Skip to main content Skip to footer

The Data Protection Act 2018 (DPA 2018) [1] and the UK General Data Protection Regulations (UK GDPR) [2] set out the legal requirements for video surveillance, including CCTV. 

Individuals (staff, patients and other visitors) attending the dental practice have a right to privacy. Therefore, you must consider how installing CCTV could impact these individuals and take account of their concerns about being recorded. You should be able to explain your rationale for using CCTV (e.g. to deter aggression towards reception staff). As a rule, only visual images should be recorded, audio should not be recorded unless there are exceptional circumstances and you can justify this. 

If the use of CCTV is likely to result in a high risk to individuals (e.g. continuous monitoring of staff), a Data Protection Impact Assessment (DPIA) is required to identify the impact this may have on individuals attending your practice (see Data Protection Impact Assessments).   

The Information Commission Office provides guidance and a checklist for using CCTV. 

Staff can contact the ICO if they feel the CCTV is being used unfairly. 

Before starting to use CCTV, you must: 

  • register with the ICO as a data controller and pay the annual data protection fee
  • display a sign/poster that indicates that CCTV  is being used, the reasons for this and who to contact if an individual has queries regarding this
  • check the camera angle so the CCTV only records what is intended. CCTV should not be used in areas that are considered private (e.g. toilets and changing rooms)
  • ensure that any sound recording facility is turned off or disabled 
  • update your privacy notices to reflect that you are using CCTV 
  • have a CCTV policy in place. The ICO provides a checklist for a CCTV policy and data protection requirements
  • decide on the retention period for CCTV images and record this in the CCTV policy and privacy notices. You must not keep images for any longer than required and you must have a process in place for deletion
  • keep CCTV images secure (e.g. password protected) and only allow designated people to view them. The ICO must be notified if there is a data breach (e.g. if the images are viewed by individuals who are not authorised to do so)
  • ensure the CCTV system allows you to retrieve stored images. Under the Data Protection Act 2018 (DPA 2018) and UK General Data Protection Regulations (UK GDPR), individuals have a right to have a copy of the personal information, including CCTV images, held about them (see Subject access requests).  

Sources of information

  1. Data Protection Act (2018)
  2. UK GDPR guidance and resources. Information Commission Office