CCTV GDPR Rules for UK Employers and Property Managers


0
A security camera monitors an apartment entrance beside a privacy shield and GDPR document.
Visual guidance for responsible workplace surveillance

CCTV is a form of video surveillance that can solve one problem and create another. A surveillance system recording an identifiable person may fall under the UK GDPR, the Data Protection Act 2018 and wider UK privacy laws, making the footage personal data and bringing CCTV GDPR rules into play.

For employers, landlords and managing agents, the question is not whether cameras feel sensible. It is whether their use is necessary, properly documented and fair to the people being recorded. Start with the purpose, then build the system around it.

What CCTV GDPR rules apply to your property?

The UK GDPR and the Data Protection Act 2018 apply when an organisation uses video surveillance to capture identifiable people through CCTV. This includes workers, visitors, tenants, contractors and passers-by.

The Information Commissioner’s Office (ICO) expects organisations to apply the core data protection principles: lawful, fair and transparent processing; data minimisation; security; storage limitation; and accountability.

CCTV camera above a gated brick and glass property entrance at dusk.

Footage is personal data

Video footage is personal data when somebody can be identified directly or indirectly. A clear face is the obvious example, but clothing, a vehicle registration mark, location and time can identify somebody too.

Recorded sound creates an additional privacy issue. Audio is more intrusive than ordinary video and needs a stronger, practical justification.

Know who the data controller is

The data controller decides why video surveillance is used and how its surveillance system operates. In a managed building, that may be the freeholder, property management company, managing agent or employer. A security provider may be a processor acting under instructions.

Contracts should state those roles plainly. The controller remains accountable for the surveillance system, including notices, access requests and secure management of footage. It must also ensure the processor operates within its instructions.

Choose a lawful basis before switching cameras on

Security is a legitimate objective, but CCTV and other video surveillance aren’t automatically lawful because the aim is crime prevention. You must identify and document an Article 6 UK GDPR lawful basis before recording begins.

For many organisations, legitimate interests is the appropriate basis. The ICO’s surveillance data protection guidance explains that a lawful basis for video surveillance must be documented, not assumed.

Complete a legitimate interests assessment

A legitimate interests assessment, or LIA, should answer three direct questions:

  1. What legitimate interest is the CCTV protecting, such as preventing break-ins, vandalism or unauthorised access?
  2. Is recording necessary, or would better locks, lighting, access control or a different camera angle do the job?
  3. Does the security benefit outweigh the privacy impact on people recorded?

Your legitimate interests assessment should show why the surveillance system meets the test of necessity and proportionality. Keep the LIA and legitimate interests decision with your data protection records. Revisit them if camera positions, purpose or monitoring arrangements change.

Do not rely on consent at work

Employee consent is rarely a sound basis for workplace surveillance or monitoring. The power imbalance means workers may not feel able to refuse freely.

Be honest about the purpose. A camera installed to protect a reception area should not become a routine tool for measuring staff performance without a separate assessment and proper notice.

When a Data Protection Impact Assessment is mandatory

A Data Protection Impact Assessment, or DPIA, is required where video surveillance is likely to create a high risk to people’s rights and freedoms. It is also good operational discipline for any surveillance system that covers shared residential areas, large sites or staff workspaces.

The paperwork is not decorative. It should identify actual risks and record the measures chosen to reduce them, including necessity and proportionality.

High-risk uses need proper scrutiny

A DPIA is likely to be needed for extensive video surveillance of publicly accessible areas, cameras that systematically track workers, facial recognition, or surveillance in sensitive settings.

Assess the location, hours of operation, people affected and whether the surveillance system could reveal sensitive information. Cameras in toilets, changing rooms and similar private spaces will almost never be appropriate.

Consult workers and consider alternatives

The Information Commissioner’s Office says employers should involve workers, or their representatives, when planning monitoring, as set out in its worker monitoring guidance.

Record less intrusive options, even if you decide they don’t meet the security need. That short record can matter later, particularly after a complaint or incident.

