CCTV policy for a shop or workplace

A CCTV policy for a business's premises, drafted for the business with the privacy notice, cookie notice and consent guidance, for a fixed fee of £595 in five working days.

Share

CCTV policy for a shop or workplace

Buy now, £595

A CCTV policy is the internal document that makes a business's cameras lawful: it records why the cameras are there, where they point and where they must not, who may view and export footage, how long it is kept, how requests are handled, and how the system is reviewed, so that the privacy notice and the signs the public see are backed by practice the business can show the regulator. I draft the CCTV policy with the privacy notice and the cookie notice for the business for a fixed fee of £595, delivered in five working days, with guidance on the signage and the records.

Who this is for

Shops, offices, warehouses, workshops, hospitality venues, gyms and any business in England and Wales operating cameras on its premises, and managers who have inherited a system with no paperwork.

What matters in a CCTV policy

The policy, the privacy notice and the signs as three parts of one system

As controller, the business must under Article 13 of the UK GDPR tell the people it films, which the signs and the privacy notice do, and the policy is the internal document that governs how the system is run so that what the signs and the notice say is true; the Information Commissioner's guidance on video surveillance expects an operator to have a documented purpose, an assessment, a policy on access and retention, and a process for requests, and the policy is where those live; the three documents should say the same thing, because a sign that says 'for your safety' above a camera the policy says is for monitoring staff is the inconsistency a complaint exposes.

The purposes the cameras serve and the assessment that records them

The policy should state the purposes (the prevention and detection of crime, the safety of staff and customers, the protection of property, the investigation of incidents) and the lawful basis (legitimate interests under Article 6(1)(f) of the UK GDPR, with the balance recorded), should record the data protection impact assessment under Article 35 that systematic monitoring of a publicly accessible area requires (the risks to the people filmed, the alternatives considered, the measures adopted), and should say that footage is not used for other purposes (routine performance monitoring of staff, for example) unless the policy and the notices are changed first; a camera installed for one purpose and used for another is processing without a basis.

Siting, coverage and the areas that are off limits

The policy should list the cameras and their fields of view, should confine coverage to the business's own premises and the immediate approaches (not the neighbouring property or the street beyond what is incidental), should prohibit cameras in toilets, changing rooms, rest areas and anywhere people expect privacy, should state whether audio is recorded (it should not be, unless a specific justification is recorded), and should say how new cameras are approved; the plan of the cameras is the document the regulator asks for when a complaint arrives, and the policy should keep it current.

Access, retention and the log

The policy should name the roles that may view live and recorded footage, the roles that may export it, the authorisation needed for each, the log kept of every viewing and export (who, when, why, what was taken), the security of the recorder and any remote access (the installer's default password changed, remote access limited and logged), the retention period (a stated number of days, with automatic overwriting) and the exception where footage is preserved for an incident, investigation or request, with the preserved footage deleted when the matter is closed; a retention period the system does not enforce is a policy the business is not following.

Requests for footage from the police, insurers, staff and the public

The policy should set the procedure for each request: the police (a written request identifying the investigation, under the crime exemption in Schedule 2 to the Data Protection Act 2018, recorded and reviewed before disclosure), insurers and solicitors (for incidents and claims, with the footage limited to the incident), staff and the public who appear in footage (a subject access request under Article 15 of the UK GDPR, answered within one month with other people obscured where possible, or an explanation of why the footage cannot be provided), and third parties who want footage of someone else (refused unless a lawful route applies); the procedure protects the business from the request it should refuse as much as from the one it should grant.

Review, new cameras and the system that grows

The policy should set an annual review of the cameras, the purposes, the retention and the assessment, should require the assessment to be revisited before cameras are added or upgraded (facial recognition, number plate recognition, analytics and body-worn cameras each raise the risk and some involve special category data under Article 9), should say who owns the policy, and should be issued to the staff who operate the system with training recorded; the privacy notice and the cookie notice drafted alongside cover the business's website and customers, the signage guidance sets what the signs say and where they go, and the notice can record the business's registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

We have signs and a privacy notice. Do we also need a CCTV policy?

The policy is needed too: it is the internal document that governs access, retention and requests so that what the signs and the notice say is true, and it holds the assessment the regulator expects for systematic monitoring of a public area.

How long should we keep footage?

A stated short period (commonly weeks), overwritten automatically, with footage preserved only for an incident, investigation or request and deleted when the matter is closed. The policy states the period and the system should enforce it.

The police have asked for footage. Can we hand it over?

On a written request identifying the investigation, reviewed and recorded by a named person, under the crime exemption. The policy sets the procedure, which protects the business from handing footage to anyone who asks.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.