Almost nobody installs CCTV as a data protection decision. There is a break-in, or a dispute about who damaged what, or an insurer asks, and a fitter is booked. Four cameras go up, an app goes on your phone, and nothing else happens. The paperwork side arrives eighteen months later when an ex-employee asks for footage, a neighbour complains that a camera overlooks their garden, or a letter turns up about an unpaid fee you did not know existed.

None of this is hard. It is one afternoon of work, and the version of you who does it now is doing a considerable favour for the version who gets the letter.

The camera makes you a data controller

Recognisable images of people are personal data. The moment your business records them, UK GDPR applies to you in full, and the exemption that covers household CCTV does not — that only covers purely personal or domestic use, which running a business is not.

In practice that means you need three things written down before anything else: what the cameras are for, what lawful basis you are relying on, and how long you keep footage. For most small businesses the purpose is crime prevention and staff safety, and the lawful basis is legitimate interests. Write the reasoning in a paragraph and keep it. If you ever have to justify the system, that paragraph is the whole defence.

The fee almost nobody realises they owe

This is the one that catches people. If you use CCTV for crime prevention, you must pay the ICO's annual data protection fee — the exemptions that let some very small businesses avoid registering do not apply once you are running surveillance.

The fee is tiered by size. Tier 1 is £52 a year for micro organisations with no more than ten staff or turnover no higher than £632,000. Tier 2 is £78 for organisations up to 250 staff or £36 million turnover. Tier 3 is £3,763 for everyone above that. Paying by direct debit takes £5 off each tier. For most independent shops, salons, cafes and trades businesses, that is £47 a year.

Fifty-two pounds, once a year, is the cheapest item on the entire compliance list — and it is the one most likely to generate correspondence you do not want.

Signs, and the four sentences that do most of the work

People have to know they are being recorded before they are recorded. A sign at each entrance and in each monitored area needs to say that CCTV is in operation, who operates it (your business name), why, and how to contact you. That is it — four short lines on a laminated A5 sign.

Add a short CCTV section to your privacy notice covering the same ground plus retention and people's rights. If you have staff, tell them in writing where the cameras are and what they are for, ideally in the handbook. Surveillance a team discovers by accident is where grievances start, and it does more damage to trust than the cameras were ever worth. Our piece on the GDPR job we put off for two years covers where the rest of the paperwork sits.

Retention: pick a number and stick to it

There is no statutory retention period for CCTV. The requirement is that you keep footage only as long as you need it for the purpose you wrote down, and that you can justify the period you chose. Which means the compliant answer is not a specific number of days — it is having a defined period, applying it automatically, and being able to explain it.

Work it backwards from how you actually use the system. If shrinkage is spotted at the weekly stock count, you need at least enough days to cover a full count cycle plus the time it takes anyone to notice and act. Set the recorder to overwrite on that cycle, write the number in your privacy notice, and stop thinking about it. What you must not do is keep everything indefinitely because the hard drive is big.

The exception is footage you have pulled for a specific incident. Once it is evidence in a live matter — an insurance claim, a police report, a disciplinary — take it off the rolling system, store it separately, note why you are holding it, and delete it when the matter closes.

Where small businesses actually go wrong

Audio. Most modern cameras record sound by default and almost nobody turns it off. The ICO's position is that surveillance systems should not normally be used to record conversations between members of the public, and audio is treated as significantly more intrusive than video. Unless you have a specific, documented reason, switch the microphones off at installation.

Overspill. A camera that covers the pavement, the car park you share, or next door's garden captures people who have nothing to do with your business. Angle cameras down and inward, and use the privacy-masking function almost every system has to black out areas you have no business recording. This is the single most common source of complaints about small-business CCTV.

Pointing it at staff. Cameras covering a till or a stockroom are usually defensible. Cameras covering rest areas, changing rooms or toilets are not, and continuous monitoring of individuals at work needs a much stronger justification than general crime prevention. If the real purpose is monitoring performance, say so and assess it properly — do not let a security system quietly become a productivity system.

When you need a DPIA, and what happens when someone asks for footage

A data protection impact assessment is mandatory where processing is likely to result in high risk — systematic monitoring of a publicly accessible area on a large scale, large-scale monitoring of workers, or anything involving facial recognition. Four cameras inside a shop generally will not meet that bar. A system covering a public square, a large workforce, or any biometric matching will.

Then there is the request. Anyone recorded has the right to ask for a copy of footage of themselves. You have one calendar month to respond, and you cannot charge for it. The awkward part is that you must not disclose other identifiable people in the process, so you either blur them or, where redaction genuinely is not possible, explain why you are withholding. Trying to do that at speed on a system you have never exported from before is unpleasant — which is why the useful thing to do this week is export one clip and see how long it takes. The subject access request from an ex-employee covers what the wider request involves.

The afternoon's work

Write your purpose and lawful basis in one paragraph. Pay the fee by direct debit. Put a compliant sign at each entrance. Add a CCTV paragraph to your privacy notice and your staff handbook. Set the overwrite period and write down why. Turn the audio off. Mask anything outside your boundary. Do one practice export. That is the whole list, and it is a genuinely finishable afternoon.

Common questions

Do I have to pay the ICO fee just for having CCTV?

Yes, if the cameras are used for crime prevention. Some very small organisations are otherwise exempt from paying the data protection fee, but running CCTV for crime prevention purposes removes that exemption regardless of what else your business does. The tiers are £52 a year for micro organisations with no more than ten staff or turnover up to £632,000, £78 for organisations up to 250 staff or £36 million turnover, and £3,763 above that, with £5 off each tier for paying by direct debit. It is an annual fee, payable to the ICO, and it is separate from anything you pay your alarm or camera provider.

Can I put cameras where my staff work?

Usually yes, if the purpose is proportionate and you are open about it. Cameras covering a till, a stockroom or a yard entrance are ordinarily defensible on crime prevention and safety grounds. Cameras in rest areas, changing rooms or toilets are not, and continuous monitoring of individual employees needs a much stronger justification than general security. Tell staff in writing where cameras are and what they are for before they go live, ideally in the handbook. If the actual purpose is monitoring performance rather than preventing crime, say that openly and assess it on its own terms, because a security system that quietly becomes a productivity system is where grievances come from.

Someone has asked for footage of themselves. Do I have to hand it over?

Broadly yes. Anyone recorded can make a subject access request for footage of themselves, you have one calendar month to respond, and you cannot charge a fee. The complication is other people in the frame: you must not disclose identifiable third parties, so you either blur them or, where redaction genuinely is not achievable with the tools you have, explain why you are withholding the footage. Ask the requester to narrow the date, time and camera, because a vague request over weeks of recording is unworkable for both sides. Test an export from your system before you ever receive one of these.

What if my camera covers the pavement or a neighbour's garden?

It is still your responsibility, and it is the most common source of complaints about small-business CCTV. Recording beyond your own boundary captures people with no connection to your business, which makes the processing harder to justify and can turn a neighbour dispute into a complaint to the ICO. The fix is mechanical: angle cameras down and inward so they cover your property, and use the privacy-masking function built into virtually every modern system to black out areas you have no reason to record. Do it at installation, and check it again after anyone repositions a camera for a different reason.