In this context, urban security management plays a key role. For example, video management systems, consisting of cameras installed in public spaces capable of recording and transmitting images, represent one of the most sensitive areas in terms of information protection.
According to Rafael Martín Enríquez, Sales Director Southern Europe at Genetec, “solutions like Security Center SaaS demonstrate how video management solutions within the European public administration can evolve in a modern and efficient way, while guaranteeing full compliance with current regulations, even in highly sensitive and regulated environments.”
Cloud and Security: What the Regulations Say
Faced with digital transformation, public sector organizations often find themselves at a crossroads. The desire to modernize and improve efficiency is frequently tempered by concerns related to data security, regulatory compliance, and, in some cases, the need to obtain approval from supervisory bodies. However, authorities in countries such as France and Italy allow the use of external cloud services, including the storage of sensitive data, provided they meet the security and data protection requirements established by European regulations.
Security Center SaaS does not impose restrictions on the use of video management systems deployed in public sector environments. Its regulatory compliance framework is based on two key regulatory pillars:
• GDPR (EU Regulation 2016/679):
Genetec guarantees high standards of personal data protection and rigorous management of access rights, ensuring that all data access occurs exclusively under the client's control.
• NIS2 Directive:
The Genetec platform enables and facilitates compliance with its requirements.
Certifications and Azure Infrastructure
In public sector environments that manage sensitive data, certifications are essential for building trust.
The services provided by Genetec solutions are based on an Information Security Management System (ISMS) certified according to ISO standards, including:
• ISO/IEC 27001 (information security management)
• ISO/IEC 27017 (cloud security)
• Coming soon, ISO/IEC 27018 for the protection of personal data in cloud environments
These certifications are complemented by:
• SOC 2 Type II audits (AICPA)
• CSA STAR Level 1 certification
• Annual third-party penetration tests based on the OWASP Top 10 vulnerabilities
From an operational standpoint, Security Center SaaS runs on the Microsoft Azure cloud platform. The data centers used for public administration are located within the European Union, specifically in the Netherlands, ensuring compliance with GDPR requirements.
Rafael Martín Enríquez of Genetec adds that “the effectiveness of this approach is demonstrated by real-world deployments; for example, several European municipalities have adopted Security Center SaaS to manage their urban video surveillance systems, benefiting from a secure and scalable platform that improves operational efficiency while meeting strict regulatory and data protection requirements.”
For more conservative public administrations: the hybrid approach
For more conservative local administrations or those subject to specific restrictions, there is a strategic architectural option: a hybrid configuration enabled by Cloudlink, Genetec's hardware device that acts as a secure bridge between local cameras and the cloud platform.
Using Cloudlink allows organizations to:
• Record video data locally, maintaining physical control of the recordings on-premises.
• Keep sensitive data within national borders, eliminating the risks associated with international data transfers.
Although it is not a legal requirement, the integration of this component is an effective recommendation to facilitate the adoption of the cloud by the most prudent administrations, offering the ideal balance between the efficiency of the SaaS model and the total control of an on-premise infrastructure.
