CCTV Compliance Check: Ensure UK Data Protection Laws
Verify your CCTV systems meet UK GDPR & DPA 2018 standards to avoid fines and legal risks
Why data-protection paperwork matters under UK GDPR
Every day, UK businesses—from high-street shops to small offices—rely on CCTV to deter crime, monitor premises, and protect staff. But many don’t realise that running a camera system isn’t just about security: it’s about data protection compliance. Under the Data Protection Act 2018 (DPA2018), CCTV footage is personal data, and how you collect, store, and use it can expose your business to fines, complaints, or even enforcement action from the Information Commissioner’s Office (ICO).
The risks aren’t theoretical. In 2023, the ICO issued multiple fines to businesses for CCTV breaches—including a £100,000 penalty for a company that failed to properly inform employees about workplace monitoring. Even small oversights—like missing signage or keeping footage for too long—can trigger subject access requests (SARs), complaints, or reputational damage.
This isn’t just a problem for big corporations. Small businesses, landlords, and community groups are just as likely to be caught out. If you use CCTV, you must have a CCTV compliance document—a written policy that explains why you’re recording, how long you keep footage, and how you protect people’s rights. Without one, you’re operating in the dark, and the ICO won’t accept ignorance as an excuse.
Is your document complete and internally consistent?
A strong CCTV compliance document isn’t just a formality—it’s your first line of defence if the ICO investigates. A "good" document should:
- Clearly state why you’re using CCTV (your legitimate interest).
- Explain how you inform people (signage, privacy notices).
- Set retention limits (how long you keep footage).
- Cover workforce monitoring (if you record employees).
- Include data protection safeguards (who can access footage, how it’s secured).
If your document is vague, outdated, or missing key details, you’re leaving gaps that could cost you.
UK GDPR and the Data Protection Act 2018 — plain English
The Data Protection Act 2018 (DPA2018) is the UK’s main data protection law. It doesn’t ban CCTV, but it regulates how you use it. Here’s what it means for your business:
- CCTV footage is personal data – If your cameras capture people (even in public), you’re processing their personal data. That means you must comply with data protection principles, like fairness, transparency, and security.
- You need a lawful basis – The most common basis for CCTV is "legitimate interest" (e.g., crime prevention, health and safety). But you must document why your interest outweighs people’s privacy rights.
- People must know they’re being recorded – You can’t just point a camera at a pavement or staff area without clear signage and a privacy notice explaining why you’re recording.
- You can’t keep footage forever – The DPA2018 says you must delete data when you no longer need it. Keeping footage "just in case" isn’t good enough.
- Workforce monitoring has extra rules – If you record employees, you must balance your business needs with their privacy. Covert monitoring is almost always illegal.
The ICO has detailed guidance on CCTV, but many businesses still get it wrong. The key is having a written policy that proves you’ve thought about these rules—and that’s where a CCTV compliance check comes in.
Five privacy-document checks organisations miss
1. CCTV signage: Are you telling people they’re being recorded?
Why it matters The DPA2018 requires you to be transparent about CCTV. If people don’t know they’re being recorded, you’re breaking the law. The ICO has fined businesses for missing or unclear signs—even if the cameras were obvious.
What "good" looks like
- Signs are visible at all entry points (not just near the camera).
- They include:
- A clear statement (e.g., "CCTV in operation").
- Your business name (so people know who’s recording them).
- A contact point (e.g., email/phone for data requests).
- A brief reason (e.g., "for crime prevention").
- Signs are large enough to read (not tiny stickers).
Practical tip Walk your premises as a customer would. If you can’t see a sign from where people enter, you’re not compliant. Update signs if you move cameras or change your policy.
How VetroCheck helps VetroCheck’s CCTV Compliance Check scans your document for signage requirements and flags missing details—so you can fix gaps before the ICO does.
2. Retention: Are you keeping footage for too long?
Why it matters The DPA2018 says you must delete personal data when you no longer need it. Keeping CCTV footage "just in case" isn’t a valid reason—and it increases your risk if there’s a data breach or SAR.
What "good" looks like
- Your policy sets a clear retention period (e.g., 30 days).
- You automatically delete footage after that period (no manual overrides).
- You document exceptions (e.g., footage kept for legal disputes).
- You don’t keep footage indefinitely (even if it’s "useful").
Practical tip Check your DVR/NVR settings. Many systems default to "keep forever"—change this to match your policy. If you keep footage for legal disputes, note the date and reason in a log.
How VetroCheck helps VetroCheck’s check highlights retention gaps in your document and suggests improvements—like adding a deletion schedule or explaining exceptions.
3. Legitimate interest: Can you prove your reason for recording?
Why it matters Most businesses rely on "legitimate interest" as their lawful basis for CCTV. But the ICO can challenge this if your interest isn’t necessary and proportionate. If you can’t justify why you’re recording, you’re at risk.
What "good" looks like
- Your policy explains your specific interest (e.g., "to prevent theft in our shop").
- You’ve done a legitimate interest assessment (LIA)—a short document weighing your interest against people’s privacy rights.
- You limit recording to what’s necessary (e.g., not recording staff break rooms unless there’s a proven need).
- You document alternatives (e.g., "we considered security guards but CCTV is more cost-effective").
Practical tip If you haven’t done an LIA, do one now. The ICO provides a template. Keep it with your CCTV policy.
How VetroCheck helps VetroCheck’s check reviews your legitimate interest statement and flags weak or missing justifications—helping you clarify the document record.
