If site cameras can identify people, the images are likely to count as personal data under UK data protection law. That applies to time-lapse stills and live streams as well as CCTV. Here is what the Information Commissioner’s Office (ICO) expects, and how to plan cameras with it in mind.
This is general guidance, not legal advice. The ICO’s video surveillance guidance is under review following the Data (Use and Access) Act, so check the latest ICO guidance before you rely on it.
Is time-lapse footage personal data?
It depends on whether people can be identified. The ICO says viewing images in real time still counts as processing personal data “if you can identify individuals directly or indirectly”. A wide view from a long distance may not identify anyone; a close view of a site entrance probably will. High-resolution cameras make identification more likely, so plan views with that in mind.
Who is responsible?
The ICO says the organisation that decides what is recorded, how it is used and who it is shared with is the controller, and is legally responsible for compliance. On a construction project that is usually the client or contractor who commissions the cameras. A camera supplier that stores images on your behalf should be covered by a written contract that sets out its responsibilities.
What the ICO expects
- A lawful basis. For site cameras this is usually legitimate interests, and a legitimate interests assessment helps you show it.
- A DPIA where the risk is high. The ICO lists monitoring publicly accessible places on a large scale and monitoring people at work as examples that need a Data Protection Impact Assessment.
- Clear signs. People should know they are entering an area where cameras operate, before they enter it.
- Only what you need. Point cameras at the area of interest and restrict wider views that are not needed.
- Retention based on purpose. There is no fixed legal period. Keep images for the shortest time that meets your purpose, then delete them.
- Security. Restrict access to authorised people and store images securely, encrypted where possible.
What to put on your signs
The ICO’s own example is a building site with large, prominent notices telling people about the cameras, that they are there for safety and security, and who to contact with a query. Signs should include:
- that cameras are in operation
- the purpose, for example progress recording, safety and security
- who operates the system, unless it is obvious
- contact details, such as a phone number, email address or website
Place signs where people will see them before they reach the cameras’ view, and size them for who will read them: pedestrians, drivers or site operatives.
Planning camera positions
The ICO gives the example of a camera that could see into a nearby flat, and says the view should be adjusted to avoid the intrusion. At our free site survey we agree camera positions and views with you, so this is the time to raise neighbouring homes, public footpaths or areas that should stay out of shot.
How Site-Eye protects your images
- Portal access is through a secure login over an encrypted connection.
- Images are stored on our own servers in two separate UK locations, with nightly hardware clones.
- Server rooms are locked, with access only for essential staff.
- The portal stays open for six months after the project, or longer if you choose. SiteStream clips can be kept for one month or for the whole project.
Read more about our data security.
Sources
- ICO: How can we comply with the data protection principles when using surveillance systems?
- ICO: What are our responsibilities in terms of accountability?
Planning cameras for a project?
Tell us about your site and we will recommend the cameras, positions and duration, then confirm it all at a free site survey.






