Business CCTV and Data Protection: What the ICO Expects
CCTV is one of the most sensible investments a business can make. It deters crime, protects staff and stock, and gives you evidence when something goes wrong. Door entry and video intercom systems do the same for access. What many business owners do not realise is that the moment those cameras capture an identifiable person, you are processing personal data, and that puts you squarely under UK data protection law. The Information Commissioner’s Office (ICO) enforces those rules, and in 2025 it issued 28 monetary penalty notices, its highest annual total since the current regime began.
The good news is that getting CCTV right is not complicated. Here is what the ICO expects, and what tends to land businesses in trouble.
Your CCTV makes you a data controller
Under the UK GDPR and the Data Protection Act 2018 (recently updated by the Data (Use and Access) Act 2025), any organisation that operates CCTV capturing identifiable people is a data controller. That is true whether the footage is for crime prevention, health and safety, or simply keeping an eye on the car park. Being a controller means the law expects you to have thought about why you are recording, how long you keep it, who can see it, and how you tell people it is happening.
This applies to small businesses just as much as large ones. A single camera over a shop door still records members of the public, so the same principles apply, scaled to what you actually do.
What the ICO expects from you
The ICO’s video surveillance guidance comes down to a handful of practical duties:
- A documented lawful basis. Most businesses rely on “legitimate interests” for crime prevention. You should record a short legitimate interests assessment showing you weighed the benefit against people’s privacy.
- Clear signage. Visible signs at every entrance telling people CCTV is in operation, who operates it, and why. No hidden cameras.
- A retention policy. Keep footage only as long as you genuinely need it. Around 30 days is typical, unless a specific incident means you need to hold a clip for longer.
- A process for access requests. People have the right to ask for footage of themselves, known as a subject access request, and you normally have one month to respond. You need a way to find, review and redact other people from that footage.
- A DPIA for anything extensive. Systematic or large-scale monitoring, or cameras in sensitive areas, usually require a Data Protection Impact Assessment before you switch them on.
- Registration with the ICO. If you process personal data with CCTV, you almost certainly need to be registered with the ICO and pay the annual data protection fee. Our ICO registration guide covers who needs to register.
Door cameras and video entry need extra thought
Door entry cameras, video intercoms and doorbell-style cameras are increasingly common, and they raise one particular issue: what they capture beyond your own property. A camera pointed only at your entrance is usually fine. One that also records the public pavement, the street, or a neighbouring business brings all of that into scope, and the people captured have rights too.
This was tested in a well-known 2021 county court case, Fairhurst v Woodard, where a smart doorbell and cameras that captured a neighbour’s property and audio were found to breach data protection law. The principle applies to businesses just as much: if your door camera sees more than your own doorway, treat it as CCTV and follow the same rules. Audio deserves special care, as it is far more intrusive than video and much harder to justify, so most businesses are better off leaving microphones switched off.
What actually gets businesses in trouble
The common failings are simple and avoidable: no signage, footage kept indefinitely “just in case”, ignoring or fumbling a request for footage, recording audio without a good reason, and cameras that cover far more than the business needs. The ICO publishes its enforcement actions openly, and while the headline fines (up to £17.5 million or 4% of global turnover for the most serious breaches) are aimed at large organisations, the reputational damage and disruption of getting it wrong hits smaller businesses hardest.
A quick CCTV compliance checklist
- A written reason for each camera, and a legitimate interests assessment.
- Signage at every entrance, naming you as the operator.
- A retention period, with cameras set to actually delete on schedule.
- A named person who handles footage requests.
- Cameras angled to cover only what you need.
- Microphones off unless you can justify audio.
- Registered with the ICO, fee paid.
Getting it right, without the headache
Business CCTV should make you safer, not create a compliance risk. We design, install and maintain camera and door entry systems as part of our business CCTV and integrated physical and cyber security services, and we set them up to meet the ICO’s expectations from day one, from camera angles and signage through to retention and access. As a UKAS ISO/IEC 27001 certified provider, protecting data properly is simply how we work.
If you are not sure whether your current setup is compliant, get in touch and we will take a look.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


