CCTV and Video DSARs: Where Good Processes Break Down

by

in ,

CCTV and video DSARs fail more often than document-based requests because organisations improvise: footage is copied to unmanaged systems, redacted with editing tools, and disclosed without a record of what was reviewed or excluded. This affects any operator of CCTV, body-worn video, or dashcams answering subject access requests under Article 15 of the UK GDPR. The medium is not the problem; the absence of process is.

Why do video DSARs go wrong more often?

Many organisations approach video DSARs as an exception rather than as part of their core disclosure framework. This is understandable. Video files are large, sensitive, and difficult to review efficiently. They frequently involve third parties whose identities must be protected, and they often capture moments that carry emotional or reputational weight. The difficulty is that improvised handling increases risk.

Where document-based processes may rely on established workflows, video requests often prompt ad-hoc solutions. Files are copied to isolated systems. Redaction is performed manually using tools designed for editing rather than disclosure. Decisions about what to obscure, what to exclude, and what to retain are made quickly, sometimes without consistent documentation.

What does the ICO expect from video surveillance operators?

The ICO’s video surveillance guidance treats footage of identifiable individuals as personal data like any other: subject to the right of access, subject to third-party protections, and subject to the accountability principle. An operator must be able to respond to a subject access request for footage within the statutory timescale, protect other people captured in the frame, and explain the decisions it made along the way. None of that is optional because the data happens to be visual.

What questions will you be asked afterwards?

Video DSARs are particularly prone to complaint because data subjects often have strong expectations about what footage exists and what it should show. If a response is perceived as incomplete or unclear, scrutiny follows quickly. A common failure point is the lack of recorded reasoning. While the final redacted video may be retained, the steps taken to reach that version are often not. Which clips were reviewed? Why was a particular segment excluded? How were third parties considered? Without clear records, organisations struggle to answer these questions convincingly — the same gap described in audit trails are not evidence unless they capture reasoning.

There is also the issue of consistency. When different teams or individuals handle video requests in different ways, the organisation’s overall disclosure posture becomes fragmented. This is difficult to defend, particularly where similar requests produce different outcomes.

How do you bring video inside a structured disclosure process?

Good disclosure processes are media-agnostic in principle. The same governance questions apply whether the data is textual or visual. What differs is the tooling and the temptation to bypass structure in favour of expedience.

Organisations that manage video DSARs effectively apply the same principles they use for documents. They treat video as disclosure data rather than as a technical anomaly. They ensure that review activity is recorded, that redaction decisions are documented, and that exclusion reasoning is preserved.

Platforms that extend structured disclosure controls to video reduce the need for improvisation — Redaktr handles video and CCTV redaction inside the same case-based workflow as documents. By applying consistent audit and reasoning frameworks across formats, they allow organisations to respond to complex requests without undermining their overall compliance posture.

Video DSARs are not an edge case. They are a stress test. Processes that cope well under this pressure tend to cope well everywhere else.

Frequently asked questions

Do individuals have a right to CCTV footage of themselves?

Yes. Footage in which a person is identifiable is their personal data, and they can request a copy of it through a subject access request under Article 15 UK GDPR. The operator must respond within one month, subject to any lawful extension and applicable exemptions.

Do third parties in CCTV footage have to be blurred?

Usually, yes. Disclosing footage that identifies other people means disclosing their personal data, so operators generally need to obscure third parties — by blurring or masking — unless it is reasonable to disclose without doing so. The decision, and the reasoning behind it, should be recorded.

Is video editing software enough for CCTV redaction?

It can obscure faces, but it leaves no disclosure record: no log of which clips were reviewed, what was excluded, or why. Editing tools solve the visual problem while leaving the defensibility problem untouched. A disclosure-grade process records the decisions as well as producing the redacted output.