AI CCTV and UK GDPR: The Data Protection Guide for Business Owners
CCTV footage that shows identifiable people is personal data. That has been true since long before AI arrived, and it means any business running cameras is already subject to UK GDPR and the Data Protection Act 2018. Adding AI analytics does not create a new legal regime, but it does change how regulators look at your system. Software that automatically detects, classifies and tracks people is more intrusive than a recorder in a cupboard, so you need to be able to show you have thought it through.
This guide sets out what UK business owners need to have in place. It is general guidance, not legal advice, and you should take advice on your own circumstances where the stakes are high.
Who this applies to
If you control why and how the cameras are used, you are the controller. That is usually the business owner or site operator, not the installer. A provider like Fortix AI, which processes footage on your instructions, acts as a processor, and there should be a written data processing agreement between us.
Most organisations that process personal data, including through CCTV, must also pay the data protection fee to the Information Commissioner's Office (ICO) unless an exemption applies.
1. Have a clear purpose and a lawful basis
Write down exactly why you use cameras and AI. Typical purposes include preventing crime, protecting staff, health and safety compliance, and detecting fly tipping or trespass.
For most businesses the lawful basis is legitimate interests. To rely on it you should complete a short legitimate interests assessment covering three questions:
• Is there a genuine interest, such as preventing theft or protecting staff?
• Is the processing necessary for that purpose, or is there a less intrusive way to achieve it?
• Do the interests of the people being filmed override yours?
Public authorities such as councils generally rely on public task instead, and will also need to have regard to the Surveillance Camera Code of Practice.
2. Carry out a Data Protection Impact Assessment
A DPIA is required where processing is likely to result in a high risk to individuals. The ICO lists systematic monitoring of publicly accessible areas, and innovative technology, among the triggers. AI video analytics often ticks both boxes, so in practice you should assume a DPIA is needed.
A good DPIA for AI CCTV covers:
• What each camera can see, including neighbouring property and public highway
• Which AI features are switched on and why each one is needed
• Where processing happens (on the device at the edge, or in the cloud)
• Who can view live footage, alerts and recordings
• How long data is kept and how it is deleted
• Risks to individuals and the measures that reduce them
Keep it as a living document and review it whenever you add cameras or switch on new detection features.
3. Minimise what you collect
Data minimisation is where AI can actually help compliance rather than hinder it.
Edge processing. Fortix AI analyses video on a processor at the site. Rather than streaming everything to the cloud, the system sends only alerts, snapshots and short event clips. Less data travelling and stored means less risk.
Event based retention. Instead of keeping weeks of continuous footage of everyone, you can keep continuous recording for a short period and retain only flagged events for longer, where justified.
Privacy masking. Mask windows of neighbouring homes, gardens and areas you have no reason to monitor.
Switch off what you do not need. If you only need vehicle detection at a gate, there is no reason for person tracking or face analysis to be active there.
4. Tell people they are being filmed
People have a right to know. Put clear signs at entrances and at the edge of the monitored area, stating:
• That CCTV is in operation
• Who operates it, with contact details
• The purpose, where it is not obvious
• Where to find your full privacy notice
Your privacy notice should mention AI analytics specifically, for example that cameras automatically detect people and vehicles to generate security alerts.
5. Set and enforce retention periods
UK GDPR does not set a fixed retention period for CCTV. You must keep footage no longer than necessary for your purpose. Many businesses settle on around 30 days for routine recording, which is usually long enough to notice an incident and extract footage. Whatever you choose, write it down, justify it in your DPIA, and make sure the system deletes automatically.
Footage relating to an incident can be kept longer if it is needed for an investigation, insurance claim or prosecution.
6. Be ready for subject access requests
Anyone can ask for a copy of footage of themselves. You normally have one month to respond. You must be able to find the relevant footage, provide it, and protect other people who appear in it, usually by blurring or redacting them.
The Data (Use and Access) Act 2025 amended parts of UK GDPR, including confirming that controllers need only carry out reasonable and proportionate searches when responding to access requests. Good search tools still make a big difference. AI indexing (for example, finding every clip with a person in a red jacket at the loading bay on a given day) turns a request that could take hours into a few minutes of work.
7. Facial recognition needs extra care
Facial recognition processes biometric data to identify individuals, which is special category data under Article 9 of UK GDPR. You need both a lawful basis and an additional Article 9 condition, a robust DPIA, and a very clear case for why it is necessary and proportionate. The ICO has taken enforcement action against organisations using facial recognition without adequate justification.
For that reason, Fortix AI ships facial recognition switched off by default. Most security, safety and fly tipping use cases are met by person, vehicle and behaviour detection that does not identify anyone. Where a customer has a genuine need, such as controlled access to a restricted area with informed staff, we help them work through the assessment before it is enabled.
8. Lock down access and security
• Limit who can view live and recorded footage, and use individual accounts rather than shared logins
• Turn on multi factor authentication for remote access
• Keep camera and recorder firmware up to date and change default passwords
• Encrypt footage in transit and at rest
• Keep an audit trail of who viewed or exported footage and why
A security breach involving CCTV footage may need to be reported to the ICO within 72 hours if it poses a risk to people.
9. Avoid decisions made solely by the machine
AI should prompt a human to look, not make significant decisions about people on its own. An alert that someone is on site out of hours should go to a person who reviews the clip before anyone is challenged, disciplined or reported. Keeping a human in the loop is good practice and helps you stay on the right side of the rules on automated decision making.
A quick compliance checklist
• Purpose documented and lawful basis identified
• Legitimate interests assessment completed, where relevant
• DPIA completed and reviewed when the system changes
• Data processing agreement in place with your provider
• Signs at every entrance and an updated privacy notice
• Retention period set, justified and automated
• Process for subject access requests, including redaction
• Facial recognition off unless separately justified
• Access controls, MFA and audit logs enabled
• Data protection fee paid to the ICO
How Fortix AI helps
Compliance is designed into the platform rather than bolted on: edge processing to minimise data, event based retention, privacy masking, role based access, audit logs and facial recognition off by default. We will also help you prepare the information you need for your DPIA.
If you would like to review an existing CCTV system against UK GDPR, or plan a new AI deployment the right way from the start, get in touch with the Fortix AI team.