Government and public-sector work carries an extra requirement: everything has to be documented. Who holds access, who authorised it, how long footage is kept and on what basis.
Full access records, retention set deliberately rather than by default, and documentation you can hand to an auditor.
Counters and reception areas covered, with panic alarms where staff deal with the public face to face.
Records, server rooms and staff-only floors kept on their own permissions and schedules, away from public circulation.
Systems specified with data protection in mind — signage, retention periods and a clear process for releasing footage when it is requested.
Public-sector buildings have to do two contradictory things at once. They must stay genuinely open to the people they serve, and they must protect staff, records and systems from a population that walks in off the street unannounced.
The line between the two is what needs designing. Counters and waiting areas are public and should feel it. Behind them, staff corridors, records stores, server rooms and cash-handling areas belong on their own permissions, with entry recorded rather than assumed. Getting that boundary right removes most of the friction, because staff stop having to police it themselves.
Where staff deal with the public face to face, panic alarms at the counter matter more than any amount of recording. They are what someone reaches for while an incident is happening, rather than afterwards.
The requirement that separates public-sector work from commercial work is that everything has to be explainable afterwards. Why does that camera exist. Who authorised that person’s access. How long is footage kept, and on what basis. Who released a recording, to whom, and under what authority.
We specify with that in mind: retention set deliberately rather than left at whatever the recorder shipped with, compliant signage, access records that can be exported for audit, and a defined process for handling requests for footage — including from members of the public asking for recordings of themselves.
Where Fortify maintains the system, those requests can run through our documented disclosure process at Request CCTV footage, which logs every release against a reference number and produces a record you can hand to an auditor.
Long enough to be useful and no longer — for most premises that lands somewhere between fourteen and thirty-one days, set against a documented reason rather than the recorder’s default. We will help you decide and record why, which is the part that matters if you are ever asked.
They are entitled to ask, and the request needs handling within statutory time limits. Where we maintain the system, requests can go through our disclosure process, which verifies the requester, seeks authorisation from the data controller, and logs the release against a reference number.
Yes. We are happy to provide specifications, certifications, insurance details and company documentation for a tender, and to quote against a written specification rather than proposing our own.
Yes. Every credential use is recorded and can be exported by door, by person or by period, which is usually what an internal audit actually asks for. Who holds which permission is equally reportable.