However, there are also data protection responsibilities when it comes to the footage.
Positioning of cameras, how long footage is stored for and who can access the recordings are just some of the consideration operators should take into account.
At Poppleston Allen’s recent licensing conference, associate solicitor Joe Harvey outlined why operators should take GDPR and CCTV seriously as if not, it can result in fines, enforcement and compensation having to be paid.
Here are seven key considerations operators should have on their radar:
1. CCTV is personal data
Any image or recording that can identify individuals falls within the scope of data protection regulations.
This is likely to become more important as technology evolves with facial recognition and AI coming into play, which could be subject to stricter legal requirements.
2. Fines and enforcement action can be costly
Harvey highlighted the consequences of non-compliance, which could result in an investigation from the Information Commissioner’s Office and taking action where organisations fail to comply with data protection laws.
He went on to lay out how operators could face compensation claims should data be mishandled.
3. You need a lawful reason for recording people
Businesses must demonstrate a legitimate reason for collecting data.
For most, this will be crime prevention, detection and public safety. In some cases, it is likely licence conditions require CCTV systems to be in place and in good working order, resulting in an additional legal basis for processing footage.
4. Vulnerable people and children require extra consideration
Operators may need to complete a Data Protection Impact Assessment where CCTV is likely to record vulnerable individuals or children, Harvey advised.
However, the threshold for needing the assessment can be low. Those who welcome families and young people should consider whether additional documentation and safeguards are needed to demonstrate compliance.
5. Signage is more important than you might think
A common area of non-compliance can be around inadequate CCTV signage.
GDPR means businesses have to tell people they are being recorded, who controls the data, the reason it is being collected and how they can exercise their rights.
If cameras capture people outside a venue, such as on a public road or pavement, signage may need to be visible before customers enter the monitored area.
Furthermore, if facial recognition is being used, this also needs to be made clear.
6. You cannot record more than you need
Areas where there is a reasonable expectation of privacy such as staff welfare areas should not be filmed.
Also, operators should regularly review whether cameras are covering unnecessary areas or capturing more than is needed for security purposes.
Moreover, if recordings are being used to prevent crime, it should not be used for unrelated reasons, for example, monitoring staff performance.
7. Managing access and sharing footage is a legal responsibility
Only authorised staff should have access to CCTV and systems should be protected by secure networks, passwords and encryption where possible.
Operators should also ensure there are clear retention policies in place as any premises licences needed footage to be stored for at least 31 days.




