Short answer: When someone requests commercial CCTV footage, route the request to the responsible decision-maker before sending a clip. Establish what they are asking for, preserve relevant recordings appropriately, check the authority to disclose and use a controlled transfer with a clear record.

A facilities team in Watford might receive a police enquiry, an insurer’s email and a visitor’s request about the same recording. These need different decisions. A simple process helps staff move requests forward without treating access to the recorder as permission to release its contents.

1. Identify the request before exporting anything

Record when the request arrived, who made it, the date and approximate time of the recording sought, and enough detail to locate it. Keep this information in the organisation’s restricted request register rather than an open shift notebook.

Separate three common situations:

  • An individual asking for footage of themselves: this may be a subject access request.
  • A police enquiry: identify the investigation and the information sought.
  • An insurer, contractor or other third party: establish their purpose and authority; an email alone does not settle whether disclosure is appropriate.

Staff should recognise requests made verbally as well as in writing and forward them promptly. The ICO’s CCTV governance guidance explains request handling and controlled disclosure. Avoid requiring a particular form before recognising a request.

2. Know who can make the decision

The site brief should identify the organisation responsible for deciding how recordings are used, its request contact and the people permitted to approve an export. Where a security or monitoring supplier operates the system on another organisation’s behalf, check the contract and instructions before taking action.

For a shared commercial building, clarify which organisation controls the camera concerned. A managing agent, tenant and guarding contractor may have different responsibilities. Reception staff need a clear referral route, including a substitute contact when the usual decision-maker is absent.

3. Protect the relevant recording from routine deletion

Once a potentially relevant recording is identified, escalate promptly so it can be preserved under the agreed procedure. Record the reason, restrict access and set a review point. Do not keep every camera’s recordings indefinitely because one request has arrived.

The ICO says there is no universal minimum or maximum CCTV retention period: retention should follow the purpose for which the information is needed. Its surveillance data-protection principles guidance covers retention and secure storage.

As an operational check, confirm whether the recorder’s clock is accurate and note any known offset. This helps avoid selecting a convincing-looking clip from the wrong time. Preserve the original separately from any copy prepared for disclosure, with access limited to authorised people.

4. Handle requests for someone’s own footage carefully

Someone asking for their own personal data has a different position from a third party asking to see an incident. Route the request through the organisation’s subject access process and check the applicable response requirements promptly.

The ICO’s subject access advice explains that third-party information will usually need redaction. If that is not possible, assess the rights of the requester and the other people involved, including any relevant consent or exemption, and document the decision. The presence of other people is not a reason for an automatic refusal.

Check what information is needed to confirm identity and locate the recording. Do not collect unnecessary identity documents or send an unedited recording simply because the requester recognises themselves on screen.

5. Verify police and other third-party requests

For a police request, verify the contact through an established official channel and ask what information is needed and why. The ICO’s law-enforcement sharing guidance explains how to assess necessity and the lawful basis for sharing. A court order creates a different obligation from a voluntary request.

Limit disclosure to the relevant material. Footage connected with an alleged offence can require additional data-protection consideration, so involve the organisation’s responsible adviser where necessary. For an insurer or contractor, assess the justification separately rather than borrowing the decision made for the police.

6. Check the export and record the transfer

Before release, a practical check should confirm that the clip covers the approved camera and period, opens correctly and contains any required redactions. Confirm the recipient and use the organisation’s approved secure transfer method.

Keep a disclosure record showing the date, recipient, reason, approval and material released. Do not forward footage through personal messaging accounts or post incident clips on social media. The request file should also show the next review or disposal action for retained copies.

Test the process before a real request arrives

Use a fictional request in a short desk exercise: can reception recognise it, can the manager identify the responsible organisation, and can an authorised operator prepare a controlled export? Record gaps in roles, permissions or training without circulating actual incident footage.

This checklist is general operational guidance. Use current ICO guidance and advice appropriate to the organisation for individual disclosure decisions; the ICO notes that parts of its surveillance guidance are under review following the Data (Use and Access) Act.

For help discussing how CCTV fits into a commercial site’s wider security arrangements, explore ZimCos Security’s services or send an enquiry with the site location and scope. Do not include access credentials or sensitive footage in an initial enquiry.

Leave A Comment