CCTV Storage, Retention and Data Protection

Two questions decide how a CCTV system is specified once the cameras are settled: how much footage do you need to keep, and how long may you keep it. The first is arithmetic. The second is a legal judgement that a surprising number of systems have never actually made.

What drives storage size

Recording capacity comes down to bitrate multiplied by time. Bitrate depends on resolution, frame rate, the codec and, more than anything, how much movement is in the scene. A camera watching an empty corridor produces a fraction of the data of one watching a busy road, even with identical settings.

The main levers:

  • Resolution. More pixels means more data. Worth paying for where the DORI target demands it, wasteful where it does not.
  • Frame rate. Most review work does not need 25 frames per second. Dropping to 12 or 15 roughly halves storage with little practical loss outside of fast-moving scenes.
  • Codec. H.265 typically produces substantially smaller files than H.264 for equivalent quality. Confirm that everything in the chain, including the client software people will actually use, supports it.
  • Recording mode. Continuous recording is simple and predictable. Motion-triggered recording saves a great deal of space but risks missing the seconds before an event unless pre-record buffering is configured.

Build in headroom. A system sized exactly to its retention target will fall short of it the first time the scene gets busier than the estimate assumed, and it does so silently by overwriting the oldest footage.

How long you may keep footage

CCTV footage of identifiable people is personal data, so the GDPR applies. The storage limitation principle says personal data may be kept no longer than is necessary for the purpose it was collected for.

There is no fixed retention period written into the legislation. Anyone who tells you the law specifies a particular number of days is repeating a rule of thumb, not a rule. What the law requires is that you decide a period, that the period is justified by your stated purpose, and that you can explain the reasoning.

In practice that means a short retention period for general monitoring, on the basis that an incident worth investigating is normally noticed within days. Longer periods need a reason - a site with infrequent access, a documented pattern of delayed discovery, an insurance or investigative requirement. Footage exported for a specific incident sits outside the routine cycle and is retained on its own justification.

The rest of the obligations

Retention is one duty among several, and the others are usually the ones that get missed:

  • Signage. People must be told they are being recorded, who is recording and why, before they enter the area.
  • Purpose. A stated, specific reason for the system. Cameras installed for security cannot quietly become a staff productivity tool.
  • Proportionality. Coverage limited to what the purpose needs. Cameras in bathrooms or changing areas are almost never defensible, and pointing at a neighbour’s property is a common and avoidable complaint.
  • Access requests. Individuals can request footage of themselves, and the system needs to be able to find and export it within the statutory timeframe, with other people obscured.
  • Security of the footage. Access controlled and logged. A recorder on the default password is a breach waiting to be reported.

In Ireland the Data Protection Commission publishes guidance on CCTV; in the UK the Information Commissioner’s Office does the same. Both are worth reading before writing a policy, and both expect a documented assessment for anything beyond routine premises coverage.

Training

The CCTV and Video Surveillance Fundamentals course covers recording, storage planning and responsible deployment alongside the technical material. For a starting point aimed at newcomers, there is online CCTV training for beginners.

If storage sizing has pushed you toward an IP system, see IP networks for CCTV.