CCTV Privacy Law Mapper
Laws

CCTV laws in the United Kingdom: what we map and name

What CCTV Privacy Law Mapper maps for a camera at a site in the United Kingdom, what it names without mapping, and what it leaves out. This is not every law that applies there.

Jurisdiction
the United Kingdom
Laws placed
UK GDPR, on every camera at the site
Date last read
Held and read 29 Sep 2026
Named, not quoted
Data Protection Act, Schedule 1; ICO guidance on video surveillance
Read from a list as
britain, england, gb, gbr, great britain, northern ireland, scotland, uk

Coverage here

Laws mapped and checked
Mapped
UK GDPR
Named, not mapped
Data Protection Act, Schedule 1; ICO guidance on video surveillance
The national or state layer
UK GDPR is mapped. The Data Protection Act and the ICO guidance on video surveillance are named, not mapped; employment law and the surveillance camera code for public bodies are not named.

Findings a camera here can raise

13 of the 18 can arise here

Named, not quoted

These are named so you know to open them. We do not hold their text in full and the page does not state what they require beyond the one line above.

The clauses cited here

12 clauses
UK GDPR Art. 5Principles relating to processing of personal data

Article 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What a reviewer asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
Where camera lists usually fall short: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 6Lawfulness of processing

Article 6 Lawfulness of processing. Processing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.

What a reviewer asks to see: Lawful basis recorded per processing purpose; Legitimate interests assessments for Article 6(1)(f) processing; Annex 1 condition and the requesting body's written statement kept for each recognised legitimate interest disclosure
Where camera lists usually fall short: Treating the Article 6(11) examples as automatically lawful without a balancing test; Public authorities relying on legitimate interests for their core tasks; Recognised legitimate interest claimed where no Annex 1 condition fits
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 9Processing of special categories of personal data

Article 9 Processing of special categories of personal data. Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.

What a reviewer asks to see: Article 9 condition and, where required, the Schedule 1 condition of the 2018 Act recorded per processing; Appropriate policy document where Schedule 1 requires one; Explicit consent records where that is the condition
Where camera lists usually fall short: Biometric processing for identification without an Article 9 condition; Relying on substantial public interest without the Schedule 1 condition and policy document; Health data processed outside the professional-secrecy safeguard
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 13Information to be provided where personal data are collected from the data subject

Article 13 Information to be provided where personal data are collected from the data subject. At the time of collection the controller must give its identity and contact details (and any representative's), the data protection officer's contact details, the purposes and lawful basis, the legitimate interests where Article 6(1)(f) is relied on, the recipients, and any intended transfer abroad with whether transfer regulations under Article 45A cover it or which safeguards are relied on and how to get a copy. It must also give the retention period or criteria, the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent, the right to complain to the controller and to the Commissioner, whether provision of the data is required and the consequences of not providing it, and the existence of automated decision-making subject to Article 22C safeguards with meaningful information about the logic and consequences. Before further processing for a new purpose the data subject must be told of it, unless the further processing is for research, archiving or statistics under Article 84B and telling them is impossible or disproportionate, in which case the controller must protect their interests, including by publishing the information.

What a reviewer asks to see: Privacy notices at each collection point with every Article 13 item; Version history of notices; Assessment and public statement where the Article 13(5) research exception is used
Where camera lists usually fall short: Notice missing the right to complain to the controller; Transfer information still citing adequacy decisions instead of transfer regulations; No notice update before a new purpose starts
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 26Joint controllers

Article 26 Joint controllers. Joint controllers must determine their respective responsibilities, in particular for data subject rights and the information duties, by an arrangement that reflects their roles and relationships, may designate a contact point, and must make the essence of the arrangement available to data subjects, who may exercise their rights against each of them.

What a reviewer asks to see: Joint controller arrangement allocating responsibilities; Published summary of the arrangement
Where camera lists usually fall short: Joint control unrecognised, so no arrangement exists; Arrangement silent on who answers rights requests
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 28Processor

Article 28 Processor. A controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.

What a reviewer asks to see: Article 28 compliant processing agreements for every processor; Sub-processor list with authorisation and change notices; Processor due diligence and audit records
Where camera lists usually fall short: Processors engaged on standard terms lacking the Article 28(3) clauses; Sub-processors added without notice; No evidence data were deleted or returned at contract end
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 30Records of processing activities

Article 30 Records of processing activities. Each controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.

