How Long Should You Keep CCTV Footage? A UK GDPR Retention Guide
It’s one of the questions we get asked most often after a CCTV installation: how long are we actually supposed to keep this footage for? There’s no single legal number written into UK law, which is exactly why so many businesses either delete footage too early or, more commonly, hoard years of it “just in case.” Neither is a great position to be in.
There’s no fixed legal minimum or maximum
UK GDPR and the Data Protection Act 2018 don’t specify a set number of days for CCTV retention. Instead, they require you to apply the “storage limitation” principle: keep personal data (which includes footage of identifiable people) for no longer than is necessary for the purpose you collected it for. In other words, the right retention period is whatever you can justify — and it needs to be a deliberate decision, not just whatever your recorder’s hard drive happens to hold.
What most businesses actually do
In practice, a common approach for general commercial premises is to keep rolling footage for somewhere between 14 and 31 days, overwritten automatically after that unless something flags it for longer retention. Higher-risk sites — those with a history of theft, or handling higher-value stock — sometimes justify longer periods, but “we might need it one day” isn’t, on its own, a strong enough reason under GDPR. If in doubt, shorter and clearly justified beats longer and vague.

When footage needs to be kept longer
If an incident occurs — a theft, an accident, an allegation, a police request — the relevant footage should be extracted and stored separately for as long as that specific matter requires, whether that’s weeks for an insurance claim or longer for an ongoing legal process. This is why a good NVR/DVR setup and a simple internal process for “flagging and exporting” footage matters just as much as the cameras themselves.
Documenting your policy
Whatever retention period you land on, write it down. A short CCTV policy — covering your retention period, who can access footage, how it’s stored, and how a subject access request would be handled — is something the ICO expects any organisation using CCTV to have, and it’s the first thing you’ll be asked for if there’s ever a complaint or a data protection query. It doesn’t need to be complicated; it needs to exist and be followed.
Signage isn’t optional
Finally, don’t forget the basics: clear signage telling people they’re being recorded is a legal requirement, not a courtesy. It should state that CCTV is in operation and who to contact for more information. Combined with a sensible retention period and a documented policy, that’s most of what’s needed to keep a commercial CCTV system on the right side of GDPR.