Statement of Guidance

CCTV and Surveillance at Work and at Home

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a JOIC guidance note explaining how the Data Protection (Jersey) Law 2018 (DPJL 2018) applies to CCTV and other surveillance technologies, covering both business/organisational use and home use (including doorbell cameras). It does not cover covert surveillance or law-enforcement processing under Schedule 1 of the DPJL 2018.

  • Scope of surveillance systems: Covers CCTV, ANPR, body-worn video, drones, facial recognition technology (FRT), dashcams, smart doorbells, workplace monitoring, livestreaming and AI-enabled analytics.
  • Before installing: Organisations must identify a clear purpose and lawful basis, assess proportionality, decide retention periods and security measures before deploying any system.
  • Location restrictions: Cameras should not cover private areas such as toilets or changing rooms except in exceptional, well-justified circumstances with clear signage.
  • Registration and records: Organisations processing identifiable individuals' data via surveillance must register with JOIC (paying a fee unless exempt) and, where applicable under Art.14(3) DPJL 2018, keep records of processing activities.
  • DPIAs: A Data Protection Impact Assessment is required before deployment, and mandatory where processing is likely high-risk (e.g. special category data, large-scale public monitoring, workplace monitoring, or any use of FRT/biometric or AI analytics tools). If residual high risk cannot be mitigated, the organisation must consult JOIC before starting processing.
  • FRT and biometric systems: Treated as inherently high-risk; DPIA must show necessity, proportionality, accuracy and bias evaluation, and processing may not begin until any required JOIC consultation is concluded.
  • Analytics/AI cameras: Must be risk-assessed like other high-risk processing, with DPIAs updated and human review required before any automated alert leads to a decision affecting an individual.
  • Home CCTV: The DPJL 2018 applies only if a home camera captures images beyond the user's own property boundary (e.g. neighbours' land, communal areas, public space); users in that position must have a clear reason, avoid excessive capture, give notice (signage), respond to subject access requests, delete footage regularly, and stop recording an individual who objects unless there is a legitimate reason to continue.

The guidance also sets out individuals' rights (subject access, erasure, objection) regarding footage in which they appear, and recommends informal resolution, mediation or police involvement for neighbour disputes, reserving JOIC enforcement for cases where a home user qualifies as a data controller and formal action is warranted.

Key obligations

  • Organisations must have a clear, documented purpose and identified lawful basis (Schedule 2 DPJL 2018) before installing any CCTV or surveillance system.
  • Organisations processing identifiable individuals' personal data via surveillance must register with JOIC, including paying a fee unless exempt.
  • Controllers and processors covered by Art.14(3) DPJL 2018 must keep a record of surveillance-related processing activities (controller details, purpose, categories of data/subjects, recipients, international transfers, retention, and security measures).
  • Organisations must be transparent with individuals about surveillance (e.g. via policies or signage) and must not place cameras in private areas like toilets/changing rooms without strong exceptional justification.
  • A Data Protection Impact Assessment must be carried out before deploying a surveillance system, and is mandatory for high-risk processing (special category data, large-scale public monitoring, workplace monitoring, FRT/biometric systems, or AI-based analytics).
  • Where a DPIA identifies high risks that cannot be mitigated, the organisation must consult JOIC and may not begin processing until the consultation concludes (mandatory for FRT/biometric deployments).
  • Facial recognition/biometric systems require robust access controls, audit logs, minimal retention (near-immediate deletion of biometric data absent a verified match), and must not be repurposed or linked to other databases without a lawful basis and transparency.
  • Automated alerts generated by camera analytics must be reviewed by a human before any decision affecting an individual is made.
  • Home CCTV users whose cameras capture beyond their property boundary must have a clear reason for recording, avoid capturing more than necessary, display signage, provide footage on request (subject access), delete footage regularly, and stop recording an individual who objects unless a legitimate reason justifies continuing.

Applies to

businesses and organisations (public and private sector) using CCTV or surveillance systems, data controllers and processors, home CCTV/doorbell camera users and homeowners

Topics

Version history

2026-07-30

source file (current)