{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Use of CCTV and Surveillance in Service Users’ Homes Policy
1. Purpose
The purpose of this policy is to establish clear guidelines on the use of CCTV and other surveillance systems in service users’ homes, ensuring that privacy, dignity, and legal rights are protected. This policy ensures that {{org_field_name}} complies with Care Inspectorate Wales (CIW) regulations, data protection laws, and ethical standards when CCTV or surveillance technology is used.
Our objectives are to:
- Ensure that the use of CCTV and surveillance is lawful, justified, and proportionate.
- Safeguard service users’ privacy, dignity, and human rights.
- Support service user safety while preventing abuse, neglect, or misconduct.
- Ensure all stakeholders understand their rights and responsibilities.
- Implement strict data protection and confidentiality measures for recorded footage.
2. Scope
This policy applies to:
- Service users who request or consent to the use of CCTV in their homes.
- Family members, advocates, or representatives involved in decision-making.
- All employees, including care workers, managers, and administrative staff.
- The Registered Manager and Responsible Individual, responsible for ensuring compliance.
- Third-party monitoring services, where applicable.
- Healthcare professionals and external agencies with access to CCTV footage.
3. Legal and Regulatory Framework
This policy must be applied in line with:
- The Regulation and Inspection of Social Care (Wales) Act 2016.
- The Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 (as amended) and the Welsh Ministers’ Statutory Guidance for providers of care home and domiciliary support services (last updated 27 March 2024).
- The Social Services and Well-being (Wales) Act 2014, including relevant safeguarding duties and local safeguarding procedures.
- The Mental Capacity Act 2005 (including best-interests decision-making where a person lacks capacity).
- The Human Rights Act 1998 (Article 8 – respect for private and family life).
- The Equality Act 2010 (ensuring no discriminatory application of surveillance).
- The UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and current ICO guidance on CCTV and video surveillance.
- The Protection of Freedoms Act 2012 and (where applicable) the Surveillance Camera Code of Practice.
- The common law duty of confidentiality and relevant professional codes/standards.
3.1 Definitions
For the purpose of this policy:
- CCTV / video surveillance includes fixed cameras, smart doorbells, internal cameras, webcams, baby monitors with video, and any system that records and/or transmits images from within or outside a service user’s home.
- Audio recording (microphones) and live-streaming/remote viewing are forms of surveillance and are treated as more intrusive than video-only recording.
- Covert surveillance means surveillance that is not openly communicated (for example, hidden cameras).
3.2 Roles and responsibilities (including data protection roles)
- Where CCTV is installed and controlled by the service user and/or their family/representative, they will usually be the data controller because they decide why and how the footage is used. In this situation, {{org_field_name}} remains responsible for providing safe care and support and for protecting the privacy and dignity of the service user and staff while delivering the service.
- Where CCTV is installed, accessed, or controlled by {{org_field_name}} (for example, where the service determines the purpose of monitoring and has routine access to footage), {{org_field_name}} will be the data controller and will ensure full compliance with UK GDPR/DPA requirements including DPIAs, security controls, retention, and data-subject rights handling.
- Where any third-party is used to store/monitor footage on behalf of {{org_field_name}}, a written data-processing contract must be in place and due diligence completed to ensure adequate security and lawful processing.
4. Principles for the Use of CCTV and Surveillance
At {{org_field_name}}, we follow these principles when considering CCTV and surveillance in a service user’s home:
- Consent and transparency – CCTV must only be used with explicit consent from the service user or their legal representative.
- Proportionality and necessity – CCTV should only be used where there is a genuine need to improve safety or monitor specific risks.
- Privacy and dignity – CCTV should not be used in bedrooms, bathrooms, or private spaces unless essential and agreed upon.
- Data protection and confidentiality – All recorded footage must be securely stored, accessed only by authorised personnel, and used strictly for its intended purpose.
- Compliance with legal obligations – The use of CCTV must follow GDPR requirements, ICO guidance, and CIW regulations.
