Yes, CCTV is legal across the UK. But the moment a camera captures anyone beyond your own boundary, UK GDPR and the Data Protection Act 2018 apply, and you become responsible for signage, footage security, and requests to see recordings. Act on those obligations before you switch the system on, not after someone complains.
TL;DR:
- If your CCTV system captures images beyond your own property, you become a data controller and must comply with signage, footage security, and data access obligations.
- Homeowners with cameras pointing at public or shared areas are likely to process personal data, triggering legal duties such as responding to subject access requests.
- Businesses capturing footage of people outside their property boundaries generally need to register with the ICO and pay an annual data protection fee.
- Signage is legally required only when cameras cover public or shared spaces, with size and placement rules ensuring clear communication of CCTV operation.
- Footage should be retained only for necessary periods, usually up to 30 days, with strong security measures such as password changes and access logs to prevent unauthorized access.
Table of Contents
- What laws, codes and regulators govern CCTV in the UK?
- When does data protection law apply, and what’s the domestic exemption?
- Do businesses need to register with the ICO?
- What signage and transparency rules apply to CCTV?
- How do you handle a subject access request for footage?
- How long should you keep CCTV footage, and how should you secure it?
- Is audio recording or filming private areas ever acceptable?
- When do you need a Data Protection Impact Assessment?
- How do you resolve a neighbour dispute over CCTV?
- What’s the practical compliance checklist?
- Contractor perspective: what installation actually looks like in practice
- How Smart Home Technical Ltd handles compliant CCTV installation
- Sources
What laws, codes and regulators govern CCTV in the UK?
Three legal instruments do the heavy lifting. UK GDPR and the Data Protection Act 2018 set the ground rules for handling anyone’s image, including footage stored on a hard drive in your hallway cupboard. If your camera picks up faces, number plates, or identifiable movement of people outside your own property, you’re processing personal data, and both laws apply in full.
The Protection of Freedoms Act 2012 introduced the Surveillance Camera Code of Practice, built around 12 principles covering necessity, proportionality, transparency, and limited retention. Local authorities and police forces must have regard to the code by law. Private homeowners and businesses aren’t legally bound by it, but treating it as the benchmark keeps you well clear of enforcement trouble.
Two regulators sit above all this. The Information Commissioner’s Office (ICO) is the day-to-day authority most owners will actually deal with, publishing the guidance and checklists that turn statute into practical steps. The Biometrics and Surveillance Camera Commissioner (BSCC) oversees the wider surveillance camera framework and code compliance, mostly for public-sector operators.

When does data protection law apply, and what’s the domestic exemption?
The ICO’s guidance for domestic CCTV draws a hard line: if your camera only covers your own house, garden, and driveway, you’re exempt from most data protection obligations. Point it at the street, a shared path, or your neighbour’s fence, and the exemption disappears.
This trips up more homeowners than you’d think. A doorbell camera angled to catch parcel thieves will almost always capture a slice of pavement, which technically makes you a data controller the second someone else’s image lands in your footage. Cameras covering communal stairwells in flats, shared driveways, or a sliver of a neighbour’s garden fall into the same trap.
Becoming a data controller isn’t a disaster, but it does mean new duties: responding to subject access requests, keeping footage secure, and being able to justify why you’re recording what you’re recording. Ring doorbell setups and similar smart doorbells are the most common domestic system to slip outside the exemption, simply because of where they naturally point.
Do businesses need to register with the ICO?
If your business captures images of people beyond your own property boundary, whether that’s customers on a shop floor, delivery drivers in a yard, or pedestrians on a street-facing camera, you almost certainly need to register with the ICO and pay the annual data protection fee.
Fee bands depend on turnover and staff numbers, and most small and medium businesses fall into the lower tiers, though the exact figure should be checked against the current gov.uk fee schedule rather than assumed. Some organisations are exempt, for instance certain not-for-profits or businesses using CCTV purely for domestic-equivalent purposes.
