Under UK GDPR, anyone who is identifiable in CCTV or body-worn camera footage has the right to request a copy of it as their own personal data.

NHS trusts and hospitals handle a steady stream of these subject access requests each year, covering everything from car park incidents to disputes on a ward. Many trusts also retain footage for only 30 to 31 days before it is automatically deleted, which changes how these requests need to be handled in practice.

What counts as a CCTV or body-worn camera subject access request

Footage from CCTV and body-worn cameras is personal data whenever a person in it can be identified. Under Article 15 of the UK GDPR, anyone captured on camera, whether a patient, visitor, member of staff or contractor, has the right to ask for a copy of that footage as part of a subject access request (SAR). A SAR only entitles someone to their own personal data, not footage of other people, so a request needs enough detail, such as a date, time, location and description, to allow the specific footage to be located. Most trusts also require some form of identification before releasing anything, both to confirm who is asking and to establish that they genuinely appear in the recording.

The response clock is tighter than the 30 days suggests

UK GDPR sets a statutory deadline of one calendar month to respond to a SAR, extendable by up to two further months for complex or high-volume requests. In practice, however, several NHS trusts publish CCTV and body-worn camera privacy notices stating that footage is retained for only 30 or 31 days before it is automatically deleted. That creates a much narrower practical window than the statutory deadline implies. If a request is not identified, logged and actioned within days of the incident rather than weeks, the underlying footage may already have been overwritten by the time a formal response is due. For a trust receiving even a handful of these requests a month, spotting them quickly and locating the right footage before it expires is often the harder part of compliance, not the redaction itself.

Why redacting other people takes longer than it looks

A SAR only entitles the requester to see their own data, so anyone else who appears in the footage and has not consented to disclosure normally needs to be obscured before it is released. This is straightforward to describe but time-consuming to do. A single busy corridor or waiting area camera can show dozens of different people across even a short clip, and each one may need to be tracked and blurred for the full duration they appear on screen. Reviewing and redacting just a few hours of multi-camera footage by hand can take a review team the better part of a working week, which sits uncomfortably against a retention window measured in days.

What “reasonable steps” looks like in practice

The Information Commissioner’s Office expects organisations to take reasonable and proportionate steps to comply with a SAR, rather than an impossible standard of perfection. Under the Data Protection Act 2018, a request can be treated as manifestly unfounded or excessive in some circumstances, which may allow a reasonable administrative fee or a partial refusal, though this exemption is applied narrowly and should not be relied on as a routine workaround for a slow process. What tends to matter in practice is being able to demonstrate a consistent, documented approach: a clear policy, a defined identity-verification step, and a repeatable method for locating, reviewing and redacting footage within the time available.

Getting ahead of the next request

Industry estimates suggest smaller NHS trusts typically receive somewhere in the region of 2 to 10 CCTV or body-worn camera SARs a year, with larger acute trusts seeing anywhere from 10 to 50 or more. At that volume, a published privacy notice and a documented process are only part of the answer, since the constraint is rarely the policy itself but the practical speed of locating and redacting footage within a 30-day retention window. Estates, security and information governance teams working from separate systems for CCTV and body-worn camera footage tend to find this hardest, simply because there is more ground to cover manually before a deadline that arrives faster than it appears to.


Frequently Asked Questions

How long do NHS trusts keep CCTV footage?

Retention periods vary between trusts, but many hospitals hold CCTV footage for only 30 or 31 days before it is automatically deleted. A copy may be kept separately for longer once a specific request has been logged and is being processed. It is worth checking a specific trust’s own CCTV and body-worn camera privacy notice, since retention periods are set locally rather than nationally.

What is the time limit to respond to a CCTV subject access request?

Under UK GDPR, organisations have one calendar month to respond to a subject access request, which can be extended by up to two further months for complex or high-volume requests. In practice, the retention period for the footage itself is often the tighter constraint, since some trusts delete recordings after 30 or 31 days regardless of the statutory response deadline.

Can a hospital refuse to provide CCTV footage?

A request can be refused or restricted in specific circumstances, for example where releasing footage would only identify other people rather than the requester, or where a request is manifestly unfounded or excessive under the Data Protection Act 2018. Requests connected to an ongoing police investigation are usually handled through the police rather than released directly to the individual.

Do NHS trusts have to redact other people from CCTV footage?

Yes. Anyone else who is identifiable in the footage and has not consented to disclosure normally needs to have their face and other identifying features obscured before it is released. This applies to both CCTV and body-worn camera footage and is one of the more time-consuming parts of fulfilling a request.

What happens if the footage has already been deleted when a request arrives?

If footage has been automatically deleted under a trust’s normal retention schedule before a request is received, it is not usually possible to recover it, and the trust would confirm that no data is held. This is why trusts with short retention windows benefit from identifying and acting on a potential request as early as possible, ideally within days of an incident rather than weeks.

Is body-worn camera footage handled the same way as CCTV under GDPR?

The same UK GDPR principles apply to both, since footage of an identifiable person is personal data regardless of which type of camera captured it. Body-worn camera footage often includes audio as well as video, which adds an extra layer to the redaction process compared with silent CCTV recordings.

Can a trust charge a fee for a subject access request?

Subject access requests are normally free of charge. A reasonable administrative fee may be charged only where a request is considered manifestly unfounded or excessive, and this exemption is applied narrowly rather than as standard practice.

Who can request CCTV or body-worn camera footage from an NHS trust?

Anyone who is identifiable in the footage can submit a subject access request for a copy of their own data, and this can also be made on their behalf by a solicitor or other authorised representative. Requests relating to a crime are usually directed through the police, while road traffic incidents without police involvement are typically handled via an insurer.


Faster, Compliant CCTV and Body-Worn Camera Evidence Management

Whether reviewing hours of CCTV footage, redacting body-worn camera recordings, or building a faster subject access request process from scratch, 2CL Communications can advise on the right combination of technology and support for a trust’s estate.

Contact Us


Also See