Recording people on CCTV or a body-worn camera is handling their personal information, so data protection law applies to it.[1] In practice that means signs telling people CCTV is in operation, a named person accountable for the system, no recording in private spaces such as toilets, and footage kept secure and seen only by authorised staff.[2][3]
This guide covers that data protection foundation. The CCTV operator qualification’s legislation unit goes further, into how human rights and the rules on covert surveillance affect CCTV operations, and the offence of voyeurism.[4][5][6] This guide does not cover those.
The Data Protection Act 2018 and the ICO guidance quoted here apply across the UK.
What the security specifications expect
The door supervisor specification sets out the legal implications of using CCTV as examples: the system must be registered, must have a named person responsible and accountable for its use, must display signs telling people CCTV is in operation, and must not record in private spaces such as toilets.[2]
Understand the legal implications of using CCTV, e.g must be registered must have a named person who is responsible and accountable for its use must display signs to inform people that CCTV is in operation must not record in private spaces such as toilets; Must comply with current data protection legislation, e.g when storing data including any recordings restricting access to certain staff by using recordings appropriately.
It also asks you to recognise CCTV’s limitations, including privacy concerns, misuse, vulnerability to damage, and the fact that it cannot prevent crime.[7]
Body-worn camera images must be stored in line with data protection law and can only be viewed by authorised personnel.[3] When handling anyone’s personal information, security operatives must follow data protection law, their organisation’s procedures and their assignment instructions, and keep the information confidential.[8]
For security officers, maintaining the confidentiality of site and personal data and complying with data protection law are listed among the main responsibilities of the role.[9]
The law in outline
The Data Protection Act 2018 makes provision about processing personal data, and most processing is subject to the UK GDPR, which the Act supplements. A separate part covers processing by competent authorities for law enforcement purposes.[10]
Together they require personal data to be processed lawfully and fairly, give people rights to information about how their data is used and to have inaccurate data corrected, and give the Information Commissioner responsibility for monitoring and enforcement.[11]
The seven principles
The ICO states that its guidance on the principles is under review because of changes made by the Data (Use and Access) Act, and may be subject to change.[12] The principles below come from Article 5 of the UK GDPR, as that guidance quotes it; each source entry shows the exact wording.[13]
- Lawfulness, fairness and transparency: processed lawfully, fairly and in a transparent manner.[13]
- Purpose limitation: collected for specified, explicit and legitimate purposes, and not further processed in a way incompatible with them.[14]
- Data minimisation: adequate, relevant and limited to what is necessary for the purpose.[15]
- Accuracy: accurate and, where necessary, kept up to date.[16]
- Storage limitation: kept in a form that identifies people for no longer than is necessary for the purpose.[17]
- Integrity and confidentiality: processed with appropriate security, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage.[18]
- Accountability: the controller is responsible for compliance and must be able to demonstrate it.[19]
Applied to a camera system, storage limitation means footage identifying people is not kept for longer than its purpose needs, and integrity and confidentiality means protecting it against unauthorised access and loss.[17][18]
The penalties are serious. The ICO notes that breaching the basic principles falls in the highest tier of fines, up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher.[20]
A lawful basis, decided in advance
Every use of personal information needs a valid lawful basis. There are seven, and the right one depends on the purpose and the relationship with the person.[21]
The basis has to be settled before the information is used, and documented.[22] Most bases require the processing to be necessary, which the ICO explains means more than useful: a targeted and proportionate way of achieving a specific purpose, with no less intrusive way of achieving it.[23]
One basis is directly relevant to security work. Recognised legitimate interest covers a set of pre-approved purposes that include preventing or investigating crime and safeguarding vulnerable people.[24] A public authority cannot rely on it for information it handles in carrying out its own tasks as an authority.[25]
The rights of people you record
The ICO lists the rights individuals have over their personal data. They include the right:[26]
- to be informed about the collection and use of their data;[26]
- to access and receive a copy of it;[26]
- to have inaccurate data rectified, and to have data erased;[26]
- to restrict processing, and to object to it in certain circumstances.[27][28]
CCTV and data protection are part of the common units, which appear in the Door Supervisor mock test. This site has no published CCTV Operator paper yet. For using footage as evidence, see the incident reports guide.
