CCTV Compliance
Can UK Businesses Share CCTV Footage? 2026 Guide
UK businesses can share CCTV with police and selected staff when it is necessary and secure. See the ICO's July 2026 rules and the system features you need.
CCTV Compliance
UK businesses can share CCTV with police and selected staff when it is necessary and secure. See the ICO's July 2026 rules and the system features you need.
A UK business can share relevant CCTV with the police, selected staff and a properly governed business crime partnership. Share only what is needed, use a secure transfer method and keep a record. Publicly posting images of suspected offenders is unlikely to be justified. If staff alerts contain suspected criminal activity, the business may also need a DPIA and an appropriate policy document.
Yes. A UK business can share CCTV footage to prevent or investigate crime, including with the police, selected staff and properly governed business crime partnerships. The business must limit the sharing to what is necessary, send it securely and keep a record of what was shared and why.
There is an important limit: the ICO's July 2026 guidance says publicly posting images of suspected offenders on social media is unlikely to be justified. A private staff alert or police evidence upload is very different from publishing a face to an unlimited audience.
Short answer: share a relevant clip through a controlled channel. Do not put a suspect image on Facebook, WhatsApp groups with uncontrolled membership or a public noticeboard. Keep the original footage and record the decision.
The ICO published new advice on 3 July 2026 for small businesses using personal information to tackle theft, abuse and violence. It was written with retailers in mind, but the principles apply more widely to businesses that use CCTV to protect staff, customers and premises.
The starting point is permission, not prohibition. Data protection law does not prevent a proportionate response to crime. It sets conditions for collecting, using and sharing footage without creating a second problem through inaccurate or uncontrolled disclosure.
Yes. The ICO says a business can share footage with the police to help investigate an incident. For a police handover, keep it simple:
A request from the police does not mean every camera or every hour of footage should be supplied. Ask what period and view they need, then provide a clean export with the correct time and date.
Yes, where the alert is necessary and fair. A business can warn relevant colleagues about a person who presents a known risk, such as someone who has been violent or aggressive at the premises.
The alert should stay within the group that needs it. Use a clear still image, describe the known facts and explain what staff should do if the person returns. Crop or blur unrelated people. Add a review date so the alert is removed when it is no longer needed.
Suspected criminal activity is criminal offence data. If a business is creating and circulating staff alerts of this kind, the ICO says it is likely to need a data protection impact assessment. An appropriate policy document is also required when using criminal offence data under the relevant conditions. The documents should explain the purpose, lawful basis, access controls, retention and review process.
They can, but an informal group chat is a poor way to do it. The ICO recommends using a regional or local business crime reduction partnership where possible. A properly run partnership should have a data sharing agreement, secure access, defined purposes and rules on retention and rights requests.
Each member still needs to understand its role. Keep a record of images supplied, why they were relevant and when the alert should be reviewed. Do not assume that joining a scheme transfers every data protection responsibility to the partnership.
The ICO's answer is no. Public posting is unlikely to be a justifiable response because the business loses control of the image and how other people reuse it. There is also a real risk of identifying the wrong person or presenting an allegation as a proven fact.
Safer routes are a police report, a controlled staff alert or a governed business crime partnership. A poster visible only to security staff is different from a notice in a shop window where every customer can see it.
ProtectUK's 2026 security toolkit tells businesses to review commercial CCTV coverage, blind spots and lighting. If an incident exposed a weak view or poor lighting, fix it while the details are still fresh.
A camera count is not enough. If footage may need to support a police investigation or rights request, the recorder and software should make the following jobs practical:
Put these requirements in the design brief and handover. Finding out that nobody can export a usable clip after a serious incident is far too late. FIDEC's commercial CCTV installation service in Manchester covers camera purpose, recording, remote access and user handover as part of the site survey and system design.
UK law does not set one retention period for every business CCTV system. Keep footage only as long as the documented purpose requires. The period should reflect the time it usually takes to discover and report an incident.
When a specific incident is under investigation, preserve that footage separately for as long as it is needed. Do not increase the retention period for every camera simply because one clip must be held. Review storage settings after cameras are added or recording quality changes, because those changes can shorten the actual number of days available.
A person can make a subject access request for CCTV that contains their personal information. In most cases the business must respond within one calendar month. The system should allow staff to locate and extract the relevant material, then redact other people where needed.
This is separate from a police evidence request. A business should have a named person who can recognise the difference, find the footage before it is overwritten and decide what can be disclosed.
Yes. Businesses should tell people that CCTV is in use, explain why and provide a contact route for questions. The privacy notice and CCTV policy should match what the system actually does, including audio, analytics, remote viewing and sharing.
Recording audio is much harder to justify than recording images. A camera having a microphone does not mean it should be left on. The ICO advises businesses to consider whether audio is necessary and whether a less intrusive option can solve the problem.
Test a real export from each recorder. Check the timestamps, playback, image quality and user permissions. Confirm who can respond to a police request or subject access request, and make sure that person knows how to protect footage from overwrite.
FIDEC can survey, install, upgrade and maintain commercial CCTV systems across Greater Manchester and the North West. For sites with older or poorly documented equipment, a fire and security system takeover review can check recording, access, faults and maintenance alongside the wider security setup.
Yes. A business can share relevant footage with the police to help investigate an incident. It should provide only what is necessary, use a secure police upload route, record what was shared and preserve the original footage in line with its retention policy or any police request.
Yes, when the alert is necessary and fair. Limit it to staff who need the information, use a clear image and known facts, crop unrelated people and set a review date. Suspected criminal activity is criminal offence data, so a DPIA and appropriate policy document may be required.
The ICO says public social media posts of suspected offenders are unlikely to be justified. The business loses control of the image and risks misidentification or unfair disclosure. Use the police, a controlled staff alert or a properly governed business crime reduction partnership instead.
They can where the sharing is necessary, controlled and properly documented. The ICO recommends using a local or regional business crime reduction partnership with a data sharing agreement, secure access, defined roles and clear retention rules rather than an informal group chat.
There is no single legal retention period for every system. Keep footage only for as long as the documented purpose requires. Preserve a specific incident separately when it is needed for an investigation, claim or rights request, without automatically extending retention for every camera.
Choose a system with accurate timestamps, fast search, reliable clip export, protection from overwrite, named user accounts, role-based permissions and an audit trail. It should also support third-party redaction where necessary for subject access requests.