You are currently viewing Garda Access to Event CCTV: EIAI Calls for Clearer Rules for Temporary and Multi-Party Systems

Garda Access to Event CCTV: EIAI Calls for Clearer Rules for Temporary and Multi-Party Systems

The Event Industry Association of Ireland has made a submission to An Garda Síochána’s public consultation on the proposed Code of Practice governing Garda access to live CCTV feeds operated by third parties. The consultation arises from the Garda Síochána (Recording Devices) Act 2023 and is intended to establish a formal framework for circumstances in which Garda personnel may access live CCTV systems that are not controlled by An Garda Síochána.

Third-party CCTV is already widely used across Ireland and has become an important operational tool at festivals, concerts, sporting fixtures, exhibitions and other large or temporary events. These systems can support crowd monitoring, incident identification, perimeter management, emergency access, security deployment and wider Event Control functions. EIAI supports the introduction of a clear, lawful and proportionate framework through which An Garda Síochána can access live third-party CCTV for legitimate policing, public-order and public-safety purposes. Our submission focuses on ensuring that the final Code also reflects the particular way in which CCTV is commissioned, controlled and operated within temporary event environments.

Temporary events do not operate like permanent CCTV installations

One of the central issues raised by EIAI is that event CCTV frequently operates within a much more complex structure than a permanent system controlled by a single organisation. A venue may own an existing camera network while an organiser commissions additional temporary cameras specifically for an event. A specialist CCTV supplier may install, configure and technically maintain the system, while a separate security contractor provides the personnel who actively monitor the live feeds. The organiser or venue may determine the purposes for which CCTV is being used, while information generated through the system may also be shared within Event Control to support safety, crowd management and security decision-making.

The result is that ownership of the equipment, technical administration of the system, physical operation of the cameras and legal responsibility for the personal data being processed may sit with different organisations. The draft Code states that the third party remains the data controller for personal data captured by the live feed, while the statutory framework provides that Garda personnel may process the live feed only where the appropriate authorisation or approval is in place.

For the event industry, the practical question is therefore who, within a multi-party arrangement, is regarded as the relevant third party for the purposes of the legislation. The individual capable of displaying a particular camera feed may be employed by a security contractor, while the person with administrator access may work for a technical supplier, and neither may be the organisation legally responsible for deciding whether access should be provided. EIAI has recommended that the final Code, or accompanying operational guidance, explain clearly how the relevant third party should be identified where ownership, technical control, live monitoring and data-protection responsibilities are divided between different organisations. This should include clarity on who receives an authorisation or approval, the role of the contracted security operator and the position of a technical supplier that maintains administrator access but does not undertake live monitoring.

This is especially important because temporary arrangements may exist for only a matter of days. The respective responsibilities of the organiser, venue, CCTV supplier and security contractor should therefore be capable of being determined during event planning, rather than requiring frontline personnel to resolve legal and operational responsibilities while an incident is already underway.

Garda requests within a multi-agency Event Control

The distinction between ordinary operational requests and statutory Garda access also becomes particularly important in a multi-agency Event Control environment. Major events may bring together representatives of An Garda Síochána, local authorities, fire and emergency services, medical providers, event management and private security, all of whom may legitimately request information or camera coverage during an event. The draft Code establishes a more specific statutory process for Garda access to a third-party live feed. In normal circumstances, access is provided through an authorisation granted by the District Court. In urgent circumstances, the legislation also allows an independent Garda Superintendent to approve access where the statutory requirements are satisfied. Such an approval is generally limited to 72 hours, with further access requiring the additional process provided for in the legislation.

EIAI has recommended that the final guidance clearly explain how a third party should implement access once an authorisation or approval has been granted. Operators should be able to verify the identity and authority of the Garda personnel concerned, understand which cameras or areas are covered, know whether any conditions or restrictions apply, and be clear about when the access begins, expires and must be terminated.

This clarity is particularly important during urgent incidents. CCTV operators may be working under considerable operational pressure, especially where Garda personnel are physically present within Event Control or the CCTV control room. Operational urgency does not remove the requirement for the statutory process to be followed, but neither should operators be expected to make complex legal determinations while simultaneously managing a safety or security incident. A straightforward verification and escalation process would support rapid lawful access while reducing the risk that urgency, physical proximity or operational pressure causes required safeguards to be bypassed.

Garda access must not compromise event-safety monitoring

Another important issue concerns the continuing operational role performed by event CCTV while Garda access is being facilitated. At a large event, CCTV may simultaneously be supporting crowd movement, ingress and egress, perimeter management, incident detection, emergency access and the deployment of security and stewarding personnel. Access provided under the new statutory framework should therefore be implemented in a way that does not remove or materially reduce the ability of the event CCTV team to continue performing these safety-critical functions.

This has implications for both operator capacity and welfare. Additional access-related tasks should not result in an operator becoming so occupied with the Garda process that attention is diverted from essential event monitoring. The practical arrangements introduced alongside the Code should therefore take account of the fact that an event CCTV operator may already be managing a demanding operational workload.

Temporary CCTV systems also have technical characteristics that can differ considerably from permanent installations. An event system may depend on temporary power, wireless links, mobile communications infrastructure or equipment installed specifically for a short-duration event. Even where those systems have been properly planned, installed and maintained, a camera may fail, connectivity may be lost, picture quality may degrade or a temporary power supply may be interrupted. EIAI has therefore asked for guidance on the expected response where authorised Garda access is affected by a camera failure, network interruption, communications failure, loss of power or wider system outage. That guidance should clarify whether An Garda Síochána must be notified, what reasonable steps the third party is expected to take and where responsibility ends when a failure is outside that organisation’s reasonable control. Technical failure should not be treated as though it were a deliberate refusal to comply with an authorised request.