The quickest way to find out where you stand is the ICO’s self-assessment tool, which asks a handful of questions about your processing activity and tells you whether registration is required. Skipping this step is one of the more common compliance gaps small business owners fall into, usually because they assume CCTV is a security matter rather than a data protection one.
What signage and transparency rules apply to CCTV?
Anyone entering a space monitored by CCTV needs a fair chance to know it’s happening before they walk into shot. That’s the transparency principle behind signage requirements, and it applies whenever your cameras cover anything beyond strictly private, domestic space.
A compliant sign should cover a few essentials:
- A clear statement that CCTV is in operation
- The purpose of recording (security, crime prevention, and so on)
- Who operates the system and how to contact them
- Placement before someone enters the monitored area, not after
Sizing matters more than people expect. Indoor signage around A4 size and outdoor signage closer to A3 tends to be legible from a sensible distance, which matters if you’re relying on the sign to prove transparency later.
If your setup is genuinely domestic, covering only your own home and garden with nothing spilling onto public or shared land, signage generally isn’t a legal requirement. It’s still good practice, particularly if you want to deter opportunistic break-ins rather than just record them after the fact.
How do you handle a subject access request for footage?
Anyone who appears on your CCTV can ask to see that footage under a subject access request (SAR), and once you’re a data controller you’re obliged to respond, usually within one calendar month according to gov.uk guidance on CCTV.
Preparing for this starts with knowing where your footage actually lives and how quickly you can pull a specific date and time range. When you locate the clip, you’ll usually need to redact or blur any third parties who appear alongside the person requesting it, since their privacy rights don’t disappear just because someone else asked first.

You can refuse or limit disclosure in specific circumstances, for example where handing over footage would seriously compromise another individual’s rights or where the request is manifestly unreasonable. Outright refusal without a documented reason is risky. If someone also asks you to delete footage of them (a right to erasure request) or objects to being recorded, you need a process for weighing that against your own legitimate interest in keeping the system running.
How long should you keep CCTV footage, and how should you secure it?
Keep footage only as long as you can justify keeping it. That’s the core principle running through UK data protection law, and for most domestic and small-business systems, a rolling retention window of somewhere between a few days and 30 days covers most legitimate security needs. Automatic overwrite settings, standard on most modern recorders, do the deleting for you without anyone needing to remember.
Longer retention needs a reason: an ongoing investigation, a specific incident under review, or a legal dispute where footage is evidence. Once that reason ends, delete the clip rather than leaving it to expire naturally.
Security matters as much as retention limits. A recorder with a factory-default password, accessible from anywhere on the internet, is a genuine liability, not just a compliance box left unticked. Sensible baseline measures include:
- Changing default passwords immediately on installation
- Restricting viewing access to named, authorised individuals
- Encrypting stored footage where the hardware supports it
- Keeping an access log of who viewed or exported footage, and when
Is audio recording or filming private areas ever acceptable?
Rarely, and almost never without strong justification. Audio recording is considerably more intrusive than video, picking up conversations that have nothing to do with security, and ICO guidance treats it as hard to justify in most domestic and workplace settings. Unless you have a specific, documented reason, leave audio disabled.
Filming toilets, changing rooms, or similar private spaces is treated as a near-total prohibition. The bar for justifying it, even in a workplace with a genuine security concern, sits extremely high and usually needs specialist legal advice before you even consider it.
Covert recording, cameras hidden from the people they capture, carries real legal risk outside narrow, specific circumstances such as a formally authorised investigation. Assume covert filming is off the table unless you’ve had it confirmed otherwise.
When do you need a Data Protection Impact Assessment?
A DPIA becomes necessary whenever CCTV use is likely to create a high risk to the people it captures, and ICO guidance for organisations lists several common triggers:
- Monitoring staff systematically, rather than covering entrances or tills
- Large-scale coverage of public or customer-facing areas
- Any camera capturing normally private spaces
- Automatic number plate recognition (ANPR) or facial recognition features
A solid DPIA for CCTV documents the purpose of recording, why less intrusive options wouldn’t work, what mitigations you’ve put in place (masking, angle restrictions, retention limits), and who can access the footage.
