The short answer
Deploy cameras only after mapping every device to a stated purpose, defining the exact observable area, listing who may access recordings and setting a purpose-driven retention rule. Before go-live, run a data protection impact assessment: describe the processing, test necessity and proportionality, identify risks to individuals and record mitigations. Document lawful basis, post clear signage and configure automatic deletion of recordings.
Key takeaways
- A DPIA is a legal requirement before deploying most video surveillance because monitoring people is inherently high risk; skipping it is itself an infringement.
- Consent is rarely a valid lawful basis for cameras in public or semi-public spaces; rely instead on legitimate interests (with an LIA) or public task.
- Map every camera to a specific problem and record why less intrusive alternatives, such as improved lighting or physical access control, are insufficient.
- Avoid filming toilets, changing rooms, prayer rooms and other spaces where people reasonably expect privacy; restrict the field of view to the minimum necessary.
- Retention must be purpose-driven: delete routine footage promptly, typically within days or weeks, and preserve only incident-related extracts until the matter is resolved.
- Signage must be visible before a person enters the monitored area and should identify the controller, the purpose and who to contact about the system.
Build the purpose and zone map before you buy cameras
A camera system purchased because it is affordable or new technology, rather than because it solves a documented problem, will struggle to pass regulator scrutiny. The ICO guidance on surveillance systems is explicit: you must consider less privacy-intrusive alternatives and record why they are not suitable. Start with an incident log, a risk assessment of theft or vandalism, and a specific statement of what the camera is expected to achieve.
For every camera, record: the physical ID, the area it intentionally covers, the field of view settings, the problem it addresses, and the named person responsible for the device. This inventory becomes the backbone of the DPIA and demonstrates that each point was deliberately designed rather than blanket coverage.
In the workplace, continuous video monitoring of individual employee performance is almost never proportionate under the GDPR; lawful monitoring is generally limited to protecting people and property, ensuring health and safety, or preventing specific crimes. State that boundary clearly in your privacy notice.
- Write the purpose as an operational outcome: preventing theft in a stockroom, not vague security.
- Draw camera positions and lens directions on a site plan; keep the drawing with the DPIA.
- Document the alternative assessment in three sentences per camera or camera group.
Select the lawful basis and justify necessity
Under Article 6 UK GDPR, legitimate interests is the most workable basis for private organisations using CCTV, while public authorities will usually rely on public task. Consent is rarely appropriate: people in an open car park or a shared corridor cannot refuse without changing their behaviour, which undermines the voluntary nature of consent. Document your legitimate interests assessment alongside the DPIA.
If a system includes facial recognition or other biometric identification that uniquely identifies individuals, this is special category data under Article 9 UK GDPR and triggers an even higher threshold. You will need a separate Article 9 condition, documented reasoning about necessity and proportionality, and in most European jurisdictions a prior consultation with the supervisory authority if residual risk remains high.
Legal bases do not flow down from the camera vendor or the security contractor; as controller you must assess and document them yourself before the system goes live. In shared systems where two organisations jointly decide purpose and means, each must clarify its role and record joint controllership arrangements.
- Prepare a legitimate interests assessment covering the three-part test: purpose, necessity, balancing.
- Do not collect audio unless you can prove it is indispensable; audio is considered far more intrusive than image alone.
- Check whether your use requires registration with the data protection authority or payment of a data protection fee.
Draw the privacy-risk zones and constrain the field of view
A central principle in the EDPB Guidelines on video devices is that data minimisation applies to the visual field itself. Point cameras away from neighbouring properties, public pavement beyond your entrance, and towards the specific asset or doorway you need to protect. The ICO gives a classroom example: a café camera capturing a neighbour's flat must be re-angled to exclude the private dwelling.
Certain areas should almost never be monitored: toilets, changing rooms, showers, quiet rooms and, in workplaces, spaces where employees take breaks. Even where a serious problem exists, such as vandalism in a school toilet, a rigorous proportionality test will almost always fail because less intrusive options such as increased supervision or redesign are available.
For public authorities monitoring streets or public squares, separate national regimes (for example, the French interior security code requiring prefectural authorisation) coexist with the GDPR; private operators recording a public street from their premises may also need local permissions. Verify the applicable national rules before pointing a lens beyond your boundary.