Proportionality becomes particularly important at major events

EIAI strongly supports the emphasis placed within the draft Code on necessity, proportionality and fundamental rights. The Code requires an authoriser or approver to consider the interference that proposed CCTV access may create with the rights and freedoms of members of the public, including privacy, freedom of expression, freedom of assembly and protection from discrimination. It also requires consideration of the number of cameras involved, the geographical coverage of the activity and whether a policing objective could be achieved through a less intrusive alternative.

These considerations can take on particular significance at a large event. A substantial event CCTV system may cover extensive public areas and large numbers of attendees, most of whom will have no connection with the policing purpose for which access has been requested. Where the objective can be achieved through access to fewer cameras, a smaller geographic area or a shorter period of time, those options should be considered before broader access is provided. The position can become more complex again where several CCTV systems operate concurrently. Temporary event cameras may sit alongside permanent venue CCTV and, under separate legal arrangements, local-authority, transport or other public CCTV infrastructure. The combined surveillance footprint can therefore be considerably greater than that created by any one individual system.

EIAI is not suggesting that CCTV systems falling outside the scope of this Code should be brought within it. Rather, our submission recommends that where Garda access under this framework operates alongside access to other CCTV systems under separate legal arrangements, the overall surveillance footprint should, where relevant, form part of the proportionality assessment. Particular care may also be warranted where coverage includes children, medical or welfare areas, locations where individuals may have a heightened expectation of privacy, or lawful demonstrations and assemblies.

CCTV increasingly involves more than a live picture

Modern CCTV systems may also incorporate functionality that goes significantly beyond the traditional camera feed. Event systems can include crowd-density monitoring, automated alerts, object tracking and other forms of video analytics, while more advanced systems may potentially incorporate facial recognition, biometric identification or other particularly sensitive forms of processing.

The draft Code defines CCTV broadly and recognises systems capable of processing images and accompanying information. EIAI nevertheless believes that clearer practical guidance would be helpful in determining whether an authorisation for access to a live feed extends only to the underlying video or whether it can also include analytical outputs generated by the third-party system.

This is important because Garda access should not itself be treated as creating a lawful basis for additional processing by an organiser, venue or CCTV provider. Where a third party is using analytics or other enhanced functionality, that processing must continue to have its own lawful basis. An authorisation for Garda access should not automatically legitimise additional forms of analysis that would not otherwise be lawful.

Live access and recorded footage should remain clearly separate

The distinction between live access and recorded CCTV is another important feature of the proposed framework. The draft Code is specifically concerned with Garda personnel accessing CCTV operated by a third party through a live feed. It states that An Garda Síochána is not to record the live feed under this framework and that, where recorded third-party footage is subsequently required, the established process under the Data Protection Act 2018 should be followed separately.

That distinction needs to be understood clearly within event operations because the person who facilitates live access may not be the person responsible for exporting, retaining or releasing recorded material. EIAI has recommended that this distinction be reflected clearly in practical guidance and operator briefings so that providing authorised live access is not mistakenly regarded as authority to release stored CCTV footage.

Audit trails, shift handovers and responsibility after the event

Temporary events also create particular governance and accountability issues because the CCTV environment may cease to exist shortly after the event ends. A control room can close within hours, temporary equipment may be dismantled, security contractors may leave the site and control of any permanent system may revert to the venue or another organisation. EIAI has therefore recommended that the final guidance identify the minimum operational record that a third party should maintain when Garda access is facilitated. This could include the relevant authorisation or approval reference, Garda contact details, the individual who facilitated access, the cameras or areas involved, the time access commenced and ended, any applicable conditions or restrictions, and any technical or operational issues that arose during the period of access.

The guidance should also clarify whether there is a particular retention period for those operational records and which organisation is responsible for maintaining them. This is especially important where several contractors are involved and where the party that facilitated access may no longer be present once the temporary event infrastructure has been removed.

Shift changes require similar consideration. Where authorised access remains active when one CCTV operator hands over to another, the incoming operator should be informed of the authority under which access is being provided, its scope, any applicable conditions, its expiry or review time and any relevant technical or operational issues. The same principle should apply where responsibility for a system transfers from an event organiser to a venue or supplier while an authorisation remains active. A clearly identified post-event contact would also support accountability if An Garda Síochána subsequently requires information about how access was facilitated, who was responsible or whether a technical issue occurred during the event.

Clearer guidance would support both policing and the event industry

There is a strong public-interest case for enabling An Garda Síochána to make appropriate use of third-party live CCTV. Used within a clear statutory framework, access can support the prevention and detection of crime, the maintenance of public order and the protection of public safety.  For the event industry, however, effective implementation will depend on organisers, venues, security contractors, CCTV suppliers and control-room personnel being able to understand their respective responsibilities before an incident arises. EIAI’s submission does not seek to weaken the safeguards or statutory authorisation requirements contained within the proposed framework. Instead, it asks that the final Code, or accompanying practical guidance, expressly recognise the operational reality of festivals, concerts, sporting fixtures, exhibitions and other temporary or large-scale events.

Clear guidance on responsibility, authorisation, multi-agency boundaries, technical implementation, continuity of event-safety monitoring, operator competence and workload, technical failure, proportionality, analytics, audit trails, shift handovers and post-event responsibility would provide greater certainty for the organisations expected to comply with the new regime while supporting the policing and public-safety objectives of the legislation.

The public consultation on the Third-Party Live CCTV Feeds Code of Practice closes on 14 September 2026.

EIAI_AGS_CCTV_COP_Submission_13092026

Elaine O'Connor

http://ie.linkedin.com/in/elaineoconnor