Coleraine: 02870 878077Derry/LDerry: 02871 878123Belfast: 02890 993566Magherafelt: 02879 668330Omagh: 02882 888166

What Is a CCTV Redaction Service? A Guide for Northern Ireland Businesses

A CCTV redaction service removes or obscures the faces, licence plates, and other identifying details of third-party individuals from video footage before that footage is shared with a requester. In most cases this is legally required when responding to a subject access request (SAR) under UK GDPR. Businesses that skip redaction risk ICO complaints and data breach liability.

When Does a Business Need CCTV Footage Redacted?

There are four situations where businesses in Northern Ireland regularly need CCTV footage redacted before it leaves their control.

Subject Access Requests (SARs). Under UK GDPR Article 15, any individual has the right to request a copy of personal data an organisation holds about them, including CCTV footage in which they appear. You can provide footage showing the requester, but you are legally required to blur or mask any other identifiable individuals in the same clip. If a member of the public or an employee was involved in an incident captured on your cameras and makes a formal SAR, you need to act within one calendar month (UK GDPR Article 12(3)).

Police and criminal investigations. When police request footage as part of a criminal investigation, they typically view it under their own legal gateway and redaction may not be required for the submission itself. However, if the same footage is later used in court proceedings or disclosed to a defendant, redaction requirements apply. Legal advice specific to your situation should be sought here.

Insurance claims. Many insurers require CCTV footage when processing liability or property claims. If the footage contains identifiable third parties who are not party to the claim, those individuals’ data must be protected before submission to the insurer.

Employment disputes. If CCTV footage is used in a disciplinary or grievance process and the employee requests a copy, the footage must be redacted to remove colleagues or members of the public before it is handed over.

What CCTV Redaction Actually Involves

Redaction is not a single click on a video file. Done correctly, it is a systematic, frame-by-frame process.

Step 1: Request received and scoped. The specific time window, camera, and the identity of the data subject requesting footage are confirmed in writing. This creates the audit trail.

Step 2: Footage located and secured. The relevant recording is copied and the original preserved in its unaltered state. Chain of custody is documented from this point.

Step 3: Third-party identification. A trained operator reviews the footage to identify every frame containing an individual who is not the requesting data subject. This includes partial views, reflections in windows or mirrors, and incidental appearances at the edge of frame.

Step 4: Redaction applied. Professional redaction software applies blurring, pixelation, or masking to each identified individual in every affected frame. The process is applied consistently throughout the clip, not just to obvious moments.

Step 5: Quality review. A second review confirms no unredacted identifiers remain. Licence plates, signage containing personal information, and other incidental data are also checked.

Step 6: Delivery and documentation. The redacted file is delivered to the requester in the agreed format. A record of the request, the footage provided, the redaction undertaken, and the date of delivery is retained for compliance purposes.

This process takes significantly longer than most businesses expect, particularly for footage spanning several hours, multiple camera angles, or busy public-facing locations. The ICO does not accept “we ran out of time” as a reason for missing the one-month SAR deadline.

CCTV footage is personal data. When you operate a CCTV system, you are a data controller. That status carries obligations.

Lawful basis. You need a lawful basis to process CCTV footage. For most businesses this is legitimate interests (UK GDPR Article 6(1)(f)), documented in a legitimate interests assessment and referenced in your privacy notice. This should already be in place if your CCTV system is properly compliant.

Responding to SARs. When you receive a SAR relating to CCTV footage, you have one calendar month to respond. You must either provide the requested footage (redacted) or explain in writing why you cannot (for example, if the footage no longer exists or the request is manifestly unfounded). You cannot charge a fee for a standard SAR.

Third-party data protection. UK GDPR Article 5(1)(f) requires that personal data be processed with appropriate security, including protection against unauthorised disclosure. Providing unredacted footage that reveals identifiable third parties to the requester is a disclosure of those third parties’ personal data without a lawful basis. That is a data breach and must be reported to the ICO within 72 hours if it is likely to result in a risk to individuals’ rights and freedoms.

Data processor agreements. If you engage an external CCTV redaction service, they are a data processor handling personal data on your behalf. Under UK GDPR Article 28, you must have a written data processing agreement (DPA) with them before they handle the footage. Any reputable professional redaction service will have a standard DPA ready to execute.

What to Look for in a CCTV Redaction Service Provider

Not every company offering video editing or post-production services has the data protection competence to handle SAR-related footage correctly. When selecting a provider, verify the following.

Data processing agreement. If a provider cannot produce a UK GDPR-compliant DPA within minutes of being asked, walk away. This is a basic requirement, not an optional extra.

Documented chain of custody. You need evidence of what footage was received, when, by whom, and what was done with it. This protects you if the SAR or any related legal matter is later disputed.

Secure data transfer. Footage should be transferred over an encrypted connection, not emailed as a plain attachment or posted on an unprotected file-sharing link.

Audit trail and record of redaction. The provider should supply you with a record of what was redacted and why, alongside the redacted output. This is your evidence that you fulfilled the SAR correctly.

Turnaround time. With a one-month SAR deadline, you typically need a 5-to-10-business-day turnaround for standard requests. Confirm this before the deadline clock is already running.

