GDPR and CCTV: What UK Businesses Must Do to Stay Compliant

CCTV is one of the most effective security measures a business can install. It deters crime, supports investigations and helps protect staff and customers. But the moment your cameras record identifiable people, you are processing personal data, and that brings legal responsibilities under UK data protection law.Many businesses install cameras without realising that GDPR applies to the footage. Getting it wrong can lead to complaints, enforcement action and fines. Getting it right is straightforward once you understand what the rules actually require.This guide explains what UK businesses must do to run CCTV lawfully, using current guidance from the Information Commissioner’s Office (ICO), the UK regulator for data protection.
Concrete Security Camera

What Does GDPR Require for Business CCTV?

  • CCTV footage of identifiable people counts as personal data under the UK GDPR and the Data Protection Act 2018.
  • You must have a clear, documented lawful basis for recording, most often legitimate interests.
  • Most businesses using CCTV must register with the ICO and pay an annual data protection fee, which ranges from £52 to £3,763 depending on size.
  • Clear signage must tell people they are being recorded, who is responsible and why.
  • You should only keep footage as long as you need it, then delete it securely.
  • People have the right to request footage of themselves through a subject access request.
  • Serious breaches can lead to ICO fines of up to £17.5 million or 4% of worldwide turnover, whichever is higher.

Why GDPR Applies to Your CCTV

Under the UK GDPR, personal data is any information relating to an identifiable living person. The ICO is clear that video footage showing recognisable faces falls squarely within that definition. If your cameras capture people who could be identified, your system is processing personal data and the law applies.

This covers far more than traditional cameras. ICO guidance extends to Automatic Number Plate Recognition (ANPR), body worn video, drones, facial recognition technology and even smart doorbells used in a business context. If it records identifiable people, it is in scope.

There is one clear exception. Domestic CCTV that only covers your own home and garden is treated as personal or household use and falls outside these business rules. Once a camera points beyond your boundary, or is used for business, the obligations begin.

You Need a Lawful Basis to Record

The ICO requires you to identify and document a lawful basis under Article 6 of the UK GDPR before you start recording. You cannot simply install cameras and decide why later.

For most businesses, the relevant basis is legitimate interests, such as preventing crime and protecting the safety of people and premises. The ICO points out that consent rarely works for CCTV, because you cannot realistically obtain genuine consent from everyone who walks into shot in a public space.

Whatever basis you choose, write it down. Record why the system is necessary, what problem it solves and why the intrusion is proportionate. This documentation is your evidence of compliance if the ICO ever asks.

Register With the ICO and Pay the Fee

If your CCTV processes personal data, you almost certainly need to register with the ICO and pay an annual data protection fee. This is a legal requirement under the Data Protection (Charges and Information) Regulations 2018, separate from any fine for a breach.

According to the ICO, the fee sits in three tiers based on your size and turnover:

  • Tier 1, for small organisations with turnover up to £632,000 or no more than 10 staff, is £52.
  • Tier 2, for organisations up to £36 million turnover or no more than 250 staff, is £78.
  • Tier 3, for larger organisations, is £3,763.

The ICO checks its register against Companies House and other sources to find businesses that have not paid. Failure to register can bring a separate penalty of up to £4,000, so this is one of the simplest compliance steps to get right.

Tell People They Are Being Recorded

Transparency is a core principle of the UK GDPR, and for CCTV it starts with signage. You must let people know, before or as they enter a monitored area, that recording is taking place.

Effective CCTV signs should:

  • Be clearly visible and readable at the points where people enter.
  • State that CCTV is in operation.
  • Explain the purpose, such as crime prevention and safety.
  • Name the organisation responsible for the cameras.
  • Provide contact details for questions or requests.

Good signage does two jobs. It meets your legal duty to be transparent, and it strengthens the deterrent effect of the cameras themselves.

Follow the Data Protection Principles

Article 5 of the UK GDPR sets out seven principles that should sit at the heart of how you run any CCTV system. In practice, this means recording only what you need and handling the footage responsibly.

The principles translate into these practical duties:

Only cover the areas you genuinely need, and avoid places where people expect privacy, such as toilets and changing rooms.

Limit audio recording, which the ICO says should be used only in rare circumstances as it is far more intrusive.

Keep footage secure, using measures such as password protection, restricted access and encryption where appropriate.

Restrict who can view live and recorded footage to authorised people only.

Keep footage only as long as necessary for its purpose, then delete it securely.

There is no fixed legal retention period. You set your own based on need, document it, and stick to it. Many businesses find that a short retention window of around 30 days meets most security purposes, but the right period depends on your circumstances.

When a DPIA Is Required

A Data Protection Impact Assessment (DPIA) is a structured way of identifying and reducing the privacy risks of your system. The ICO requires one wherever your processing is likely to result in a high risk to people’s rights.

For routine CCTV in a small shop, a full DPIA may not be mandatory, though it is good practice. For more intrusive systems, it becomes essential. This includes large scale monitoring, facial recognition, ANPR or any system that captures a lot of people or sensitive activity. If you are in doubt, completing one protects you and demonstrates accountability.

Respect People’s Right to Their Footage

Anyone recorded on your CCTV has the right to request a copy of footage showing themselves. This is called a subject access request, and the UK GDPR gives you a limited time to respond, usually one month.

When you release footage, you must protect the privacy of others who appear in it. That means redacting or blurring third parties before you share anything. The ICO expects your system to be capable of this, so it is worth checking that your setup allows footage to be exported and edited when you buy or upgrade it.

Keep Up With Changing Rules

Data protection law is not static. The Data (Use and Access) Act 2025 received Royal Assent on 19th June 2025 and made a number of reforms to the UK data protection framework, with changes being introduced in stages.

As a result, some ICO guidance, including parts of its CCTV and surveillance material, is under review and may change. The core obligations covered here remain in force, but businesses should review their arrangements periodically and check the ICO website for updates rather than assuming a system set up years ago is still compliant.

Getting CCTV Compliance Right

Running CCTV within the law is not complicated, but it does require care. Identify your lawful basis, register with the ICO, put up clear signage, secure your footage, set a sensible retention period and be ready to handle requests. Document each step as you go.

Businesses that treat compliance as part of the installation, rather than an afterthought, get the security benefits of CCTV without the legal risk. A system that is planned properly protects your premises and respects the people it records.

Need Expert CCTV Security Advice?

At Croma Fire & Security, we install CCTV systems that protect your business and are built with compliance in mind, from camera placement and signage to secure storage and footage retrieval. We help you get the security you need while meeting your data protection responsibilities.

If you would like advice on a compliant CCTV system or a new CCTV installation, contact Croma Fire & Security today to speak with one of our experienced security specialists.

Blog   Croma Locksmiths   UK

Roberto Fiorentino

Chief Executive Officer

About the Author

Roberto Fiorentino is Chief Executive Officer of Croma Security Solutions Group Plc and brings over 40 years of experience across the full spectrum of the security industry.

 

A recognised pioneer in the sector, Roberto has played a key role in evolving security from a traditional deterrent-based approach to the delivery of integrated, technology-driven solutions that actively protect people, businesses, and assets.

 

In the early 1990s, he was among the first to explore remote CCTV monitoring via telephone lines, later advancing to the development of remote mobile viewing over data connections—innovations that helped shape modern security practices.

 

Under his leadership, Croma has strengthened its core operations through a clear focus on technological innovation, alongside the successful execution of a number of strategic acquisitions.

Read More Insights