In anticipation of International Data Protection Day, Genetec Inc. has shared recommended practices for safeguarding sensitive physical security data. This initiative is particularly significant for organisations aiming to protect data derived from video surveillance, access records, and license plate information amidst stringent privacy regulations and increasing cyber threats.
Mathieu Chevalier, Principal Security Architect at Genetec Inc., emphasised the sensitivity of physical security data, noting, "Physical security data can be highly sensitive, and protecting it requires more than basic safeguards or vague assurances. Some approaches in the market treat data as an asset to be exploited or shared beyond its original purpose. That creates real privacy risks. Organisations should expect clear limits on how their data is used, strong controls throughout its lifecycle, and technology that is designed to respect privacy by default, not as an afterthought."
Data protection strategies
Marking the annual International Data Protection Day on January 28, the focus is placed on the collective responsibility of data protection. For teams handling physical security, the integration of well-defined strategies, robust technologies, and reliable partnerships is indispensable in adapting to evolving risks and regulations. Genetec proposes several best practices to aid in safeguarding data throughout physical security systems.
Firstly, it is crucial to establish a comprehensive data protection strategy. Organisations should evaluate the specifics of the data they collect, its purpose, storage locations, retention periods, and access controls. Documenting these processes helps minimise data exposure risks, identify gaps in policy, and maintain compliance as regulations evolve. Transparency in data handling practices is also vital for ensuring trust among employees, clients, and the public.
Privacy by design
Encrypting data, using strong authentication, & enforcing granular access controls reduce unauthorised accessIntegrating privacy-by-design principles is essential in mitigating privacy risks. This approach involves more than just security controls; it encompasses how personal data is collected, utilised, and governed. Organisations should apply principles like purpose limitation and data minimisation to collect and retain only the data necessary for their security objectives.
Strong measures such as encrypting data both in transit and at rest, enforcing robust authentication, and implementing granular access controls help prevent unauthorised access. Additionally, using privacy-enhancing technologies like automated anonymisation and masking supports transparency and protects identities while maintaining the utility of security data.
Ongoing cyber defence
Continuous maintenance of strong cyber defences is essential for effective data protection. This involves regularly hardening systems, managing vulnerabilities, and applying timely updates to address emerging cybersecurity threats. Privacy and cybersecurity should be viewed as continuous operational responsibilities to uphold a solid security posture.
Cloud services and partner selection
Deploying cloud services can bolster organisational resilience and compliance by keeping security patches, privacy controls, and compliance features up to date, thereby easing the burden on internal teams. Many entities are adopting hybrid deployment models to balance scalability, control, and data residency needs.
When selecting technology partners, organisations must assess their commitment to privacy and transparency. Vendors should be evaluated based on their personal data governance, data use limitations, and transparent communication about privacy practices. Adherence to independent security standards and certifications, such as ISO/IEC 27001, ISO/IEC 27017, and SOC 2 Type II, offers assurance on data protection and management.
Assessing vendors' vulnerability disclosure processes, data governance policies, and approach to artificial intelligence is also crucial, particularly regarding transparency, safety, and human-led decision-making with personal data.
To support Data Protection Day, Genetec Inc. (“Genetec”), the global leader in enterprise physical security software, is sharing best practices to help organisations protect sensitive physical security data while maintaining effective security operations.
Physical security systems generate large volumes of information from video footage, access control records, and license plate information. As this data plays a growing role in daily operations and investigations, organisations are under increasing pressure to manage it responsibly amid evolving privacy regulations, rising cyber threats, and heightened expectations around transparency.
Sensitive data
“Physical security data can be highly sensitive, and protecting it requires more than basic safeguards or vague assurances,” said Mathieu Chevalier, Principal Security Architect at Genetec Inc.
“Some approaches in the market treat data as an asset to be exploited or shared beyond its original purpose. That creates real privacy risks. Organisations should expect clear limits on how their data is used, strong controls throughout its lifecycle, and technology that is designed to respect privacy by default, not as an afterthought.”
Best practices
Observed annually on January 28, International Data Protection Day serves as a reminder that protecting personal data is a shared and ongoing responsibility. For physical security teams, adopting clear strategies, resilient technologies, and trusted partnerships can help ensure privacy and security objectives remain aligned as risks and regulations continue to change. Genetec recommends the following best practices to help organisations strengthen data protection across physical security systems:
- Start with a clear data protection strategy: Organisations should regularly assess what data they collect, for which purpose they collect it, where it is stored, how long it is retained, and who has access to it. Documenting these practices helps reduce unnecessary data exposure, identify policy gaps, and support ongoing compliance as regulations continue to evolve. Transparency around data handling practices also plays an important role in building trust with employees, customers, and the public.
- Design systems with privacy built in: Privacy-by-design means limiting privacy risk not only through security controls, but also through how personal data is collected, used, and governed. Organisations should apply purpose limitation and data minimisation principles to ensure only the data required for defined security objectives is collected and retained. Strong security measures, including encrypting data in transit and at rest, enforcing strong authentication, and applying granular access controls, help reduce the risk of unauthorised access. Privacy-enhancing technologies, such as automated anonymisation and masking, further support transparency and help protect individuals’ identities while preserving the operational value of security data.
- Maintain strong cyber defenses over time: Data protection is an ongoing process. Regular system hardening, vulnerability management, and timely updates are essential to address new cybersecurity risks as they emerge. Treating privacy and cybersecurity as continuous operational responsibilities helps organisations maintain a stronger overall security posture.
- Use cloud services to support resilience and compliance: Cloud-managed and software-as-a-service deployments can help organisations stay current with security patches, privacy controls, and compliance features, while reducing the operational burden on internal teams. Many organisations are adopting flexible deployment approaches that allow them to balance scalability, control, and data residency requirements across on-prem and cloud environments.
- Choose partners committed to privacy and transparency: Working with trusted technology partners is critical. Organisations should evaluate vendors based on how they govern personal data, define clear limits on data use, and communicate transparently about their privacy practices. Independent security standards and attestations, such as ISO/IEC 27001, ISO/IEC 27017, and SOC 2 Type II reports, provide important assurance around how systems and data are protected and managed, and help reduce privacy risks associated with unauthorised access or misuse. Organisations should also assess vendors’ vulnerability disclosure processes, data governance practices, and approach to developing and deploying artificial intelligence, including whether they prioritise transparency, safety, and human-led decision-making when personal data is involved.