Workplace CCTV cannot become constant supervision

Employers may use workplace CCTV for targeted video surveillance to protect people, premises and assets. However, video surveillance shouldn’t become background monitoring of ordinary employee behaviour because management prefers greater visibility.

A camera in a loading bay may be justified. A surveillance system aimed permanently at one worker’s desk needs a very different explanation. Continuous observation of an individual worker is unlikely to satisfy necessity and proportionality.

Keep purpose and camera placement aligned

Position cameras to cover entrances, stock areas, car parks or other genuine risk points. Keep the surveillance system away from private break areas, neighbouring homes and public pavements where possible.

If an incident requires reviewing footage, limit the video surveillance review to the relevant date, time and purpose. Casual viewing creates risk and weakens trust.

Treat audio with particular caution

Continuous audio monitoring of individual workers is justified only in rare circumstances. It can capture private conversations, health information and trade union discussion that video alone would not reveal.

Disable audio unless there is a clear, documented need. If it is retained, include the reason in the DPIA and privacy information.

CCTV should address a defined security risk, not fill gaps in day-to-day management.

Signs and privacy notices must be useful

People should know when video surveillance is operating before recording begins. A small sticker hidden behind a gate is not meaningful notice.

The ICO’s practical CCTV guidance for organisations sets out the basic expectation: clear signage, a stated purpose and contact details where the operator is not obvious.

Put signs where people can see them

Use signs at entrances to the monitored area and before people are recorded. They should say that video surveillance is operating, identify the purpose in plain terms and direct people to the fuller privacy notice.

For example: “CCTV operates on these premises for the prevention and detection of crime.” Include the controller’s contact details, or a clear route to them.

Give workers and tenants fuller information

A privacy notice should explain the controller, purposes, lawful basis, retention period, who receives footage and how people can exercise their rights. The CCTV policy should also identify these details, including when the lawful basis is legitimate interests.

Employees need this in an accessible workplace policy. Keep the privacy notice easy to find for residential tenants and visitors, including in communal entrances, car parks, lift lobbies and booking information. A surveillance system should never rely on signs alone.

Retention, access and sharing of CCTV footage

There is no fixed legal number of days for retaining commercial video surveillance footage. A company is not automatically compliant because it deletes recordings after 30 days, or because its surveillance system uses that default.

Set a period that matches the reason for recording. Your CCTV policy should document and justify the setting. Apply data minimisation, automate secure deletion where possible and retain a clip longer only when an incident, claim or investigation requires it.

Hands beside a locked evidence case and monitor in a dark security control room.

Set a retention period you can defend

A busy retail site may need enough time to identify theft or damage reported after the event. A low-risk office entrance may need less. The point is not to choose the shortest period without thought, but the shortest period that meets the stated purpose.

Review the setting regularly. Old video surveillance footage held “just in case” is difficult to justify.

Limit access and record disclosures

Only authorised people should view, download or export footage. Use access controls on the surveillance system, with individual accounts, strong passwords, encryption, export restrictions and an access log.

When sharing CCTV footage with police, insurers, solicitors or another party, verify the request and disclose only what’s relevant. Log what left the system, and don’t send an entire day’s recording for one clip. If a data breach occurs, secure the system, preserve logs and follow your response process.

Handling a CCTV subject access request

A person can make a data subject access request for CCTV footage showing them, often called a SAR or DSAR. The request can be verbal or written, and it doesn’t need legal wording.

Organisations usually have one calendar month to respond. Check the person’s identity where proportionate, then ask for the date, approximate time, location and a description if needed to locate the CCTV footage in your surveillance system. Don’t use these details to create unnecessary delay.

Protect other people’s privacy

Footage may include other individuals whose rights also matter. Redact, blur or crop third parties where possible before disclosing the recording.

The ICO’s SAR advice for organisations confirms that viewing footage may be an appropriate option where providing a copy would disclose other people’s data.

Keep a clear request record

Log the request date, identity checks, searches completed, decision, response and any redaction. If footage has already been routinely deleted, say so clearly.

