Office CCTV is lawful under GDPR, and almost every installation gets three things wrong: the lawful basis, the notice, and the retention period. Footage of identifiable people is personal data, so the whole regulation applies. Consent is the wrong basis because employees and visitors cannot freely refuse a camera, which means you are on legitimate interests and have to pass a necessity and proportionality test you should write down before the cameras go up.
This article covers the lawful basis and how the balancing test applies to premises security, why a "CCTV in operation" sign is not notice, where cameras may and may not point, how long footage can be kept, and what happens when someone asks for a copy of themselves.
The Lawful Basis, And Why It Is Not Consent
Cameras that capture recognisable faces process personal data. There is no threshold below which a small office is exempt.
Consent fails here for the same reason it fails across the employment relationship: it must be freely given, and a person who has to walk past a camera to reach their desk or your reception cannot meaningfully decline. A visitor cannot either. The EDPB's position is the same — for video surveillance the likely bases are legitimate interests or a public-interest task, with consent workable only in rather exceptional cases. So the basis is almost always legitimate interests under Article 6(1)(f), and that carries the three-part test.
The legitimate interest is usually easy: securing premises, protecting property, safeguarding staff, investigating incidents. Necessity is harder and is where installations fail — the question is not whether cameras help, but whether a less intrusive measure would achieve the same end. Better locks, an alarm, a visitor log and controlled door access all address the same risk with far less processing. If they would work, blanket coverage is not necessary.
The balancing limb turns on what people reasonably expect. A camera on an external door and a stockroom is expected. A camera on the desks where people work all day is a different proposition, and one that starts to look like monitoring performance rather than securing a building. That distinction matters: watching people work is a separate subject with its own rules, covered in our guide to employee surveillance under GDPR. This article is about cameras on premises.
Write the assessment down. A legitimate interests assessment that exists only in someone's head is indistinguishable, after an incident, from never having done one.
Signage Is Not Notice
"CCTV in operation" is a sign. It is not compliance with Articles 13 and 14, which require you to tell people who the controller is, why you are processing, on what basis, how long you keep the footage, who else sees it, and what rights they have.
The EDPB's Guidelines 3/2019 on processing of personal data through video devices — adopted in final form on 29 January 2020 and still the reference document on this subject — set out the workable pattern, and it is layered. The most important information goes on the warning sign itself, which is the first layer; the remaining mandatory detail is provided by other means and made available somewhere easily accessible, which is the second. The guidelines add that the sign should also carry anything that would surprise the person — onward transmission to a third party being the usual example.
In practice that means a sign visible before someone enters the covered area, naming the controller, stating the purpose in a few words, and pointing to where the full information lives. The second layer carries everything Article 13 requires.
Two details that get missed. Staff need the information too, and burying it in a handbook nobody has read since onboarding is weak. And if you install cameras in an area already in use, people should be told before the cameras go live, not discover them afterwards.
A DPIA is likely. Article 35(3)(c) makes one mandatory for systematic monitoring of a publicly accessible area on a large scale, which a small office reception may not meet — but the WP29 criteria push the same way regardless, because systematic monitoring and employees as vulnerable data subjects are two high-risk indicators, and two generally point to a DPIA.
Where Cameras May And May Not Point
Placement is where proportionality becomes concrete.
Areas where people have a heightened expectation of privacy are effectively off-limits: toilets, changing areas, prayer or wellbeing rooms, and medical rooms. Break rooms and kitchens are difficult to justify because the purpose is almost never security. Cameras trained on individual workstations are hard to defend as premises security and easy to characterise as performance monitoring.
Overshoot is the other common failure. A camera covering your entrance frequently also covers the pavement, the neighbouring doorway or a car park you do not control. Capturing more than your own premises widens your processing without widening your justification, and it is usually fixable with angle, masking or a lower mounting point.
Two capabilities change the analysis entirely. Audio recording is substantially more intrusive than video, captures conversations that have nothing to do with security, and is rarely proportionate — most systems have it on by default and it should usually be off. Facial recognition used to identify individuals processes biometric data under Article 9, which means you need an Article 9(2) condition on top of your Article 6 basis, and the Working Party's view is that facial recognition in workplace video analytics is likely to be disproportionate.
