Need a taxi instead? Visit Green Metro Cars for local journeys, airport transfers and private hire.

Take Me to Green Metro Cars

Vehicle CCTV Data Policy

Hire a Coach for Your Next Ride. Travel Comfortably with Our Local Experts.

  1. Purpose

This policy sets out the arrangements for the use of Closed-Circuit Television (CCTV) systems installed in company vehicles. The purpose of the system is to protect the safety and welfare of passengers, employees and members of the public, safeguard vulnerable individuals, assist in the investigation of incidents, deter criminal or inappropriate behaviour, protect company property, and provide evidence where required.

The organisation is committed to ensuring that CCTV is operated lawfully, fairly, transparently and in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and relevant guidance issued by the Information Commissioner’s Office (ICO).

  1. Scope

This policy applies to:

  • All vehicles fitted with CCTV
  • All employees, contractors and agency
  • Passengers using company
  • Any individual whose personal data may be captured by the CCTV

  1. Purpose of CCTV

Vehicle CCTV is installed to:

  • Protect passengers, particularly children and vulnerable
  • Promote the safety and wellbeing of drivers and passenger
  • Deter violence, abuse, criminal damage and anti-social
  • Assist with safeguarding
  • Investigate accidents, complaints or
  • Protect company assets and
  • Support insurance
  • Assist law enforcement and regulatory authorities where
  • Improve service quality and operational

CCTV will not be used for routine monitoring of staff performance unless footage is required as part of an investigation into a specific incident or allegation.


  1. Legal Basis

The processing of personal data through vehicle CCTV is carried out in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Human Rights Act 1998 (where applicable) The lawful basis relied upon is:
  • UK GDPR Article 6(1)(f) – Legitimate Interests

Where transport is provided under statutory duties or public service contracts, processing may also be justified under:

  • Article 6(1)(e) – Public Task (where applicable)

Where CCTV may incidentally capture information relating to health or safeguarding concerns, such information will only be processed where permitted under the Data Protection Act 2018 and UK GDPR.

The organisation has completed a Data Protection Impact Assessment (DPIA) before implementation of vehicle CCTV. The DPIA will be reviewed whenever there are significant changes to the system or its operation.


  1. Vehicles Covered

CCTV may be installed in all company vehicles where the organisation considers it necessary following assessment of operational and safeguarding requirements.

This includes any vehicle used for transporting passengers under company services.

  1. Coverage

The CCTV system may record:

  • Internal passenger seating
  • Driver
  • Vehicle entrance and exit
  • Immediate external views where cameras are fitted for safety or security

The system records:

  • Video

Audio recording will not be enabled.

If audio recording is introduced in future, the organisation will undertake a further DPIA and update this policy before implementation.


  1. Signage

Clear signage will be displayed:

  • On the exterior entrance doors where
  • Inside every CCTV-equipped vehicle in locations visible to passengers before boarding or immediately upon entry.

Signage will inform individuals that:

  • CCTV is in
  • The purpose of
  • The organisation responsible for the
  • How further information can be

Privacy information will also be available through the organisation’s Privacy Notice.


  1. Access to Footage

Access to CCTV footage is strictly controlled.

Authorised persons include:

  • Managing Director (or equivalent)
  • Operations Manager
  • Safeguarding Lead
  • Data Protection Lead / Data Protection Officer (where appointed)
  • Senior Managers authorised by the organisation
  • Designated IT or CCTV system administrator (for maintenance purposes only) Footage may only be viewed where there is a legitimate business need, including:
  • Investigation of safeguarding
  • Road traffic
  • Passenger
  • Employee
  • Health and Safety
  • Criminal
  • Insurance
  • Subject Access
  • Requests from law enforcement or regulatory Drivers will not have routine access to recorded footage.

Every access to footage will be logged, including:

  • Date and
  • Person
  • Reason for
  • Footage
  • Any copies
  • Any disclosures

Periodic audits of access logs will be undertaken by the Data Protection Lead or nominated manager.


  1. Retention and Deletion

Routine CCTV footage will normally be retained for 31 days.

Where footage is required for an investigation, legal proceedings, safeguarding enquiry, insurance claim or Subject Access Request, it will be retained only for as long as necessary for that purpose.