- Use camera masking or privacy zones to blank out areas that are not relevant to the stated purpose.
- Confirm that staff break rooms, locker rooms and sanitary facilities are outside every camera's field of view.
- If a camera is adjusted, record the change and the reason in the system log.
Define the access matrix and audit trail
Access to live feeds and recorded footage should be restricted by role rather than by rank. The typical allowed roles are the security operator, the data protection officer or nominated responsible person, and the legal or HR lead dealing with an incident. Facilities management, reception staff and external maintenance providers should have no standing access to the archive.
Log every instance of viewing, copying or exporting footage: operator identity, date, time, camera ID and the reason for access. This log is your defence when an individual asks who has seen their image and is also a means of detecting internal misuse, theft of footage or snooping. The ICO expects clear documented procedures for disclosure to law enforcement and for handling subject access requests.
If a third-party processor hosts or monitors footage, conclude a written contract that complies with Article 28 UK GDPR: it must instruct the processor only to act on documented instructions, to delete or return data on termination and to support the controller in responding to data subject rights. Do not rely on verbal agreements or the processor's general terms alone.
- Keep an up-to-date list of people with access to the video management system; revoke promptly on role change.
- Protect remote access with multi-factor authentication and a VPN.
- Record all data-sharing requests, including from police, in a dedicated register with the legal basis.
Set purpose-driven retention and automate deletion
The GDPR contains no minimum or maximum retention window for CCTV; the correct period is whatever is necessary to achieve the purpose. For routine security monitoring in an office or shop, many data protection authorities expect deletion after days or weeks, not months. The Dutch supervisory authority uses a guideline of around 14 to 28 days for standard surveillance; the CNIL points to a few days for most shops with one month as a rare justified maximum.
Design the system to delete recordings automatically at the end of the retention period. If this is not possible, implement a documented manual deletion routine performed by a named individual, with records kept. Keeping footage indefinitely on the grounds that it might become useful later directly breaches the storage limitation principle and will draw regulatory criticism even if no complaint arises.
When footage is needed as evidence of an incident, extract only the relevant segment, note the extraction in the access log, and preserve the extract separately for as long as the investigation or legal proceeding requires. The remainder of the recording continues to be deleted on the routine schedule.
- Write the retention period per zone or purpose in the DPIA and in the privacy notice.
- Configure automatic overwrite or scheduled deletion in the video management software.
- Document the process for freezing footage related to an incident and for releasing the freeze when the matter closes.
Publish transparency information and answer requests
People must know they are being recorded before they walk into the monitored area. Place signs at the boundary of each zone, sized and positioned so that a pedestrian or a driver can read them in advance; a tiny sticker inside the shop next to the camera does not satisfy the requirement for prior notice. The sign should name the controller, state the purpose and provide contact details for queries.
Signage alone does not exhaust your transparency obligations. You must also give privacy information through an easily accessible channel, usually a page on your website, that explains the lawful basis, categories of data, retention periods and rights. For employees, provide a specific workplace privacy notice and hold consultations where required by works councils or trade unions.
Processing video of identifiable people engages all the usual subject rights. Prepare a procedure for responding to subject access requests asking for extracts of footage, and note that in practice poor search capabilities in CCTV systems can make compliance difficult. Design recordings so that the controller can locate and extract footage relating to an individual or incident without excessive effort.
- Add a QR code to signs linking to the full privacy notice.
- Keep a version history of privacy notices so you can show what was communicated at any time.
- Train front-line staff on how to recognise and forward a subject access request about CCTV footage.
Put it into practice
Checklist: DPIA-ready camera deployment
Complete this checklist before switching on any new camera on a site you control, and re-run it at least annually or when a camera is moved, re-angled or equipped with analytics.
- Camera inventory sheet completed with device ID, location, lens direction, masking zones and intended outcome.
- Statement of purpose written for each camera; alternatives assessed and recorded in three or more sentences.
- Lawful basis identified (legitimate interests with LIA, or public task) and documented in DPIA.
- Field of view checked against neighbouring properties and public spaces; privacy zones configured.
