Opening & Shipping Times

Sales & Collections (Leicester) : Monday~Friday 9am-5pm
Shipping : Monday~Friday 3pm cut off time
- Closed Weekends & Bank Holidays -

Authorised UK Wholesaler
Hikvision & HiLook
Same-Day Dispatch
Order by 3pm
Genuine UK Stock
Official UK products
up to 5-Year Warranty
Full UK manufacturer
Secure Checkout
UK PSD2 compliant

UK GDPR & CCTV Surveillance — Installer and Operator Obligations (2025/2026)

If you operate or install CCTV in the UK, your legal duties have changed significantly since the Data Protection Act 1998. This guide covers the current UK framework — UK GDPR and the Data Protection Act 2018 — and translates the law into a practical installer and operator checklist.

Disclaimer: this is general information, not legal advice. For case-specific guidance consult the ICO or a qualified data-protection adviser.

The law at a glance (2025/2026)

The Data Protection Act 1998 was replaced on 25 May 2018 by a two-part framework:

  • UK GDPR — the retained form of the EU General Data Protection Regulation, written into UK law after Brexit. It sets out the six lawful bases, the seven data-protection principles, individual rights, and the accountability duties.
  • Data Protection Act 2018 (DPA 2018) — the UK statute that sits alongside the UK GDPR, fills in UK-specific detail, and extends data-protection rules to law-enforcement and intelligence processing.

Public-sector operators (councils, police, certain statutory bodies) also have to follow the Surveillance Camera Code of Practice issued under the Protection of Freedoms Act 2012. The ICO's Video Surveillance Guidance (the successor to the old "CCTV Code of Practice") is the authoritative plain-English reference for all other operators.

Does your CCTV system fall under UK GDPR?

Almost certainly yes. The UK GDPR applies whenever you process personal data, and images or audio of an identifiable living individual are personal data. The only CCTV use that generally falls outside the regime is the purely "domestic" exemption — a homeowner recording inside and on their own property only. As soon as cameras face a public footpath, a neighbour's garden, or a shared area, the domestic exemption disappears and UK GDPR applies.

Pick a lawful basis before you install

Under UK GDPR you must identify one of six lawful bases before you start processing. For CCTV the practical choices are:

  • Legitimate interests (Article 6(1)(f)) — the most common basis for commercial and residential CCTV. You must run and document a Legitimate Interests Assessment (LIA) balancing your purpose (crime prevention, staff safety, evidence) against the intrusion on individuals.
  • Legal obligation (Article 6(1)(c)) — where a statute requires CCTV, e.g. the mandatory CCTV requirements in English and Welsh abattoirs.
  • Public task (Article 6(1)(e)) — for public authorities exercising official functions.
  • Consent — rarely workable for public-facing CCTV because consent must be freely given, specific, and revocable.

If you record audio, treat it as a much higher privacy risk. The ICO's position is that audio recording in CCTV is intrusive and will rarely be justifiable, so audio-enabled cameras need a stronger justification and clear signage.

Data Protection Impact Assessment (DPIA)

A DPIA is mandatory whenever processing is likely to result in a high risk to individuals. For CCTV, the ICO has indicated that DPIAs are required in most public-area deployments, any ANPR or facial-recognition system, and any use of covert cameras. The DPIA must be completed before cameras are commissioned and kept under review. A solid DPIA covers:

  • The processing operations and the purposes
  • The lawful basis and the LIA if legitimate interests is used
  • Necessity and proportionality
  • Risks to individuals and how they are mitigated
  • Who is consulted (staff, DPO, ICO if residual high risk)

Data-protection principles applied to CCTV

Article 5 of the UK GDPR sets seven principles. Translated into a CCTV context:

  1. Lawfulness, fairness and transparency — install visible signage at the approach to every monitored area. Signs must identify the operator, the purpose, and at least one contact route (phone, email, URL) for further information.
  2. Purpose limitation — use footage only for the purpose you documented. Reusing recordings for HR performance monitoring or marketing is a separate processing activity and generally unlawful without a fresh basis.
  3. Data minimisation — camera angles, resolution, coverage and audio features must be no more than you need. Mask neighbouring properties and public space where you can.
  4. Accuracy — keep clocks, camera orientation and recording quality in working order.
  5. Storage limitation — retain recordings for the shortest period that meets your purpose. Typical retentions: 14–31 days for general-purpose CCTV, up to 90 days for cash-handling areas, and indefinite only where an incident is under investigation.
  6. Integrity and confidentiality (security) — protect the system from unauthorised access. See the technical checklist below.
  7. Accountability — document everything. The ICO can ask to see your DPIA, LIA, retention schedule, access-request procedure and security measures.

