00:00:00/Guide
CCTV and GDPR: what you can and can't do
Running CCTV at a business in the UK is legal, provided you can say why you're recording, tell people you're doing it, keep footage no longer than you need, and hand it over when someone asks for footage of themselves. The rules come from UK GDPR and ICO guidance, and they're more manageable than they sound.
Most operators running CCTV aren't being cavalier, they're just unsure whether they're doing it right. This page is the practical checklist rather than a legal treatise, and the short version is reassuring: ordinary CCTV, done carefully, is routine under UK GDPR.
The operator's checklist
- Know your lawful basis for recording (usually legitimate interests) and write it down.
- Put up clear signage saying recording is happening and who's responsible for it.
- Set a retention period you can justify, and actually delete footage on that schedule.
- Be ready for subject access requests: people can ask for footage of themselves.
- Restrict who can view footage, and keep any exports controlled.
Where AI analytics fits
Adding analysis on top of CCTV is still data processing, so the same duties apply: a lawful basis, signage, retention, the lot. What actually matters is what kind of processing you're adding. Describing scenes and searching those descriptions sits in a different category from identifying individuals, and that distinction does a lot of work in how much risk a system carries.
Biometrics is the high-risk line
Facial recognition and other biometric identification is the category UK GDPR treats as special category data, with the heaviest requirements and the most ICO attention. Svid avoids it by design: no facial recognition, no biometric IDs, and no re-identification either. The only AI in the product describes images, checks conditions on them, and embeds the descriptions for search. For sites that can't send frames to the cloud, a fully on-prem appliance mode keeps everything inside the building, which simplifies the data-flow story considerably.
- 01
Write down why each camera exists
A short, honest reason per camera is the basis for everything that follows.
- 02
Check the signage is visible and current
It should say recording is happening and who's responsible.
- 03
Set and document retention
Pick a period you can justify, and confirm deletion actually happens on that schedule rather than footage just piling up.
- 04
Agree a process for access requests
Decide how you'd find and hand over footage of a specific person before someone actually asks.
- 05
Record what any analytics adds
When you switch on AI analysis, note what processing it introduces and confirm it doesn't add biometric identification.
There's a small upside worth a dry mention: if footage is already searchable by description, answering a subject access request stops being an afternoon of scrubbing and becomes typing what the person was wearing.
- Do I need a sign if I have CCTV at my business?
- Yes. Clear signage saying recording is happening and who's responsible is a basic expectation under UK GDPR and ICO guidance.
- How long can I keep CCTV footage?
- As long as you can justify and no longer. There's no fixed statutory number; the ICO's guidance is the place to check what's reasonable for your situation.
- Can someone ask me for footage of themselves?
- Yes, subject access requests cover CCTV footage of a named individual. It's worth having a process for finding and handing over footage before one actually arrives.
- Is AI video analysis legal under UK GDPR?
- It's processing like the CCTV itself, so the same duties apply, with biometric identification as the high-risk line. Svid avoids that category by design, but that's a description of the approach, not a guarantee of compliance for your setup.
See description-based search in practice
If the biometrics line is the bit that worries you, create an account at app.svid.ai and see what description-based search looks like on your own footage.
Related footage