DPIAs for district CCTV and ANPR
When a district camera scheme legally needs a data protection impact assessment, what it has to contain, and the commonly published rules that turn out not to be rules at all.
If you run a camera scheme across a district, an estate or a town centre, this is the part that stalls schemes. Not the cameras. The question a member business, a councillor or a local reporter eventually asks: what gives you the right to film me?
There are good answers. They are not complicated. But a lot of published guidance on this subject is out of date, and several things repeated as rules are not rules at all.
What this is, and is not. This is general information about how the law applies to district camera schemes, written for the person who has to put a paper in front of a board. It is not legal advice, and a scheme with unusual features — facial recognition, audio, cameras overlooking homes, or a police data-sharing arrangement — should be checked with your own adviser.
It describes the law of England and Wales. Scotland has no Surveillance Camera Code and has its own Scottish Biometrics Commissioner and statutory code; Northern Ireland operates under PACE (NI) Order 1989. The UK GDPR and the Data Protection Act 2018 apply throughout, but several points below do not.
On this page
- Does our scheme need a DPIA?
- What a DPIA has to contain
- Does the Surveillance Camera Code apply to us?
- What is your lawful basis?
- When your cameras start processing special category data
- Who is the data controller?
- Signage
- How long can we keep it?
- What people can ask you for
- Four more things a district scheme gets asked about
- Security, breaches and records
- Nine things not to put in your board paper
- Common questions
- Where this fits
Does our scheme need a DPIA?
Almost certainly yes, and it is a legal requirement rather than good practice.
Article 35(3)(c) of the UK GDPR requires a data protection impact assessment for "a systematic monitoring of a publicly accessible area on a large scale" (legislation.gov.uk).
For ANPR specifically the ICO leaves no room:
"Regardless of the sector you operate in, if you are using or intend to use an ANPR system, it is important that you undertake a DPIA prior to deployment."
And on video surveillance generally:
"This is a legal requirement and applies in most cases relating to video surveillance given the inherent privacy risks involved in the use of these systems."
The ICO's own list of high-risk indicators reinforces it from another direction: tracking ("processing which involves tracking an individual's geolocation or behaviour"), data matching and biometrics all appear on it, and a district ANPR scheme engages the first two by design.
The joint Surveillance Camera Commissioner and ICO guidance states the consequence bluntly:
"failure to complete a DPIA prior to the deployment of a surveillance camera system could result in the ICO taking enforcement action."
When "large scale" applies. The ICO says to weigh the number of people affected, the volume and variety of data, how long the processing runs, and the geographical extent of it. A district scheme is squarely within that.
Do it before you install. The obligation is to assess "prior to the processing". A DPIA written to justify cameras already on poles is not doing the job the law asks, and it is far harder to change a design at that point.
If you cannot reduce a high risk, you must consult the ICO — and in the ICO's words, "You cannot go ahead with the processing until you have consulted us."
What a DPIA has to contain
Article 35(7) sets the minimum:
- A systematic description of what you are doing and why, including the legitimate interest you are pursuing if that is your basis.
- An assessment of necessity and proportionality.
- An assessment of the risks to people's rights and freedoms.
- The measures you will use to address those risks — safeguards, security, and how you will demonstrate compliance.
Three duties sit alongside it: take your data protection officer's advice if you have one (35(2)); seek the views of the people affected, or their representatives, where appropriate (35(9)); and review it when the risk changes (35(11)).
That consultation duty is worth dwelling on. For a levy-funded scheme it is not only a legal requirement — it is the same consultation that makes the scheme defensible at a board and at a ballot. Done once, properly, it serves both.
And treat 35(11) as a live obligation, not a filing date. Moving a camera, adding a lane, turning on a new analytic, extending the covered area or adding a new recipient are all triggers to revisit the assessment. Give it an owner and a version history.
Use the free template rather than starting from scratch
The Surveillance Camera Commissioner and the ICO jointly publish a DPIA template written specifically for surveillance cameras, free, on gov.uk: Data protection impact assessments for surveillance cameras.
It is explicitly intended for private operators as well as public bodies. It asks for what a board will ask about anyway: where the cameras are and why, with supporting evidence such as crime statistics; who is affected and whether any vulnerable groups are; how data flows from collection to destruction; who else receives it; your lawful basis; your signage; your retention period and your reasons for it; how you handle subject access; and a risk table scored for likelihood and severity.
