Form

Checklist Surveillance System Deployment Businesses Organisations

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a practical checklist published by the Jersey Office of the Information Commissioner (JOIC) to help businesses and organisations assess and manage CCTV and other surveillance systems for compliance with the Data Protection (Jersey) Law 2018. It is guidance rather than binding law, intended to be adapted to individual circumstances and not a substitute for formal legal advice.

  • Preliminary assessment: Document the purpose and lawful basis for surveillance, assess necessity and proportionality, carry out a DPIA for high-risk deployments, and assign a responsible person.
  • Design and procurement: Build in privacy by design (masking, encryption, limited resolution), display clear signage, put Data Processing Agreements in place with third parties, and control access.
  • Deployment and operation: Train staff, publish a surveillance policy and privacy notices, handle data subject rights requests within statutory timeframes, maintain a breach response policy (including notifying JOIC within 72 hours where required), and review the system annually.
  • Technology-specific measures: Additional steps for drones/UAVs, ANPR, body-worn video, and audio recording, such as CAA Jersey registration for drones and limiting ANPR capture to number plates.
  • Required documentation: Maintain a surveillance policy, DPIA, privacy notice, processor agreements, retention schedule, access log, breach/incident log, and annual review record.

The checklist is aimed at any business or organisation operating CCTV or similar surveillance technology, and reflects underlying obligations under Jersey's data protection law rather than creating new statutory duties itself.

Key obligations

  • Notify JOIC within 72 hours of a personal data breach where there is likely risk to individuals
  • Respond to subject access, erasure, objection, and restriction requests within statutory timeframes
  • Carry out and keep under review a Data Protection Impact Assessment for high-risk surveillance deployments
  • Provide clear and prominent signage and privacy notices for surveillance systems
  • Maintain required documentation including a surveillance policy, retention schedule, access log, and breach/incident log
  • Review surveillance systems annually and update DPIA/ROPA as required
  • Register drones/UAVs with CAA Jersey where used for surveillance

Applies to

businesses, organisations, data controllers operating CCTV or surveillance systems

Deadlines

  • within 72 hours: Notifying JOIC of a personal data breach where risk to individuals is likely
  • annually: Review of the surveillance system to reassess necessity, effectiveness, retention, and equipment

Topics

Version history

2026-07-30

source file (current)