Sooner or later, someone asks you for your CCTV footage. It might be a police officer investigating a break-in, an insurer processing a claim, a lawyer building a case, or simply a customer who wants to see themselves walking through your shop. Each of these requests is governed by a different part of GDPR, and the single most common mistake is treating them all the same way: handing over the raw file and exposing every bystander who happened to be in frame.
Disclaimer: This content is for general informational purposes only and does not constitute legal advice. Regulations and supervisory authority guidance vary by jurisdiction and change over time. Always consult a qualified legal or data protection professional for advice specific to your situation.
TL;DR
- Police requests: you can generally disclose without consent under a lawful basis (legal obligation or legitimate interest in crime prevention). Get the request in writing, share only the relevant window, log it. Full-clip disclosure to police is usually fine: verification is what matters, not redaction.
- Subject access requests (Article 15): someone filmed has the right to a copy of footage of themselves. You have one month to respond. Article 15(4) requires you to redact every other identifiable person before disclosure: this is the part organizations get wrong.
- Insurers, lawyers, and other private parties: no automatic right to footage. You need consent, a legitimate claim basis, or a court order, and you should still minimize and redact third parties.
- Exporting and redacting by hand is where most small organizations stall. Anonymize CCTV footage automatically: detect faces and plates, keep the right person visible, pixelate everyone else.
Not every request is the same request
If you operate any camera that captures identifiable people (a shop entrance, an office lobby, a warehouse loading bay, a residential complex), you are, under GDPR, a data controller for that footage. That status doesn't just create obligations around how you record and retain video; it creates obligations every time someone asks you to hand it over.
The three request types you'll actually encounter are:
- Law enforcement, investigating a crime or incident.
- The person who appears in the footage, exercising their right of access.
- A private third party (an insurer, a lawyer, an employer, a neighbor) who wants footage for a claim, dispute, or investigation.
The legal basis, the deadline, and your redaction obligation are different for each one. Get the categorization wrong and you either over-disclose (exposing bystanders' data unlawfully) or under-disclose (failing a statutory obligation). For the underlying framework (lawful basis, retention, signage, and DPIAs), see our guide to GDPR video surveillance requirements.
Police and law enforcement requests
This is the case most CCTV operators worry about most and understand least. In practice, it's usually the simplest.
You can generally disclose footage to the police without the consent of the people in it, relying on one of two lawful bases under Article 6 GDPR:
- Legal obligation (Article 6(1)(c)): if a formal production order, warrant, or specific statutory duty compels disclosure, you must comply.
- Legitimate interests (Article 6(1)(f)): for an informal but genuine investigative request, both your interest and the police's interest in preventing or investigating crime typically justify sharing the relevant footage, provided it's proportionate.
Best practice, not just legal minimum:
- Get the request in writing, identifying the requesting officer, the case or reference number, and the reason footage is needed.
- Share only the time window and camera(s) that are actually relevant, not a full day's recording because it's easier to export.
- Log the disclosure: date, officer, footage description, legal basis relied on.
You are not generally required to redact bystanders before handing footage to the police for a lawful, documented investigative purpose: a full, unedited clip is often what makes it useful as evidence. The obligation that trips people up here isn't redaction, it's verification: confirm the request is genuine (a phone call from someone claiming to be an officer, with no written follow-up, is not enough) before you disclose anything. If you operate in the UK, the same logic applies almost exactly under UK GDPR and ICO guidance.
Subject access requests: when the person in the footage asks
This is the request type that actually causes operational headaches, and it's worth slowing down on.
Article 15 GDPR gives anyone whose personal data you process (including anyone whose face appears in your CCTV) the right to obtain a copy of it. If a customer, employee, or passerby asks "can I have the footage of me from Tuesday afternoon," that is a formal subject access request (SAR), whether or not they use that phrase.
Two things follow from that:
The one-month clock starts immediately. Article 12(3) gives you one calendar month to respond from the day the request arrives, extendable by up to two further months only for complex or high-volume requests, and you must notify the requester of the extension within the first month, with a reason. "We'll get to it eventually" is not compliant.
Article 15(4) is the obligation that matters most. The right of access must not "adversely affect the rights and freedoms of others." A single twenty-minute clip from a shop-floor camera can easily contain dozens of other shoppers, plus staff going about their day, none of whom consented to being disclosed to a third party. You cannot lawfully hand over a raw clip that identifies them just because one person in it has a right to their own data.
