AI CCTV
Can UK Businesses Use Facial Recognition CCTV? 2026 Guide
Can UK businesses use facial recognition CCTV? The 2026 rules on DPIAs, biometric data, watchlists, human checks, signs and supplier questions.
AI CCTV
Can UK businesses use facial recognition CCTV? The 2026 rules on DPIAs, biometric data, watchlists, human checks, signs and supplier questions.
UK businesses can use facial recognition CCTV, but only where the use is necessary, proportionate and properly documented. Before scanning anyone, the business needs a valid lawful basis, conditions for biometric and criminal offence data where relevant, a detailed DPIA, an appropriate policy document, clear signs, tightly controlled watchlists and a process for checking possible matches. If ordinary CCTV or less intrusive analytics can solve the problem, facial recognition may be difficult to justify.
Yes. A UK business can use facial recognition CCTV to help prevent crime, but it cannot treat the technology like an ordinary camera upgrade. Live facial recognition scans people in the camera's field of view, creates biometric data and compares it with a watchlist. That brings a much higher legal and practical threshold.
The Information Commissioner's Office, or ICO, says a business must show that facial recognition is necessary and proportionate. It must consider less intrusive options first, identify the correct legal grounds, complete a detailed data protection impact assessment and put strict controls around watchlists, signs, retention, access and possible matches.
If a conventional commercial CCTV system, better camera positions or non-biometric video analytics can deal with the problem, facial recognition may be hard to justify. Work through the purpose, evidence and safeguards before asking an installer for a quote.
Facial recognition CCTV is legal for UK businesses in some circumstances. It is not automatically lawful just because the aim is crime prevention. The business using it remains responsible for proving why it is needed and how people's information is protected.
The ICO's July 2026 advice for small businesses gives a direct answer: facial recognition can be used to protect a business from crime, but its lawful use in public places has a high bar because it scans everyone, not only people already suspected of an offence.
Retail crime is pushing more businesses to look beyond recorded CCTV. The Association of Convenience Stores reported 5.8 million shop theft incidents in its 2026 Crime Report. It also found that convenience retailers spent a record £313 million on crime prevention and detection, including CCTV, facial recognition and AI store monitoring.
The law is moving too. The Crime and Policing Act 2026 created a specific offence of assaulting a retail worker and removed the old treatment of low-value shop theft under section 22A of the Magistrates' Courts Act. Better evidence and safer staff response still matter, but new criminal offences do not remove a retailer's data protection duties.
That combination explains the interest: businesses want earlier warning, while regulators want the use of biometric data to remain fair, accurate and controlled.
"AI CCTV" is a loose sales term. Some camera analytics detect a person crossing a line, a vehicle entering a yard or movement in a closed area. Those systems can still process personal information, but they do not necessarily identify anyone.
Facial recognition is different. It uses technical processing to create a biometric template from a face and tries to identify or recognise that person. Live facial recognition usually compares people entering a space against a watchlist in real time. Retrospective facial recognition searches older footage or still images later.
Ask a supplier to state in writing whether the proposed system creates biometric templates, identifies individuals, estimates personal characteristics, stores watchlists or sends data to a third party. "Smart camera" is not a useful answer.
Facial recognition can involve several layers of regulated information:
The business must identify an Article 6 lawful basis and a separate Article 9 condition for special category biometric data. If the system processes criminal offence data, it also needs a valid route under Article 10 and the Data Protection Act 2018. The ICO says an appropriate policy document may be required and tells businesses considering crime prevention watchlists to have one in place.
Consent is not a quick fix in a public shop. Consent must be specific, informed and freely given, with a genuine alternative for anyone who refuses. A person who has to be scanned to enter the only available shop has not necessarily been given a meaningful choice.
A DPIA is not a supplier brochure with a signature at the bottom. It is the business's record of the decision. The ICO describes it as a living document that should be reviewed before deployment and updated when the purpose, location, watchlist or technology changes.
A useful DPIA should answer:
If the remaining risk is still high after safeguards, the business may need to consult the ICO before going live.
A watchlist should not become a permanent collection of poor screenshots and staff suspicions. The ICO expects each use to be justified on its own facts. A business should set a threshold for adding someone, record the evidence behind the decision and use images accurate enough for the intended comparison.
Entries need review dates. Someone should be removed when the information is no longer necessary, the evidence is unreliable or the agreed period has ended. Access should be limited to people who need it, with a record of additions, removals and disclosures.
Publicly posting suspected offenders on social media is a different and riskier act. The ICO's current small-business guidance says this is unlikely to be justifiable because the business loses control over who sees and reuses the image. Sharing a necessary clip securely with the police is normally a much clearer route.
A member of staff glancing at an alert and accepting the software's answer is not meaningful review. The reviewer needs training, enough time, access to the comparison images and authority to reject the match.
The response plan should also be written before launch. A possible match might lead to discreet observation, a check by a trained manager or a call to security. It should not turn a software score into an accusation. False matches affect real people and can create safety problems for staff as well as legal problems for the business.
During a trial, record every alert, confirmed match, rejected match and operational outcome. If the system is not achieving its stated purpose, stop or change the processing rather than leaving it running because the equipment has already been paid for.
A supplier can explain how its product works. The business using the system must still decide whether that use is lawful and proportionate at its premises.
Many premises can improve security without identifying every person who enters. A survey may find blind spots at the door, poor facial image quality at the till, weak coverage of stock routes or no reliable way to export footage for the police.
Other useful options include detector-activated cameras for closed areas, remote monitoring after hours, better staff-only door control, a maintained intruder alarm and a clear incident process. Our retail CCTV security guide explains how to start with the incidents the footage needs to prove. The wider commercial CCTV installation guide covers camera purpose, storage, remote access and handover.
FIDEC can survey the technical side of a commercial CCTV project: camera positions, image quality, recording, retention settings, secure access, networking, monitoring and integration with intruder alarms or door access control.
For facial recognition, the technical design has to follow the business's documented purpose and data protection assessment. FIDEC does not replace independent legal or data protection advice, and we would not treat facial recognition as the default answer to a CCTV problem.
Book a free CCTV site survey, call 0333 3662 007, or email info@fidecss.co.uk.
Yes, in some circumstances. A business must show that facial recognition is necessary and proportionate for a specific purpose, consider less intrusive options, identify the correct legal grounds, complete a detailed DPIA and put safeguards around watchlists, signs, access, retention and human review. Ordinary crime prevention aims do not make every deployment lawful.
Facial recognition used to identify or recognise a person creates biometric data through technical processing of facial features. When that data is used to uniquely identify someone, it is special category biometric data under UK GDPR. Some video analytics only detect movement, people or vehicles without identifying anyone, so businesses should ask suppliers exactly what the system processes.
Yes. The ICO expects a detailed data protection impact assessment because facial recognition is likely to create a high risk to people's information rights. The DPIA should be completed before deployment and reviewed when the purpose, cameras, watchlist, supplier or response process changes. It should also explain why less intrusive measures are not enough.
A shop may be able to use a tightly controlled watchlist for crime prevention, but each entry needs evidence, a clear purpose, an appropriate legal condition, an expiry or review date and restricted access. The business also needs to account for criminal offence data and the risk of false matches. A staff suspicion or poor image should not become a permanent watchlist record.
Often, yes. Analytics that detect movement, line crossing or activity in a closed area can be less intrusive because they do not necessarily identify people or create biometric templates. They still need a clear purpose and data protection controls where personal information is processed. Businesses should compare these options before deciding that facial recognition is necessary.