Reviewed, sourced guidance

Business CCTV privacy questions for a new system

Direct answer

Define the purpose, consider whether surveillance is necessary and proportionate, limit recording to what is needed, explain the use to people, control access, and set a retention period tied to the purpose. The ICO’s organisational CCTV guidance is under review following the Data (Use and Access) Act, so check it again before acting.

Before specifying a CCTV system, identify which organisation decides the purpose and key means of each data-processing activity. Assign operational and supplier roles in writing.

Key takeaways

  • Decide and document the purpose before purchasing a system.
  • Assess privacy impact and whether a DPIA is needed for high-risk processing.
  • Set access, security and retention around the purpose.
  • The ICO guidance pages were marked under review when checked on 25 September 2026.

Purpose, necessity and privacy impact

Ask what problem CCTV is intended to address and what evidence supports that need. Consider less intrusive ways to achieve the same purpose.

The ICO says organisations should assess necessity and proportionality, and carry out a DPIA where processing is likely to result in high risk to people.

Sources for this section: ICO, accountability responsibilities for video surveillance (observed 2026-09-25; under review)ICO, data protection principles for surveillance systems (observed 2026-09-25; under review)

Notice, access and retention

Ask how people will be told about the cameras, who can view or export footage, how requests will be handled, and how long recordings are kept.

The ICO states there is no single fixed minimum or maximum CCTV retention period in data-protection law. The organisation should set a period linked to its purpose and delete data when it is no longer needed.

  • Check the current GOV.UK and ICO guidance: does your organisation need to register with the ICO and pay the data protection fee for this use?
  • Check the current GOV.UK and ICO guidance: what visible signage will tell people cameras are operating, and where will fuller privacy information be provided?
  • How will subject access and other footage requests be handled under the current guidance?

Sources for this section: ICO, data protection principles for surveillance systems (observed 2026-09-25; under review)ICO, checklist for limited CCTV systems (observed 2026-09-25; under review)GOV.UK, Data protection and your business: Using CCTV (Exa fallback excerpt observed 2026-09-28; full page not independently verified)

Assign duties to the correct data-protection roles

The organisation deciding the purposes and key means of surveillance processing is likely to be the controller. A supplier may be a processor, joint controller or controller for a separate activity, depending on its actual decisions and role.

Identify the role for each processing activity and agree responsibilities in writing. Do not infer a data-protection role from equipment ownership, job title or contract label alone.

The ICO pages linked here stated they were under review after the Data (Use and Access) Act. Recheck the live guidance and seek qualified advice for a site-specific decision.

Sources for this section: ICO, CCTV and video surveillance guidance for organisations (observed 2026-09-25; under review)ICO, accountability responsibilities for video surveillance (observed 2026-09-25; under review)ICO, determine whether you are a controller or processor (observed 2026-09-25; under review)

Next steps

  1. Read the current ICO material before procurement.
  2. Write down who will operate and govern the system.

Sources

Add privacy questions to the brief