NEWS AND EVENTS

Stay Connected with SCAN

Understanding EU CCTV Retention Policies: Key GDPR Considerations for Businesses

Understanding EU CCTV Retention Policies: Key GDPR Considerations for Businesses

June 15, 2026

Supply chain compliance is rarely simple, particularly when organizations must navigate evolving regulations such as the General Data Protection Regulation (GDPR) alongside varying country-specific requirements. For companies operating across Europe, CCTV retention is one area where compliance expectations can quickly become complex.

To help organizations better understand these requirements, SCAN recently issued a member notice outlining key considerations related to EU CCTV retention policies, GDPR requirements, and Authorized Economic Operator (AEO) expectations.

Download the EU CCTV Retention Policies Infographic (PDF).

Why There Is No Single EU CCTV Retention Standard

One of the most common misconceptions about CCTV retention in Europe is that GDPR establishes a universal retention period. In reality, no single EU-wide standard exists.

Instead, organizations are expected to determine appropriate retention periods based on factors such as necessity, proportionality, risk, and legitimate business needs. As a result, retention practices can vary significantly between countries, making it essential for organizations to understand the specific requirements that apply to their operations.

For businesses with facilities, suppliers, or partners located across multiple jurisdictions, a one-size-fits-all approach may create unnecessary compliance risks.

Key GDPR Principles for CCTV Compliance

Although retention periods differ by country, GDPR provides a consistent set of principles that organizations should follow when managing CCTV footage.

Organizations should:

Establish a legitimate purpose for CCTV monitoring.
Retain footage only for as long as necessary.
Document retention periods and business justifications.
Protect footage through appropriate security measures.
Restrict access to authorized personnel.
Delete footage when retention periods expire.

These principles help ensure that surveillance programs support operational and security objectives while respecting privacy requirements.

Understanding AEO Considerations

For organizations involved in international trade, AEO requirements introduce additional considerations.

AEO programs often expect organizations to maintain effective CCTV coverage, active monitoring practices, secure storage, documented procedures, and the ability to provide footage during investigations or customs audits when required.

However, AEO expectations do not override GDPR obligations. Any retention period must remain justified, documented, and aligned with applicable privacy requirements. Organizations should ensure that security objectives and data protection principles are considered together when developing CCTV policies.

What Organizations Should Do Next

As regulatory expectations continue to evolve, organizations should take a proactive approach to CCTV compliance.

Key actions include:

Review country-specific retention requirements for all relevant locations.
Document the rationale behind retention periods and related policies.
Align legal, compliance, and security teams on retention decisions.
Ensure CCTV programs support audit, investigation, and security requirements.
Regularly review policies to address regulatory changes and emerging risks.

A well-documented and consistently applied retention strategy can help reduce compliance risk while supporting broader business and security objectives.

Compliance Requires More Than Audits

At SCAN, compliance goes beyond identifying gaps. Organizations also need practical guidance to navigate complex regulations and implement effective solutions.

In addition to auditing business partners, identifying compliance gaps, managing corrective actions, and providing ongoing monitoring and tracking, SCAN helps members address evolving regulatory challenges through actionable insights and industry expertise.

As CCTV retention requirements continue to develop across Europe, staying informed and maintaining clear, well-supported policies can help organizations achieve both compliance and operational resilience.

 

Security and trust: the invisible architecture that underpins the USMCA

Security and trust: the invisible architecture that underpins the USMCA

7 May 2026
By Carlos E. Ochoa, Executive Director, SCAN Association

Sharing this post from the latest edition of T21 – a leading specialized media outlet in Mexico focusing on the logistics, transportation, and foreign trade sectors, providing in-depth analysis of industry trends.

In today’s environment of geopolitical tension, supply‑chain reconfiguration, and heightened regulatory scrutiny, trust has become the most valuable currency in North American trade. For the U.S.–Mexico partnership to remain strong, security can no longer be viewed as a cost or a box‑checking exercise. It is a strategic enabler of commerce.

