Whitesec ID
Technical Implementation

CCTV & Facial Recognition Implementation

Cameras that actually cover what matters, and face data you can account for

  • Facial Recognition
  • Access Control
  • Camera Network Segmentation
  • Biometric DPIA

We design and install CCTV with facial recognition for offices, plants, and warehouses. Camera positions come out of a site survey, not out of a quoted unit count. Cameras run on their own network, separate from the office network, and biometric data is handled under Law No. 27 of 2022 — with a documented lawful basis, a retention period, and a procedure for releasing footage.

What you receive

  • Camera layout drawings and the system design document
  • NVR, VMS, and network configuration with a change log
  • Biometric DPIA, retention policy, and notice wording
  • Coverage and facial recognition accuracy test results
  • Operator runbook and training for your security team
Context & Urgency

Why this matters now

Cameras are no longer just a physical security device. The moment a face becomes an identity, the system moves into personal data protection territory, and the obligations change with it.

  • Face data is specific personal data

    Law No. 27 of 2022 places biometric data in a special category. Processing it requires a clear lawful basis, notice to the people recorded, and stronger safeguards than ordinary data.

  • Camera devices are a common way in

    NVRs and cameras left on default passwords and exposed to the internet are routinely picked up by automated scanning. From there an attacker moves into the office network sharing the same segment.

  • Footage without a retention rule becomes a liability

    Recordings kept indefinitely widen the damage of any breach, and make deletion requests from data subjects difficult to answer honestly.

Signs your organisation needs this

  • Cameras are installed, yet key areas are uncovered or the image is unreadable
  • Facial recognition is in use with no notice signage or consent documentation
  • The NVR sits on the same network as staff workstations
  • There is no formal process when footage is requested internally or externally

Any one of these is reason enough to start the conversation early.

Scope

What we cover

  • Site Survey & Camera Design

    Lens coverage, lighting conditions, cable routes, and blind spots mapped before a single unit is bought.

  • Facial Recognition & Watchlists

    Face enrolment, match thresholds, false-match handling, and a procedure for adding or removing watchlist entries.

  • Access Control & Door Integration

    Turnstiles, cards, and locked doors tied to attendance records and a visitor log that holds up to review.

  • Camera Network Segmentation

    A separate VLAN, default credentials replaced, firmware updated, and no device exposed directly to the internet.

  • Storage & Footage Retention

    NVR capacity, retention period, encryption, and a formal process for requesting and releasing recordings.

  • Biometric DPIA & Notices

    Impact assessment, lawful basis, on-site signage, and a working route for data subject requests.

How We Work

Clear stages, with no surprises along the way

Every stage has agreed deliverables, so progress is never in question.

  1. 01

    Site Survey

    Mapping areas, weak points, cable routes, and available power and network capacity.

  2. 02

    Design

    Camera layout, device specifications, network design, and storage requirements.

  3. 03

    Installation

    Cameras, network equipment, NVR, and access control integration put in place.

  4. 04

    Testing & Enrolment

    Coverage checks, facial recognition accuracy testing, and staff enrolment.

  5. 05

    Handover

    Operator runbook, hands-on training, and the biometric compliance documentation.

Reference Basis

The standards and regulations we work from

Every recommendation traces back to the references below and can be verified independently.

  • Law No. 27 of 2022Personal data protection, with biometric data treated as specific personal data.
  • ISO/IEC 29134Guidance for carrying out a privacy impact assessment.
  • IEC 62676Standard for video surveillance systems used in security applications.
  • ISO/IEC 27001:2022 Annex A 7.4Physical security monitoring control.
  • Government Regulation No. 71 of 2019Obligations on operators of electronic systems.

Success indicators

Agreed upfront so the work is judged objectively rather than by impression.

  • Share of priority areas covered as the camera design intended
  • False match rate observed in facial recognition testing
  • Number of camera devices still on default credentials
  • Adherence to the footage retention period that was set
Glossary

Terms that come up in these discussions

The vocabulary you will meet in documents, reports, and conversations with auditors.

NVR
Network Video Recorder — the device that receives and stores footage from network cameras and governs who may play it back.
False Acceptance Rate
How often the system matches the wrong person to an enrolled identity. This figure drives how tightly the match threshold is set.
Watchlist
A list of faces that raises an alert on detection, for example former employees or people barred from a particular area.
DPIA
Data Protection Impact Assessment — the assessment carried out before processing high-risk data such as biometrics.
Frequently Asked

The questions we hear most

Still unanswered? Send your question and our team will reply on a working day.

Ready to build stronger security?

Talk your organisation's needs through with our team. Free, and without obligation.