GDPR: What organisations get wrongDPO Centre
  4. CCTV checklistInformation Commissioner's Office (UK)