Two of its questions catch most schemes out:
- It asks what less intrusive alternatives you considered — and suggests better lighting or improved physical security as examples. If nobody considered them, your necessity case is weak.
- It asks whether there is a risk of function creep. A scheme installed for crime prevention that gradually becomes a parking enforcement tool or a footfall counter has changed its purpose. That needs revisiting rather than assuming.
One caveat: the template dates from 2020 and uses pre-Brexit language throughout. It is a live tool and gov.uk has not withdrawn it, but do not lift its legal phrasing into your own document. Use its structure and cite the UK GDPR directly.
Here is what the statutory minimum looks like against what you actually write:
| Article 35(7) requires | For a district scheme, that means |
|---|---|
| A systematic description of the processing and its purposes | Every camera position and what it covers; what is captured (plate, overview image, timestamp); who operates it; retention at each stage; every recipient |
| The legitimate interest pursued, where applicable | The specific crime and safety problem, evidenced — police.uk data, incident logs, member survey results — not "security" in the abstract |
| Necessity and proportionality | Why cameras rather than lighting, physical measures or wardens; why these positions; why this retention period; why ANPR as well as CCTV |
| The risks to rights and freedoms | Being recorded going about lawful business; misidentification from a cloned plate; function creep; an over-broad disclosure; residents overlooked |
| The measures addressing them | Signage; access control; retention limits; the objection route; redaction capability; staff training; a written disclosure policy |
Does the Surveillance Camera Code apply to us?
This is the question most often answered wrongly, in both directions.
ANPR is covered by the Code's subject matter. Section 29(6) of the Protection of Freedoms Act 2012 defines a surveillance camera system as "closed circuit television or automatic number plate recognition systems".
But the duty to have regard to the Code binds only "relevant authorities." Section 33(5) lists them and it is a closed list of public bodies — local authorities, the Greater London Authority, police and crime commissioners, chief officers of police and a handful of others. A BID company, an estate management company or a private landlord is not on it. The Code says so:
"Other operators of surveillance camera systems who are not defined as relevant authorities are encouraged to adopt this code and its guiding principles voluntarily and make a public commitment to doing so. Such system operators do not have to have regard to this code but it is still considered best practice."
Two ways it reaches you anyway, and district schemes hit both:
- By contract. The Code requires a relevant authority to push the obligation down: contracts or memoranda with third-party partners "must ensure that contractors are obliged by the terms of the contract to have regard to the code." If your scheme involves the council or the police — and most do — check your agreement before assuming it does not apply.
- By constitution. Plenty of BIDs are council-owned companies, or have the council as accountable body. If that is you, the council's own duty may bite on the scheme directly.
The Code is also "admissible in evidence in criminal or civil proceedings".
The Code was not abolished — correcting a widespread error
Much commentary published since 2023 states that the Surveillance Camera Commissioner and the Code have been abolished. That is wrong, and if it is in your board papers it should come out.
Abolition was proposed in the Data Protection and Digital Information (No. 2) Bill, whose clause 104 would have abolished the office and removed the Code. That Bill fell when Parliament was dissolved in May 2024, and the provisions were not carried into the Data (Use and Access) Act 2025.
Part 2 Chapter 1 of the Protection of Freedoms Act 2012 is intact and in force. The Code in force is the amended version that took effect on 12 January 2022. Professor William Webster took office as Biometrics and Surveillance Camera Commissioner on 1 November 2025. Home Office guidance for local authorities on the Code was updated as recently as August 2026.
One expectation to set, from the Commissioner's own office:
"The commissioner has no enforcement or inspection powers regarding surveillance cameras and works with relevant authorities to make them aware of their duty to have regard to the code."
The regulator with enforcement teeth here is the ICO.
What is your lawful basis?
The ICO's position for surveillance:
"In practice, it is difficult to obtain genuine consent from individuals that are subject to video surveillance in public spaces. Therefore, it is likely the appropriate lawful basis will be either legitimate interests, or a reliance on public task (if you are carrying out your tasks as a public authority in the public interest or under official authority)."
For a BID or estate company that means legitimate interests. For a council running its own scheme, public task — and public authorities are barred from relying on legitimate interests for their own tasks.
Consent is not the answer, and a sign is not consent. Walking into shot is not a freely given, specific, informed choice, and a person who cannot avoid the area cannot refuse.