4. Workforce monitoring: Are you recording employees fairly?
Why it matters Recording employees is high-risk. The DPA2018 and ICO guidance say you must balance your business needs with their privacy. Covert monitoring (e.g., hidden cameras) is almost always illegal, and even overt monitoring can lead to complaints or tribunal claims.
What "good" looks like
- Your policy explains why you’re monitoring staff (e.g., "to prevent fraud at the till").
- You’ve consulted employees (or their representatives) before installing cameras.
- You don’t record private areas (e.g., toilets, changing rooms, break rooms—unless there’s a very strong reason).
- You limit access to footage (only authorised staff can view it).
- You tell staff how to request their own footage (via a SAR).
Practical tip If you record staff, update your employment contracts to reference the CCTV policy. This shows you’ve been transparent.
How VetroCheck helps VetroCheck’s check reviews your workforce monitoring section and highlights risks—like missing consultation records or overbroad recording.
5. Data protection safeguards: Is your footage secure?
Why it matters CCTV footage is sensitive data. If it’s hacked, leaked, or accessed without permission, you could face fines, reputational damage, or legal claims. The DPA2018 requires you to keep data secure.
What "good" looks like
- Your policy lists security measures (e.g., password protection, encryption, restricted access).
- You train staff on handling footage (e.g., not sharing it on social media).
- You limit who can access footage (e.g., only managers, not all staff).
- You log access (who viewed footage and why).
- You have a breach plan (what to do if footage is lost or stolen).
Practical tip Check your DVR/NVR security settings. Default passwords (like "admin/admin") are a major risk. Change them and enable two-factor authentication if possible.
How VetroCheck helps VetroCheck’s check reviews your security section and flags missing safeguards—like no access logs or weak passwords.
Data-protection mistakes that create complaint risk
1. No signage (or hidden signs)
Mistake: A small shop installs CCTV but only puts a tiny sticker near the camera. A customer complains to the ICO, who finds the signage inadequate. Consequence: The ICO issues an enforcement notice, requiring the shop to update signs and train staff—costing time and legal fees.
2. Keeping footage "just in case"
Mistake: A pub keeps CCTV footage for 6 months "in case of disputes". The ICO investigates after a SAR and finds no valid reason for the long retention. Consequence: The pub must delete all old footage and rewrite its policy—plus pay for a solicitor to respond to the ICO.
3. Covert monitoring of staff
Mistake: A warehouse installs hidden cameras to catch theft. An employee finds out and reports it to the ICO. Consequence: The ICO fines the business £20,000 for unfair processing and orders them to destroy the footage.
FAQ
What does the CCTV Compliance Check: compliance and gap review review?
The CCTV Compliance Check is an information-only audit of your data CCTV compliance document. It focuses on four key areas:
- CCTV signage (are you informing people properly?).
- Retention (how long are you keeping footage?).
- Legitimate interest (can you justify why you’re recording?).
- Workforce monitoring (are you recording employees fairly?).
The review highlights gaps in your document and suggests improvements—backed by references to the Data Protection Act 2018 (DPA2018).
Which legal sources are used in the review?
The analysis is based on:
- The Data Protection Act 2018 (DPA2018).
- ICO guidance on CCTV and workplace monitoring.
- UK GDPR principles (where relevant to CCTV).
The review does not provide legal advice—it’s an information-only audit to help you spot compliance gaps.
Which specific points are checked?
The agent checks:
- CCTV signage: Does your document explain where signs are placed and what they say?
- Retention: Does your policy set a clear deletion schedule?
- Legitimate interest: Does your document justify why you’re recording?
- Workforce monitoring: Does your policy cover staff recording fairly?
- Data protection safeguards: Does your document list security measures?
Each finding is backed by a citation from your uploaded document.
Which documents can I upload?
The CCTV Compliance Check accepts PDF files up to 20 MB. Suitable documents include:
- Your CCTV policy (the main compliance document).
- Your privacy notice (if it covers CCTV).
- Your legitimate interest assessment (LIA).
- Any internal guidance on CCTV use.
The review is not for live footage, contracts, or non-data documents.
How much does the review cost and how long does it take?
The full analysis costs £12.99. Once you upload your document, results are usually ready within a few minutes as a PDF download. The report includes:
- A compliance score (how well your document meets key requirements).
- Detailed feedback on gaps and risks.
- Actionable suggestions to improve your policy.
Check your privacy paperwork — £12.99
Your next steps
- Gather your documents – Find your CCTV policy, privacy notice, and any legitimate interest assessments.
- Run the CCTV Compliance Check – Upload your document to VetroCheck for a fast, affordable audit.
- Fix the gaps – Use the report to update your policy, signage, and retention rules.
- Train your team – Make sure staff know the rules (e.g., who can access footage).
- Review annually – CCTV compliance isn’t a one-time task. Check your policy at least once a year.
How VetroCheck helps
VetroCheck’s CCTV Compliance Check gives you a clear, actionable report in minutes—no legal jargon, no guesswork. Our AI scans your document for key compliance risks and tells you exactly what to fix.
Important note: VetroCheck is not a law firm and is not regulated by the SRA. Our checks provide information-only audits—they are not legal advice, and no solicitor–client relationship is created. For complex issues, consult a data protection solicitor.
Ready to check? Upload your document for a structured PDF review — £12.99.
Check your document now — £12.99
Also see the agent topic page for statute themes and related checks.
Check your document now — £12.99
Upload your PDF for a structured review. One-time analysis from £12.99 — not legal advice.