Individual rights you must respect

Individuals captured on your CCTV have the following rights under UK GDPR:

  • Right of access (Subject Access Request / SAR) — you must respond within one calendar month and provide a copy of footage that identifies them, with other people's faces obscured. You can no longer charge the £10 fee from the 1998 Act; the SAR is free.
  • Right to erasure — limited in CCTV because retention is normally short and the legitimate interests basis means erasure is not automatic, but you must consider each request.
  • Right to object — individuals can object to processing based on legitimate interests; you must reassess and stop unless you can show compelling grounds.
  • Rights relating to automated decision-making — relevant if you use facial recognition, ANPR enforcement, or behavioural analytics to take decisions about people.

Registering and paying the ICO fee

Almost every UK CCTV operator must register with the ICO and pay the annual data protection fee. Tiers and amounts are published at ico.org.uk; the Tier 1 fee for small organisations currently starts at £40 per year. Failure to pay is itself a breach and the ICO can fine up to £4,350.

Breach notification

If an incident occurs — stolen NVR, ransomware on the VMS, misdirected footage export — you must assess whether it poses a risk to individuals. If yes, notify the ICO within 72 hours of becoming aware. If the risk is high you must also notify the affected individuals without undue delay.

Installer's technical checklist

The security principle is where installers can most help operators stay compliant. A defensible CCTV install in 2025/2026 should meet all of the following:

  • Change every default password on cameras, NVRs, DVRs, switches and routers before commissioning.
  • Isolate CCTV on its own VLAN or physical network, with no route to the internet except through a controlled gateway.
  • Disable unused services (Telnet, FTP, UPnP, SNMPv1) on every device.
  • Use HTTPS and SRTP for any browser, mobile or off-site access. Never rely on HTTP or plain RTSP over the public internet.
  • Patch firmware — both at install and on a defined schedule. Keep a record of the firmware version against each device.
  • Restrict physical access to the NVR/DVR, hard drives and the cabinet.
  • Role-based accounts — individual named accounts for staff, no shared "admin" logins.
  • Export workflow — a documented SAR export procedure that redacts third parties and records who was given what, when.
  • Retention automation — NVRs should overwrite after the agreed retention period without manual intervention.
  • Signage — provided by the installer at handover, positioned at every camera approach.

Most of these map directly to features in modern Hikvision, HiLook, Ajax and Ruijie kit. Our Hikvision CCTV Network Security Hardening post walks through the specific menus and settings.

Quick reference — what changed vs DPA 1998

  • Subject Access Requests are now free and must be answered in 1 month (was £10 fee and 40 days).
  • DPIA is a new, mandatory step for higher-risk CCTV.
  • Fines are now up to £17.5 million or 4% of global turnover (was capped at £500,000).
  • Breach notification to the ICO in 72 hours is new.
  • Children's data, biometrics, and special-category data have stronger protections — important for face-recognition terminals and ANPR.
  • The annual ICO data protection fee is now compulsory for almost every operator, replacing the voluntary "notification" system.

Useful references

How Netview helps installers stay compliant

We stock CCTV, intruder, fire and network kit that supports the technical controls above out of the box — role-based accounts, VLAN-capable switches, signed firmware, encrypted remote access and configurable retention. Our Leicester warehouse dispatches same day on in-stock Hikvision, HiLook, Ajax, Pyronix and Ruijie lines, and our sales team can advise on product selection for compliance-sensitive installs. Call 01163 800 838 or email [email protected].

Last reviewed April 2026.



What's this? Check "Remember Me" to access your shopping cart on this computer even if you are not signed in.