Are outdated DVRs putting your clients at risk of 2026 UK GDPR enforcement?

An old recorder does not automatically breach the UK GDPR. However, unsupported firmware, weak passwords, excessive retention or uncontrolled access can prevent a business showing that personal data is protected appropriately.
The Information Commissioner’s Office fined Capita plc and Capita Pension Solutions Limited a combined £14 million in October 2025 after finding serious security failings connected with a breach affecting 6.6 million people. Although unrelated to CCTV, it shows why appropriate technical and organisational measures matter.
The Data (Use and Access) Act 2025 increased maximum PECR penalties to £17.5 million or 4% of worldwide annual turnover, whichever is higher. PECR mainly concerns electronic marketing, cookies and communications. CCTV is generally governed by the UK GDPR and Data Protection Act 2018, which already carry equivalent maximum penalties.
Why an ageing recorder may create risk
The ICO does not require businesses to replace a recorder simply because it is old. Compliance depends on the risks, the footage collected and the controls in place. A recorder becomes difficult to defend when security updates have ended, remote access is exposed, users share credentials or exports are uncontrolled.
A modern NVR may provide these functions, but technology labels alone prove nothing. Configuration, maintenance and staff procedures remain essential.
What installers should raise with clients
During a survey or maintenance visit, check the recorder model, support status, user accounts, remote-access method, retention settings, time synchronisation and export process. Record any limitations clearly without presenting legal conclusions.
A useful report might state: “The recorder no longer receives confirmed security updates and currently uses shared administrator access. We recommend a documented risk review and either remediation or replacement.”
Our guides to CCTV signage and privacy basics and what's changing in CCTV specs and compliance cover wider responsibilities. For maintenance planning, see software and firmware upgrades, the true cost of replacing failed cameras and reducing return visits through better CCTV planning.
Who is responsible?
The organisation deciding why and how CCTV is used is usually the data controller. An installer may also become a processor if it can access, host or maintain footage on the client’s behalf. In that situation, written contractual terms and appropriate security duties are important. Documenting advice is sensible, but it does not automatically remove liability for poor installation, insecure remote access or mishandling of footage.
As a security camera wholesale supplier, FVS CCTV offers NVRs wholesale, cctv recorder wholesaler products and cctv accessories supplier stock for trade installations.
Frequently asked questions
Must every old DVR be replaced?
No. If it remains supported and can be configured securely, replacement may not be necessary. Assess its actual capabilities, risks and intended purpose first.
Does better image quality guarantee compliance?
No. Clear footage supports the stated security purpose, but organisations must also justify camera coverage, limit access, set retention periods, display suitable signs and respond properly to information rights requests.
Help clients improve CCTV security
Review the system before recommending replacement. Where an upgrade is justified, browse the NVR range, apply for a trade account, call 0208 863 0666 or get in touch online.
