Under GDPR, CCTV footage that identifies individuals is considered personal data. This means your business is responsible for storing, using, and protecting it lawfully.
To comply, you must:
- Display clear signage informing people they are being recorded
- Store footage securely and restrict access to authorised personnel
- Only keep footage for as long as necessary (typically 30 days unless required for an investigation)
- Ensure footage is encrypted and protected from unauthorised access
- Provide access to individuals who request to see their recorded data
At Edmondson’s, our CCTV systems are fully GDPR-compliant, offering encrypted storage, password protection, and role-based access controls. We can also advise on secure retention policies and remote viewing settings.


