The short answer
Lawful public CCTV starts from a documented purpose, not from what hardware can store. Under UK GDPR there is no fixed minimum or maximum retention: the storage-limitation principle requires you to delete footage once its purpose is served, typically after days or a few weeks rather than months. A data protection impact assessment justifies necessity and proportionality, and your retention policy should drive automatic overwrite rather than the reverse. Always check local and sector rules in your jurisdiction.
Key takeaways
- Public-space CCTV is lawful only where it is a necessary and proportionate response to a documented problem; consent is rarely a workable basis on a street or plaza.
- Under UK GDPR there is no fixed minimum or maximum retention for surveillance footage: the purpose of processing sets the period, typically days to around a month.
- Never let manufacturer defaults decide retention — keeping footage for six months merely because storage allows it is not defensible.
- Run a DPIA before deployment and be transparent: readable signs before the monitored field should name the operator, purpose and a contact point.
- When an incident occurs, extract footage to secure storage with a case end-date, while the routine archive keeps its normal short cycle.
- Where a national or sectoral rule sets a minimum or a cap, that rule overrides your own preference; document the stricter position.
Why a purpose must come before the cameras
Public-space CCTV is not banned, but it is lawful only as a necessary and proportionate answer to a concrete problem such as crime prevention, public safety or protecting property. Regulators expect you to start with the outcome you need and to consider less intrusive alternatives — better lighting, fencing, patrols or clearer sight lines — before committing to recording crowds.
In UK practice consent is rarely workable in an open space because people cannot meaningfully opt out. The realistic lawful bases are legitimate interests for most operators and public task for authorities acting in the public interest or under official authority. Both require a documented assessment and, because monitoring in public space is high-risk processing, a data protection impact assessment (DPIA) before deployment.
- Write one sentence defining the problem and the metric that will show the scheme works.
- Run a DPIA before the first day of recording; most public-space systems clear the high-risk threshold.
- Prefer cameras that cover only the relevant space and mask out neighbouring homes and unrelated areas.
Retention is a function of purpose, not of disk capacity
The governing rule is the storage-limitation principle: keep footage no longer than needed to serve the stated purpose and delete it once that purpose is achieved. Under UK GDPR there is no prescribed minimum or maximum period that applies to every surveillance system; the controller defines a period that reflects how long evidence is realistically required.
A common trap is letting manufacturer defaults decide. The ICO is explicit that footage should not be kept for six months merely because the recording device allows that length of time, or simply in case it becomes useful later. Anchor retention to your incident cycle instead: how quickly you detect an event, verify it and decide whether to hand footage to police. Many operators settle on a few days to roughly a month, with longer periods reserved for live incidents or legal proceedings.
- Set a retention ceiling that matches your detection-to-reporting cycle rather than hardware capacity.
- Extract and preserve footage separately when an incident is logged; the extracted copy can outlive the routine archive for the investigation.
- Automate deletion or overwrite so the routine archive expires by policy, not by human memory.
- Record the period and its rationale in your retention policy and DPIA.
Privacy by design in the open
People expect to be seen on CCTV in shops, streets and transport, but not everywhere. You must tell them they are being recorded before they enter the monitored field, using readable signs placed before the entrance and reinforced inside. Signs should name the operator, the purpose and a point of contact, satisfying the transparency requirement of Article 13 UK GDPR.
Respect heightened-expectation areas such as toilets, changing rooms and homes, where recording is justified only in exceptional circumstances. Keep fields of vision narrow and mask out private windows. Also weigh the chilling effect on how freely people move and meet: if recording changes behaviour without reducing the actual problem, the scheme may be neither necessary nor fair.
- Place signs before the field of view, at a distance people can read before being captured.
- Name the operator, purpose and contact details; do not rely on a website post alone.
- Restrict fields of vision and mask unrelated or private areas from the start.
Know which rule binds you: local caps versus purpose-based logic
Even within the EU the practical answer differs by country. Some national legislatures and data-protection authorities impose hard caps on how long public-space recordings may be kept, while others, such as the UK, leave the duration to the purpose test under the storage-limitation principle. Where a national cap exists, it is the maximum you may store; where none exists, the purpose test governs.
Sector rules can also bind you: transport, critical infrastructure, education and sporting venues often impose minimum archiving durations that exceed a routine privacy-based period. Reconcile the two by keeping at least as long as the sector minimum but never longer than the lawful maximum, and document why. Verify the current position with your own regulator, as guidance and legislation change.
- Check for a hard cap in your country before setting your own period.
- Reconcile sector minimums with privacy-based maximums and keep the stricter rule.
- Re-verify your position annually as regulators update guidance and law changes.
Running the system day to day
A compliant scheme needs an accountable owner, a written retention schedule, access controls and logs. Decide who may view live or recorded footage and why, and record every access. Keep the routine archive on its normal short cycle so the bulk of personal data does not accumulate.