From the U.S. perspective, trade flows efficiently only when governments can trust that supply‑chain actors operate under robust, verifiable security standards. That is precisely the logic behind programs like CTPAT and OEA: identifying low‑risk partners so trade can move faster, not slower.
This is where SCAN (Supplier Compliance Audit Network) adds tangible value to the USMCA framework.

SCAN operationalizes trust. It connects importers already certified by the U.S. and Canadian governments with suppliers that are independently audited under globally recognized security standards aligned with CTPAT, OEA, and the WCO SAFE Framework. By doing so, SCAN translates government‑to‑government trust into factory‑level, importer‑level, and supply‑chain‑level confidence.

For governments, this means:

Greater visibility and consistency across shared supply chains
Independent, credible evidence of compliance beyond country‑level recognition

Reduced risk without creating friction for legitimate trade
For the USMCA, it means transforming security into facilitation—supporting nearshoring, regional integration, and resilience while preserving strong enforcement.

The equation is simple but powerful:
Security enables trust. Trust enables facilitation. Facilitation sustains USMCA.

In a world where trust moves trade, supply‑chain security is the common language—and initiatives like SCAN help ensure both governments are speaking it with confidence.

Security and trust: the invisible architecture that underpins the USMCA – T21

Supply chain security: how importers in the US came together to make suppliers audit efficient and impactful

Supply chain security: how importers in the US came together to make suppliers audit efficient and impactful

2 March 2026
By Carlos E. Ochoa, Executive Director, SCAN Association

We’re proud to share that SCAN is featured in the latest edition of WCO News by the World Customs Organization.

The article explores how importers are working together to streamline supplier audits, reduce duplication, and strengthen supply chain security through a shared, standardized approach.

As global trade grows more complex, collaboration and trust are more important than ever—and SCAN is helping lead the way.

Available in English, French, and Spanish.

Supply chain security: how importers in the US came together to make suppliers audit efficient and impactful – WCO

BSI is Providing Complimentary Access to In-depth COVID-19 Related Supply Chain Insights and Intelligence

BSI is Providing Complimentary Access to In-depth COVID-19 Related Supply Chain Insights and Intelligence

April 2020 – BSI, the business improvement company, announced today that they are providing open access to the COVID-19 section of their Supply Chain Risk Exposure Evaluation Network (SCREEN) tool.

SCREEN is a web-based, comprehensive global supply chain intelligence system available by subscription, which includes valuable information for companies to anticipate, quickly respond to, and avoid supply chain disruptions.

As referenced in BSI’s recently released Supply Chain Risk Insights 2020 Report, the COVID-19 outbreak has highlighted the current fragility of global supply chains, wherein the failure of one link in the chain has the potential to cause extensive disruptions throughout.

As the pandemic has progressed, causing considerable disruption to every-day life and a negative impact on the workforce, companies have had to significantly re-evaluate their supply chains. Initially this was caused by the downtime and slowed restart of Chinese manufacturing, however the continued spread of the pandemic has led to complex and varied responses by individual governments to contain the virus, creating further disruptions and requiring businesses to adopt adaptive business continuity measures.

Whether this means that restaurants are closing their dining rooms and only providing carry-out and delivery, or hospitals restricting access to anyone other than critical patients, the New Not Normal is here and the need for comprehensive business continuity planning that considers all types of potential natural disasters, including disease outbreaks, has never been more acute.

Lessons learned from the COVID-19 outbreak about how to better mitigate disease spread and absorb delays to manufacturing and global shipping will shape how organizations and supply chains are effectively able to respond to other disruptions in the future.

For this reason, BSI is providing open access to SCREEN’s COVID-19 intelligence. “These insights will allow companies to sharpen their actions in the face of this crisis, focus their business continuity plans for their recovery and have a stronger continuity plan for the future,” said Jim Yarbrough, Global Intelligence Program Manager at BSI. “Our priority is to bring the global community reliable and actionable insights and information, curated by our team of experts, around COVID-19 to protect public health and mitigate business disruption.”

To view the SCREEN COVID-19 intelligence, visit: screen.bsigroup.com/Covid19/