UK GDPR & CCTV Surveillance — Installer and Operator Obligations (2025/2026)
Monthly Archive
Topics
- Hikvision Client Software
- Hikvision Firmware
- Hikvision Tools Software
- Alarm
- Hikvision ColorVu Technology
- Hikvision Warranty
- Hikvision Company News
- LiveGuard
- IVMS-4200
- AoC
- Hybrid
- Specifications
- AcuSeek
- Hikvision Video Intercom
- Security
- How To
- Ajax
- Fire Detection
- Ruiji
- AcuSense
- 12MP
- 16MP
- Router
- Hilook IP Cameras
Tags
If you operate or install CCTV in the UK, your legal duties have changed significantly since the Data Protection Act 1998. This guide covers the current UK framework — UK GDPR and the Data Protection Act 2018 — and translates the law into a practical installer and operator checklist.
Disclaimer: this is general information, not legal advice. For case-specific guidance consult the ICO or a qualified data-protection adviser.
The law at a glance (2025/2026)
The Data Protection Act 1998 was replaced on 25 May 2018 by a two-part framework:
- UK GDPR — the retained form of the EU General Data Protection Regulation, written into UK law after Brexit. It sets out the six lawful bases, the seven data-protection principles, individual rights, and the accountability duties.
- Data Protection Act 2018 (DPA 2018) — the UK statute that sits alongside the UK GDPR, fills in UK-specific detail, and extends data-protection rules to law-enforcement and intelligence processing.
Public-sector operators (councils, police, certain statutory bodies) also have to follow the Surveillance Camera Code of Practice issued under the Protection of Freedoms Act 2012. The ICO's Video Surveillance Guidance (the successor to the old "CCTV Code of Practice") is the authoritative plain-English reference for all other operators.
Does your CCTV system fall under UK GDPR?
Almost certainly yes. The UK GDPR applies whenever you process personal data, and images or audio of an identifiable living individual are personal data. The only CCTV use that generally falls outside the regime is the purely "domestic" exemption — a homeowner recording inside and on their own property only. As soon as cameras face a public footpath, a neighbour's garden, or a shared area, the domestic exemption disappears and UK GDPR applies.
Pick a lawful basis before you install
Under UK GDPR you must identify one of six lawful bases before you start processing. For CCTV the practical choices are:
- Legitimate interests (Article 6(1)(f)) — the most common basis for commercial and residential CCTV. You must run and document a Legitimate Interests Assessment (LIA) balancing your purpose (crime prevention, staff safety, evidence) against the intrusion on individuals.
- Legal obligation (Article 6(1)(c)) — where a statute requires CCTV, e.g. the mandatory CCTV requirements in English and Welsh abattoirs.
- Public task (Article 6(1)(e)) — for public authorities exercising official functions.
- Consent — rarely workable for public-facing CCTV because consent must be freely given, specific, and revocable.
If you record audio, treat it as a much higher privacy risk. The ICO's position is that audio recording in CCTV is intrusive and will rarely be justifiable, so audio-enabled cameras need a stronger justification and clear signage.
Data Protection Impact Assessment (DPIA)
A DPIA is mandatory whenever processing is likely to result in a high risk to individuals. For CCTV, the ICO has indicated that DPIAs are required in most public-area deployments, any ANPR or facial-recognition system, and any use of covert cameras. The DPIA must be completed before cameras are commissioned and kept under review. A solid DPIA covers:
- The processing operations and the purposes
- The lawful basis and the LIA if legitimate interests is used
- Necessity and proportionality
- Risks to individuals and how they are mitigated
- Who is consulted (staff, DPO, ICO if residual high risk)
Data-protection principles applied to CCTV
Article 5 of the UK GDPR sets seven principles. Translated into a CCTV context:
- Lawfulness, fairness and transparency — install visible signage at the approach to every monitored area. Signs must identify the operator, the purpose, and at least one contact route (phone, email, URL) for further information.
- Purpose limitation — use footage only for the purpose you documented. Reusing recordings for HR performance monitoring or marketing is a separate processing activity and generally unlawful without a fresh basis.
- Data minimisation — camera angles, resolution, coverage and audio features must be no more than you need. Mask neighbouring properties and public space where you can.
- Accuracy — keep clocks, camera orientation and recording quality in working order.
- Storage limitation — retain recordings for the shortest period that meets your purpose. Typical retentions: 14–31 days for general-purpose CCTV, up to 90 days for cash-handling areas, and indefinite only where an incident is under investigation.
- Integrity and confidentiality (security) — protect the system from unauthorised access. See the technical checklist below.
- Accountability — document everything. The ICO can ask to see your DPIA, LIA, retention schedule, access-request procedure and security measures.
Individual rights you must respect
Individuals captured on your CCTV have the following rights under UK GDPR:
- Right of access (Subject Access Request / SAR) — you must respond within one calendar month and provide a copy of footage that identifies them, with other people's faces obscured. You can no longer charge the £10 fee from the 1998 Act; the SAR is free.