- Personal plan / care plan recording – Any agreed use of CCTV/surveillance (including locations, whether audio is enabled, who can view, and the purpose) must be recorded in the individual’s personal plan/care plan and kept under review.
- Overt and clearly indicated – CCTV must be openly communicated and clearly indicated to those entering the home (including staff, professionals and visitors), unless Section 7.5 (Covert surveillance) applies.
5. Obtaining Consent for CCTV Installation
5.1 Service User Consent
- The service user (or their legal representative) must provide written consent before CCTV is installed.
- Consent should be informed, voluntary, and documented in the care plan.
- If the service user lacks mental capacity, consent must be obtained via a best interest decision process under the Mental Capacity Act 2005.
5.2 Family and Carer Involvement
- Families must be involved in discussions if they request CCTV for safeguarding or monitoring purposes.
- Any decision must prioritise the service user’s preferences and rights.
- Disputes between family members and the service user regarding CCTV use must be resolved through mediation or legal guidance.
How we manage this efficiently:
- A structured consent form is used to document decisions and agreements.
- Regular reviews ensure consent remains valid and service users have the right to withdraw at any time.
5.3 Staff, professionals and visitor transparency
- The service user/family must tell {{org_field_name}} before care starts if CCTV/smart doorbells are in use, and must confirm camera locations and whether audio recording and/or live viewing is enabled.
- {{org_field_name}} will ensure staff attending the call are informed in advance (for example through the care plan/rota notes).
- Staff, visiting professionals and other visitors must be able to see that CCTV is in use (for example by signage/notice at entry points and/or written notice in the care plan documentation held in the home).
5.4 Audio recording and live-streaming/remote viewing
- Audio recording and live-streaming/remote access are higher-intrusion measures and are not permitted by default.
- If audio and/or live viewing is requested, this must be explicitly agreed in writing, recorded in the care plan, and supported by a specific risk assessment showing why video-only recording is insufficient.
5.5 Intimate care and privacy-sensitive tasks
- Cameras must be positioned to avoid recording personal care, undressing, toileting, bathing or other privacy-sensitive activities.
- Where a camera cannot be repositioned and intimate care is required, the expectation is that recording is paused/disabled for that period, unless an exceptional, documented decision has been made that meets Section 6 and Section 7.5 requirements.
6. CCTV Placement and Use Restrictions
- CCTV must not be installed or used in bathrooms, toilets, bedrooms, or areas where intimate personal care is delivered unless there is an exceptional and time-limited justification that has been risk assessed, recorded in the care plan, and approved by the Registered Manager (and, where relevant, discussed with safeguarding professionals). Any such arrangement must use the least intrusive camera position/field of view and be reviewed at least monthly.
- Cameras should only record areas relevant to safety and security.
- The service user should be aware of all camera locations and have access to their own recordings if desired.
How we manage this efficiently:
- CCTV placement is agreed upon in writing and logged in the service user’s care plan.
- A checklist is used to confirm that camera positioning complies with privacy laws.
7. Data Protection and Security of CCTV Footage
7.1 Storage and Access Control
- CCTV footage is encrypted and stored securely, with restricted access to authorised individuals only.
- Footage must not be retained for longer than necessary (typically 30 days, unless required for an investigation).
- Any request to access footage must be recorded and approved by the Registered Manager.
7.2 Sharing and Disclosure of CCTV Footage
- CCTV footage must never be shared on social media or unauthorised platforms.
- Footage may only be shared:
- With law enforcement if a crime is suspected.
- With CIW or safeguarding authorities if required.
- With legal representatives, following data protection laws.
How we manage this efficiently:
- A CCTV data access log is maintained, documenting all requests and disclosures.
- Staff training ensures that all employees understand GDPR and confidentiality obligations.
