CCTV Surveillance Register

CCTV Surveillance Register

Data Controller
TK Talous Oy (0925979-9)
Luvakuja 16
21260 Raisio

Contact Person for Register Matters
Kari Virtanen
kari.virtanen(at)tktalous.fi

Register
CCTV Surveillance Register

Date of Preparation
28 October 2024

Legal Basis for Processing
Legitimate Interest

Purpose of the Processing of Personal Data
The legal basis for the processing is the Data Controller’s legitimate interest. Personal data is processed, where necessary, in connection with the investigation of potential security incidents on the Data Controller’s premises and, where required, by the competent authorities in connection with criminal investigations. The purpose of CCTV surveillance is to protect property, prevent crime and assist in the investigation of criminal offences that have already occurred. In addition, the purpose of the surveillance is to ensure and enhance the safety of the Data Controller’s personnel and visitors. Persons designated by the Data Controller are authorised, by virtue of their duties or position, to process personal data obtained through CCTV surveillance (for example, by viewing and, where applicable, listening to recordings). Personnel providing administrative services and, where necessary, individuals assigned to investigate a particular matter are also authorised to process such data. In addition, the employer is entitled to use the data contained in the register in the situations specified in Section 17(2), paragraphs 1–3, of the Finnish Act on the Protection of Privacy in Working Life (759/2004) in order to establish the grounds for the termination of employment, to investigate and verify harassment or sexual harassment referred to in the Act on Equality between Women and Men (609/1986), harassment or inappropriate conduct referred to in the Occupational Safety and Health Act (738/2002), and to investigate occupational accidents or other situations involving danger or threat as referred to in the Occupational Safety and Health Act.

Basis of Legitimate Interest
The legal basis for the processing of personal data is the Data Controller’s legitimate interest (Article 6(1)(f) of the EU General Data Protection Regulation (GDPR)). The Data Controller must process personal data in order to carry out activities related to its business operations. In this context, the processing of personal data cannot necessarily be justified on the basis of a legal obligation or a contract concluded with the data subject. Following a Legitimate Interest Assessment (LIA), the Data Controller has determined that legitimate interest constitutes the most appropriate legal basis for the processing, taking into account the nature and scope of the processing as well as the rights and freedoms of the data subjects. The Data Controller has assessed that processing based on legitimate interest does not cause significant harm to the rights and freedoms of the individuals concerned (data subjects).

Categories of Personal Data
The register contains the following personal data in the form of video recordings relating to all persons moving within the CCTV surveillance area of the Data Controller’s premises:
1. A person’s appearance and distinguishing characteristics.
2. The date, time and precise location of movement within the property.
Information is recorded whenever a person moves within the CCTV surveillance area, as the surveillance system operates using motion detection. The presence of recording CCTV surveillance is indicated by appropriate signage. The cameras are installed at entrances, in common areas, along access routes, in courtyard areas, and at certain locations that require enhanced surveillance due to operational reasons and their particular vulnerability.

Recipients and Categories of Recipients
The Data Controller’s own personnel.
Personal data is not routinely disclosed without a lawful basis (Act on the Protection of Privacy in Working Life 759/2004). Personal data is disclosed to the police only in exceptional circumstances through the criminal reporting procedure where a criminal offence has occurred or is suspected to have occurred and, where necessary, to an insurance company in connection with insurance claims arising from damage. Personal data may also be disclosed to persons holding managerial positions within the Data Controller’s organisation for the purpose of investigating and substantiating occupational accidents, harassment, sexual harassment or other inappropriate conduct.

Contents of the Register
The register contains the following personal data in the form of video recordings relating to all persons moving within the CCTV surveillance area of the Data Controller’s premises:
1. A person’s appearance and distinguishing characteristics.
2. The date, time and location of movement within the property.
Information is recorded whenever a person moves within the CCTV surveillance area, as the surveillance system operates using motion detection. The presence of recording CCTV surveillance is indicated by appropriate signage. The cameras are installed at entrances, in common areas, along access routes, in courtyard areas, and at certain locations that require enhanced surveillance due to operational reasons and their particular vulnerability.

