The short answer
There is no single universal retention number. Privacy regulators require that video and event data be kept only as long as a documented purpose requires, not as long as your storage allows. A defensible approach is a short default (roughly 7–30 days) for routine footage that covers your realistic incident-detection window, an explicit longer tier for exported evidence kept through the investigation or claim, and separate justified periods for access logs and event metadata. Automatic deletion, documented reasons, and a human decision close the loop.
Key takeaways
- No jurisdiction sets one universal figure: GDPR and UK GDPR storage-limitation principles tie retention to documented purpose and data minimization, with no fixed statutory minimum or maximum.
- Keep a short operational default (commonly ~30 days or less) sized to your incident-detection window, and treat incident footage separately as exported evidence.
- Give event metadata and access logs their own justified shelf life instead of treating all data as one continuous video archive.
- Base retention on the time it realistically takes to notice and report an incident, never merely on hard-drive or vendor-default capacity.
- Automate deletion or overwrite and log every view, copy, and deletion so you can prove compliance.
- Check sector and local rules (transport, education, finance) that can impose longer minimums than the general baseline.
Retention follows purpose, not storage capacity
Under GDPR and UK GDPR, video of identifiable people is personal data, and the storage-limitation principle says it may be kept no longer than necessary for the purpose for which it was collected. The UK Information Commissioner's Office is explicit that no specific minimum or maximum retention is prescribed for surveillance systems: the purpose of processing determines the necessary period, and you should not keep footage for six months merely because the manufacturer's default settings allow it.
Data protection authorities translate this into concrete expectations. Luxembourg's CNPD, for example, considers routine surveillance images acceptable for about 8 days by default, exceptionally up to 30 days with justification recorded in the register of processing, and longer periods generally disproportionate. Ireland's DPC likewise instructs controllers to fix a retention period that is no longer than necessary for the original purpose. In short, the familiar “30 days” is a practical baseline reflecting typical detection needs, not a hard statutory maximum in every jurisdiction.
- Purpose and lawful basis (e.g., legitimate interests or public task) documented before rollout.
- Storage limitation applies regardless of what the recorder can technically hold.
- DPA guidance in several jurisdictions clusters routine retention around days-to-30 days.
- 30 days is a common baseline and a starting point for justification, not a universal deadline.
Set the default from your incident-detection window
Retention should comfortably cover the realistic window in which an incident is noticed and reported to you. That window differs by context: a shop or office may hear about a problem within a few days to two weeks, a warehouse or distributor may need to span the period goods are in transit and being received (often 2–4 weeks), and high-security or regulated sites need longer. Once the window closes, routine footage loses most of its value and can be overwritten or deleted.
Use a two-tier model. Keep an operational rolling archive at the short default, and the moment an incident is detected, export the relevant clip into a separate evidential archive with controlled access. That evidence clip should live until the investigation, insurance claim, or legal dispute closes, then be deleted. Export promptly: in a cyclic system the raw segment can otherwise be overwritten before anyone acts on it.
- Retail/office: detection window of days to ~2 weeks.
- Warehouse/supply chain: cover the shipping-and-receiving window (~2–4 weeks).
- High-security/regulated sites: weeks to months, per policy or sector rule.
- Export evidence clips immediately to a separate, access-controlled archive.
Give event data and access logs their own shelf life
Continuous video, event metadata, and access logs are different classes of data with different value curves. Camera events — motion triggers, alarm activations, detection alerts — are useful for fast triage and investigation and can often be retained on a shorter or event-linked cycle. Access-control logs, by contrast, are frequently kept longer because organizations rely on them for audits, shift reviews, and disputes; some retain them around two years. Both must still be justified against the purpose, never held “just in case.”
Operationally, record who views, copies, or deletes footage and access logs, and keep an audit trail of the access to them. When event metadata and video are combined into an evidence file, retention of the combined record follows the rules of the underlying document or investigation it supports.
- Continuous video: short operational cycle at the default.
- Event/metadata clips: tied to the triggering event and its review.
- Access logs: own justified period, often longer than video.
- Audit trail: who viewed, copied, or deleted, and when.
A four-step decision framework
Build the schedule as a document you can defend to legal, security, and regulators. Step one: identify the purpose and lawful basis for each camera group and zone and complete a DPIA where processing is high-risk. Step two: determine each zone's incident-detection window from how incidents actually surface in your operation. Step three: set tiered periods — short operational defaults, an evidential tier tied to the end of each matter, and separate periods for event metadata and access logs.
Step four: encode the schedule in a written policy with automatic deletion configured, access roles defined, and deletion evidence logged, then schedule an annual review. Avoid vague wording; state the number of days, the condition that triggered longer retention (a recorded incident), and what happens at expiry.
- 1. Document purpose and lawful basis per zone; run a DPIA where required.
- 2. Measure the realistic detection window for each zone.
- 3. Set tiered periods: operational, evidential, event logs, access logs.
- 4. Write the policy, automate deletion, log access, review annually.
Sector and jurisdiction checkpoints
Before you finalize numbers, check whether sector rules override the general baseline. Transport-security requirements in several countries mandate keeping surveillance data at least 30 days; education and stadium settings can run months; financial institutions often follow regulator guidance of 60–90 days or more. Different data protection authorities also set different expectations — some give short default windows with exceptional extensions of 30 days, while others simply require a purpose-driven period documented in the register.
Because national laws, sector codes, and even versions of privacy guidance change, treat any schedule as living documentation. Verify the current position on the relevant authority's site before rollout and at each annual review, and note in the policy which jurisdiction and instruments you relied on.
