After the Data (Use and Access) Act commencement: what to add to CCTV handover packs

After the Data (Use and Access) Act commencement: what to add to CCTV handover packs

After the Data (Use and Access) Act commencement: what to add to CCTV handover packs

Since the main data protection and privacy provisions of the Data (Use and Access) Act 2025 came into force on 5 February 2026, the CCTV handover pack you leave with a customer has become even more important. It is the document that helps prove the system was set up with privacy, access and complaint handling in mind from day 1.

The core rules still sit under UK GDPR and the Data Protection Act 2018. The Act amends those rules rather than replacing them, so most good CCTV practice remains the same. What has changed is the level of clarity customers need around subject access requests, internal complaints and the records that support lawful use. It is worth reading this alongside our wider look at UK CCTV compliance in 2026.

You have probably lived this. The customer signs off, you pack the van, and 2 weeks later they ring because someone wants a copy of themselves on camera. If the pack covers that, the call takes 5 minutes. If not, it lands back on you. Getting handover, training and audit trails right is the cheapest insurance you can hand a client.

What the Act changed for CCTV

The Act did not rewrite the CCTV rulebook. It clarified parts of data protection law that matter to any organisation using cameras.

Subject access requests now have a clearer footing. A customer responding to a request only needs to carry out searches that are reasonable and proportionate. The response clock can also be paused where the customer reasonably needs clarification from the person making a vague request.

Data protection complaint handling has also changed. Since 19 June 2026, organisations must have a route for people to complain about how their personal data is handled. They must acknowledge a complaint within 30 days and respond without undue delay. Your customer is usually the data controller, so the obligation is theirs. But they will often look to the installer for help when footage, exports or redaction are involved. The government’s commencement timetable sets out the staged dates.

What to put in the handover pack

Treat the pack as the answer sheet for questions your customer will face later. The baseline below suits a corner shop and scales to a multi-site retailer.

Item

Why it matters

Purpose and lawful basis note

Records why the cameras exist, often legitimate interests, so the system can be justified

Retention schedule

Sets how long footage is kept and confirms automatic deletion or overwrite

Signage confirmation

Shows people were told recording takes place, in line with signage and privacy basics

SAR and complaints route

Gives a named contact and process for requests and complaints

Export and redaction instructions

Helps the customer retrieve footage without exposing other people unnecessarily

Equipment and firmware record

Lists cameras, recorders, drives and versions so support stays traceable

DPIA note, where needed

Flags high-risk features such as facial recognition, biometric matching or intrusive staff monitoring

Two practical notes matter. First, storage is where handovers quietly fail. The law does not set a fixed CCTV retention period. Around 30 days is common, but the customer must choose a period they can justify and actually deliver. Fit undersized surveillance-grade hard drives and a 30-day retention promise can become 11 days in reality. Match the drive to the channel count, frame rate and recording mode, then log it.

Second, if you are replacing an ageing recorder, explain why older DVRs can create GDPR risk. Weak passwords, limited export options and unsupported firmware can all make SAR handling harder. Quoting current IP CCTV NVRs is often a compliance upgrade, not just a hardware swap.

Where a customer wants people counting, ANPR, facial recognition or face matching, the pack needs a clear risk note and, where the use is high risk, a Data Protection Impact Assessment reference. Our overview of AI and smart analytics explains where that line often sits. For a standard job, a clean list of the fitted IP CCTV equipment and signage and accessories keeps the record tidy. Offering a service and maintenance plan gives you a reason to revisit and keep the documentation current.

Frequently asked questions

Does the Data (Use and Access) Act mean I need new CCTV signs?
Not automatically. Signage duties still flow from UK GDPR transparency rules. Signs must still explain that CCTV is in use, why it is used and who to contact.

Who is responsible for a subject access request, the installer or the customer?
Usually the customer, because they are the data controller. The installer should make sure the handover pack explains how footage can be retrieved, exported and redacted.

How long should CCTV footage be kept in the UK?
There is no fixed legal period. The customer must choose the shortest period that meets their purpose and stick to it.

Is a DPIA always needed?
No. It is needed where the CCTV use is likely to create high risk, such as facial recognition, intrusive monitoring or use in sensitive areas.

Handover packs are easier with the right kit behind them

A tidy handover starts with equipment you can document and stand behind. As a trade-only CCTV distributor, FVS CCTV supplies the recorders, drives and signage your packs depend on, with free technical support if a compliance question comes up on site. Set up a trade account or call the team before your next handover.