Regular Sources of Personal Data
The regular source of personal data is the CCTV surveillance system. The register consists of video footage captured by the cameras operating within the recording surveillance system.

Retention Period for Personal Data
Personal data collected in the register is retained only for as long as, and to the extent that, it is necessary for the original or compatible purposes for which the personal data was collected. Personal data is stored on the server of the Data Controller’s CCTV service provider. Personal data relating to data subjects is retained for 30 days. After this period, the data is deleted. If, during the retention period, a report of criminal damage or another criminal offence is received, the relevant recording will be retained for the period necessary to investigate the matter.
The Data Controller deletes the stored personal data once there is no longer a lawful basis for processing it. The Data Controller regularly assesses the necessity of retaining personal data in accordance with its internal policies.

Regular Disclosure of Personal Data
Personal data is not disclosed outside the Data Controller or the Data Processor acting on behalf of the Data Controller, except where disclosure is required in connection with the investigation of criminal offences.

Transfers of Personal Data Outside the EU or EEA
Personal data contained in the register is not routinely transferred outside the European Union (EU) or the European Economic Area (EEA).
However, it is possible that processing may involve service providers located outside the EU/EEA or cloud services hosted outside the EU/EEA. In such cases, transfers are carried out on the basis of the European Commission’s Standard Contractual Clauses (SCCs).
In addition, supplementary safeguards have been implemented for such transfers, including internal instructions concerning the pseudonymisation of personal data and equivalent protective measures, as well as, where required, a Transfer Impact Assessment (TIA).
Where an organisation processing personal data has committed to the EU–US Data Privacy Framework (DPF), this framework shall serve as the legal basis for the transfer for as long as it remains valid.

Principles of Register Protection
A. Manual Records
No manual records are maintained.

B. Electronic Records
Personal data is processed and stored confidentially.
The data is stored in databases located on a secure server. The databases are protected by passwords and other appropriate technical security measures. User IDs and passwords required to access the register are granted only to persons who are authorised to use the register.

Right of Access to Personal Data
The data subject has the right to obtain confirmation as to what personal data concerning them is contained in the register. A request for access must be submitted in writing from a verifiable email address.

Right to Data Portability
The data subject does not have the right to transfer their personal data from one system to another.

Right to Rectification
Personal data contained in the register that is inaccurate, unnecessary, incomplete or outdated in relation to the purposes of the processing must be rectified, erased or supplemented. A request for rectification must be submitted either by means of a written request bearing the data subject’s handwritten signature to the Company’s customer service or from a verifiable email address. The request must specify which personal data is to be rectified and the grounds on which the request is based.
The rectification shall be carried out without undue delay, where technically feasible.
The rectification shall be notified to the party from whom the inaccurate personal data was obtained or to whom the personal data has been disclosed. Where a request for rectification is refused, the person responsible for the register shall provide the data subject with a written certificate stating the reasons for the refusal. The data subject has the right to refer the matter to the Office of the Data Protection Ombudsman for consideration.

Right to Restriction of Processing
The data subject has the right to request the restriction of the processing of personal data, for example where the personal data contained in the register is inaccurate.
Requests should be addressed to the person responsible for the register.

Right to Object
The data subject has the right to object to the processing of personal data relating to them and to request the rectification or erasure of their personal data. Requests may be addressed to the contact person for the register.

Right to Lodge a Complaint with the Supervisory Authority
If you consider that the processing of your personal data infringes the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the competent supervisory authority. You may also lodge a complaint with the supervisory authority in the Member State of your habitual residence or place of work.

Contact Details of the National Supervisory Authority
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki
Postal address: P.O. Box 800, FI-00531 Helsinki
Telephone (switchboard): +358 29 566 6700
tietosuoja(at)om.fi
(https://tietosuoja.fi)

Other Rights Relating to the Processing of Personal Data
The data subject has the right to prohibit the disclosure and processing of their personal data for the purposes of direct marketing and other marketing activities, to request the anonymisation of personal data where applicable, and to exercise the right to be forgotten.

GDPR Compuance