In practice this means: before you release the footage, you must locate and redact every other identifiable person in frame (faces, and anything else that identifies them) while leaving the requester's own image intact. This is precisely the point where manual redaction becomes a real bottleneck. A twenty-minute multi-camera export can hold hundreds of bystanders across a busy afternoon; blurring each one, frame by frame, in a general-purpose video editor is a day of work for a request you're legally obliged to answer inside a month.
Insurers, lawyers and other private parties
Unlike the police, an insurer, opposing counsel, or a private investigator has no automatic right to your CCTV footage. You need one of:
- Explicit consent from the individuals whose data would be disclosed (rarely practical for bystanders).
- A legitimate legal claim, where sharing footage is necessary to establish, exercise, or defend that claim.
- A court order or formal legal process compelling disclosure.
Even when one of those applies, the same data-minimization principle from Article 15(4) is good practice here too: share only the relevant time window, and redact everyone who isn't a party to the claim unless there's a specific reason they need to remain visible (for example, they're a witness relevant to the dispute). Treat these requests with more scrutiny than a police enquiry, not less: a private party asking for surveillance footage is a common vector for people fishing for information they have no right to.
How to respond to a CCTV footage request
The workflow is the same shape regardless of who's asking; only the redaction decision changes.
- Verify the requester's identity and legal basis. Confirm who is asking and why before you touch the recorder. Police requests should come with a case reference; SARs need identity verification against the footage; insurers and lawyers need to show consent, a claim basis, or an order.
- Locate the footage and export only the relevant window. Pull the specific camera channel and time range. A narrower export means fewer people to redact and less exposure if something goes wrong downstream.
- Identify every third party and identifying detail in frame. Faces, license plates, badges, screens, anything that identifies someone who isn't the requester.
- Redact everyone who isn't entitled to appear. Pixelate bystanders for a SAR while keeping the requester visible; redact all third parties by default for insurers, lawyers, and other private requests.
- Deliver the file securely and log the disclosure. No open links or unencrypted email for anything containing personal data. Record what you shared, with whom, on what basis, and when.
- Apply your retention policy to the working copies. Once the disclosure is done, delete the exported and redacted files per your documented retention period: don't let ad hoc exports pile up outside your normal CCTV storage rules.
Where Medianonymizer fits
Step 4 is the one that stalls most small organizations, because "blur every bystander except one person, frame by frame, across a moving multi-camera clip" is exactly the kind of task that breaks down in a general-purpose video editor.
Medianonymizer's CCTV anonymizer is built for that specific job. Upload your exported clip in a common video format, and the AI detects faces, license plates, and on-screen text across every frame automatically. You review the detections in a preview, then choose selective redaction: keep the requester's own movements intact and pixelate everyone else, or blur every identifiable person if the disclosure calls for it. The output is deterministic (the flagged pixels are re-encoded and destroyed, not covered by an overlay you could peel back later), which matters if a regulator ever asks how the redaction was done. There's no account required, you pay per file (video from €4.99), and it handles long exports (recordings running up to roughly two hours) without you touching a timeline or a keyframe.
This doesn't replace judgment about who is entitled to what. It replaces the frame-by-frame manual masking that makes the redaction obligation feel impossible to meet inside a one-month deadline. For the same reasoning applied to sharing footage more broadly (with the press, in FOIA-style releases, or for training), see how to anonymize CCTV and surveillance footage.
Build the request procedure into your CCTV policy
A footage-request procedure shouldn't be improvised the first time someone asks. It belongs in the same CCTV policy that covers your signage, your lawful basis, and your retention period: who receives requests, how identity and legal basis get verified, the redaction default for each request type, and where the disclosure log lives. If you haven't documented that yet, our guide to GDPR video surveillance requirements covers the full framework, and our comparison of anonymization versus pseudonymization explains why irreversible redaction (not a reversible mask) is what actually takes a disclosure out of GDPR's scope for the recipient.
Respond to your next CCTV request without the manual redaction work
Whether it's a police enquiry, a subject access request, or an insurer's claim, the shape of the problem is the same: export the right window, work out who's entitled to what, and redact everyone else before it leaves your control.
Frequently asked questions
You are generally permitted, but not automatically obliged, to share footage with the police. A written request citing a legal basis (a legal obligation, or your legitimate interest and theirs in preventing or investigating crime) is enough to disclose it lawfully. Verify the request is genuine, keep it in writing, share only the relevant time window, and log the disclosure. If a formal court order or production order specifically compels disclosure, you must comply with that.

