How to Respond to a CCTV Subject Access Request: A Step-by-Step Guide

by

in ,

Responding to a CCTV subject access request involves six steps: verify the requester’s identity, locate and preserve the footage before it is overwritten, confirm the requester is identifiable in it, assess any third parties captured, redact and record your decisions, and disclose securely within one calendar month. This applies to any UK organisation operating CCTV, body-worn video, or dashcams — the right of access under Article 15 of the UK GDPR covers footage exactly as it covers documents.

The steps below set out the process in order, with the decision points that most often go wrong. For why video requests fail more often than document requests, see CCTV and video DSARs: where good processes break down.

Step 1: Verify identity and pin down the footage requested

Confirm you are dealing with the data subject (or someone properly authorised to act for them), using a proportionate identity check. Then ask for the information you reasonably need to locate the footage: date, approximate time window, location, and a description of what the person was wearing or doing if the site is busy. Asking for this is legitimate — the ICO’s video surveillance guidance recognises that operators may need it to find the right recording — and since 5 February 2026 the response clock can be paused under the statutory “stop the clock” provision in Article 12A(5) UK GDPR while you wait for it. Record the date the request was received and the date any clarification was requested and answered.

Step 2: Locate and preserve the footage immediately

This is the step that decides most CCTV requests. Surveillance systems typically overwrite footage on a rolling cycle — often fourteen to thirty-one days. Once a request is received, the relevant footage must be identified and taken out of that cycle straight away, and the preservation itself should be logged: who exported it, when, from which camera, covering which period. Deliberately allowing footage to be destroyed after a request has been received is not just a compliance failure — altering or erasing personal data to prevent disclosure is a criminal offence under section 173 of the Data Protection Act 2018.

Step 3: Confirm the requester appears and is identifiable

Review the preserved footage and confirm the requester is actually in it and identifiable. Footage in which they do not appear, or cannot be identified, is not their personal data — but the review that reached that conclusion should be recorded, because “we checked and you are not in it” is a disclosure decision that may itself be challenged. Note which recordings were reviewed and by whom.

Step 4: Assess third parties in the frame

Most footage captures other people, and disclosing it discloses their personal data too. For each third party, the options are to obscure them (blurring or masking), to seek their consent, or — in limited circumstances — to conclude that it is reasonable to disclose without either. In practice, obscuring third parties is the default for CCTV. Whatever the decision, record it per person or per segment, with the reason. This balancing exercise is exactly the kind of judgement that must be evidenced later, not reconstructed — the point made in audit trails are not evidence unless they capture reasoning.

Step 5: Redact and record the decisions

Apply the redactions decided at step 4 — blurring faces, masking screens or number plates, trimming segments that fall outside the request. Use tooling designed for disclosure rather than general video editing: the output must be genuinely irreversible, and the process should generate a record of what was obscured, what was excluded, and why. Ad-hoc editing software produces a redacted file and nothing else; a disclosure platform produces the file and the decision record together. This is the core of Redaktr’s defensibility approach, and its video redaction capability exists precisely so footage goes through the same case-based workflow as documents.

Step 6: Disclose securely and on time

Provide the redacted footage within one calendar month, measured since 5 February 2026 from the “relevant time” under Article 12A UK GDPR (inserted by the Data (Use and Access) Act 2025) — in practice, the date you received the request or any identification you reasonably asked for. It is extendable by up to two further months for complex requests provided the requester is told within the first month. Transfer it securely — an encrypted download or secure portal, not an email attachment — in a format the requester can actually view. Then retain the case record: the request, the preservation log, the review notes, the third-party decisions, and the redaction record. If a complaint follows, that record is the response.

Handled this way, a CCTV subject access request is demanding but routine. Handled ad hoc, it is the request most likely to end up in front of the ICO — usually because the footage was overwritten at step 2 or the decisions were unrecorded at steps 4 and 5. If you would rather hand the whole exercise over, Redaktr also offers done-for-you DSAR processing.

Frequently asked questions

Can we refuse a CCTV subject access request because the footage has been deleted?

If the footage was genuinely overwritten under your normal retention cycle before the request arrived, you hold no data to disclose and should say so, explaining the retention period. Deleting or allowing deletion after the request has been received is different: altering or erasing personal data to prevent disclosure is a criminal offence under section 173 of the Data Protection Act 2018.

Can we charge a fee for providing CCTV footage?

No, not in the ordinary case. A subject access request must be answered free of charge. A reasonable fee, or a refusal, is only available where the request is manifestly unfounded or excessive — a high bar that the organisation must be able to justify.

What if someone requests footage of another person?

That is not a subject access request — the right of access is to the requester’s own personal data. Footage of someone else can only be shared with the other person’s authority or under a separate lawful route, such as a request from the police or a court order. Treat it as a third-party disclosure decision and record it accordingly.