UK CCTV Rules for Businesses: A Simple Compliance Guide

CCTV can be one of the most effective ways to protect a business, deter theft, improve staff safety and monitor activity around commercial premises. However, business CCTV in the UK must be used responsibly.

If your CCTV system records customers, staff, visitors, delivery drivers or members of the public, the footage may count as personal data. This means your business needs to follow UK data protection rules, including the UK GDPR and the Data Protection Act 2018.

This guide explains the main CCTV rules for businesses in the UK and what you should check before installing or upgrading a commercial CCTV system.

1. You must have a clear reason for using CCTV

Before installing CCTV, a business should be able to explain why cameras are needed. Common reasons include:

  • Preventing theft or vandalism
  • Protecting staff, customers and visitors
  • Monitoring entrances, exits and car parks
  • Supporting health and safety
  • Recording evidence if an incident happens

CCTV should not be installed “just in case” without a clear purpose. The system should be necessary and proportionate for the risk you are trying to manage.

For official guidance, see the ICO CCTV and video surveillance guidance.

2. You may need to register with the ICO and pay a data protection fee

Most UK businesses using CCTV for crime prevention need to register with the Information Commissioner’s Office and pay a data protection fee, unless they are exempt.

GOV.UK explains that businesses using CCTV must register their details with the ICO and pay the fee unless an exemption applies. You can read the official GOV.UK page here: Data protection and your business: using CCTV.

You can also check the ICO’s own page here: ICO data protection fee.

3. CCTV signs must be clear and visible

If your business uses CCTV, people should know they are being recorded. This usually means placing clear CCTV signs where people can see them before entering the monitored area.

A good CCTV sign should usually include:

  • A clear statement that CCTV is in operation
  • The reason for the recording, such as crime prevention or staff safety
  • The name of the organisation responsible for the system
  • Contact details or a way to find more information
  • A link or reference to your privacy notice, where possible

Signs should be easy to read and placed at entrances, reception areas, car parks, shop floors or anywhere cameras are operating.

4. Do not record more than necessary

Business CCTV should only cover areas that are relevant to your security purpose. Cameras should be positioned carefully so they do not capture unnecessary footage.

For example, avoid pointing cameras at:

  • Neighbouring properties
  • Public areas that are not relevant to your premises
  • Toilets, changing rooms or private staff areas
  • Workstations where constant monitoring is not justified

If a camera captures too much, consider repositioning it, adjusting the angle or using privacy masking.

5. Be careful when using CCTV to monitor staff

Businesses can use CCTV in workplaces, but employee monitoring must be fair, necessary and transparent. Staff should normally be told that CCTV is in use, why it is being used and how the footage may be handled.

Covert CCTV should only be used in exceptional situations, such as a serious investigation, and only where it is justified.

The ICO has guidance for employers here: Employee monitoring: is it right for your business?.

6. Store CCTV footage securely

CCTV footage should be protected from unauthorised access. This means your business should control who can view, export, copy or delete recordings.

Good security measures include:

  • Password-protected CCTV systems
  • Strong admin passwords
  • Limited user access
  • Secure NVR or DVR storage
  • Regular software and firmware updates
  • Encrypted remote access where available
  • A record of who accesses or exports footage

Remote viewing should also be secured properly. Weak passwords, old firmware and open network ports can create security risks.

7. Do not keep footage for longer than needed

There is no single fixed CCTV retention period for every UK business. Instead, you should keep footage only for as long as necessary for your stated purpose.

Many businesses choose a retention period such as 14, 21 or 30 days, depending on their risk level, insurance needs and operational requirements. If footage is needed for an incident, investigation or legal claim, it can usually be kept for longer while that issue is ongoing.

Your business should have a written retention policy explaining:

  • How long CCTV footage is normally kept
  • When footage may be kept for longer
  • Who can approve extended retention
  • How footage is securely deleted

8. People can request CCTV footage of themselves

Individuals have the right to request personal data that your business holds about them. This can include CCTV footage where they are identifiable.

This is known as a subject access request, or SAR. If someone asks for CCTV footage, your business should have a process for checking the request, locating the footage and protecting other people’s privacy.

