CCTV & AI use policy
Last updated: September 2026
Imperium Security Ltd uses CCTV, AI video analytics and related technology to protect our clients’ people, property and neighbourhoods. This policy explains how we do that lawfully, proportionately and with a human in control. We are registered with the Information Commissioner’s Office (ICO), and design every deployment around UK GDPR, the Data Protection Act 2018, the ICO’s guidance on video surveillance and the Surveillance Camera Code of Practice.
1. Our principles
- A human decides. AI flags events; a trained control-room operator reviews every alert before anyone acts on it. No decision about a person is made by AI alone.
- Only where justified. Cameras and analytics are deployed for a specific, documented security purpose and only where less intrusive measures would not be enough.
- Transparent. Monitored areas carry clear signage naming the operator and how to get in touch.
- Secure and accountable. Access to live and recorded footage is restricted, logged and audited.
2. Who is responsible for the data
When we monitor a client’s own cameras or site, the client is normally the data controller and Imperium acts as its data processor under a written data processing agreement. Where Imperium runs its own cameras or patrols (for example community patrol schemes), Imperium is the controller. The role for each deployment is set out in the client contract.
3. What the technology does
AI video analytics
Our analytics detect events such as people or vehicles in restricted areas, loitering, line-crossing, unauthorised entry, fire and panic, and camera faults. They classify activity; they do not identify individuals unless facial recognition has been separately approved for that site.
Facial recognition
Watchlist facial recognition is used only at specific retail or high-risk sites, and only after a data protection impact assessment (DPIA) has been completed and a lawful basis confirmed. Watchlists are limited, reviewed regularly and governed by documented criteria. Faces that do not match a watchlist are not retained. Every potential match is checked by an operator before any action is taken.
Officer GPS tracking
Our officers’ positions are tracked while on duty so the nearest unit can be dispatched and clients can see patrol evidence. Officers are informed of this, and tracking stops when they are off duty.
Imperium SOS app
When a user raises an alert, the app shares their location and alert details with our control room so we can respond. Location is shared only during an active alert or as described in the app’s own privacy notice.
4. Lawful basis
We usually rely on legitimate interests (preventing and detecting crime and protecting people and property), balanced against the privacy of people captured on camera. Where special category or criminal offence data is involved — such as facial recognition watchlists — we also rely on the substantial public interest condition for preventing or detecting unlawful acts under Schedule 1 of the Data Protection Act 2018, with an appropriate policy document in place.
5. Retention
Footage retention periods are agreed with each client and documented before go-live. Unless an incident is flagged, recordings are overwritten automatically at the end of that period. Clips linked to an incident are retained with the incident report for as long as needed for investigation, insurance or legal proceedings, and then deleted.
6. Sharing footage
We share footage with the client concerned, and with the police or other authorities where required by law or to prevent or detect crime. Each disclosure is logged. We never sell footage or use it for marketing.
7. Your rights
If you believe you have been recorded by a system we operate, you can ask for a copy of the footage (a subject access request), or ask us to restrict or erase it. Please give the date, time and location, and a description of yourself so we can find the footage. Email info@imperiumsecurity.co.uk. Where we act as a processor, we will pass your request to the site owner promptly and help them respond.
You can complain to the ICO at ico.org.uk.
8. Review
We review this policy, and each deployment’s DPIA, at least annually and whenever the technology or its use changes.