Introduction
CCTV is one of the most effective ways to protect premises, staff, and assets. But in the UK, using surveillance cameras isn’t just about security — it also means following strict legal requirements.
Failing to comply with CCTV laws can expose your business to fines, reputational damage, and even enforcement action from the Information Commissioner’s Office (ICO).
This guide explains the key CCTV laws in the UK, how GDPR applies to surveillance, and the steps every business and installer should follow to stay compliant.
The Legal Framework for CCTV in the UK
CCTV use is governed by several pieces of legislation:
-
Data Protection Act 2018 (DPA 2018) – Implements GDPR in the UK and sets rules for processing personal data.
-
UK GDPR – Applies to all personal data, including video footage where individuals can be identified.
-
Human Rights Act 1998 – Protects privacy rights and ensures surveillance is proportionate.
If your CCTV captures identifiable individuals — staff, visitors, or the public — it falls under these regulations.
Key Legal Responsibilities
1. Clear Signage
You must inform people that they’re being recorded. This means:
-
Placing visible signs near cameras
-
Including the purpose of recording (e.g., crime prevention)
-
Adding contact details for the organisation responsible
2. Data Storage & Retention
-
Footage should only be stored as long as necessary — typically 30 days unless required for investigation.
-
Access must be restricted to authorised staff only.
-
Systems must be secure to prevent tampering or unauthorised use.
3. Subject Access Requests (SARs)
Individuals have the right to request a copy of footage where they appear. You must:
-
Provide this within one month (unless exemptions apply)
-
Ensure other people’s identities are protected (e.g., by blurring)
4. Lawful Purpose
CCTV must be used for a legitimate reason (e.g., crime prevention, health and safety monitoring). You cannot use CCTV to monitor staff without justification.
GDPR and CCTV
Under GDPR, CCTV footage counts as personal data. This means:
-
You need a lawful basis for processing (usually legitimate interests).
-
You must keep a record of processing activities.
-
Security measures (encryption, password protection, restricted access) must be in place.
If you’re an installer, advising clients on GDPR compliance is critical.
Installer’s Quick Checklist
✅ Carry out a Data Protection Impact Assessment (DPIA) before installation
✅ Position cameras to avoid unnecessary coverage (e.g., private property)
✅ Display clear, visible signs at all entrances
✅ Configure systems for automatic deletion after retention period
✅ Provide clients with a CCTV compliance policy
Consequences of Non-Compliance
The ICO has the power to:
-
Issue fines up to £17.5 million or 4% of global turnover under GDPR
-
Order removal of CCTV systems
-
Publicly name organisations in breach
For businesses, non-compliance isn’t worth the risk.
Conclusion
CCTV is an essential tool for security — but only if used responsibly and within the law. By following the UK’s CCTV regulations, you protect not only your property but also your reputation.
At Securetronics, we supply compliant CCTV solutions and offer expert guidance for businesses and installers.
👉 Explore our CCTV range or contact us today for advice on staying compliant.