Pro Tip: If your DPIA still shows high residual risk after every mitigation you can think of, that’s the point to consult the ICO directly rather than pressing ahead and hoping it holds up later.
How do you resolve a neighbour dispute over CCTV?
Most neighbour disputes over cameras start the same way: someone notices a lens pointing roughly their direction and assumes the worst. Talking to them first, explaining what the camera actually covers and why, resolves more of these than any formal process ever will.
If the angle genuinely does capture more of their property than yours, technical fixes are usually straightforward: privacy masking software blacks out a defined zone in the recorded image, repositioning the camera a few degrees narrows the field of view, and cropping the recorded frame removes the disputed area entirely without losing your own coverage.
Where a neighbour won’t engage or the dispute escalates, gov.uk’s guidance on resolving neighbour disputes points towards mediation before anything more formal. The ICO becomes relevant only if there’s a genuine data protection complaint, not simply a disagreement about aesthetics or where a fence line falls.
What’s the practical compliance checklist?
Setting this up properly, rather than bolting it on after a complaint, generally takes a homeowner an afternoon and a small business a week or two once registration and documentation are factored in. Work through it in this order:
- Define the specific purpose for recording before buying anything
- Angle and mask cameras to capture only what that purpose requires
- Install signage wherever coverage extends beyond your private boundary
- Set a retention period and configure automatic overwrite
- Register with the ICO and pay the data protection fee if the business exemption doesn’t apply
- Complete a DPIA if any high-risk trigger applies
- Write down your SAR process so you’re not improvising when a request lands
| Requirement | Applies to | Key action |
|---|---|---|
| ICO registration and fee | Businesses capturing images beyond boundary | Complete ICO self-assessment |
| Signage | Any coverage of public/shared space | Sign before entry point, purpose and contact stated |
| Retention limit | All CCTV operators | Set and document an overwrite schedule |
| DPIA | High-risk uses (staff monitoring, ANPR, large scale) | Document purpose, mitigation, access controls |
| SAR process | Anyone holding footage of identifiable people | Locate, redact third parties, respond within one month |
Keep a written CCTV policy, your DPIA if one was required, and an access log on file. The ICO’s CCTV checklist and gov.uk’s guidance are the two documents worth bookmarking for updates.
Contractor perspective: what installation actually looks like in practice
Most compliance failures I come across start with a camera bracket, not a policy document. Someone mounts a unit at the angle that happens to catch the best light, and only later realises it’s framing the neighbour’s kitchen window or clipping the edge of a pavement. Positioning has to be decided before the drill comes out, not adjusted afterwards once someone complains.
Where a property also has solar panels, camera brackets and cable runs need planning around the array and its junction boxes, partly for aerial interference reasons and partly because retrofitting cabling around panels after installation is far messier than routing it first.
A proper handover pack should include a field-of-view diagram, the signage wording used, retention settings, and a plain-English SAR process the owner can actually follow. If you’re planning a CCTV installation and want it done with that documentation built in from day one, get in touch.
— Simon
How Smart Home Technical Ltd handles compliant CCTV installation
Smart Home Technical Ltd is the practical alternative to fitting a camera yourself and guessing at the angles: a proper site survey, positioning that avoids capturing neighbouring property, and a handover pack built around ICO requirements from the outset, not bolted on after a complaint.

That means a system where signage wording, retention settings, and the SAR process are documented and configured before the installer leaves site, so you’re not scrambling to work out how to export a clip when a request actually lands. It’s the same site-survey discipline brought to solar installations, where camera positioning, cabling, and existing rooftop equipment all need to be considered together rather than as separate jobs.
If you’re weighing up a CCTV installation alongside other electrical work, whether that’s an EV charger, battery storage, or a solar retrofit, consider engaging a professional electrical contractor for a site survey and a compliant setup from day one.