Camarilla Data Security & IT Policy

Camarilla is committed to ensuring the confidentiality, integrity, and availability of data entrusted to us by clients, collaborators, and the public. As a video production and strategic communications business handling sensitive assets and narratives, we take data protection seriously and adhere to best practices across all areas of digital and physical security.

1. Data Handling & Client Confidentiality

  • All client data, including footage, documents, and communications, is treated as confidential and stored securely.

  • Access to client assets is restricted to essential personnel and subcontractors, all of whom are bound by confidentiality agreements or NDAs.

  • Client data is only used for agreed purposes and never shared without prior written consent.

2. Storage & Backups

  • Project files are stored on encrypted hard drives and cloud services with two-factor authentication (2FA) enabled.

  • Regular backups are maintained in secure, geographically separate locations to prevent data loss.

  • Raw footage and sensitive materials are retained only for as long as necessary, then securely deleted or archived upon client request.

3. Device & Network Security

  • All work devices are protected with strong passwords and biometric security where available.

  • Devices are regularly updated and protected with antivirus and endpoint protection software.

  • Public Wi-Fi is avoided for any transfer of sensitive information unless through a secure VPN.

4. File Sharing & Transfer

  • Encrypted cloud-based platforms (such as Frame.io, Google Workspace, or WeTransfer Pro) are used for file sharing.

  • Sensitive documents or media assets are shared using password-protected links and/or time-limited access.

  • Physical media (e.g. drives) are only used when absolutely necessary and are securely transported and tracked.

5. Subcontractor & Freelancer Access

  • All collaborators are briefed on data protection standards and only provided access to files essential to their role.

  • Contracts and NDAs are in place for all freelance or third-party contributors to protect client data and intellectual property.

6. Compliance

  • Camarilla complies with the UK GDPR and the Data Protection Act 2018.

  • Any data breaches or suspected breaches are reported and handled in line with legal requirements and best practice protocols.

  • We review and update our policies regularly to ensure alignment with evolving standards and regulations.