In brief
The footage from your workshops is industrial data. Knowing which territory it is hosted in, who can technically access it, and what happens to the system if your supplier stops the service is no longer a security question: it is an information-systems question. Here are the three questions to put to your provider, and what to look for in the answers.
For a long time, video surveillance on an industrial site was a guarding matter. You installed cameras, plugged a recorder into a technical room, and that was that. The IT department was not in the loop — there was not much to put in it.
That time has passed. A modern camera is a computer: it has an operating system, an address on your network, user accounts, and it produces a continuous stream of data. Multiply it by forty across a site, then by the number of sites in the group, and it becomes one of the largest estates of connected devices in the company — and often the least well maintained.
What is a sovereign video protection solution?
A video protection solution is described as sovereign when the data it produces is hosted on national territory, subject only to national and European law, and when the operator retains control over access, updates and service continuity — without depending on a decision taken outside the European Union.
The distinction matters, because “data hosted in France” is not enough. A datacentre located in France but operated by a company subject to extraterritorial legislation does not place your footage beyond the reach of that legislation. The question is not only where the data sits, but which law it falls under and who technically holds the keys.
Why the question is now landing on the CIO’s desk
Three movements have converged.
The first is regulatory. The European NIS2 directive significantly widens the scope of organisations subject to cybersecurity obligations, bringing in industrial and logistics sectors that were previously outside it. The GDPR, for its part, has governed the processing of footage since 2018 wherever it allows individuals to be identified — which is the case in a production area where employees work.
The second is technical. Attacks on industrial companies increasingly come through poorly maintained peripheral equipment, and cameras are part of that: firmware never updated, factory accounts left in place, no network segmentation. A forgotten camera sitting on the same VLAN as production is a door.
The third is contractual. A system whose operation depends on a foreign online service is a system whose availability escapes you. A change in pricing policy, the discontinuation of a product line, or a distant regulatory decision can render unusable an installation you have paid for.
Worth remembering: sovereignty is not a patriotic argument, it is a continuity clause. It answers a very concrete question — if my supplier disappears or changes its mind, will my installation still work tomorrow morning?
The three questions to ask your provider
They fit into three sentences and can be asked without being a specialist. It is the answers that are instructive.
1. Where is the footage hosted, and which law governs the host?
Ask for the country where the servers are located and the nationality of the company operating them. A precise answer is a good sign; an answer that talks about a “secure cloud” without naming either the location or the operator is a bad one.
2. Who can technically access the streams, outside my own teams?
Any supervised system involves maintenance access. The question is not to remove it, but to know who holds it, how it is logged, and whether you can revoke it yourself. A serious provider shows you the access log without you having to insist.
3. What happens if you cease trading or discontinue this product?
This is the question that brings dependencies to light. If the answer is that the hardware becomes unusable, you do not own your installation: you are renting the use of it, on revisable terms.
A camera is a network device: what that implies
Treating the video estate as an IT estate changes practice. The points we systematically check during an industrial site audit:
- Network segmentation — the video estate must be isolated from both the production network and the office network.
- Accounts and passwords — no factory accounts left in place, named credentials, and differentiated rights by profile.
- Firmware updates — with an inventory of devices and a defined update cycle, not on an ad-hoc basis.
- Stream encryption — between cameras, recorder and operating workstations.
- Traceability of viewing — knowing who watched what, and when. This is also a GDPR requirement.
- Retention periods — configured and documented, with automatic purging at expiry.
On that last point, a useful reminder: the GDPR requires retention to be limited to what is necessary, that filmed individuals be informed, and that a system must not place an employee under permanent surveillance at their workstation. The precise arrangements should be checked with your national data protection authority — in France, the CNIL, which publishes regularly updated sector recommendations.
What if the existing installation does not tick these boxes?
That is the most common situation, and it does not call for a complete replacement. On the industrial sites we take over, a significant share of the equipment in place remains usable: what is missing is generally the supervision layer, the upkeep of the estate and control over access — not the cameras.
The approach we propose therefore starts with an inventory of what exists: what can be kept, what must be replaced for security reasons, and what can wait. Current contracts are taken over as they fall due, site by site, without interruption of service. It is slower than a wholesale replacement, and considerably less expensive.
One industrial group entrusted us with taking over its estate on the back of a simple observation: it could not answer the first of the three questions above. Unifying supervision and overhauling access management were carried out on the existing estate, without a full redeployment.
Frequently asked questions
What is a sovereign video protection solution?
It is a solution whose data is hosted on national territory and subject only to national and European law, and whose operator retains control over access, updates and service continuity, without depending on a decision taken outside the European Union.
Is hosting the data in Europe enough to be sovereign?
No. A datacentre located in Europe but operated by a company subject to extraterritorial legislation does not put the data beyond the reach of that legislation. You have to consider the hosting location, the law applicable to the operator, and who technically holds the access keys.
Does NIS2 apply to video surveillance cameras?
NIS2 widens the scope of organisations subject to cybersecurity obligations, bringing in industrial and logistics sectors. Since cameras are network devices connected to the information system, they fall within the assets to be secured for the entities concerned. Precise applicability depends on the sector and the size of the company.
How long can video footage be kept?
The GDPR requires retention to be limited to what is necessary for the purpose pursued. National data protection authorities publish recommendations on usual retention periods and on informing filmed individuals; those recommendations are the reference for configuring a system.
Does an existing installation have to be replaced entirely?
Rarely. On most industrial sites, a large share of the equipment remains usable. What is most often missing is the supervision layer, the upkeep of the estate (firmware, accounts, segmentation) and control over access. A preliminary inventory distinguishes what must be replaced from what can be kept.
Take stock of your estate
A conversation to position your existing installation against the three questions in this article.
Contact us