- Right to erasure — limited in CCTV because retention is normally short and the legitimate interests basis means erasure is not automatic, but you must consider each request.
- Right to object — individuals can object to processing based on legitimate interests; you must reassess and stop unless you can show compelling grounds.
- Rights relating to automated decision-making — relevant if you use facial recognition, ANPR enforcement, or behavioural analytics to take decisions about people.
Registering and paying the ICO fee
Almost every UK CCTV operator must register with the ICO and pay the annual data protection fee. Tiers and amounts are published at ico.org.uk; the Tier 1 fee for small organisations currently starts at £40 per year. Failure to pay is itself a breach and the ICO can fine up to £4,350.
Breach notification
If an incident occurs — stolen NVR, ransomware on the VMS, misdirected footage export — you must assess whether it poses a risk to individuals. If yes, notify the ICO within 72 hours of becoming aware. If the risk is high you must also notify the affected individuals without undue delay.
Installer's technical checklist
The security principle is where installers can most help operators stay compliant. A defensible CCTV install in 2025/2026 should meet all of the following:
- Change every default password on cameras, NVRs, DVRs, switches and routers before commissioning.
- Isolate CCTV on its own VLAN or physical network, with no route to the internet except through a controlled gateway.
- Disable unused services (Telnet, FTP, UPnP, SNMPv1) on every device.
- Use HTTPS and SRTP for any browser, mobile or off-site access. Never rely on HTTP or plain RTSP over the public internet.
- Patch firmware — both at install and on a defined schedule. Keep a record of the firmware version against each device.
- Restrict physical access to the NVR/DVR, hard drives and the cabinet.
- Role-based accounts — individual named accounts for staff, no shared "admin" logins.
- Export workflow — a documented SAR export procedure that redacts third parties and records who was given what, when.
- Retention automation — NVRs should overwrite after the agreed retention period without manual intervention.
- Signage — provided by the installer at handover, positioned at every camera approach.
Most of these map directly to features in modern Hikvision, HiLook, Ajax and Ruijie kit. Our Hikvision CCTV Network Security Hardening post walks through the specific menus and settings.
Quick reference — what changed vs DPA 1998
- Subject Access Requests are now free and must be answered in 1 month (was £10 fee and 40 days).
- DPIA is a new, mandatory step for higher-risk CCTV.
- Fines are now up to £17.5 million or 4% of global turnover (was capped at £500,000).
- Breach notification to the ICO in 72 hours is new.
- Children's data, biometrics, and special-category data have stronger protections — important for face-recognition terminals and ANPR.
- The annual ICO data protection fee is now compulsory for almost every operator, replacing the voluntary "notification" system.
Useful references
- ICO — Video Surveillance Guidance
- ICO — SME self-assessment checklist
- Surveillance Camera Code of Practice (public authorities)
- ICO data protection fee
How Netview helps installers stay compliant
We stock CCTV, intruder, fire and network kit that supports the technical controls above out of the box — role-based accounts, VLAN-capable switches, signed firmware, encrypted remote access and configurable retention. Our Leicester warehouse dispatches same day on in-stock Hikvision, HiLook, Ajax, Pyronix and Ruijie lines, and our sales team can advise on product selection for compliance-sensitive installs. Call 01163 800 838 or email [email protected].
Last reviewed April 2026.
Share this post


About the Author

Netview CCTV Ltd is an Authorised Hikvision Wholesaler: Verify
- Website:https://www.netviewcctv.co.uk
- E-mail:[email protected]
- Our Hikvision Authorised Partner ID:HIK00004832
Our business has established itself as a highly trusted Trade distributor & retailer specializing in Leading Edge CCTV surveillance systems & accessories.
We have the technical expertise to help you make the correct choice for your requiremants.
All the products we sell offer excellent value for money, outstanding quality and superb performance
We are a Bricks & Mortar company, not just online, and we hold substantial stocks ready for immediate dispatch or collection at our premises in Leicester.
We are authorized Hikvision UK Distributors and offer full UK Hikvision Warranty with all our products. All produucts are fully upgrade-able with UK firmware.
Our contact details are:
Netview CCTV Ltd
Earls Way
Leicester
LE4 8FY UK
Telephone Leicester: 0116 3800838
Telephone London: 0203 6370383
Email Sales: [email protected]
Support: [email protected]
Website: www.netviewcctv.co.uk
Our page on FACEBOOK
Follow us on Twitter: @netviewcctv
Skype us on our id: netviewcctv
Watch our videos & demos on YOUTUBE
Netview CCTV Ltd follows the CCTV code of Practice which is part of the 1998 Data Protection Act. This can be found at www.ico.gov.uk
Netview CCTV, netviewcctv, netviewcctv.co.uk, netviewcctv.com are all trading names for NETVIEW CCTV Ltd registered in the UK company reg number: 08412263