Professional indemnity insurance. If a mistake is made and an unredacted frame is delivered, professional indemnity insurance provides a financial backstop. Confirm the provider carries it.

Professional Insight: What We See in the Field

The most common mistake we encounter when businesses come to us after a SAR has gone wrong is a belief that basic blurring applied to a highlight clip is sufficient. In most incidents captured on CCTV, the footage that matters spans several minutes of context either side of the key moment. A data subject making a SAR is entitled to all footage in which they appear, not just the ten seconds their solicitor is focused on.

Businesses also underestimate the data volume involved. A single camera recording at 15 frames per second over four hours generates over 200,000 frames. Reviewing that manually without systematic software support is not realistic. Missed frames are not acceptable to the ICO. Professional redaction software processes footage systematically and flags frames requiring human review, rather than relying on an operator to spot every occurrence manually.

The second area where businesses get caught out is the audit trail. When a data subject or their solicitor challenges the completeness of a SAR response, you need to be able to demonstrate exactly what footage existed, what was redacted, and what was provided. Without a documented process, that defence is very difficult to mount.

Advanced Overwatch provides CCTV redaction as part of its broader security management offering for businesses across Northern Ireland. Our team works under a formal data processing agreement, documents every step of the chain of custody, and delivers redacted footage with a full written record of the process. SSAIB certified (NIRE127) and ISO 27001 accredited, we handle footage under the same information security standards we apply to all client data.

Is CCTV footage classed as personal data under UK GDPR?

Yes. CCTV footage that captures identifiable individuals is personal data under UK GDPR. The fact that a person can be identified from the footage, whether by their face, gait, clothing, or vehicle, is sufficient. This means any organisation that operates a CCTV system is a data controller under UK GDPR and must comply with all associated obligations, including responding to subject access requests and protecting the data against unauthorised disclosure. The Information Commissioner’s Office has issued detailed guidance on CCTV and UK GDPR, which is publicly available on the ICO website.

What happens if I miss the one-month deadline for a CCTV subject access request?

If you fail to respond to a SAR within one calendar month without a valid reason, the requester can complain to the ICO. The ICO can investigate, issue a reprimand, or in more serious cases, issue an enforcement notice requiring you to comply. Persistent or deliberate failures can result in financial penalties. In practice, the ICO is more likely to pursue enforcement where an organisation failed to respond at all or where there is evidence of deliberate delay. If you are struggling with a complex request, you can invoke the two-month extension by notifying the requester within the first month, before the deadline passes.

Does a police evidence disclosure request require the same redaction as a SAR?

Not necessarily. When police request footage under their own legal powers (such as a production order or a Data Protection Act 2018 Schedule 2 paragraph 2 exemption), the normal SAR process does not apply and you are generally required to provide what is requested without redaction. However, if that footage is subsequently used in legal proceedings and a copy is provided to a defendant or their legal team, the data protection obligations on the recipient apply, and redaction may be required at that stage. This is a complex area and legal advice appropriate to your specific circumstances is recommended before disclosing footage in a criminal or civil matter.

Standards Explained

UK GDPR (United Kingdom General Data Protection Regulation)
The retained version of EU Regulation 2016/679, applicable in UK law since 1 January 2021. UK GDPR sets out the principles for processing personal data (Article 5), lawful bases for processing (Article 6), individual rights including the right of access (Article 15), and obligations on data controllers to protect third-party data (Article 5(1)(f)). CCTV footage is personal data within the scope of UK GDPR. The one-month SAR response deadline is set in Article 12(3).

Data Protection Act 2018
UK primary legislation that works alongside UK GDPR to form the complete data protection framework. The DPA 2018 provides specific exemptions relevant to CCTV, including the law enforcement processing provisions (Part 3) and the intelligence services processing provisions (Part 4). For most businesses, the relevant parts are the main UK GDPR regime supplemented by DPA 2018 Schedule 2, which includes exemptions for national security, crime prevention, and certain professional legal obligations. Organisations unsure whether an exemption applies to a specific SAR should seek ICO guidance or legal advice before relying on it.

ICO CCTV Guidance
The Information Commissioner’s Office publishes detailed guidance on CCTV, surveillance cameras, and related data protection obligations. This includes guidance on when to respond to SARs for CCTV footage, how to handle redaction, and what constitutes a lawful basis for surveillance camera operation. While ICO guidance is not legally binding in the same way as legislation, the ICO uses its own guidance as the benchmark when investigating complaints and enforcement cases. Following ICO guidance therefore provides the strongest available defence in any regulatory investigation.

Advanced Overwatch provides professional CCTV installation, maintenance, and data compliance services for businesses and homes across Northern Ireland. SSAIB certified (NIRE127). ISO 9001, 14001, 27001, and 45001 accredited. Call 028 7087 8077 or visit advancedoverwatch.com for a free consultation.

1st Floor, Beresford House, 2 Beresford Road, Coleraine, BT52 1GE

Previous ArticleNext Article
Call Me Back
Complete the form to receive a call back from a member of staff.

    Your Name

    Phone Number