Don’t delete relevant video surveillance recordings once you receive a request. Preserve them while the request is assessed.

Domestic CCTV is different, but not consequence-free

A domestic CCTV camera used wholly within a private property boundary may fall outside the UK GDPR’s domestic purposes exemption. The position changes when a doorbell camera records a shared hallway, neighbour’s garden, public space or communal car park. That home video surveillance system may then be subject to wider responsibilities.

This matters to landlords and property managers who install cameras at houses, blocks or managed estates. A surveillance system covering shared areas is not treated like a purely private camera.

Minimise what the camera captures

Angle cameras away from neighbouring windows and unnecessary public areas. Use privacy masking where the equipment allows it, switch off audio if it is not needed and delete recordings regularly. This supports data minimisation and helps avoid unnecessary intrusion under privacy laws.

The ICO’s home CCTV guidance also advises users whose systems capture beyond their boundary to display a sign and respond to access requests.

A communal area is not a private household space

A landlord’s camera in a shared entrance or a managing agent’s car-park system is organisational processing. Treat it as such, with a controller, lawful basis, privacy notice and CCTV policy explaining the purpose, retention period and access process.

The fact that a camera is small, wireless or attached to a doorbell does not reduce the responsibility. Video surveillance still needs appropriate controls, particularly where a communal surveillance system records residents, visitors or workers.

Key takeaways for responsible CCTV use

  • Define the purpose of your video surveillance, document how the surveillance system operates, who it protects, and what less intrusive option was considered.
  • Use an LIA for legitimate interests, and complete a DPIA where surveillance is likely to create high risk.
  • Give workers, tenants and visitors clear notice before recording begins.
  • Restrict viewing rights, set a justified deletion period and keep disclosure records.
  • Treat subject access requests as an operational process, not an awkward exception after an incident.

Frequently asked questions about CCTV GDPR rules

Can an employer monitor staff using CCTV?

Yes, where there is a genuine, documented security purpose and monitoring is necessary and proportionate. A workplace video surveillance system should not become constant observation of workers. Tell staff what it records, why and how long footage is kept.

How long can a business keep CCTV footage?

There is no universal legal retention period. Retain it only for as long as the stated purpose requires, then delete it securely. Keep incident footage longer only where there is a clear reason, such as an active police enquiry or insurance claim.

Does a home video doorbell need a privacy notice?

For domestic CCTV, the domestic exemption may apply when recording stays within your property boundary. If a doorbell captures beyond that boundary or into a public space, you may need a privacy notice and a process for handling access requests. You may also need to handle a DSAR appropriately. For complex arrangements, check current ICO guidance or seek tailored advice.

Does every CCTV system need a Data Protection Impact Assessment?

No. A DPIA is mandatory where processing is likely to create a high risk. For extensive video surveillance, a DPIA can test whether a proposed surveillance system is proportionate before installation. It is still a sensible measure for workplace, communal or extensive surveillance, because it tests whether the proposal is proportionate before the system is installed.

A defensible system is built before the first recording

Proper CCTV compliance is ordinary, unglamorous work: a clear purpose, sensible camera placement, good records and controlled access for video surveillance. A CCTV policy should record the lawful basis, including legitimate interests where appropriate, retention period, access controls, security measures and review date for the surveillance system. These details protect the organisation and the people on camera, while supporting compliance with privacy laws.

Check current Information Commissioner’s Office guidance and obtain specialist legal advice where the system is extensive, records audio, monitors workers closely or captures sensitive areas. This article offers general information, not a substitute for tailored legal advice. CCTV GDPR rules are easier to follow when privacy is part of the installation, not an afterthought.


Like it? Share with your friends!

0

What's Your Reaction?

hate hate
0
hate
confused confused
0
confused
fail fail
0
fail
fun fun
0
fun
geeky geeky
0
geeky
love love
0
love
lol lol
0
lol
omg omg
0
omg
win win
0
win

0 Comments

Your email address will not be published. Required fields are marked *

Cookie Consent with Real Cookie Banner