Guide

GDPR CCTV rules for businesses: what the ICO actually requires

Updated

Switching on a camera makes you a data controller. The obligations are not onerous, but they are real, and almost none of them come in the box.

Six things to have in place

  1. A documented lawful basis. The ICO says that for any use of surveillance systems you need to identify and document a lawful basis under Article 6 UK GDPR, and that because genuine consent is often difficult to obtain in public spaces, the appropriate basis is likely to be legitimate interests, or public task for a public authority. A legitimate interests assessment helps you demonstrate it.
  2. Signs people can actually read. The ICO's transparency checklist asks for signs that are clearly visible and readable, that explain the system is in operation, and that include the organisation operating it, the purpose, and basic contact details such as a website, telephone number or email address, sized for the context.
  3. A retention period you decided on purpose. See how long CCTV footage should be kept.
  4. A way to answer subject access requests. The ICO expects personal data to be easily retrievable in response to a subject access request, and systems to be capable of redacting footage where third parties need to be obscured. See CCTV subject access requests.
  5. A DPIA where the risk is high. The ICO states a DPIA must be performed for processing likely to result in a high risk to individuals, including processing special category data, monitoring publicly accessible places on a large scale, or monitoring individuals at a workplace. If high risks cannot be mitigated, prior consultation with the ICO is required.
  6. Registration and the data protection fee. The ICO states that if you are a controller and your surveillance system processes the personal data of identifiable individuals, you are required to register and pay a data protection fee, unless exempt or already paying it.

Records of processing

Article 30 UK GDPR requires organisations to maintain a record of processing activities, and the ICO says this applies to both controllers and processors using surveillance systems. The record should cover the purposes of the surveillance, any data sharing agreements, and the retention periods. In a small business that is a page, not a project, but it needs to exist before someone asks for it.

Necessary and proportionate, not just possible

The ICO is direct that surveillance should not be seen as the cure to the problems an organisation faces, but a supporting tool where it is lawful, necessary and proportionate. In practice that means being able to say what problem each camera solves, and being willing to move or remove one that does not. Cameras in toilets, changing areas or covering a neighbour's garden are where complaints come from.

Buying with compliance in mind

  • Ask whether the system can export a single clip with third parties redacted, without you buying separate software.
  • Ask how footage is deleted at the end of the retention period, and whether that happens automatically.
  • Ask who can access the recorder remotely, including the installer, and get that in writing.
  • Ask for signage as part of the installation, positioned where people see it before they are recorded.
  • Keep the installer's handover pack: camera positions, retention setting and access list are what your records of processing are built from.

The ICO's detailed guidance is aimed at larger organisations, and it points small businesses to its own small business resources. Both say the same things: know why you are recording, tell people, keep it no longer than you need, and be able to hand over a copy when someone asks.

Questions, answered directly

Do I need to tell people I have CCTV?

Yes. The ICO's transparency checklist asks for signs that are clearly visible and readable, explaining that the system is in operation, and naming the organisation operating it, the purpose, and contact details such as a website, telephone number or email address. Sign size should suit the context, for example whether the signs are read by pedestrians or drivers.

Do I need to register with the ICO for CCTV?

The ICO states that if you are a controller and your surveillance system processes the personal data of identifiable individuals, you are required to register and pay a data protection fee, unless you are exempt or already pay it.

Do I need a DPIA for business CCTV?

You must carry one out where the processing is likely to result in a high risk to individuals. The ICO gives three examples that cover many business systems: processing special category data, monitoring publicly accessible places on a large scale, and monitoring individuals at a workplace. Where high risks cannot be mitigated, you must consult the ICO before deploying.

Get a specification, not a camera count.

Two minutes of questions and commercial CCTV installers who cover your postcode quote you directly. Free, no obligation.

Get CCTV quotes