Get in touch with us and we'll get back to you within one business day.
If your business operates CCTV, you are responsible for ensuring that any footage containing identifiable individuals is handled in line with UK GDPR and data protection law. This includes establishing a lawful basis for recording, completing a Data Protection Impact Assessment where required, displaying clear privacy notices, setting an appropriate retention period, and responding correctly to subject access requests.
ICO CCTV compliance is not limited to the initial installation. Businesses must continue reviewing how cameras are used, who can access recordings, how long footage is stored, and whether the system remains necessary and proportionate.
This guide explains the practical steps London businesses should take to manage CCTV responsibly. For wider guidance on the legal considerations, read our overview of CCTV privacy laws. Our security surveillance and CCTV services can also be tailored around your premises, operational requirements, and ongoing data protection responsibilities.
CCTV footage is classed as personal data when it captures people who can be identified directly or indirectly. If your organisation decides why and how the system operates, it will usually act as the data controller and must comply with the UK GDPR and Data Protection Act 2018.
This means your CCTV use must follow the core data protection principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, storage limitation, security, and accountability. You must also identify and document an appropriate lawful basis before collecting footage. The ICO's video surveillance guidance confirms that organisations processing footage of identifiable individuals must meet these legal requirements.
These obligations apply throughout the CCTV system's lifespan, from planning and installation to monitoring, storage, disclosure, and deletion. They cover cameras used in public-facing areas, workplaces, car parks, reception areas, and other shared spaces. Your organisation should also assign responsibility for the system, keep its use under review, and ensure the cameras continue to serve a necessary and proportionate purpose.
A Data Protection Impact Assessment helps you identify and reduce the privacy risks associated with a proposed CCTV system. You must complete one before processing begins when the surveillance is likely to create a high risk to individuals, such as monitoring employees, recording private areas, or using more intrusive technology. The ICO also recommends considering a DPIA for any major project involving personal data.
A CCTV DPIA should clearly document what the system will record, including camera locations, coverage, audio capabilities, and the personal data captured; the purpose of the surveillance and the lawful basis relied upon; why the monitoring is necessary and proportionate, including whether less intrusive measures could achieve the same aim; the potential risks to employees, visitors, customers, residents, or members of the public; the safeguards used to reduce those risks, such as restricted access, encryption, limited coverage, and defined retention periods; and who reviewed and approved the assessment, along with the date of completion.
The DPIA must be completed before the cameras are activated. It should then be reviewed whenever the purpose, coverage, technology, or risks change significantly. If a high risk remains after reasonable safeguards have been applied, you must consult the ICO before beginning the processing.
Businesses must tell people that CCTV is in use before they enter a monitored area. Signs should be clearly visible and positioned at entrances or other appropriate points so visitors, employees, and customers understand that recording is taking place.
CCTV signage should state that CCTV is operating, why the surveillance is being used, which organisation controls the system, and how people can contact the organisation with questions. The ICO's CCTV guidance confirms that signs should be easy to see, explain the purpose of the monitoring, and provide contact information.
The sign can direct people to a fuller privacy notice containing more detailed information, including the lawful basis for processing, retention period, data-sharing arrangements, and how individuals can exercise their rights. The ICO describes this as part of the right to be informed under UK GDPR.
For sites with several entrances or monitored areas, signage should be placed wherever someone may enter the camera's coverage. Privacy notices and signs should also be reviewed whenever the system's purpose, camera coverage, retention period, or contact details change.
UK GDPR and the Data Protection Act 2018 do not set a fixed retention period for CCTV footage. Instead, your business must decide how long recordings are genuinely needed for the purpose for which they were collected. The ICO confirms that surveillance data should be kept only for the minimum period necessary, with the chosen timeframe clearly documented.
There is no automatic 30-day rule for commercial CCTV. A shorter or longer period may be appropriate depending on your premises, security risks, incident-reporting process, and the time normally needed to identify an event. Whatever period you choose must be necessary, proportionate, and supported by a clear business justification.
Your retention arrangements should include a documented retention period in your CCTV policy and privacy information; automatic overwrite or deletion settings that reflect the agreed timeframe; restricted procedures for preserving footage linked to an incident, investigation, or subject access request; regular reviews to confirm that the retention period remains appropriate; and records covering each camera's location, purpose, access controls, and retention arrangements. The ICO also advises businesses to establish a process for securely deleting footage once it is no longer required, and automatic overwrite functions should be checked regularly to make sure they are working as intended.
Individuals have the right to request access to personal data held about them, including CCTV footage in which they can be identified. Once a valid Subject Access Request is received, your business must usually respond without delay and within one month. This period may be extended by up to two additional months when a request is complex or several requests have been submitted, but the requester must be informed within the original deadline.
Your CCTV system and internal procedures should allow you to locate the relevant footage quickly; preserve it before the normal overwrite cycle deletes it; confirm the requester's identity where necessary; review whether other identifiable people appear in the recording; redact or obscure third-party information where appropriate; provide the footage securely and in an accessible format; and record how the request was assessed and handled.
Where other individuals appear in the footage, you may need to blur, mask, or otherwise remove identifying details before disclosure. If redaction is not possible, you must consider the rights of the requester alongside the privacy rights of those third parties before deciding what can reasonably be released.
A documented SAR procedure should be in place before a request arrives. Responsibility should be assigned to a named person or team, with clear processes for searching recordings, preventing deletion, applying redaction, approving disclosure, and recording the final response.
