Skip to content

Audit trail for your camera system: see who viewed which footage

Written and reviewed by , security adviser and certified engineer at CameraInstallatie.nl · updated 8 oktober 2026

Something happened, and someone played back the footage. Or exported it. Or a camera was switched off at exactly the wrong moment. As an administrator you want to know one thing: who was it? That is what the audit trail of your camera system is for.

Short answer

Which video surveillance system shows which user did what?

A video management system with an audit trail, such as Nx Witness. It records who logged in and from which IP address, who watched live or played back, which camera and which time window, who exported and who changed a setting. A standalone recorder with one shared login can’t, because there everyone is the same user.

The Nx Witness audit trail keeps 183 days by default, and you can set it longer. You filter by period, user and type of action, and export the entries as HTML or CSV.

What it records

What does the Nx Witness audit trail log?

  1. Every session. Who logged in, when, for how long, and from which IP address.
  2. Viewing. Who watched live and who played back, with the cameras and the time window.
  3. Exports. Who saved footage to take away.
  4. Changes. Changes to cameras, servers and settings.
  5. Users and permissions. Since version 6 also who added users to groups, and who connected or shared the system through the cloud.

Only administrators and power users can view the audit trail. Entries of users who have since been deleted remain.

Why it matters

Why do you need an audit log when nothing is wrong?

Because you only miss it when something is wrong. And then it is too late to switch it on.

A few situations we come across. An employee claims a colleague passed on footage of him. An insurer asks who exported the clip of the break-in, and when. A camera was off on the evening of an incident and nobody knows why. Without an audit trail it stays a suspicion. With one you see: this account, this camera, at 14:32.

It is not a theoretical risk. In a case described by the US Department of Justice, a technician at an alarm company linked his own email address to around 200 customer accounts and viewed their cameras more than 9,600 times. With a personal account per user and an audit trail you can trace something like that. With a shared login you never can.

GDPR

Is unauthorised viewing of CCTV footage a data breach?

Under the GDPR, yes. Camera footage is personal data, and unauthorised access to personal data is a personal data breach. That includes a former employee still watching with an old login.

A breach has to be reported to the supervisory authority within 72 hours, unless it is unlikely to result in a risk, and every breach has to be documented internally, reported or not. To make that assessment you need to know what was viewed. Without an audit trail you can’t even check.

Frameworks

What do NIS2 and ISO 27001 say about logging?

ISO 27001 has logging as a separate control (Annex A 8.15): logs that record activities, are kept and protected, and are reviewed. NIS2 member-state rules work in the same direction; the Dutch implementation asks you to log relevant events, keep the logs for a set period and protect them against changes. If your camera system sits on your network, it is part of that.

So document how long you keep the camera system’s audit trail, and why. The default half year is fine for many organisations. If you want or need longer, you set it.

Honest

Where are the limits of the audit trail?

It is stored per server. On a system with several servers each server keeps its own part. We read it out centrally and combine it into one export.

An administrator can switch it off. It is on by default. That is exactly why the admin account belongs to one person, and not to everyone who ever got the login. More on that in the offboarding checklist for security systems.

How the audit trail fits into access management across all your sites is on access management for cameras, alarms and intercoms. Or test your own situation with the access check.

Questions about the audit trail

How long does Nx Witness keep the audit trail?

183 days by default. You can set it longer. Document the period you choose in your policy.

Can I export the audit trail for an investigation?

Yes. You filter by period, search term and type of action, and export the entries as HTML or CSV. With several servers we merge the exports for you.

Who can view the audit trail?

In Nx Witness only administrators and power users. Document who those are in your organisation, and keep the group small.

Should employees know there is an audit trail?

They should. Include it in your camera policy and, if there are cameras in the workplace, in your agreements with employee representatives. An audit trail everyone knows about also works as prevention.

Can you show who watched?

We switch on the audit trail, set the retention and show you how to read it. Also on a system that wasn’t ours.

Marc Herdes, Mede-oprichter en beveiligingsspecialist

A quick word

Questions about your situation? Call Marc.

Has worked in security since 1999. On large migrations he is there himself on day one. Describe your situation and you will hear straight away what we would do — with no obligation.

Marc Herdes · Co-founder and security specialist

Want to talk it through?

Tell us what you have and what you want to be able to do

You will hear within one working day what is possible, what it costs and what we would do — including if that turns out to be less than you expected.

  • Reply within 1 working day
  • Advice is free
  • No obligation whatsoever

Rather speak to someone now?
036 52 90 007 or send us a WhatsApp message

Leave your details

We will call or email you back with a concrete answer.

We only use your details to get in touch. privacy policy.