The three-part test
- Purpose — what is the legitimate interest? Usually crime prevention and detection, community safety, protecting property.
- Necessity — will this achieve it, and is it proportionate? The ICO asks directly: "Can you achieve your purpose by using the information in another, more obvious or less intrusive way?"
- Balance — do people's interests, rights and freedoms override yours? You must include people's reasonable expectations.
A precision point plenty of guidance overstates: the three-part test is legally required. Writing it up as a "legitimate interests assessment" is not. The ICO's words: "The UK GDPR doesn't require you to do an LIA. But you should do one anyway." Do it — you need it for the DPIA regardless — but do not tell your board the law demands a document it does not. The ICO publishes a sample LIA template.
A new option, flagged rather than recommended
The Data (Use and Access) Act 2025 created "recognised legitimate interest" — Article 6(1)(ea), in force 5 February 2026. Where it applies you must still show necessity, but not the balancing test. Annex 1 paragraph 5 covers crime: processing necessary for "detecting, investigating or preventing crime" or "apprehending or prosecuting offenders". Paragraphs 6 to 8 cover safeguarding, which may fit some district schemes better.
On the face of the statute a private district crime-prevention scheme meets it. It is also, counter to intuition, available to a private BID company and not to a council acting in its public tasks.
Three reasons the saving is smaller than it looks:
- The ICO has never applied it to CCTV or ANPR. Its video surveillance guidance does not mention it, and that guidance is under review.
- The right to object survives. Article 21(1) was amended on 5 February 2026 to include point (ea). So you drop the balancing test at the front door and meet it again whenever somebody objects, with the burden on you.
- It is an Article 6 basis only. It does nothing for special category data or criminal offence data, so a scheme with any biometric element gains nothing from it.
The conservative position — and the ICO says expressly you "don't have to change lawful basis" if you already rely on legitimate interests — is to stay where you are with a documented three-part test. If your scheme is being designed now, this is a question for your own adviser.
When your cameras start processing special category data
This is the section most likely to be missing from a scheme's paperwork, and the one with the sharpest consequences.
Ordinary CCTV of people's faces is personal data, not special category data. The ICO is clear: "Not all biometric data is automatically special category biometric data. It only becomes this if you use it to uniquely identify someone."
But some analytics cross the line, and "AI-enabled" cameras are frequently sold without anyone asking which side they sit on:
- Facial recognition — matching a face against a watchlist to identify a person — processes special category biometric data. You then need an Article 9(2) condition as well as an Article 6 basis. For a private operator the realistic route is the substantial public interest conditions in Schedule 1 Part 2 of the Data Protection Act 2018, which are narrow and carry an appropriate policy document requirement.
- Analytics inferring age, sex, ethnicity or health may reveal special category data even without identifying anyone.
- Appearance-based search — finding a person by clothing colour or by gait — is a harder question than it looks, and depends on whether it is being used to identify a specific individual.
The case to know about. R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058 is the only appellate authority in this field. The Court of Appeal found the force's use of live facial recognition unlawful, and one of the grounds was that its DPIA was deficient. If you take one thing from this page: a defective DPIA is not a paperwork problem, it is the thing that makes the processing unlawful.
Footage of a suspected offence is also special. It is criminal offence data under Article 10, and needs a Schedule 1 condition of its own — usually paragraph 10, preventing or detecting unlawful acts.
The practical instruction: before you buy, ask the supplier in writing which analytics run, what each infers, and whether any of it uniquely identifies a person. If the answer includes facial recognition, that is a materially different scheme with a materially harder compliance case, and it needs its own advice.
Who is the data controller?
On a district scheme several organisations touch one camera system: the BID or estate company, the local authority, the police, the managing agent, sometimes member businesses. Working out who is responsible for what decides who answers a complaint, who handles a subject access request, and who is liable.
The test is who decides. Whoever "decides what is to be recorded, how it should be used and to whom it may be disclosed" is the controller. Paying for the cameras does not make you a controller — so a BID that sets the purpose, positions, retention and disclosure policy is the controller even though member businesses fund it through the levy.
Article 26 applies where two or more organisations jointly determine the purposes and means. They must then, "in a transparent manner, determine their respective responsibilities" by an arrangement between them, and "the essence of the arrangement shall be made available to the data subject".
