CCTV Thrapston


The Short Version
  • UK GDPR requires you to keep footage only as long as necessary for the purpose it was collected — the ICO considers 31 days standard for most commercial premises
  • Most DVR and NVR systems default to overwrite-on-full-capacity, not a fixed retention period — your actual retention may be far shorter than you think
  • Anyone who appears in your footage can request a copy — you have 30 days to respond to a Subject Access Request
  • Every CCTV system requires a written retention policy and an entry in your data protection register

Your CCTV system has been recording continuously for two years. When did you last check how long footage is stored before it overwrites? If the answer is never, your system may be retaining personal data far beyond what UK GDPR permits — or overwriting useful footage after seven days because the hard drive is undersized for the number of cameras you added.

CCTV footage is personal data. It captures identifiable individuals and falls squarely within the scope of the UK General Data Protection Regulation. The ICO (Information Commissioner’s Office) treats CCTV operators as data controllers, which means the same obligations that apply to your customer database apply to the footage your cameras record. The law does not specify an exact retention period. It requires you to make a documented decision about what is appropriate for your context and be able to justify it.

31
Days: ICO standard retention for most commercial premises
30
Days to respond to a Subject Access Request
~40GB
Storage per camera per day at 1080p H.264
Free
LNS CCTV health check, Northamptonshire

01What UK Law Says

What UK Law Says

UK GDPR’s storage limitation principle (Article 5(1)(e)) states that personal data must be kept in a form that permits identification of individuals for no longer than necessary for the purposes for which it was processed. Applied to CCTV: you must decide how long you need footage to fulfil the purpose of having the system (security, deterrence, incident evidence), set a retention period to match, and delete footage when that period expires.

The ICO’s guidance on CCTV and surveillance (updated 2023) states that 31 days is appropriate for most general security purposes. The guidance does not set 31 days as a legal maximum. It describes it as a reasonable default that most businesses can justify without needing to document exceptional circumstances.

If you deviate from 31 days in either direction, you need to record your reasoning. Keeping footage for 90 days without a documented reason exposes you to an ICO complaint. Keeping footage for 7 days because your hard drive filled up is a configuration failure, not a policy decision.

The ICO can and does act on complaints about CCTV. Common triggers include Subject Access Requests that go unanswered, footage shared with third parties without a lawful basis, and CCTV systems that cover public footpaths or neighbouring properties beyond what is necessary. A documented retention policy, visible CCTV notices, and ICO registration cost almost nothing to put in place. A formal reprimand or fine costs considerably more.

02The 31-Day Standard

The 31-Day Standard: Why It Exists

The ICO arrived at 31 days because most incidents that CCTV footage might evidence — theft, vandalism, a slip or trip, a dispute between parties — are reported within a few days of occurring. A 31-day window gives a meaningful buffer between the incident date and the point at which footage overwrites. It also limits the volume of personal data held at any given time, which reduces the scope of a potential data breach.

The figure assumes your system actually achieves 31 days of continuous retention. Many do not. A DVR or NVR set to overwrite-on-full-capacity with insufficient storage for the number of cameras at the configured resolution may overwrite footage within 10 to 14 days. The setting says one thing; the available storage determines what actually happens. Check the system’s current oldest footage timestamp to confirm actual retention, not the configured setting.

What your system should show

Log into your NVR or DVR management interface and check the timestamp of the oldest available footage. If you have eight cameras running at 1080p and your recorder holds 4TB, you may have less than two weeks of footage before it overwrites. Increasing storage to 8TB or 12TB, or switching from H.264 to H.265 encoding (which cuts storage by around 50% at equivalent quality), brings actual retention in line with your policy.

03Longer Retention

When to Keep Footage Longer

Some premises have legitimate reasons to retain footage beyond 31 days. The ICO accepts extended retention where you can articulate why the standard period is insufficient for your specific operational context. The reason must be documented in your CCTV policy.

  • Cash handling premises. Disputes over cash transactions, till discrepancies, or alleged theft by staff or customers can take weeks to surface. Retailers and hospitality businesses frequently retain footage for 60 to 90 days on this basis.
  • Premises with previous incidents. If your site has a history of break-ins, vehicle crime, or anti-social behaviour, you can document that as justification for a longer retention period matched to the typical investigation timeline for those offences.
  • Lone worker environments. Where staff work alone outside standard hours, extended retention supports incident review, duty-of-care obligations, and health and safety investigations.
  • High-value asset storage. Warehouses, plant yards, and equipment storage sites can align retention to the typical insurance claim investigation timeline, which may run to 60 or 90 days.
  • Active police investigations. When you provide footage to police as part of an ongoing investigation, preserve the relevant material until the investigating officer confirms it is no longer required.

In all cases, the extended period applies to the category of footage that requires it. A retail business retaining footage for 90 days does not need to justify retaining car park footage for the same period if there is no specific risk there. Segment your justification by camera zone where the retention periods differ.

04Storage

Storage Requirements

Storage requirements depend on four variables: number of cameras, resolution, encoding format, and whether recording runs continuously or on motion detection only.

Estimating storage

A single 1080p camera recording continuously at a typical CCTV bitrate (2 to 4Mbps) uses approximately 25GB to 50GB per day. At H.264, an eight-camera system recording continuously uses 200GB to 400GB per day. Achieving 31 days of retention at that rate requires 6TB to 12TB of storage in the recorder.