CCTV used in public-facing or shared areas requires careful planning because it may record customers, employees, residents, visitors, and members of the public. This includes systems operating in shops, car parks, reception areas, building entrances, corridors, lifts, and communal residential spaces.
Your cameras should capture only the footage needed for the stated security purpose. Their positioning, field of view, and recording settings should be reviewed to avoid monitoring neighbouring premises, public areas, or spaces where people have a greater expectation of privacy unless this is necessary and proportionate. The ICO's data minimisation principle requires organisations to collect only the personal data needed for their purpose and no more.
For each monitored area, your business should define and document the purpose of the camera; position it to minimise unnecessary or excessive recording; use privacy masking where parts of the image do not need to be captured; avoid toilets, changing rooms, and similarly private areas except in exceptional, clearly justified circumstances; display appropriate signs before people enter the monitored space; record the camera's coverage and justification within the DPIA; and review the footage periodically to confirm the camera remains necessary. The ICO advises that surveillance in areas such as toilets and changing rooms would not usually be fair or proportionate, and where exceptional circumstances justify such monitoring the organisation needs strong evidence and must clearly inform those affected.
CCTV compliance problems often arise when organisations install or operate surveillance systems without documenting why the monitoring is necessary, how personal data will be protected, or who is responsible for ongoing governance.
Common failures include operating CCTV without identifying and recording a valid lawful basis for processing personal data, which the ICO confirms every surveillance system requires; introducing monitoring that presents a high risk to individuals without completing a DPIA before recording begins; failing to tell people that CCTV is operating, why it is being used, and who is responsible; recording neighbouring premises, public areas, or private spaces beyond what is necessary for the stated purpose; keeping footage for longer than required without a documented reason or effective deletion process; allowing recordings to be viewed, copied, or shared by people who do not need access; being unable to locate, preserve, redact, and disclose relevant footage within the applicable SAR response period; and failing to update the DPIA, privacy notice, camera register, retention policy, or processing records when the system changes.
The ICO can investigate complaints and take enforcement action where CCTV footage is handled unlawfully or without appropriate safeguards. Its compliance checklist covers system management, camera positioning, signage, disclosure, and secure operation.
Although UK GDPR principles apply to all commercial CCTV systems, the practical requirements vary according to the premises, the people being recorded, and the purpose of the surveillance.
CCTV in offices requires particular care where cameras capture employees during their normal working day. Monitoring must be necessary, proportionate, and supported by a documented lawful basis. Employees should be told what is being recorded, why monitoring is taking place, and how the footage will be used. The ICO also advises employers to consult their workforce, particularly while completing a DPIA. Covert monitoring should only be considered in exceptional circumstances, such as a specific and time-limited investigation where informing those involved would undermine its purpose. Read our guide to CCTV rules in the workplace for further guidance on employee monitoring. Our corporate security services can also incorporate CCTV into wider access control and premises protection arrangements.
Retail CCTV commonly covers entrances, tills, shop floors, stockrooms, and delivery areas. Camera coverage should remain limited to locations where recording is necessary for purposes such as crime prevention, safety, and loss reduction. Cameras should not monitor toilets, changing rooms, or staff rest areas under normal circumstances. The ICO states that surveillance in private spaces would rarely be fair or proportionate and would require strong justification in exceptional cases.
CCTV and Automatic Number Plate Recognition systems in car parks must have a defined purpose and lawful basis. Signs should alert drivers to the use of cameras and provide sufficient information about who operates the system and why their data is being collected. The ICO specifically requires appropriate signage where cameras monitor roads or vehicle-accessible areas such as car parks. Camera positioning should also be proportionate and avoid capturing neighbouring properties or unrelated public areas where this is not necessary.
CCTV in residential blocks may capture residents, visitors, contractors, and delivery workers in shared spaces such as entrances, corridors, lifts, and car parks. Where a management company or building operator determines how and why the system is used, it will usually be responsible for meeting the relevant data protection obligations. Residents should receive clear information about the purpose of the cameras, retention periods, access arrangements, and how they can exercise their rights. For further information on choosing and operating a suitable system, read our guide to understanding CCTV surveillance systems.
Many London businesses appoint third-party providers to install CCTV systems, monitor live feeds, or store recorded footage. Where the provider processes personal data solely on your documented instructions, it will usually act as the data processor, while your business remains the data controller and retains overall responsibility for UK GDPR compliance.
Before monitoring begins, you should confirm each party's role and put a written data processing agreement in place. This agreement should define the nature, purpose, and duration of the processing; the categories of personal data and individuals involved; the security measures the provider must maintain; how subject access requests and data breaches will be handled; whether sub-processors may be appointed; how footage will be returned or securely deleted when the contract ends; and your rights to review, audit, and obtain evidence of compliance.
UK GDPR requires controllers to use processors that can provide sufficient guarantees that appropriate technical and organisational measures are in place, and a binding contract must contain the required Article 28 provisions. You should therefore assess the provider's access controls, staff training, data storage arrangements, incident procedures, and ability to support your compliance obligations. The contract does not transfer your responsibilities to the provider, so the arrangement should be reviewed regularly to make sure its practical operation still matches the documented terms.
We can help you plan CCTV monitoring around your premises, security requirements, and data protection responsibilities.
Explore our manned guarding services or view our security services to discuss a suitable approach for your organisation.
Sign up to our newsletter for the latest security news, information and updates.