The ICO addresses this scenario directly:
"If you make joint decisions with another organisation about the purposes for, and operation of, the surveillance system then you are joint controllers for this processing." "In a shared service situation you should also make clear who is legally in control of what information at any given time."
The distinction most guidance blurs
- A data sharing agreement is not legally mandatory. The ICO's statutory data sharing code says so in terms, and warns that having one "does not provide immunity from breaching the law".
- A joint controller arrangement under Article 26 is legally required where you are joint controllers.
That does not make a data sharing agreement pointless — quite the opposite. A well-drafted DSA that allocates responsibilities, names who answers data subjects, and whose essence you publish can be your Article 26 arrangement. The failure mode is having a document that describes what data moves where without ever allocating responsibility for compliance. Check yours does the second thing.
Two points people find uncomfortable and should know:
"regardless of those arrangements, each controller remains responsible for complying with all the obligations of controllers." "Each joint controller will be liable for the entire damage caused by the processing… The arrangement made between controllers is irrelevant for these purposes."
And one that is useful: individuals can exercise their rights against any joint controller, whatever your arrangement says. So it needs to name who actually picks up the phone.
Your suppliers are usually processors. A monitoring contractor running your control room to your instructions, or a software provider hosting your data, is a processor and needs a written contract meeting Article 28 — scope, duration, security, sub-processors, assistance with rights requests, and what happens at the end. Note Article 28(10): a processor that starts deciding purposes for itself becomes a controller, with its own liability.
Where police are involved, a second regime appears. Police process for law enforcement purposes under Part 3 of the Data Protection Act 2018, not the UK GDPR. Once you disclose footage to a force, they hold it under Part 3 while you remain under the UK GDPR. Different rules, different subject access route, different retention. The National ANPR Service is a Part 3 operation.
Signage
Signs must be clearly visible and readable, and must give:
- that surveillance is in operation
- who is operating it
- the purpose
- contact details — at minimum a website, telephone number or email address
The ICO's model wording:
"Images are being monitored and recorded for the purposes of crime prevention and public safety. This system is controlled by XXXXX. For more information, visit our website at (web address) or call 01234 567890."
Placement matters as much as content. Signs go "before the entrance to the system's field of vision", reinforced inside the area. The ICO's reasoning is memorable:
"it is not considered fair for an individual to read a sign that warns them about particularly intrusive surveillance technology in the area, if the system has already captured them whilst reading it."
And directly on point for a district:
"As a general rule, signs should be more prominent and frequent in areas where people are less likely to expect that they will be monitored by a surveillance system. For example, this is particularly important when you are using a system to cover a large public area."
For ANPR the bar is higher. ICO guidance says signs "must make clear that cameras are in use and explain who is operating them", and adds a road-safety point most people miss: consider how much time a driver actually has to read the sign, particularly where the speed limit is high.
A caution on numbers. The ICO publishes no figure for sign size, height, font or spacing. Its test is "an appropriate size depending on the context". If a supplier gives you a specific measurement attributed to the ICO, it is not from the ICO.
Publishing your privacy information on a website is not enough on its own, but a sign pointing to a fuller notice online is a recognised approach — and a sensible one where the detail will not fit on a pole.
How long can we keep it?
There is no statutory retention period for CCTV or ANPR in the UK.
"The UK GDPR and the DPA 2018 do not prescribe any specific minimum or maximum retention periods which apply to surveillance systems… Rather, it is the purpose of your processing that should determine your retention period… Therefore your retention period should be the shortest period for that purpose."
And aimed squarely at how most systems are configured:
"You should also not determine your retention period simply by the storage capacity of any surveillance system, or just in case you think the data may be useful in the future."
Two figures you will be told are rules.
"The ICO says 31 days." The phrase appears nowhere in the ICO's video surveillance guidance or its DPIA guidance. The number comes from the Home Office, not the regulator: the National CCTV Strategy of 2007 discussed a 28-to-31-day norm in the context of giving police time to collect footage, and the Home Office's UK police requirements for CCTV systems says only that "retention beyond 31 days may be useful in some circumstances." That is a permissive statement about a floor the police would like, not a ceiling set by the regulator. Around a month remains a sensible starting point — but your retention period still has to be justified by your purpose, in writing.
"ANPR data must be kept for 12 months." That is the police standard for the National ANPR Service, which states that it "does not cover the use of Automatic Number Plate Recognition for any purpose that is not law enforcement." It does not apply to your scheme.