H.265 (HEVC) encoding cuts storage by around 50% at comparable image quality. If your cameras and NVR support H.265, switching encoding format may double your effective retention period without adding any hardware.

Motion-triggered recording reduces storage further — often by 60 to 80% on cameras that cover quiet areas. A camera covering a car park entrance that sees 30 minutes of actual movement per day uses a fraction of the storage of a camera recording a busy production floor continuously. Configure motion detection accurately and the storage saving is real; configure it too broadly and it records almost everything anyway.

Calculate your daily storage consumption before setting retention targets. Divide the total NVR storage by the daily consumption to get your current actual retention window. If the result is 12 days and your policy says 31 days, your system does not meet your own policy. Fix the storage before the policy, or the policy becomes meaningless.

05Subject Access Requests

Subject Access Requests

Any individual who appears in your CCTV footage can submit a Subject Access Request (SAR) under UK GDPR Article 15, asking for a copy of footage in which they appear. You have 30 days from receipt of the request to respond. Failing to respond within the deadline is a breach you can be reported to the ICO for.

What the response involves

You must locate the relevant footage, export a clip covering the period the requestor specifies, and redact or blur any third parties who appear in that footage before providing it. Sharing unredacted footage containing other individuals who have not consented to disclosure is a separate breach of UK GDPR. Most NVR and DVR systems include basic export tools; dedicated video redaction software handles blurring automatically.

Preserve footage immediately on receipt

When a SAR arrives, locate and preserve the relevant footage before processing the request. If the footage would overwrite during the 30-day response window, export it immediately. A SAR that arrives on day 28 of your 31-day retention period leaves three days before the footage overwrites. If the footage is gone when you try to respond, you face both a SAR failure and a question about whether your retention period was appropriate.

Keep a SAR log

Maintain a simple log of every SAR received: date of request, requestor name, the footage period requested, date footage was located, date of response, and what was provided. The ICO may ask for this log if a complaint is raised. A one-line spreadsheet entry per request takes two minutes and demonstrates a controlled process.

06Your Policy

Your Retention Policy

Every CCTV system requires a written retention policy. The ICO’s surveillance camera code of practice sets out what it should contain. A document of one to two pages covers the requirement.

What your CCTV retention policy must cover
  • The purpose of each camera and what area it covers
  • The retention period chosen and the documented reason for that period
  • Who within the business has access to live and recorded footage
  • The process for handling a Subject Access Request
  • The process for sharing footage with police or third parties, including the lawful basis
  • How footage is deleted at the end of the retention period (automatic overwrite or manual deletion)
  • The date the policy was written and the review schedule

Beyond the written policy, the ICO requires visible CCTV notices at each camera location. The standard notice includes the name of the data controller, the purpose of the system, and an ICO registration number. Most businesses operating CCTV must register with the ICO as a data controller; registration costs £40 to £60 per year depending on organisation size.

Your CCTV system should also appear in your data protection register (the record of processing activities required by UK GDPR Article 30). One entry covering the system as a whole, with the categories of data captured, the retention period, and the legal basis, satisfies this requirement.

07Questions

Frequently Asked Questions

Do we need to register with the ICO if we have CCTV?
Most businesses operating CCTV must register with the ICO as data controllers. Sole traders with no employees may qualify for an exemption, but limited companies and partnerships operating CCTV on business premises generally must register. Registration is straightforward via the ICO website and costs between £40 and £60 per year. Operating without registration when registration is required is a criminal offence.

Who within the business is allowed to view CCTV footage?
UK GDPR requires that access to personal data is restricted to those with a legitimate need. For CCTV, this typically means designated security staff, senior management, and the person responsible for data protection. Staff should not be able to access the recording system without authorisation. Access controls on the NVR or DVR management software, including individual login credentials rather than a shared password, satisfy this requirement and produce an access log.

What if footage is needed for an insurance claim after the retention period expires?
Footage overwritten before a claim is submitted cannot be recovered. The practical solution is to review footage promptly after any incident and export relevant clips to a separate secure location before they reach the end of the retention period. Some businesses set a shorter routine retention period (31 days) for general footage but retain incident-flagged exports indefinitely, stored separately with a record of why the footage was preserved.

Does UK GDPR apply to dummy cameras?
Dummy cameras that record nothing are not processing personal data and fall outside UK GDPR’s scope. However, the ICO’s surveillance camera code of practice advises against using dummy cameras alongside real ones without clear signage indicating that not all cameras record. A member of the public who submits a SAR for footage they believe exists, only to be told the camera was a dummy, may feel misled. Separating real cameras from deterrent-only cameras clearly in your CCTV policy and notices avoids this.

Can LNS check whether our current CCTV system meets the 31-day retention target?
Yes. We carry out CCTV health checks across Northamptonshire that cover storage capacity, actual retention achieved, camera condition, recording quality, and system configuration. We also advise on CCTV notices and data protection documentation. Call 01604 422760 or contact us online to arrange a free visit.

Free · No Obligation

Book a Free CCTV Health Check

We will check your actual retention period against your storage capacity, review your camera configuration, and confirm whether your system meets UK GDPR requirements. No sales pressure, no generic report.

Book Your Free Health Check

Need IT and Security Support?

Local engineers. Proactive monitoring. No jargon. Serving Northamptonshire businesses since 2009.

01604 422760

Leave a Reply

Your email address will not be published. Required fields are marked *

— Work with us

Ready to take IT and Security off your plate?

We work with Northamptonshire SMEs to keep systems running, secure, and supported. Get a free site survey with no obligation.