- Transport and regulated infrastructure often set a minimum (e.g., ~30 days or more).
- Finance and high-assurance sites commonly operate 60–90+ days.
- DPA expectations differ: some set an 8-day default with 30-day exceptional; others require purpose-driven justification.
- Review annually and when rules or guidance change.
Sizing storage to the policy, not the other way around
Once the policy sets the retention period, compute capacity to match it. Storage grows with resolution, bitrate, frame rate, camera count, and recording mode. A rough estimate is bitrate in megabits per second multiplied by about 0.45 GB per hour, then by 24 hours, the number of days, and the number of cameras; motion-only recording multiplies the result by the duty cycle, for example 25%.
Cost and retention pull against each other, so manage trade-offs deliberately: adopt a modern codec such as H.265, which is markedly more efficient than H.264; lower resolution and frame rate where fine detail is unnecessary; record on motion or event triggers rather than continuous full-res where appropriate. A hybrid model — recent footage local, flagged clips promoted to a separate archive — lets you keep a short, affordable operational cycle while protecting evidence.
- Storage ≈ bitrate (Mbit/s) × 0.45 × 24 × days × cameras.
- Motion recording: multiply by the duty cycle (e.g., ×0.25).
- H.265 can be substantially more efficient than H.264.
- Archive evidence clips separately so cyclic overwrite cannot destroy them.
- Leave headroom in channels and disk for future cameras.
Put it into practice
Video and event-data retention decision matrix
Work through this matrix top to bottom to convert an abstract question into a documented, defensible schedule. Each line forces the decision a retention policy must actually make — purpose, window, tier, and evidence handling.
- Purpose and lawful basis documented for each camera group and zone.
- Detection window defined per context: retail/office ~14 days, warehouse/supply ~30 days, high-security longer.
- Operational retention default set (e.g., 14–30 days) with automatic overwrite or deletion at expiry.
- Evidence procedure defined: immediate export of incident clips to a separate controlled archive.
- Evidential retention rule set: keep until investigation/claim closes, then delete — not indefinitely.
- Event metadata and access-log periods set separately and justified (access logs often longer than video).
- Sector and jurisdiction checked for minimums that override the baseline (transport, finance, education).
- Policy written with clear expiry conditions and a recorded-incident exception.
- Automatic deletion configured, roles limited, and view/copy/delete actions logged.
- Annual review scheduled and rationale recorded for any extension.
Questions people ask
Is there a legal default retention period for CCTV and event data?
No universal legal default exists. Under GDPR and UK GDPR, the storage-limitation principle requires that footage and event data be kept no longer than necessary for the documented purpose, and regulators generally do not prescribe a fixed statutory minimum or maximum. In practice authorities converge on a baseline of roughly a few days to 30 days for routine footage, with longer periods allowed only where a specific circumstance or sector rule justifies them. Some authorities, such as Luxembourg's CNPD, suggest routine images be kept about 8 days by default and exceptionally up to 30 days, while sector rules for transport or finance can impose longer minimums. Your policy must therefore state the period and the reason.
Can we keep video for months because our system has the capacity?
Not without a documented reason. The UK ICO explicitly warns against setting retention simply according to the storage capacity or vendor default of the surveillance system — footage should not be kept for six months just because the recorder allows it. Holding identifiable footage beyond the purpose is a storage-limitation breach and increases exposure if data is misused or disclosed. Extend retention only where a recorded incident, an investigation, a claim, or a sector rule provides a genuine basis, and document that basis in your register and policy.
What should we do with footage once an incident occurs?
Export the relevant segment as soon as possible into a separate evidential archive with controlled access, because in a cyclic system the raw footage can be overwritten within days. Keep that evidence until the investigation, insurance claim, or legal dispute is resolved, then delete it. Record who accessed or copied the clip. If law enforcement requests footage, disclose under the appropriate lawful process and document the transfer. Routine footage unrelated to the incident continues to follow the normal operational retention period.
Do access-control and event logs need the same retention as video?
No. Continuous video, event metadata, and access logs are distinct classes of data with different value curves and should each have a justified period. Event or metadata records are typically useful for fast triage and can be retained on a shorter, event-linked cycle. Access-control logs are frequently kept longer because organizations use them for audits, shift reviews, and disputes — in some cases around two years. Whatever period you choose, it must be proportionate to a stated purpose and documented in policy, and access to these logs should itself be audited.
What risks follow from keeping footage too long or deleting it too early?
Keeping footage too long breaches the storage-limitation principle and raises the risk that identifiable data is later misused or disclosed, which can draw regulatory action and undermine trust. Deleting too early can destroy evidence needed for an investigation, insurance claim, or legal dispute. The balance is a documented tiered schedule: a short operational default sized to your realistic detection window, immediate export of incident clips to an evidential archive kept until the matter closes, and automatic deletion at the end of each period. A person makes the final call on extensions.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- How can we comply with the data protection principles when using surveillance systems? (ICO, UK)Information Commissioner's Office (ICO)
- Video surveillance: principle of storage limitation (CNPD)Commission nationale pour la protection des données (Luxembourg)
- Guidance on the use of CCTV (DPC)Data Protection Commission (Ireland)
- Guidelines for the Use of Video Surveillance (IPC Ontario)Information and Privacy Commissioner of Ontario
- Видеонаблюдение и персональные данные: требования, согласие и хранение записейКибероснова (152-ФЗ)
- Сроки хранения видеозаписей в компании: как выбрать и обосноватьRixet
- Как долго камеры видеонаблюдения хранят записи? (Ajax)Ajax Systems