Trelowen Mor ltd has identified the need to undertake a Data Protection Impact Assessment with regard to the installation of CCTV in order to balance the need to meet its required licensing objectives and improve security and safety whilst also protecting the privacy of its staff and customers.
This Impact Assessment sets out the proposed system and its purpose then identifies potential problems and risks and how the company will mitigate them.
What are the purposes for operating the CCTV system?
What is the problem that the Company is seeking to address? Why is CCTV the best solution? Why can the matter not be addressed by way of less intrusive means?
The key purpose for the CCTV is to provide a safe and secure environment for staff and customers; and in particular this means the:
– Prevention and Reduction of crime & disorder especially with regard to theft and burglary or potential anti-social behaviour including but not limited to harassment, intimidation or violence
– Prevention and Reduction of damage and loss to the business, building & assets
– Resolution/Investigation of complaints.
CCTV acts firstly as a deterrent against potential illegal behaviour, additionally captured images assist the police in identifying offenders and securing convictions.
Specific Relevance: 25 Nov 2025
- Break-Ins over the last 18 months. Investigating police officers felt that they had insufficient evidence to progress
- Alcohol licensing police officer made explicit request (25 Sept 25) as part of the routine Licensing Review that we move in line with town centre policy
What personal data will be processed?
The CCTV captures visual recordings of individuals. These images are stored for a set period could be used to identify individuals and to give evidence of their actions at specific times if an incident requires investigation or to identify a specific health and safety or security risk
Who will be captured on CCTV?
CCTV will capture staff, suppliers and other business partners who come to the premises, customers and any other members of the public who access the premises authorised or otherwise.
What sharing with third parties, including processors is expected?
Images may be shared with law enforcement according to legal obligations or to emergency services for vital interests.
Additionally it may be shared with other specific third parties as a legitimate interest in the event of handling a complaint, grievance or insurance claim; for example, legal advisors, HR consultants, financial or fraud investigation authorities and regulatory authorities; or with other persons to whom we have a legal obligation to share data.
What is the lawful basis for operating the CCTV system?
It is in the legitimate interest of the business to provide an environment that is safe to work and relax in both for the wellbeing of staff and customers and to provide a space that people want to socialise in.
Who is/are the named person(s) responsible for the operation of the system?
The system is maintained, operated and primarily accessed by the person who is also the company Data Protection Officer.
This is currently:
Cara Sheldrake
Contact by email: castletap@gmail.com
What are the risks to the rights and freedoms of individuals who may be captured on the CCTV recordings?
The Castle Tap is a venue primarily designed for socialising and as such people may reveal or discuss personal information about themselves including that which falls into a “special category” such as political opinions, religious affiliation, trade union membership, health, sexual identity or sex life. Customers should additionally have an expectation that their private interactions are not unnecessarily tracked or recorded for marketing or any other purpose.
This is especially true for people who may be vulnerable or marginalised. Customers and Staff in The Castle Tap include people from the LGBTQ+ community who may not be safe to disclose their identity outside of the premises. Additional people who may need extra consideration include where customers may bring their children with them and local community groups including political and Trade Union groups booking meetings and socials.
Since the primary purpose of the CCTV is to promote safety and security staff have a reasonable expectation that they not be routinely monitored and that footage used for investigating disciplinary matters is managed according to appropriate procedures.
What measures are in place to address the risks identified?
Key mitigations for the risks are built into the set-up of the system. This means, for example: careful consideration of the siting of cameras and built-in digital screens to make sure they are appropriate but do not go beyond scope, plus disabling audio recording to protect privacy and prevent accidentally capturing special category data.
By reducing the facility to record special category data we not only minimise the amount of data processing we are doing but we are also reducing risks in the event of a data breach.
Furthermore the system is password protected, will not be normally connected to a screen and recording will not be routinely monitored but will instead only be accessed to investigate specific incidents as set out in the purposes and for periodically checking the system operation is appropriate and up to date. This means that the data is only accessible to authorised and trained individuals within the scope of the purposes.
Access requests must be approved and managed by a trained and authorised person to allow assessment of whether recordings contain any personal data not relevant to the request which should be protected and for suitable steps to be taken to mitigate that – this includes where recordings may need to be made available to a third party.
