Need a taxi instead? Visit Green Metro Cars for local journeys, airport transfers and private hire.
Hire a Coach for Your Next Ride. Travel Comfortably with Our Local Experts.
This policy sets out the arrangements for the use of Closed-Circuit Television (CCTV) systems installed in company vehicles. The purpose of the system is to protect the safety and welfare of passengers, employees and members of the public, safeguard vulnerable individuals, assist in the investigation of incidents, deter criminal or inappropriate behaviour, protect company property, and provide evidence where required.
The organisation is committed to ensuring that CCTV is operated lawfully, fairly, transparently and in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and relevant guidance issued by the Information Commissioner’s Office (ICO).
This policy applies to:
Vehicle CCTV is installed to:
CCTV will not be used for routine monitoring of staff performance unless footage is required as part of an investigation into a specific incident or allegation.
The processing of personal data through vehicle CCTV is carried out in accordance with:
Where transport is provided under statutory duties or public service contracts, processing may also be justified under:
Where CCTV may incidentally capture information relating to health or safeguarding concerns, such information will only be processed where permitted under the Data Protection Act 2018 and UK GDPR.
The organisation has completed a Data Protection Impact Assessment (DPIA) before implementation of vehicle CCTV. The DPIA will be reviewed whenever there are significant changes to the system or its operation.
CCTV may be installed in all company vehicles where the organisation considers it necessary following assessment of operational and safeguarding requirements.
This includes any vehicle used for transporting passengers under company services.
The CCTV system may record:
The system records:
Audio recording will not be enabled.
If audio recording is introduced in future, the organisation will undertake a further DPIA and update this policy before implementation.
Clear signage will be displayed:
Signage will inform individuals that:
Privacy information will also be available through the organisation’s Privacy Notice.
Access to CCTV footage is strictly controlled.
Authorised persons include:
Every access to footage will be logged, including:
Periodic audits of access logs will be undertaken by the Data Protection Lead or nominated manager.
Routine CCTV footage will normally be retained for 31 days.
Where footage is required for an investigation, legal proceedings, safeguarding enquiry, insurance claim or Subject Access Request, it will be retained only for as long as necessary for that purpose.
At the end of the retention period:
Footage may be disclosed where lawful and necessary to:
Requests will be assessed individually to ensure disclosure is lawful, proportionate and documented.
Footage will never be shared for personal reasons or with unauthorised individuals.
The organisation will implement appropriate technical and organisational security measures.
These include:
Drivers and unauthorised staff cannot routinely access recordings.
Portable storage devices containing footage will only be used where necessary and must be encrypted.
Individuals whose personal data has been captured by CCTV may request access to footage of themselves.
Requests should be submitted in writing to the organisation’s Data Protection Lead.
The organisation may request sufficient information to:
Responses will normally be provided within one calendar month, subject to applicable legal exemptions and consideration of the rights of third parties.
Where footage contains images of other identifiable individuals, appropriate redaction may be applied where reasonably practicable.
Anyone with concerns regarding the operation of vehicle CCTV may submit a complaint
using the organisation’s complaints procedure.
Complaints may relate to:
Complaints will be investigated promptly by the Data Protection Lead and/or senior management.
Individuals also have the right to complain to the Information Commissioner’s Office if
they believe their personal data has been handled unlawfully.
CCTV footage may be reviewed following any reported incident. Examples include:
Unauthorised access or disclosure may result in disciplinary action and may constitute a criminal offence.
Employees with responsibility for CCTV will receive appropriate training covering:
Training will be provided before access is granted and refreshed periodically.
The organisation will ensure CCTV equipment is regularly maintained and tested. Where faults are identified:
Compliance with this policy will be monitored through:
This policy will be reviewed annually, or sooner where required due to:
The review will be undertaken by the Managing Director together with the Data Protection Lead and Safeguarding Lead.
Document Control
Policy Owner: Managing Director Responsible Officer: Data Protection Lead Approved By: Senior Management Version: 1.0
Effective Date: 03/07/2026
Review Date: 12 months from approval