•   QMS ISO9001

CCTV in Care Homes – Legal Requirements for 2026

CCTV in care homes

CCTV in Care Homes – Legal Requirements for 2026

CCTV in Care Homes – Legal Requirements for 2026 1600 896 SPP Solutions

CCTV in Care Homes: What the Law Requires

In the delicate world of elderly care, where vulnerability meets trust, the installation of CCTV cameras in care homes sparks intense debate. On one hand, these systems promise enhanced safety for residents—deterring abuse, providing evidence in disputes, and monitoring high-risk areas. On the other hand, they risk eroding the privacy and dignity that every individual deserves, especially in what should feel like a sanctuary rather than a surveillance state.

As we move into 2026, the governing legislation remains unchanged and crystal clear: all care homes (private, voluntary or local authority) must comply with the UK GDPR and the Data Protection Act 2018 (DPA 2018)including ongoing CCTV compliance under ICO and Surveillance Camera Commissioner guidance.”. Organisations that use CCTV must abide by the Information Commissioner’s Office (ICO) Codes of Practice. If the care home is operated by a local authority or another “relevant authority” listed in Schedule 1 of the Protection of Freedoms Act 2012, they must also comply with the Surveillance Camera Commissioner’s Code of Practice.

The law demands a clear-eyed judgement: privacy and safety are not zero-sum. While CCTV can bolster security, it can never replace the human element—sufficient, well-trained carers who observe, respond, and build trusting relationships. Relying on cameras as a substitute for adequate staffing is not only unethical but also legally risky. If CCTV is installed but not actively monitored (or at least not subject to rapid review protocols), it provides almost no real-time protection for residents. Unwatched footage may record harm after the event, but it does nothing to prevent it.

This guide outlines the legal landscape for 2026, drawing on CQC expectations, the UK GDPR, the Data Protection Act 2018, and ethical best practice.

The Purpose of CCTV in Care Environments

CCTV is often presented as protection against abuse, neglect or unobserved falls. In communal areas, it can deter misconduct, help manage wandering among people with dementia, and provide evidence if allegations arise. The CQC accepts that, in specific circumstances and when less intrusive measures are inadequate, surveillance can be justified.

However, the purpose must always be precise and documented. Both the Surveillance Camera Code of Practice and the ICO require that CCTV is deployed only to address identified risks, never as blanket monitoring. In 2026, the core message remains unchanged: if cameras are not actively monitored—whether by staff watching live feeds, AI-triggered alerts, or same-shift review—their contribution to resident safety is minimal. Proper safety comes from adequate staffing ratios and vigilant, compassionate care, not from hard drives full of footage reviewed weeks later.

Bedrooms and bathrooms remain effectively no-go zones unless an exceptional, fully documented case (usually involving the safeguarding of an individual lacking capacity) can be made under the Mental Capacity Act 2005 and approved through a best interests process.

Data Protection Rules

CCTV footage from care homes is personal data and almost always special-category data (because it reveals health information). Processing is therefore governed by:

– UK GDPR – Articles 6 and 9 (lawful basis and special-category condition)

– Data Protection Act 2018 – particularly Part 3 (law enforcement processing, if police request footage) and Part 2 (general processing, including the additional conditions in Schedule 1 for health and social care)

Before installation, you MUST complete and document a Data Protection Impact Assessment (DPIA) under section 64 of the DPA 2018. The ICO regards failure to carry out a proper DPIA for care-home CCTV as one of the most common and serious breaches.

Other mandatory requirements in 2026:

– Clear, prominent signage and updated privacy notices

– A documented lawful basis (usually “legitimate interests” for communal areas; explicit consent or best-interests decisions for any private-area recording)

– Retention limited to the minimum period necessary (typically 7–30 days)

– Secure, encrypted storage with strict access controls and audit logs

– Contracts with any cloud provider that meet UK GDPR/DPA 2018 standards

The CQC and ICO continue to work closely; inspectors routinely ask to see DPIAs, retention schedules and access logs during inspections.

Avoiding Compliance Risks

Breaches of the UK GDPR and DPA 2018 can lead to ICO monetary penalties of up to £17.5 million or 4 % of global turnover, alongside CQC enforcement action (including potential cancellation of registration). Residents or families can also bring claims directly under the Human Rights Act 1998 or under section 168 of the DPA 2018 (compensation for distress).

Common 2026 pitfalls remain:

– No or inadequate DPIA

– Installing cameras in bedrooms without rigorous justification and consultation

– Relying on “consent” from residents who lack capacity

– Indefinite or excessive retention periods

– Failing to apply the Surveillance Camera Code (where applicable)

The most straightforward way to stay compliant—and to deliver genuine safety—is to treat CCTV as a supplement, never a substitute, for proper staffing. Invest first in people; use technology sparingly, monitor it actively, and always be able to demonstrate that privacy impacts have been minimised.