Describe the CCTV system
The system is a Reolink- RLK8-520D4-5MP. It has cameras which have a high resolution of 2560×1920 with nearly 5MP and embedded infrared LEDs and advanced IR technology for a 100ft night vision range. The cameras are mounted and in a fixed position and will record 24hrs not based on motion sensing. The cameras are linked by ethernet cable back to an 8 Channel NVR System with 1 TB storage which can be then additionally connected to a screen. Wireless capabilities are switched off. The system is password protected.
- Reasons for Technical Specifications:
- Images:
Cameras allow identification of individuals both in full light and in darker environments where necessary and ensure that clear images are produced so that they can be used for the purpose for which they are intended. Continuous rather than motion activated recording reduces likelihood of error and helps allow persons to be tracked from camera location to camera location. - Security:
Direct Ethernet with no connection over the internet helps prevent unauthorised remote access. Password, lock screens and requirement to bring screen, cables and device to transfer material help reduce ease of on-site unauthorised access. Plenty of storage means no need for regular transfer of recordings or cloud storage which also reduces that likelihood.
b. Siting of Cameras and Reasons:
Cameras cover main areas for anyone attempting unauthorised access to the premises (including alley and roof), the access around main money & stock holding spaces and additionally covers public seating areas where the majority of public interactions will take place, including where appropriate from more than one angle to help with identification and continuous monitoring.
· How cameras have been sited to avoid capturing images which are not necessary for the purposes of the CCTV system;
Cameras are not situated in areas where customers and staff may have an expectation of privacy such as toilets or staff changing areas or in communal staff areas such as social or food preparation spaces.
Additionally the system allows for digital privacy screens to be added which are used to prevent recording of neighbouring properties
c. Where signs notifying individuals that CCTV is in operation are located and why those locations were chosen;
Signs for customers are located at all entry doors and at the bottom of the garden and on main event notice boards as well as on the website, additionally there is a reminder for staff in the main kitchen area. This is aimed at making people aware of the system when they choose to enter the premises and reminding staff about their position on a daily basis.
d. Third Parties – Safety & Security Mitigations
In the event of a serious incident on the premises, for example a break-in or an assault, staff and management will know either during or immediately after the fact and should notify the DPO as soon as possible so that the appropriate footage can be obtained and put in a suitable format for law enforcement investigation.
Where a member of staff or customer has reported an incident for investigation or the police have requested information to aid with enquiries the investigating member of staff and complainants should work with the DPO to allow them to assess which individuals are key to the events and which should have their data excluded and/or to ascertain if it is appropriate to request consent. This should be done before any decision is made by the member of staff responsible for the investigation makes a decision about whether it will be referred to a relevant third party (e.g. law enforcement, independent HR consultant, health & safety regulator). It should be noted that this is subtly different from a Subject Data Access request and therefore has its own process.
No third party should be given access to data beyond the scope of their contracted role or lawful requirements – for example recordings for extra dates or where possible involving people not relevant to the circumstances – for this reason relevant recordings should be downloaded onto a password protected hard drive to be transferred to a third party.
Where possible transfer of recordings to third parties over the internet should be avoided but may be done using a suitable secure platform using authentication and password protection. If data is sent to a third party by post a recognised carrier with recorded delivery must be used. In person handover is to be preferred.
e. Storage, Retention period of recordings & Security
As the purpose of the CCTV is to act as a deterrent and aid in investigations the normal retention period only needs to be sufficient to allow people a reasonable length of time to let us know they want something investigated – this notification period is currently set at 14 days. Where recordings are to be used for their specified purpose they should be copied and stored separately and they will kept during the investigation and only as long as appropriate records need to be kept. Please refer to Complaints & Grievance and Disciplinary policies for further information on those records.
The hard drive associated with the NVR system is additionally set to auto-rewrite over the top of existing data once it is full and this digital fail safe helps to minimise the amount of data being processed by creating an upper limit.
Except where appropriate copies are made recordings are stored only on the password protected hard drive integrated with the NVR. Where copies are made individual files should be password protected and stored on smaller hard drives with the appropriate associated materials according to Information Security policy.
Consultation
Due to the purposes for installing the CCTV and the time frames set out by TVP the system has only undergone a brief consultation period with staff. Although no issues beyond those covered in the mitigations were raised by staff a further opportunity for feedback should be given before this impact assessment and associated policies are reviewed.
An opportunity for feedback from members of the public will be provided on the website
Review
This impact assessment is due for review in One Year.