- No camera pointed at toilets, changing rooms, break rooms or similar areas; reasoning recorded in DPIA.
- DPIA completed before go-live, describing nature, scope, context, purposes, risks and mitigations.
- High residual risk consultation with the supervisory authority initiated if mitigations do not reduce risk.
- Roles and access rights defined; VMS log in place tracking view, export and deletion actions.
- Third-party processor agreement signed, including instructions on deletion and data subject support.
- Retention period set per purpose and zone; automatic deletion scheduled and tested.
- Signage posted at zone boundaries before each monitored area, with controller name and contact point.
- Employee or public privacy notice updated and made available; staff training on handling SARs completed.
Questions people ask
Is a DPIA mandatory for every CCTV installation?
Under Article 35 UK GDPR, a DPIA is required where processing is likely to result in a high risk to individuals. The ICO states that this applies in most cases relating to video surveillance because of the inherent privacy risks: monitoring publicly accessible places on a large scale and monitoring employees at work are explicitly high-risk categories. Even for a small shop with one entrance camera, the recommended practice is to complete a short DPIA to document your assessment; if you decide no DPIA is needed, you must record your reasoning and be ready to justify it.
Can employees give valid consent to workplace cameras?
Usually not. Consent under the GDPR must be freely given, specific and informed, but the employer-employee relationship creates an imbalance of power that undermines voluntariness. The EDPB and most supervisory authorities discourage reliance on consent for workplace video surveillance. Employers typically rely on legitimate interests or legal obligations, with monitoring strictly limited to acceptable purposes and clearly communicated. If a system additionally processes biometric data for identification, special conditions under Article 9 apply and worker consultation is essential.
Is it legal to keep CCTV recordings for 90 days?
No single retention period is legal or illegal under the GDPR; the test is whether the period is needed to achieve your stated purpose. Routine footage for crime prevention should be deleted when the risk period has passed, which many authorities suggest should typically be no more than a few weeks. Keeping 90 days of routine footage without justification will likely be seen as storage limitation non-compliance. If your sector regulator mandates a longer period, such as franchised transport operators retaining images for 30 days, follow that sector rule, but otherwise shorten retention to what the incident pattern actually requires.
What happens if residual risk in the DPIA remains high?
If mitigation measures are not sufficient to bring risk down to an acceptable level, you are required to consult the supervisory authority before starting processing. In the UK this consultation with the ICO is mandatory, and you cannot lawfully proceed until you have received a response. In many EU member states the same rule applies under Article 36 GDPR. A common outcome is that the authority imposes added conditions or instructs you not to deploy a particularly intrusive feature, such as facial recognition, without further safeguards.
Does a body-worn camera or drone require the same DPIA as a fixed camera?
Yes, and often the risk assessment is harder because of unpredictable coverage. Body-worn cameras record in places where people may have higher privacy expectations, while drones can capture footage of people who have no chance to read a sign beforehand. The ICO guidance confirms that the same data protection principles apply, beginning with a necessity and proportionality test and a DPIA where processing is high risk. You must also design specific mitigations, such as recording in short bursts triggered by incident, restricting later access and ensuring bystanders are informed through visible equipment and announcements where practical.
How should I respond to a subject access request for footage?
Treat it like any SAR: verify the identity of the requester, search your footage for clips in which they appear, and provide relevant extracts while removing images of other people unless their inclusion is necessary to comply. You may refuse or limit disclosure when third-party rights override the requester's access right, and you should record that reasoning. A 30-day timeline applies under UK GDPR for responding to SARs, extended for complex searches where permitted. If your VMS cannot easily search footage by time and location linked to an identified individual, that operational gap is itself a compliance weakness to fix at the system design stage.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Guidelines 3/2019 on processing of personal data through video devicesEuropean Data Protection Board
- What are our responsibilities in terms of accountability?UK Information Commissioner's Office
- How can we comply with the data protection principles when using surveillance systems?UK Information Commissioner's Office
- Caméras et autres dispositifs vidéoCommission nationale de l'informatique et des libertés
- Видеонаблюдение и персональные данные: требования, согласие и хранение записейКибероснова
- Роскомнадзор видеонаблюдение — подборка документовКонсультантПлюс