For example, if other individuals appear in the recording, you may need to blur or redact them before sharing the footage.

Official ICO guidance is available here: Subject access request advice.

9. You may need a Data Protection Impact Assessment

A Data Protection Impact Assessment, often called a DPIA, helps a business identify and reduce privacy risks before using CCTV.

A DPIA is especially important if your system involves:

  • Large-scale monitoring
  • Cameras covering public areas
  • Employee monitoring
  • Facial recognition or analytics
  • Audio recording
  • High-risk locations
  • New surveillance technology

The ICO explains DPIAs here: Data protection impact assessments.

10. Audio recording needs extra care

Audio recording is usually more intrusive than video-only CCTV. Businesses should avoid recording audio unless there is a strong and clearly documented reason.

If audio is necessary, people should be clearly informed, and the business should explain why audio recording is proportionate. In many cases, video-only CCTV will be enough.

11. Keep your CCTV policy up to date

A business CCTV policy does not need to be complicated, but it should explain how your system is used.

Your CCTV policy should cover:

  • Why CCTV is used
  • Where cameras are located
  • Who is responsible for the system
  • Who can access footage
  • How long footage is kept
  • How people can request footage
  • How footage is shared with police or insurers
  • How the system is reviewed

You should also review your CCTV setup regularly to make sure cameras are still needed and are not recording more than necessary.

12. Follow the Surveillance Camera Code where relevant

Some organisations should also consider the UK Government’s Surveillance Camera Code of Practice, especially where surveillance affects public areas or is used by public authorities.

You can read the GOV.UK guidance here: Surveillance Camera Code of Practice.

Business CCTV compliance checklist

Before installing or upgrading CCTV, check the following:

  • You have a clear reason for using CCTV
  • Cameras only cover necessary areas
  • CCTV signs are visible and easy to read
  • Staff and visitors are informed where appropriate
  • You have checked whether you need to pay the ICO fee
  • Footage is stored securely
  • Access to footage is limited
  • You have a retention policy
  • You can respond to subject access requests
  • You have completed a DPIA where needed
  • Your system is reviewed regularly

Need help choosing a business CCTV system?

Choosing the right CCTV system is not only about camera quality. A good business CCTV setup should also support privacy, security and compliance.

Lensia helps UK businesses understand CCTV options, compare systems and connect with trusted installers. Whether you need CCTV for a shop, office, warehouse, restaurant, car park or commercial building, Lensia can help you make a clearer decision before installation.

Explore more CCTV advice on Lensia or connect with a professional installer through Lensia Connect.

Frequently Asked Questions

Do businesses need CCTV signs in the UK?

Yes. If your business uses CCTV, you should make people aware that recording is taking place. CCTV signs should be clear, visible and easy to understand.

Does a business need to register CCTV with the ICO?

Many businesses using CCTV for crime prevention need to register with the ICO and pay a data protection fee, unless they are exempt. You can check the official guidance on the ICO website.

How long can a business keep CCTV footage?

There is no single fixed period for every business. Footage should only be kept for as long as necessary. Many businesses use a retention period such as 14 to 30 days, unless footage is needed for an incident or investigation.

Can employees be monitored by CCTV?

Yes, but employee CCTV monitoring must be fair, necessary and transparent. Staff should normally be told why CCTV is being used and how the footage may be used.

Can customers request CCTV footage?

Yes. If a customer is identifiable in CCTV footage, they may be able to request a copy through a subject access request. Your business must also protect the privacy of other people shown in the footage.

Is CCTV audio recording allowed in a business?

Audio recording is more intrusive than video recording and should only be used where there is a strong, justified reason. Most businesses should avoid audio recording unless it is clearly necessary.

Final thoughts

CCTV can protect your business, staff and customers, but it must be installed and managed responsibly. Clear signage, secure storage, limited access, sensible retention periods and a simple CCTV policy can help your business stay compliant.

Before choosing a system, think about what you need to protect, where cameras should be placed and how the footage will be managed. A properly planned CCTV system can improve security while respecting privacy.

Disclaimer: This article is for general information only and is not legal advice. For specific compliance questions, check the ICO guidance or speak to a qualified data protection professional.