Skip to main content

GOVERN · COMPLIANCE & PRIVACY

Privacy isn’t a setting you remember to turn on. It’s the way the data model works.

In Sentinel, privacy rules are enforced by the platform: no watching without a recorded lawful basis, no face detection without a signed impact assessment, and authorization that lapses suspends itself. Subject rights, retention, and breach timelines live in the same console as the live operation.

Lawful-basis card on a watchlist entry showing basis type, document reference, expiry date, and an ACTIVE status pillClick to enlarge

Lawful basis required on every watched subject — enforced, not optional.

6
Lawful-basis types
selectable on every watched subject
30 days
Subject-access SLA
tracked with T-5 / T-1 / overdue reminders
72 hours
Breach-notification clock
reminders at T-24h, T-12h, and T-1h
Nightly
Retention enforcement
per camera, zone, and event type — holds honored
Authorization

Lawful basis required on every watched subject.

Every watchlist entry targeting an individual requires a recorded lawful basis — enforced by the platform, not left to policy.

  • One of six basis types — judicial order, consent, vital interest, legitimate interest, public task, or contract
  • A document reference for the order, consent form, or authority that grants the basis
  • An expiry date for when the authorization stops being valid
  • A last-reviewed timestamp, so an auditor can see the basis is current, not stale
  • Alerts auto-suspend the day authorization lapses — the system stops watching a subject it is no longer permitted to watch
Watchlist entry showing basis type, document reference, expiry date, and an amber "Expiring in 12 days" bannerClick to enlarge

Authorization that lapses suspends itself.

Subject Rights

Subject access — record, verify, export or erase — in one workflow.

Sentinel handles the full subject-access lifecycle in one workflow — export assembles a portable hashed bundle, erase permanently removes the face vector, identity links, and crops, and every step is recorded against the requesting officer.

  • Open a request with subject, contact, identity-verification document, and request type
  • Clear lifecycle: received → verifying → processing → fulfilled or rejected, with a per-request audit trail
  • Export: portable bundle sealed with a hash, delivered by a one-time signed link
  • Erase: face vector deleted, event identity links nullified, face crops removed — events retained for evidentiary integrity
Subject-access request detail with lifecycle stepper, Access + Erase request type, and Export bundle / Erase subject actionsClick to enlarge

The whole subject-access workflow in one screen, on the clock.

Keep Only What You Should

Retention enforced automatically. Litigation holds always win.

Sentinel enforces retention on the schedule you set — per camera, zone, and event type — and logs every removal, while litigation holds protect whatever must be kept until explicitly released.

  • "Face matches 30 days, weapon alerts a year, motion 7 days" — configurable per camera, zone, and event type
  • Nightly enforcement removes aged events, crops, and clips — per-run audit entry with counts
  • Litigation holds always win: held material is skipped by retention until explicitly released
  • Every policy change is audit-logged
Retention policy table showing per-camera and per-event-type day counts with a "held — skipped" indicatorClick to enlarge

Retention rules you set, enforced by the platform every night.

More controls

Eight controls that make video intelligence defensible.

DPIA required before detection

A signed impact assessment can be mandated before face or plate intelligence is enabled on a camera — status pill (Signed · Pending · Expired) tells the DPO which cameras are cleared at a glance.

Per-camera privacy notice

Sentinel generates printable signage per camera from the same record that drives the impact assessment — controller, purpose, DPO contact — with a last-printed timestamp so signage cadence is provable.

Subject-access SLA tracking

A daily scan watches every open subject-access request against the 30-day statutory window and surfaces a red overdue marker on the most urgent request so the DPO never misses a deadline.

Breach workflow with the 72-hour clock

Open a breach record and the notification clock starts from detection. A guided flow tracks status from detected to closed, with reminders at T-24h, T-12h, and T-1h — and an immediate escalation if the window is missed.

Data-protection officer of record

One DPO contact per organization — name, email, phone, address, jurisdiction — automatically surfaced on camera privacy notices, subject-access correspondence, and breach notifications.

How it works

From authorization to erasure, the controls stay on.

1

Authorize

Before a person is watched, an officer records the lawful basis, document reference, and expiry. Before a camera runs detection, a DPIA is signed against it. No basis, no watching; no assessment, no detection.

2

Inform & Retain

Each camera generates its own privacy notice for signage, and a retention policy defines how long its events, crops, and clips live. A nightly job enforces the policy and logs what it removed.

3

Review automatically

Crons watch the deadlines: lawful bases expiring within 30 days are flagged and lapsed ones suspend their alerts; subject-access requests are tracked to the statutory window; breach records count down to 72 hours.

4

Respond to the subject

When an individual exercises their rights, the DPO opens a request, verifies identity, then exports the subject's data or erases it — face vector, event links, and crops — with the whole exchange on the audit record.

Specifications

What’s in the box.

Lawful basis typesJudicial order · consent · vital interest · legitimate interest · public task · contract
Lawful basis fieldsBasis type, document reference, expiry date, last-reviewed timestamp
Lawful basis reviewNightly cron flags bases expiring within 30 days; auto-suspends alerts on lapse
DPIA recordPurpose, data subjects, retention window, lawful basis, signed-by, signed-at
DPIA enforcementCan be required before face/plate detection is enabled on a camera; status pill: Signed · Pending · Expired
Privacy noticePer-camera printable signage — controller, purpose, DPO contact; last-printed timestamp
Subject access requestSubject, contact, identity-verification doc, type (access / erase / both); lifecycle: received → verifying → processing → fulfilled / rejected
DSAR exportPortable bundle: events, watchlist entries + lawful basis, related audit records, per-camera DPIA reference; hashed, one-time signed link
DSAR eraseDeletes face vector, nullifies event identity links (events retained), deletes face crops; permanent; recorded against requesting officer
DSAR SLA30-day window tracked; reminders at T-5, T-1, and overdue; overdue flag in the queue
Retention scopePer camera, per zone, per event type, with an org-wide default
Retention enforcementNightly job removes aged events / crops / clips; per-run audit with counts; honors litigation holds
Breach clock72-hour notification timer from detection; reminders at T-24h, T-12h, T-1h; escalation + banner if missed
Frameworks supportedPDPL · GDPR · RIPA · CJIS — controls map to lawful basis, accountable controller, documented retention, subject rights, and breach notification. These are frameworks we support, not endorsing authorities.
DeploymentIdentical controls in cloud, on-premise, and air-gapped modes

Frameworks listed (PDPL · GDPR · RIPA · CJIS) are frameworks we support — not named customers or endorsing authorities. Every control above maps to a shipped platform capability.

See privacy enforced, not promised.

Request demo access and we’ll walk it on live data — set a lawful basis on a watched subject and watch its alerts suspend when we expire it, open a subject-access request and export the bundle, then erase the subject and confirm the face vector, the crops, and the identity links are gone.