Build an incident lane into operations: when an event is detected, copy the relevant footage to secure storage with a defined case-retention end date, keep the running archive on its short cycle, and log any handover to law enforcement under a documented request. This keeps evidence available while preventing the system from becoming a de facto indefinite archive.
- Appoint an owner and keep an access log of live views and exports.
- Copy footage on incident detection into secure case storage with an end date.
- Schedule an annual review to confirm the scheme still meets its purpose and refresh the DPIA.
A reusable retention decision checklist
The practical asset below compresses this guidance into a sequence of decisions an auditor or data-protection officer can follow when commissioning or renewing any public-space camera scheme.
Put it into practice
Public-Space CCTV Retention Decision Checklist
Work through this before commissioning or renewing any camera scheme covering streets, squares, transport or places open to the public. It turns a vague security ambition into decisions and artefacts an auditor can follow.
- Write one sentence defining the problem and how you will judge success.
- Confirm your lawful basis — legitimate interests or public task — in a written assessment.
- Complete and approve a DPIA before the first day of recording.
- Set a retention ceiling from your detection-to-reporting cycle, not from storage capacity.
- Reconcile that ceiling with any binding national or sectoral minimum or maximum and record the stricter rule.
- Plan automatic deletion or overwrite of the routine archive at the chosen period.
- Design an incident lane: extract footage to secure storage and log a case end-date when an event occurs.
- Place readable signs before the field of view naming the operator, purpose and contact point.
- Confirm access controls and maintain an access log for who may watch or export footage and why.
- Schedule an annual review to confirm the scheme still meets its purpose and to refresh the DPIA.
Questions people ask
Is there a legal maximum retention period for public CCTV footage under UK GDPR?
No. UK GDPR and the Data Protection Act 2018 do not prescribe any specific minimum or maximum retention period that applies to surveillance systems. Instead, the purpose of your processing sets the period under the storage-limitation principle: keep footage no longer than necessary and delete it once the purpose is served. The ICO advises not to keep footage for six months merely because the storage device allows it. Practical periods run from a few days to around a month, with longer retention only for live incidents or legal proceedings.
How long should we keep CCTV footage to investigate an incident?
Retention should match your detection-to-reporting cycle. Ask how quickly you notice an event, verify it and decide whether to hand footage to police; set the routine archive to that window, often days to around a month. When an incident is logged, extract the relevant footage to secure storage and record a case end-date so it survives beyond the routine overwrite. Keeping the whole archive longer 'just in case' is not defensible under the storage-limitation principle.
Do we need consent to run cameras in a public street or plaza?
In practice, no. It is difficult to obtain genuine consent from individuals in an open public space because people cannot meaningfully opt out. The realistic lawful bases are legitimate interests (for most operators) or public task (for authorities acting in the public interest or under official authority). You must document the assessment, carry out a DPIA where processing is high risk, and be transparent through readable signage placed before people enter the monitored area.
When does CCTV footage start being biometric data?
Footage becomes special-category biometric data when it is actively processed to uniquely identify individuals — for example, running a facial recognition system to match faces against a database. Recording ordinary CCTV for crime prevention does not by itself make footage biometric. If you actively process biometric data you need an Article 9 UK GDPR condition, an appropriate policy document under the DPA 2018, and additional safeguards. Document precisely when unique identification occurs in your scheme.
What must our CCTV signage say?
Signs must be clearly visible and readable and placed before people enter the monitored field, ideally reinforced inside the area. As a minimum they should state that surveillance is in operation, name the organisation operating the system, state the purpose and give a way to contact you — a website, telephone number or email. Signs should be sized for the context, whether for pedestrians or drivers. Publishing information on a website alone is not enough to meet the transparency duty.
Can we keep footage for six months because our storage allows it?
No. The ICO states you should not determine retention simply by the storage capacity of the system or keep data just in case it may be useful later. Keeping footage for six months merely because the manufacturer settings permit it is not compliant with the storage-limitation principle. Set retention from your documented purpose and incident cycle, automate deletion or overwrite, and reserve longer storage for specific incidents or legal proceedings with a recorded end-date.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Video surveillance (including guidance for organisations using CCTV)Information Commissioner's Office (UK)
- How can we comply with the data protection principles when using surveillance systems?Information Commissioner's Office (UK)
- CCTV and video surveillance (guidance hub)Information Commissioner's Office (UK)
- Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных»ГАРАНТ
- Видеонаблюдение и персональные данные: требования, согласие и хранение записейКибероснова (152FZ)
- С 1 сентября 2026 года меняются правила видеонаблюдения на транспортеГК МОНТРАНС
- Обеспечение антитеррористической безопасности в школеМБОУ «СШ № 17», Нижневартовск (gosuslugi.ru)