What this guide does not cover
- Human rights, covert surveillance and voyeurism law, and the rest of the CCTV operator qualification’s legislation unit and exam.
- The ICO’s detailed video surveillance guidance and its CCTV self-assessment checklist. We hold the page that introduces them, not the guidance itself.
- Changes made by the Data (Use and Access) Act beyond what the ICO pages we hold already reflect.
- Processing by the police and other competent authorities for law enforcement, which has its own part of the 2018 Act.
Where to go next
Sources
Each passage below is quoted from the copy of the document we checked on the date shown. Follow the link to read it in full on the publisher’s site.
Handling personal information using video surveillance including CCTV, automatic number plate recognition (ANPR), body worn video (BWV), drones (UAVs), facial recognition technology (FRT), dashcams and smart doorbell cameras.
1. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)CCTV and video surveillanceUK wide · Checked 5 Sept 2026Understand the legal implications of using CCTV, e.g must be registered must have a named person who is responsible and accountable for its use must display signs to inform people that CCTV is in operation must not record in private spaces such as toilets; Must comply with current data protection legislation, e.g when storing data including any recordings restricting access to certain staff by using recordings appropriately.
2. Pearson Education LimitedBTEC Level 2 Award for Door Supervisors in the Private Security Industry: Specification (opens in a new tab)Unit 1, criterion 1.6, page 34UK wide · Checked 5 Sept 2026the use of body worn cameras and restrictions e.g; - images must be stored to comply with GDPR and can only be viewed by authorised personnel
3. Pearson Education LimitedBTEC Level 2 Award for Door Supervisors in the Private Security Industry: Specification (opens in a new tab)Unit 1, criterion 2.5, page 38UK wide · Checked 5 Sept 2026Identify how human rights impact on public space surveillance (CCTV) operations
4. Pearson Education LimitedBTEC Level 2 Award for CCTV Operators (Public Space Surveillance) in the Private Security Industry: Specification (opens in a new tab)Unit 2, criterion 2.4, page 70UK wide · Checked 15 Sept 2026Identify how the principles of covert surveillance impact on public space surveillance (CCTV) operations
5. Pearson Education LimitedBTEC Level 2 Award for CCTV Operators (Public Space Surveillance) in the Private Security Industry: Specification (opens in a new tab)Unit 2, criterion 2.5, page 71UK wide · Checked 15 Sept 2026Identify how the offence of voyeurism impacts on public space surveillance (CCTV) operations
6. Pearson Education LimitedBTEC Level 2 Award for CCTV Operators (Public Space Surveillance) in the Private Security Industry: Specification (opens in a new tab)Unit 2, criterion 2.6, page 71UK wide · Checked 15 Sept 2026Identify the limitations of CCTV within the security operative role; Privacy issues and concerns; Vulnerable to damage and vandalism; Misuse; Cannot prevent crime; Cost; Familiarity with scope of cover; Technology vulnerabilities.
7. Pearson Education LimitedBTEC Level 2 Award for Door Supervisors in the Private Security Industry: Specification (opens in a new tab)Unit 1, criterion 1.7, page 35UK wide · Checked 5 Sept 2026When handling any personal information or data (either their own or someone else’s) security operatives must comply with current data protection legislation follow organisational procedures follow assignment instructions maintain confidentiality of information
8. Pearson Education LimitedBTEC Level 2 Award for Door Supervisors in the Private Security Industry: Specification (opens in a new tab)Unit 1, criterion 4.7, page 46UK wide · Checked 5 Sept 2026Identify the main responsibilities of a security officer; Protect life; Prevent and deter crime; Prevent loss; Protect property and assets; Respond to incidents and emergencies; Control site access/egress; Provide assistance to employees and customers; Provide a safe and secure environment; Maintain confidentiality of site and personal data/information; Ensure compliance with current data protection legislation
9. Pearson Education LimitedBTEC Level 2 Award for Security Officers in the Private Security Industry: Specification (opens in a new tab)Unit 2, criterion 1.2, page 71UK wide · Checked 5 Sept 2026This Act makes provision about the processing of personal data. Most processing of personal data is subject to the UK GDPR. Part 2 supplements the UK GDPR. Part 3 makes provision about the processing of personal data by competent authorities for law enforcement purposes
10. legislation.gov.ukData Protection Act 2018 (opens in a new tab)Section 1: overviewUK wide · Checked 5 Sept 2026requiring personal data to be processed lawfully and fairly, on the basis of the data subject's consent or another specified basis, conferring rights on the data subject to obtain information about the processing of personal data and to require inaccurate personal data to be rectified, and conferring functions on the Commissioner, giving the holder of that office responsibility for monitoring and enforcing their provisions.
