Why does CCTV require compliance?

Did you know that data protection laws now require anyone with a surveillance system, such as Closed-Circuit Television (CCTV), even if it’s just one camera, to now comply and use their systems within the new rules set out in data protection laws? 

There are approximately six million surveillance cameras in operation around the UK according to the British Security Industry Association (BSIA). This figure does not account for the number of ‘Ring’ cameras in use in the UK, which qualify as surveillance when they are not being used for a ‘purely personal or household’ purpose. 

Just over a year ago (12 October 2021) the Oxford County Court found a homeowner guilty of breaching the Data Protection Act 2018 (DPA 2018) and UK General Data Protection Regulation (UK GDPR) by using ‘Ring’ security cameras on their property. In the court case ‘Dr Mary Fairhurst v Mr Jon Woodard’, the judge ruled that Mr Woodard was guilty of violating the transparency, data minimisation and purpose limitation principles of UK GDPR. While Mr Woodard had a legitimate interest to operate the ‘Ring’ cameras for the use of crime prevention, the judge ruled that he could’ve done so in a less intrusive manner that wouldn’t infringe Dr Fairhurst’s privacy. 

Surveillance footage, including CCTV footage, falls within the scope of personal data and special category data (biometric data) if individuals can be identified from the footage. Thus, surveillance systems, including CCTV, must also comply with data protection laws.

These data protection laws include the UK and EU GDPR, and the Biometrics and Surveillance Camera Commissioner Code of Conduct among others. A major element of the new rules includes the use of CCTV signs in public spaces that are clearly visible and include the contact details of the system’s owner so data subjects can exercise their rights and ask for more information. There are also several other measures that need to be implemented to achieve compliance. 

A key measure of compliance relies upon the registration of your surveillance camera system (even if it’s only one camera) with the ICO. Failure to do so is a criminal offence. An annual formal notification to the ICO should take place as one of your steps towards maintaining compliance. However, achieving compliance with data protection legislation and the CCTV code of conduct is an ongoing process once a CCTV system has been installed. 

If you’d like to find out some top tips on how to achieve compliance, then keep an eye out for a future blog post. 

CCTV compliance is often forgotten, and as shown by the Ring court case, it applies to everyone, whether an individual or an organisation. 

If you require additional support with demonstrating or achieving CCTV/surveillance system compliance you can contact us at info@dataprivacyadvisory.com or by calling our office at 0203 301 3384.

Related articles: 

https://www.theguardian.com/uk-news/2021/oct/14/amazon-asks-ring-owners-to-respect-privacy-after-court-rules-usage-broke-law 

https://www.huntonprivacyblog.com/2021/10/13/uk-homeowners-use-of-ring-security-camera-found-to-infringe-uk-gdpr/

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation