The regulations governing CCTV and remote monitoring in businesses are strict. Here are the key rules.
The principle of proportionality: you can only record what is necessary for a specific security purpose. Excessive surveillance is not permitted.
Informing people: you must clearly inform people that CCTV is in operation and explain its purpose. This is normally done through clearly visible signs at the entrance to the monitored area. Businesses using CCTV must also comply with applicable data protection requirements and, in many cases, pay the ICO data protection fee.
Example of an information sign
“CCTV in operation.
Data controller: [Company name].
Purpose: security of people and property.
CCTV footage retention period: [30] days.
To exercise your rights, contact: [department / email address].
More information: ico.org.uk”
Employees: the rules governing workplace CCTV protect their privacy:
- You must inform employees about the monitoring and explain its purpose.
- You must have a lawful basis for monitoring employees and ensure that the monitoring is necessary and proportionate.
- You should use the least intrusive means necessary to achieve the security objective.
- You should not use CCTV installed for security purposes to continuously monitor employee performance.
- Cameras should not normally be installed in areas where employees have a high expectation of privacy, such as toilets and changing rooms.
The ICO states that employers must be clear about the purpose of employee monitoring, document their justification and avoid collecting more information than necessary.
Customers and visitors: clear signage at the entrance informs them that CCTV is in operation.
UK GDPR and the ICO: you must also:
- identify an appropriate lawful basis for processing personal data;
- include the system in your records of processing activities, where applicable;
- limit the retention period for footage to what is necessary for the purpose of the system;
- secure access to footage, restricting it to authorised people;
- consider whether a Data Protection Impact Assessment (DPIA) is required, particularly where surveillance is likely to result in a high risk to individuals, such as workplace monitoring.
The UK GDPR does not set a universal retention period for CCTV footage. The retention period should be based on the specific purpose and business need, and should be reviewed regularly.
These requirements can sometimes be seen as a constraint. When they are properly incorporated from the design stage, however, they instead provide protection for the business, both in the event of an inspection and in the event of a dispute.