What a reviewer asks to see: Record of processing activities covering every required field; Processor record per controller; Evidence of periodic review of the records
Where camera lists usually fall short: Records not updated as systems change; Small organisations claiming the exemption despite regular processing; Security measures described only generically
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 32Security of processing

Article 32 Security of processing. Controllers and processors must implement technical and organisational measures ensuring security appropriate to the risk, taking into account the state of the art, costs, the nature and purposes of processing and the risks, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely way after an incident, and a process for regularly testing, assessing and evaluating the measures. The assessment must weigh the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Codes or certification may help demonstrate compliance, and anyone acting under the controller's or processor's authority must process data only on instructions.

What a reviewer asks to see: Risk assessment underpinning the chosen security measures; Encryption, access control, backup and restore evidence; Security testing and control effectiveness reviews
Where camera lists usually fall short: No periodic testing of controls; Restore capability never tested; Encryption absent on portable devices or data in transit
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 35Data protection impact assessment

Article 35 Data protection impact assessment. Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.

What a reviewer asks to see: DPIA screening records for new processing; Completed DPIAs with the four required elements and DPO advice; Review records when processing changes
Where camera lists usually fall short: DPIA done after launch; Screening not documented; Commissioner's list of high-risk processing ignored
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 44AGeneral principles for transfers

Article 44A General principles for transfers. A controller or processor may transfer personal data to a third country or international organisation only if the transfer complies with the rest of the Regulation and is approved by transfer regulations under Article 45A in force at the time, is made subject to appropriate safeguards under Article 46, or relies on an Article 49 derogation; safeguards or derogations cannot be used where regulations under Article 49A restrict the transfer. This replaced Article 44 on 5 February 2026.

What a reviewer asks to see: Transfer inventory mapping each flow to its Article 44A route; Checks against any Article 49A restrictions
Where camera lists usually fall short: Transfers with no documented route; Onward transfers by processors not assessed
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 45ATransfers under transfer regulations

Article 45A Transfers approved by regulations (with Articles 45B and 45C). The Secretary of State may approve transfers to a country, a sector or area within it, an international organisation or specified transfers by regulations, only where the data protection test is met: the protection for data subjects there, taken as a whole, is not materially lower than under the UK GDPR, Part 2 and Parts 5 to 7 of the 2018 Act, considering the rule of law and human rights, an enforcing authority, redress, onward transfer rules, international obligations and the country's constitution, traditions and culture. The Secretary of State must monitor developments, amend or revoke regulations when the test is no longer met, and publish lists of approved and formerly approved destinations. Adequacy regulations and retained adequacy decisions in force before 5 February 2026 are treated as made under Article 45A (Schedule 9 transitional provision). A controller relying on this route must check the destination and the transfer are covered by regulations in force at the time of transfer.

What a reviewer asks to see: Transfer records naming the regulations relied on and the scope they cover; Periodic check of the Secretary of State's published list
Where camera lists usually fall short: Relying on a partial approval (for example a certification-based bridge) for recipients outside its scope; Destination removed from the list but transfers continue
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 46Transfers subject to appropriate safeguards

Article 46 Transfers subject to appropriate safeguards. A transfer is subject to appropriate safeguards only where safeguards are provided and the controller or processor, acting reasonably and proportionately, considers the data protection test met: after transfer the protection for the data subject, taken as a whole and considering the nature and volume of data, would not be materially lower than under the UK regime. Safeguards not needing the Commissioner's authorisation are a binding instrument between public bodies, binding corporate rules, standard data protection clauses specified by the Secretary of State in regulations or issued by the Commissioner under section 119A of the 2018 Act (such as the international data transfer agreement and addendum), and approved codes or certification with binding commitments; contractual clauses and administrative arrangements need the Commissioner's authorisation. Regulations under Article 47A may add further safeguards.

What a reviewer asks to see: Executed IDTA or UK addendum or other Article 46 instrument per transfer; Transfer risk assessment recording the data protection test and its reasoning; Authorisations from the Commissioner where needed
Where camera lists usually fall short: Contract signed with no documented assessment of the data protection test; EU clauses used without the UK addendum; Assessments not revisited when the destination's law changes
Source: UK GDPR, read 29 Sep 2026

See the specimen list run Map your own list