CCTV footage can identify people, reveal their movements and record workplace or customer activity. That makes responsible handling part of security planning, not an administrative detail added after cameras are installed.
Tanzania has a personal data protection framework, and the Personal Data Protection Commission has specifically published guidance concerning surveillance systems. Every organisation should obtain advice appropriate to its activities and review current requirements directly with the Personal Data Protection Commission. This article provides operational guidance, not legal advice.
Define a lawful and specific purpose
Write down why surveillance is necessary at each location. Protecting an entrance, monitoring a cash point and investigating perimeter intrusion are specific security purposes. Recording an area simply because a camera can see it is not a sound operating reason.
The field of view should be limited to what the purpose requires. Avoid neighbouring homes, private rooms and unrelated public activity where possible. Cameras in especially sensitive places need stronger justification, restricted access and documented approval.
- Name the asset, risk or process being protected.
- Identify whose personal data may be captured.
- Record why a less intrusive measure would not meet the need.
- Set a review date so unnecessary cameras are removed or repositioned.
Make surveillance transparent
Clear signage helps visitors and employees understand that CCTV is operating, who is responsible and how to raise a question. Staff policies should explain monitoring in language that is easy to understand. Secret or unexpected monitoring creates legal, ethical and workplace trust risks.
Transparency does not require publishing camera blind spots or technical details that weaken security. It means giving appropriate notice and maintaining an accountable process behind the system.
Control access and retention
Only authorised people should view live or recorded footage. Use named accounts, strong passwords and an access log. Exports should be tied to an incident or approved request, stored securely and shared through a controlled method. Recording a clip on a personal phone or sending it casually through a group chat can destroy accountability.
Retention should match the documented need and applicable requirements. Keeping everything forever increases exposure without necessarily improving security. The organisation should define ordinary retention, incident preservation, deletion and lawful disclosure procedures.
Build privacy into maintenance
Periodic reviews should confirm that camera views have not drifted, permissions remain correct and old users have been removed. Vendors who can access the system remotely should have clear contractual and technical controls. Default passwords and unsupported recorders should be treated as security risks.
If footage is lost, disclosed incorrectly or accessed without authority, preserve logs and escalate immediately through the organisation’s incident process. Privacy and physical security support the same objective: protecting people through disciplined control of sensitive information.
Next step
Create a CCTV register covering purpose, location, responsible owner, retention and authorised viewers. K4S can help review the operational design of your surveillance programme through our technology and monitoring services.