Retention, And The Request For A Copy
GDPR sets no retention period for footage. Article 5(1)(e) requires you not to keep personal data longer than necessary for the purpose, and for premises security the honest necessity window is short — long enough to notice an incident and pull the relevant clip. Many organisations land somewhere between a few days and a month, and the number matters far less than being able to explain how you chose it and having the system actually enforce it.
The Request Nobody Plans For
Footage of an identifiable person is their personal data, so they can ask for a copy under Article 15. This is operationally the hardest thing in this article, for two reasons.
First, you have to find it, and CCTV is indexed by camera and timestamp rather than by person. If the requester cannot narrow the window, you can ask them to, but you cannot simply refuse.
Second, Article 15(4) says the right to obtain a copy must not adversely affect the rights and freedoms of others — and footage of one person in a shared space is footage of everyone else who walked through it. That means blurring or otherwise obscuring third parties before disclosure. Whether your system can do that, and who does it, is worth establishing before a request arrives rather than during the one-month clock.
Retention interacts with your wider deletion obligations too, and footage held in system backups follows the same logic as any other data — covered in our piece on deleting personal data from backups. Where CCTV sits alongside the broader question of what employee data you may collect, our HR data collection guide covers that territory.
Common Mistakes With Office CCTV
Relying on consent, or on a sign as the whole notice. Consent is not freely given in this setting, and "CCTV in operation" tells people almost nothing Articles 13 and 14 require.
Keeping footage indefinitely because the drive is large. Storage limitation applies. An undocumented retention period that defaults to whenever the disk fills is not a decision, and it is the first thing a regulator asks to see.
No plan for a subject access request. You need to locate footage by person and time, and redact everyone else in frame. Discovering you cannot do either after the clock starts is the common failure.
Leaving audio on by default. Most systems record it, most operators never chose to, and conversation capture is far harder to justify than the video it accompanies.
Treating the security contractor as a supplier rather than a processor. A firm that monitors, stores or accesses your footage processes personal data on your behalf and needs an Article 28 contract like any other processor.
FAQ
Do we need consent to install CCTV in the office?
No, and you should not rely on it. Consent must be freely given, and neither an employee nor a visitor can realistically refuse a camera at the entrance. The workable basis is legitimate interests, supported by a documented assessment showing the cameras are necessary and that a less intrusive measure would not do the job.
How long can we keep CCTV footage?
GDPR sets no fixed period. Article 5(1)(e) requires you to keep it no longer than necessary, which for premises security is usually days rather than months — long enough to spot an incident and retrieve the clip. Set a period, document why you chose it, and make sure the system enforces it automatically.
Can an employee ask for CCTV footage of themselves?
Yes. Footage of an identifiable person is their personal data and falls within Article 15. You can ask them to narrow the time and location, but you cannot refuse on the basis that searching is inconvenient. You must also obscure other people appearing in the same footage before you disclose it.
Do we need a DPIA for office CCTV?
Often yes. Article 35(3)(c) makes it mandatory for large-scale systematic monitoring of publicly accessible areas, and even below that threshold the recognised high-risk indicators — systematic monitoring, and employees as vulnerable data subjects — combine to point toward one. Doing it is cheaper than arguing about whether you needed to.
Closing Thought
Cameras get installed for a specific reason — a break-in, an insurance requirement, a nervous landlord — and then stay forever, pointed at whatever the installer found convenient, recording audio nobody asked for, keeping footage until the disk fills. The compliance problem is rarely the decision to have CCTV. It is that nobody ever revisits it.
Which suggests the useful question is not "are our cameras lawful" but "would we install these cameras, in these positions, with these settings, if we were deciding today." For most offices the honest answer is no, and that gap is exactly what a regulator would be looking at.
ComplyDog does not manage cameras. It handles the paperwork that surrounds this — your records of processing activities, where CCTV should appear as a named processing activity with its purpose and retention period, plus DPA management for the security firm and a portal for handling the access requests. You can try it free for 14 days, no credit card required.