The ANPR-specific point worth designing around. The ICO draws a distinction most schemes ignore: the justification for keeping reads of vehicles of interest is much stronger than for keeping reads of every other vehicle. Its worked example concerns a car park keeping data on vehicles that complied with the time limit, which the ICO says "is unlikely to comply with the data protection principles." A single blanket retention period across every read is therefore hard to defend. Tiered retention is both more defensible and cheaper to store.
On hashing. Some systems delete the plaintext registration mark after a period and keep a hash so movement trends survive. That is worth doing, but be precise about what it achieves: a hashed registration mark is pseudonymised, not anonymised. A registration mark has a small enough range of possible values that a hash can be worked back to the plate. The hashed archive remains personal data and stays within your retention policy, your subject access obligations and your DPIA. Treat any supplier who calls it anonymous with caution.
What people can ask you for
Subject access. Someone can ask for footage of themselves. Two things changed on 5 February 2026 that older guidance does not reflect:
- The one-month clock now starts at the latest of: when you received the request, when you received any identity information you reasonably asked for, and when any fee was paid.
- You can "stop the clock" while you wait for clarification you reasonably need — but not on a blanket basis, only where genuinely required.
You can extend by two further months for complex or numerous requests, telling the person within the first month with your reasons.
You only have to conduct a reasonable and proportionate search. This was added by the Data (Use and Access) Act and is the most useful change of 2026 for camera operators — it is the answer to "send me everything you hold of me across 54 cameras for the last month".
A practical trap: if you take the full month, your retention policy may delete the footage meanwhile. Preserve the material as soon as a request arrives. And a transcript or written description instead of the footage "is not enough to comply in most circumstances".
Other people in the footage. Disclosure must not adversely affect the rights and freedoms of others, and the Data Protection Act gives you an exemption where disclosure would reveal information about another identifiable person — unless they consent, or it is reasonable to disclose without it.
It is not true that you must always redact. The ICO's position is that you "may have to consider seeking the consent of third parties where reasonable or alternatively removing or redacting particular footage", decided "on a case-by-case basis". Blurring, masking and solid fill are the usual techniques. If you contract redaction out, that supplier is your processor and needs a written contract.
Objections. Anyone can object to processing based on legitimate interests, on grounds relating to their particular situation. You must stop unless you can demonstrate compelling legitimate grounds that override their interests, or the processing is for the establishment, exercise or defence of legal claims — and the burden is on you. One calendar month. Your privacy notice must set out this right separately from the other rights.
A scheme needs a route for this a real person can use. It is also the honest answer when a member business objects in principle: there is a mechanism, it is written down, and it will be honoured.
And from 19 June 2026, a complaints process is compulsory. The Data (Use and Access) Act inserted new section 164A into the Data Protection Act 2018. Every controller must now facilitate complaints about its handling of personal data — the Act's own illustration of what that means is "providing a complaint form which can be completed electronically and by other means" — must acknowledge a complaint within 30 days of receiving it, investigate it without undue delay and tell the complainant the outcome. For an organisation filming a whole district this is the most operationally significant new obligation of 2026, and most schemes do not yet have it.
Four more things a district scheme gets asked about
Automated decisions. If a watchlist match automatically raises an enforcement action, denies access or blacklists a vehicle without a human considering it, you may be making a decision with legal or similarly significant effects. That has its own rules, reformed by the Data (Use and Access) Act. Keep a human in the loop on anything with consequences for a person.
Audio. The ICO treats sound recording as highly intrusive and expects it to be off unless you can justify it specifically. Cameras and help points frequently ship with microphones enabled by default. Check yours, and record the check.
Cameras overlooking homes. Flats above shops are the commonest source of complaints against town-centre schemes. Privacy zones — masked areas the system will not record — are the standard answer, and they belong in the DPIA and on the camera schedule, not in someone's memory.
Children and vulnerable people. Night-time economy areas, routes to schools and places where vulnerable people gather all raise the risk profile, and the ICO's high-risk indicators name vulnerable data subjects specifically. Say in the DPIA whether your area includes them and what you have done about it.
Security, breaches and records
Two obligations that sit outside the DPIA but get asked about in the same meeting.
Breach notification. A personal data breach that risks people's rights must be reported to the ICO within 72 hours of becoming aware, and the people affected must be told where the risk is high. In this sector the archetypal breach is not a hacker — it is an over-broad export, a disclosure to the wrong person, or a lost drive. Where there are joint controllers, agree in advance who notifies.