At the end of the retention period:

  • Footage will be automatically overwritten or securely
  • Any exported copies will be securely destroyed when no longer
  • Disposal methods will ensure footage cannot be

  1. Disclosure of Footage

Footage may be disclosed where lawful and necessary to:

  •  
  • Courts or
  • Local Authority safeguarding
  • Local Authority transport
  • Schools or educational establishments where relevant to safeguarding or behavioural investigations.
  • Insurance
  • Legal
  • Regulatory authorities exercising statutory

Requests will be assessed individually to ensure disclosure is lawful, proportionate and documented.

Footage will never be shared for personal reasons or with unauthorised individuals.


  1. Information Security

The organisation will implement appropriate technical and organisational security measures.

These include:

  • Encrypted recording systems where
  • Password-protected
  • Role-based
  • Secure storage of
  • Restricted export
  • Secure transfer methods for authorised
  • Audit logging of system
  • Regular password
  • Secure deletion

Drivers and unauthorised staff cannot routinely access recordings.

Portable storage devices containing footage will only be used where necessary and must be encrypted.


  1. Subject Access Requests

Individuals whose personal data has been captured by CCTV may request access to footage of themselves.

Requests should be submitted in writing to the organisation’s Data Protection Lead.

The organisation may request sufficient information to:

  • Verify
  • Identify the relevant
  • Confirm the date and approximate
  • Locate the relevant

Responses will normally be provided within one calendar month, subject to applicable legal exemptions and consideration of the rights of third parties.

Where footage contains images of other identifiable individuals, appropriate redaction may be applied where reasonably practicable.


  1. Complaints

Anyone with concerns regarding the operation of vehicle CCTV may submit a complaint

using the organisation’s complaints procedure.

Complaints may relate to:

  • Privacy
  • Inappropriate
  • Misuse of
  • Excessive
  • Failure to comply with this

Complaints will be investigated promptly by the Data Protection Lead and/or senior management.

Individuals also have the right to complain to the Information Commissioner’s Office if

they believe their personal data has been handled unlawfully.


  1. Incident Review Process

CCTV footage may be reviewed following any reported incident. Examples include:

  • Road traffic
  • Near
  • Passenger
  • Allegations of abuse or
  • Safeguarding
  • Assaults or threatening
  • Criminal
  • Complaints made by passengers, parents, schools or members of the
  • Damage to company
  • Health and Safety Where an incident is reported:
  1. The relevant manager will secure the
  2. Access will be
  3. Footage will be reviewed by authorised personnel
  4. Relevant extracts may be
  5. Appropriate action will be
  6. Any disclosures will be

  1. Staff Responsibilities Employees must:
    • Comply with this
    • Maintain
    • Report suspected
    • Cooperate with
    • Not attempt to access or copy footage without

Unauthorised access or disclosure may result in disciplinary action and may constitute a criminal offence.


  1. Training

Employees with responsibility for CCTV will receive appropriate training covering:

  • UK
  • Data Protection Act
  •  
  • Information
  • Safeguarding
  • Appropriate use of
  • Subject Access
  • Incident
  • Secure disclosure
  • Records

Training will be provided before access is granted and refreshed periodically.


  1. Equipment Maintenance

The organisation will ensure CCTV equipment is regularly maintained and tested. Where faults are identified:

  • The fault will be reported
  • Repairs will be arranged as soon as reasonably
  • Where required by contract or service agreement, the relevant Local Authority or commissioning body will be informed if CCTV is unavailable for a significant
  • Maintenance records will be Routine checks will confirm:
  • Cameras are
  • Recording functions
  • Date and time settings are
  • Storage capacity is
  • Signage remains in

  1. Recording Standards Vehicle CCTV should:
    • Automatically record while the vehicle ignition is on or otherwise configured for operational use.
    • Record accurate date and time
  • Produce recordings of sufficient quality for evidential purposes where reasonably
  • Prevent unauthorised alteration of
  • Be maintained in accordance with manufacturer

  1. Monitoring Compliance

Compliance with this policy will be monitored through:

  • Regular access
  • Periodic review of access
  • Internal data protection
  • Review of
  • Review following any significant

  1. Policy Review

This policy will be reviewed annually, or sooner where required due to:

  • Changes in
  • Changes to CCTV
  • Changes to operational
  • Recommendations following incidents or

The review will be undertaken by the Managing Director together with the Data Protection Lead and Safeguarding Lead.


Document Control

Policy Owner: Managing Director Responsible Officer: Data Protection Lead Approved By: Senior Management Version: 1.0

Effective Date: 03/07/2026

Review Date: 12 months from approval