How to find one individual across hours of CCTV for a DSAR
A Data Subject Access Request (DSAR) can become surprisingly difficult when the requested personal data exists inside hours of CCTV footage. Finding one individual may require reviewing multiple cameras, different time periods, changing angles, crowded scenes, and recordings that were never designed to be searched manually.
The challenge is not simply locating a face. Organizations must also determine which footage actually relates to the requester, avoid disclosing information about unrelated individuals, and prepare an appropriate copy for release. Under UK GDPR, individuals generally have a right to access their personal data, although that right is subject to exemptions and the rights and freedoms of others.
A structured workflow can make this process considerably more manageable. By narrowing the search before reviewing footage, using automated detection where appropriate, and separating identification from redaction, teams can respond more efficiently without treating privacy as an afterthought.
Start by defining the search parameters
The first step is to establish as much information as possible about the requested footage. A DSAR may provide a date, approximate time, location, or description of an event. Those details can dramatically reduce the amount of footage that needs to be examined.
So, instead of searching an entire CCTV archive, establish which cameras could have captured the individual and identify the relevant time window. If someone says they visited a particular reception between 2pm and 3pm, for example, cameras covering unrelated areas may not need to be reviewed at all. This is both an efficiency measure and a privacy safeguard because it limits unnecessary access to unrelated recordings.
Identify which cameras matter
Large CCTV environments can contain hundreds or thousands of cameras. A requester may appear on several cameras while moving through a building, campus, retail site, transport hub, or other monitored area. Mapping the person's likely route can help establish which recordings should be searched first.
Camera location, field of view, timestamp synchronization, and retention periods all matter. If camera clocks are inconsistent, even a relatively precise time supplied by the requester may not correspond exactly with the timestamp shown in each recording.
Use time and location before visual search
It can be tempting to immediately search footage for a person's face, but contextual information can often reduce the workload first.
Date, time, entrance records, access-control information, appointment details, or other legitimate operational data may help establish when the individual was present. These sources should themselves be handled in accordance with applicable privacy and access requirements, but they can make the video search substantially more targeted.
The more accurately the search window is defined, the less unnecessary footage needs to be processed.
Search across multiple recordings
Finding someone in one short clip is relatively straightforward. Finding them across several hours of recordings is a different problem.
The person may change direction, leave one camera's field of view, appear on another camera, and later return. Lighting, clothing, distance, and camera quality can also affect whether visual detection remains consistent.
AI-assisted video search can help identify likely appearances across large volumes of footage. Rather than requiring a reviewer to watch every recording continuously, automated systems can narrow the material to moments where a potentially matching face or person appears.
The results should still be treated as candidates for review rather than unquestionable identification.
Don't assume facial recognition is always appropriate
Finding an individual does not necessarily mean deploying facial recognition.
Organizations should consider whether the technology is necessary, proportionate, lawful, and appropriate for the particular DSAR workflow. Depending on the circumstances, simpler methods such as time-and-location filtering or visual review may be sufficient.
Where biometric technologies are being considered, additional legal and privacy implications can arise. Teams should understand the relevant requirements before introducing them into an access-request process.
Protect other people in the footage
Once the relevant recordings have been located, another challenge begins. A CCTV clip showing the requester may also contain employees, customers, visitors, children, or members of the public. Providing an unedited recording could therefore disclose personal information about people who are not part of the request.
The UK GDPR requires organizations to consider the rights and freedoms of other individuals when responding to access requests. The fact that someone appears in the same recording does not automatically mean their information should be disclosed without consideration. This is where redaction becomes an essential part of the DSAR workflow.
Redact Before Disclosure
The objective is not necessarily to remove everyone except the requester. Instead, organizations should assess what information can appropriately be disclosed and what needs to be protected.
Faces of unrelated individuals are an obvious example, but license plates, documents, screens, badges, and other identifying details may also require consideration.
Secure Redact, developed by our team at Pimloc, can automate the detection and anonymization of faces and other sensitive visual information in video, helping teams prepare DSAR footage without manually editing every occurrence. Our automated tracking is particularly useful when the requester moves through a scene, as the protection can follow the subject rather than requiring separate edits for individual frames.
Contact us today to trial Secure Redact.
Create a separate disclosure copy
The original CCTV recording should generally remain protected. Once relevant footage has been identified, organizations can create a working copy for redaction and prepare a separate disclosure version. This keeps the source material intact while allowing privacy protections to be applied to the version provided to the requester.
It also creates a cleaner audit trail. Teams can establish which original recordings were reviewed and which processed files were ultimately disclosed.
Review the finished footage carefully
Automated processing can significantly reduce the amount of manual work, but it should not remove quality control.
A reviewer should check whether unrelated individuals remain identifiable, whether redactions stay aligned with moving subjects, and whether the footage contains additional information that could identify someone indirectly.
Particular attention should be given to crowded areas, entrances and exits, reflections, rapid movement, low-light footage, and camera changes. These situations can create challenges for automated detection.
Keep the search proportionate
A DSAR does not necessarily require an organization to review every piece of footage it has ever collected. The search should be reasonable and proportionate to the circumstances. A clearly defined request can usually be narrowed by date, location, camera, and other available information.
If the request is particularly broad or unclear, communicating with the requester may help establish a more useful scope. A narrower time period or specific location can make it easier to identify relevant information while reducing the amount of unrelated personal data that needs to be processed.
Document the process
CCTV DSARs can involve multiple decisions, particularly when footage includes other people. Therefore, organizations should keep appropriate records of the search parameters, footage reviewed, relevant recordings identified, redaction decisions, and material ultimately disclosed. This supports accountability and provides a record if the response is later questioned.
Secure Redact includes audit functionality that provides visibility into activity during the redaction process, helping teams maintain a clearer record of how a disclosure copy was prepared.
Consider retention before starting the search
CCTV footage is often retained for limited periods, meaning timing can have a significant effect on a DSAR.
Organizations should understand their retention schedules and avoid deleting relevant information simply because it is approaching its normal deletion date once a legitimate preservation requirement applies. At the same time, footage should not be retained indefinitely just because a DSAR might theoretically be made in the future.
A documented retention policy makes these decisions much easier to manage.
Making video DSARs more manageable
Searching hours of CCTV for one individual can be one of the most labor-intensive types of access request, particularly when organizations rely heavily on manual review. The combination of time-consuming searching and third-party privacy considerations makes a structured workflow essential.
Automation can help reduce the burden by narrowing large video archives to potentially relevant moments and handling repetitive anonymization work. Secure Redact also supports scalable processing for organizations handling substantial volumes of video, making automated privacy protection more practical when a single DSAR involves numerous recordings.
The most effective approach is not simply to search faster. It is to build a process that connects targeted discovery, careful verification, proportionate disclosure, reliable redaction, and secure handling from beginning to end.
Frequently asked questions
-
Yes, an individual can generally request access to CCTV footage in which they are identifiable, although the organization must consider applicable exemptions and the rights and freedoms of other people appearing in the recording.
-
They may need to be anonymized depending on the circumstances and whether disclosure would adversely affect the rights and freedoms of those individuals. Organizations should assess third-party information before releasing footage.
-
Narrowing the search by date, time, location, and camera can significantly reduce the footage requiring review. AI-assisted detection and video search can provide further assistance when large volumes need to be examined.
-
Organizations should generally preserve the original recording and create a separate copy for redaction and disclosure. This helps maintain the integrity of the source footage.
-
The applicable response period depends on the circumstances and relevant data protection requirements. Organizations should begin assessing the request promptly, particularly where CCTV retention periods could result in relevant footage being automatically deleted.