11. legislation.gov.ukData Protection Act 2018 (opens in a new tab)Section 2: protection of personal dataUK wide · Checked 5 Sept 2026Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.
12. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)A guide to the data protection principlesUK wide · Checked 5 Sept 2026(a) processed lawfully, fairly and in a transparent manner in relation to individuals (‘lawfulness, fairness and transparency’);
13. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(1)(a)UK wide · Checked 5 Sept 2026(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
14. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(1)(b)UK wide · Checked 5 Sept 2026(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
15. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(1)(c)UK wide · Checked 5 Sept 2026(d) accurate and, where necessary, kept up to date;
16. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(1)(d)UK wide · Checked 5 Sept 2026(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
17. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(1)(e)UK wide · Checked 5 Sept 2026(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
18. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(1)(f)UK wide · Checked 5 Sept 2026The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).
19. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Article 5(2)UK wide · Checked 5 Sept 2026Article 83(5)(a) states that infringements of the basic principles for processing personal data are subject to the highest tier of administrative fines. This could mean a fine of up to £17.5 million, or 4% of your total worldwide annual turnover, whichever is higher.
20. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)Why are the principles important?UK wide · Checked 5 Sept 2026You must have a valid lawful basis to handle personal information. There are seven lawful bases available for you to use. No single basis is ’better’ or more important than the others. The most appropriate basis depends on your purpose and relationship with the person.
21. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)A guide to lawful basisUK wide · Checked 5 Sept 2026You must determine your lawful basis before you start using the personal information and you must document it.
22. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)A guide to lawful basisUK wide · Checked 5 Sept 2026However, it must be more than just useful and more than standard practice. It must be a targeted and proportionate way of achieving a specific purpose. The lawful basis won’t apply if you can reasonably achieve the purpose by some other less intrusive means
23. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)When is processing ‘necessary’?UK wide · Checked 5 Sept 2026(ea) Recognised legitimate interest: the processing is necessary for one of the pre-approved purposes. These are: safeguarding “vulnerable” people; responding to emergencies; preventing or investigating crime;
24. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)What are the lawful bases?UK wide · Checked 5 Sept 2026This basis can’t apply if you’re a public authority processing personal information to perform your official tasks.
25. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)What are the lawful bases?UK wide · Checked 5 Sept 2026Individuals have the right to be informed about the collection and use of their personal data. Individuals have the right to access and receive a copy of their personal data, and other supplementary information. The UK GDPR includes a right for individuals to have inaccurate personal data rectified, or completed if it is incomplete. The UK GDPR introduces a right for individuals to have personal data erased.
26. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)A guide to individual rightsUK wide · Checked 5 Sept 2026Individuals have the right to request the restriction or suppression of their personal data.
27. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)A guide to individual rightsUK wide · Checked 5 Sept 2026The UK GDPR gives individuals the right to object to the processing of their personal data in certain circumstances.
28. Information Commissioner's OfficeInformation Commissioner's Office guidance (opens in a new tab)A guide to individual rightsUK wide · Checked 5 Sept 2026
SIA Mock Test UK is an independent study resource. It is not affiliated with, endorsed by or approved by the Security Industry Authority, GOV.UK or any awarding organisation. Practice questions are original and are not live exam questions. This service does not replace mandatory licence-linked training, practical assessment or first-aid requirements. Always confirm current requirements with GOV.UK, your approved training provider and your awarding organisation.
Contains public sector information licensed under the Open Government Licence v3.0. Read the licence.