Records of processing. Article 30 requires a record of your processing activities. For a camera scheme it is largely a camera schedule with purposes, recipients and retention against each position — which you need for the DPIA anyway.
Where the data lives. If your platform is cloud-hosted, ask where the data is stored and who can access it from where. Transfers outside the UK need a transfer mechanism and a risk assessment. It is a fair question to put to any supplier, including us, and you should get a straight answer in writing.
Nine things not to put in your board paper
Every one of these is commonly published, and every one is wrong.
- "We rely on consent, because there are signs." A sign is notice, not consent. The ICO says genuine consent is difficult to obtain in public spaces; the realistic basis is legitimate interests, or public task for an authority.
- "The Surveillance Camera Code binds us." Not if you are a private BID or estate company — unless a partner has imposed it by contract, or your BID is council-constituted. Check.
- "The Surveillance Camera Commissioner was abolished." No. That Bill fell in May 2024.
- "A data sharing agreement is legally required." It is not. A joint controller arrangement is — though a well-drafted agreement can serve as one.
- "We have a month from receiving a subject access request." The clock changed on 5 February 2026, and you can now stop it for clarification you reasonably need.
- "We must always redact third parties." It is a case-by-case judgement.
- "The ICO says keep footage for 31 days." There is no ICO rule and no statutory period. The convention has a different origin and your period still needs justifying.
- "ANPR must be retained for 12 months." That is the police national standard, which expressly excludes non-law-enforcement use.
- "Our cameras use AI, but we're not doing anything biometric." Possibly true, possibly not. If an analytic identifies a person rather than merely detecting one, you are in Article 9 and need a condition for it.
Common questions
Does a BID or estate need a DPIA for CCTV?
Yes, in almost every case, and before installation. Article 35(3)(c) requires one for systematic monitoring of a publicly accessible area on a large scale, and the ICO says a DPIA is important for any ANPR deployment regardless of sector.
Do we have to follow the Surveillance Camera Code of Practice?
Not as a legal duty, if you are a private BID or estate company — the duty binds only the public bodies listed in section 33(5) of the Protection of Freedoms Act 2012. But you may acquire it by contract through a council or police partner, and the Code is admissible in proceedings. Following it voluntarily is the recommended position.
Was the Surveillance Camera Commissioner abolished?
No. Abolition was in the Data Protection and Digital Information (No. 2) Bill, which fell at the dissolution of Parliament in May 2024. The office and the Code both continue, and a new Commissioner took office on 1 November 2025.
What lawful basis applies to a BID CCTV scheme?
Legitimate interests, with a documented three-part test. Councils use public task instead. Consent is not realistic for public-space surveillance. A new "recognised legitimate interest" basis for crime came into force in February 2026 but the regulator has not yet addressed its application to CCTV.
How long can we keep ANPR data under GDPR?
There is no statutory period. The rule is the shortest period that serves your stated purpose, written down with your reasoning. Consider tiering it: shorter for ordinary reads, longer where there is a specific reason.
Who is the data controller when a BID, a council and the police share a scheme?
Whoever decides the purposes and means. Funding a scheme does not make you a controller. Where decisions are genuinely shared you are joint controllers and Article 26 requires a documented arrangement whose essence is published — and each of you remains fully liable regardless of what it says.
Do we need a DPIA if we already have one from three years ago?
You need to review it when the risk changes. Moving cameras, extending the area, adding analytics or adding a new recipient are all triggers.
Where this fits
If you are working out what a district scheme should consist of, our page on ANPR for districts, estates and business parks covers the camera types, the Home Office performance standards and what degrades a read — including the point that the ICO treats camera quality as a data protection duty, not just a performance preference.
If your question is what happens when the police ask for footage, that is CCTV retention, evidence and police requests.
And if you would rather talk it through, book a 30-minute call. We will not sell you a camera on it.
UK data protection law was amended by the Data (Use and Access) Act 2025, with changes commencing on 20 August 2025, 5 February 2026 and 19 June 2026, and ICO guidance is still being updated to reflect them — every ICO page cited currently carries a notice that it is under review. Check the linked sources before relying on any point here in a submission.
Talk it through with us
If you would rather walk through how your scheme handles this, book a 30-minute call. We will not sell you a camera on it.
Book a 30-minute call