7.3 Lawful basis and DPIA (where {{org_field_name}} is the data controller)
Where {{org_field_name}} installs/controls/accesses CCTV footage, we will document:
- the lawful basis relied upon under UK GDPR;
- a Data Protection Impact Assessment (DPIA) where required (or where surveillance is high risk);
- why CCTV is necessary and proportionate, and why less intrusive measures are insufficient; and
- how we will meet data protection principles (data minimisation, limited retention, access controls, and secure sharing).
7.4 Access to footage and subject access requests (SARs)
- Requests for CCTV footage will be managed through {{org_field_name}}’s data protection process.
- Where footage contains images of other people (for example staff or visitors), we will consider third-party privacy and apply redaction (blurring/masking) where required and lawful.
- We will respond within the applicable statutory timescales and in line with current ICO guidance.
7.5 Data protection/privacy complaints
Any concern that CCTV footage has been used unfairly or unlawfully (including excessive monitoring, inappropriate sharing, or recording in private situations) will be handled as both:
- a service complaint under Section 9; and
- a data protection complaint under our data protection process, including providing the complainant with an outcome and (where appropriate) signposting to the ICO.
7.6 Data breaches
Any loss, unauthorised access, hacking, or inappropriate disclosure of CCTV footage must be reported immediately to the Registered Manager and handled under the organisation’s data breach procedure, including assessment of whether notification to the ICO and affected individuals is required.
7.7 Covert surveillance (hidden cameras)
- Covert surveillance in a service user’s home is not permitted as routine practice.
- Covert surveillance may only be considered in exceptional safeguarding circumstances, where there is a documented reason to suspect serious abuse or criminal behaviour and less intrusive options have been exhausted. Any such consideration must be authorised by the Responsible Individual/Registered Manager, recorded with a clear rationale, and discussed with the relevant safeguarding partners and/or police as appropriate.
- If staff believe covert surveillance may be occurring, they must report this immediately to the Registered Manager so that a risk assessment can be completed and an appropriate plan agreed with the service user/family (including whether care can continue safely and with dignity).
8. Monitoring and Compliance
- The Registered Manager oversees the ethical use of CCTV and ensures compliance with legal requirements.
- Regular audits and reviews ensure that CCTV use remains necessary and proportionate.
A CCTV Register will be maintained for any service user where CCTV is present and relevant to service delivery. This will record: purpose, ownership (service user/family or {{org_field_name}}), camera locations, whether audio/live viewing is enabled, agreed privacy safeguards (including pausing during personal care), who may access footage, retention period, date agreed, and review dates.
- Any misuse of CCTV by staff will result in disciplinary action.
How we manage this efficiently:
- Quarterly audits ensure correct CCTV usage and identify any issues.
- A service user feedback process allows individuals to report concerns about surveillance.
9. Handling Complaints and Disputes
Service users, families, or staff can raise concerns about CCTV use. Complaints will be:
- Logged and acknowledged within 5 working days.
- Investigated fairly, with input from all relevant parties.
- Escalated to external authorities (e.g., CIW, ICO) if necessary.
Where the concern relates primarily to privacy/data protection, individuals will be signposted to the Information Commissioner’s Office (ICO); where the concern relates to quality/safety of care, individuals will be signposted to Care Inspectorate Wales (CIW).
How we manage this efficiently:
- A clear complaints procedure is provided to all service users.
- A mediation process is available for disputes over CCTV use.
10. Removal or Modification of CCTV
- Service users can withdraw consent at any time, and cameras must be removed or deactivated.
- If CCTV was installed for safeguarding reasons, a risk assessment must be completed before removal.
How we manage this efficiently:
- Regular reviews of CCTV use ensure it remains necessary and proportionate.
- A structured deactivation and removal process is followed.
11. Related Policies
This policy aligns with:
- Confidentiality and Data Protection Policy (DCW34).
- Safeguarding Adults Policy (DCW13).
- Risk Management and Assessment Policy (DCW18).
- Dignity and Privacy Policy (DCW07).
12. Policy Review
This policy will be reviewed annually or sooner if required due to legislative changes, business needs, or CIW updates. The Registered Manager and Responsible Individual are responsible for ensuring compliance.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.