Since the adoption of GDPR CCTV data has become distinctly privacy sensitive. Subsequently, the criticality of systems storing CCTV data was revised (and increased), and access control measures need to be adapted accordingly. This impacted the governance of access to these systems, the periodical reviews on access, and the actual control measures in place for these systems. This discussion will cover key questions security professionals should address when considering access to such systems post GDPR.