The Data (Use and Access) Act complaints duty is now live: what to tell CCTV clients this summer

The Data (Use and Access) Act complaints duty is now live: what to tell CCTV clients this summer

The Data (Use and Access) Act complaints duty is now live: what to tell CCTV clients this summer

If your clients run CCTV, they now need a clear way to handle data protection complaints. Since 19 June 2026, new requirements under the Data (Use and Access) Act 2025 mean UK data controllers must receive, acknowledge, investigate and respond to data protection complaints properly.

For CCTV users, this matters because footage of identifiable people is personal data. A shop, warehouse, school, council, landlord, office or construction site using CCTV will normally be a controller for that processing. There is no small-business exemption from having a complaints process. The domestic household exemption may apply to purely private home use, but once cameras are used for business, public access, workplace monitoring or wider property management, the rules need to be taken seriously.

The ICO says organisations must give people a way to complain, acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep the person informed, and tell them the outcome.

What changed?

The duty sits in section 164A of the Data Protection Act 2018, added by the Data (Use and Access) Act 2025. It does not create data protection complaints from nowhere. People could already raise concerns about how their personal data was handled. The difference is that organisations now need a proper process for receiving and dealing with those complaints before the person escalates the matter to the ICO.

For CCTV operators, complaints usually come from familiar situations: someone waiting too long for footage, a camera covering a neighbour’s property, unclear signage, excessive retention, poor access controls, or smart analytics being used without enough explanation.

What your client has to do

Requirement

What it means in practice

Provide an accessible complaint route

Offer a clear way to complain, such as an online form, email address or postal route

Acknowledge within 30 days

Confirm the complaint has been received within 30 days of receipt

Investigate without undue delay

Check the facts, review footage handling and make appropriate enquiries

Keep the person informed

Update the complainant if the issue takes time to resolve

Give a clear outcome

Explain what you found, what action will be taken and their right to go to the ICO

Keep records

Log the complaint, steps taken, decision and supporting evidence

Where CCTV complaints come from

Most CCTV complaints are practical rather than unusual. A customer may ask for footage after an incident and receive no clear reply. A neighbour may object to a camera angle. A staff member may ask how long recordings are kept. A visitor may want to know who can access footage.

Good equipment makes those questions easier to answer. A recorder that exports clips cleanly can make a footage request less painful, which is one reason installers should specify capable IP CCTV NVRs rather than the cheapest recorder available. Sensible storage also matters, so size surveillance hard drives for the retention period the client can justify, not for keeping footage indefinitely.

Older recorders can make access, export and audit trails harder. Where clients are still relying on legacy kit, a staged move covered in our guide to upgrading from analogue to IP may reduce operational risk as well as improve image quality.

Transparency reduces complaints

Clear signage and a privacy notice do much of the heavy lifting. Clients should explain why cameras are used, who controls the system, how long footage is kept, how people can request footage, and how they can complain.

If a client uses ANPR, facial recognition, people counting or other smart features, the need for careful documentation increases. Our guide to AI and smart analytics in UK surveillance explains why proportionate systems are easier to defend. The same applies to the hardware: IP CCTV cameras and CCTV accessories should support restricted access, reliable recording and clean evidence handling.

There is also a commercial point for installers. Public-sector clients already have compliance pressures, as our guide to supporting local authorities with high street surveillance shows. They value suppliers who make governance easier. The same applies to reliable kit, as explained in our note on avoiding warranty issues with poor-quality equipment. This also sits alongside the FY2026 NDAA sourcing changes, which are reshaping how many clients think about trusted equipment.

Frequently asked questions

What is the DUAA complaints duty?

It is a duty for UK data controllers to provide and operate a proper data protection complaints process. It has applied from 19 June 2026.

Does a small business with CCTV need a complaints process?

Yes, if it is a controller using CCTV that records identifiable people. The ICO says there are no exemptions from having a complaints process.

How long do you have to respond to a complaint?

You must acknowledge receipt within 30 days, then investigate, keep the person informed and provide an outcome without undue delay.

Help your clients get this right

If you fit CCTV, you are well placed to make compliance easier for the people you sell to. Build systems on kit that exports footage cleanly, stores it sensibly and locks down access. Talk to us as your trade CCTV supplier, and FVS CCTV can help you specify systems that stand up to a complaint as well as a break-in.