Contents
A guest falls on the terrace and asks for the footage. The recorder overwrites on a fortnightly loop, four other diners are in frame, and the month allowed for a reply is already running — so the restaurant's own retention setting can remove the evidence in the middle of a dispute it still has to answer. Saturday, 22:10: a guest catches a heel on the terrace step and goes down hard. Day eleven: a letter arrives asking for the footage. Day fourteen: the recorder in the back office, on the retention setting it shipped with, writes over the whole evening.
None of it needed bad faith, only a privacy notice silent on cameras and nothing written down in the office. Four duties failed inside that fortnight: transparency, missed the day the cameras went up; an assessment never made; a retention period never chosen; a request nobody recognised in time. Only the last can be repaired once the letter lands, and only if the clip outlives the loop.
Before the cameras: the website page is half a notice

The instinct is to add a CCTV paragraph to the website privacy notice and call it done. The Information Commissioner's Office shuts that door in its video-surveillance guidance, in a worked example about using a website to tell people surveillance is running:
It is important to note however that publishing information on a website, by itself, is not enough to comply. You have to draw the individuals' attention to the information. Therefore, you could use physical signage with linked information, so that individuals can find out more if they are interested. This would essentially function as a layered privacy notice.
The unconditional part sits earlier in the same section: "In any case, you must let people know when they are in an area where a surveillance system is in operation."
The website page is therefore the second layer, not the whole. The first layer is a sign a diner can read before walking in, and the transparency checklist sets out what it carries: "We include details of the organisation operating the system, the purpose for using the system and who to directly contact about its use". A restaurant with a booking privacy notice already on its website has the easier half built; the camera half is usually missing at both.
Before the cameras: the basis, and the version of the page that governs
Asking a diner to consent to being filmed on the way to a table is not realistic. The ICO puts the basis elsewhere, and twice: the same page carries it in an "At a glance" summary and again "In detail", and the two differ. The fuller one reads:
For any use of surveillance systems you need to identify and document a lawful basis for processing under Article 6 of the UK GDPR. In practice, it is difficult to obtain genuine consent from individuals that are subject to video surveillance in public spaces. Therefore, it is likely the appropriate lawful basis will be either legitimate interests, or a reliance on public task (if you are carrying out your tasks as a public authority in the public interest or under official authority). A legitimate interests assessment (LIA) can help you demonstrate lawfulness of the processing, especially if you are not carrying out a DPIA. You must however independently identify an appropriate lawful basis that best suits your organisation or method of processing.
A restaurant is not a public authority, so that leaves legitimate interests and a written assessment of why the cameras are necessary and proportionate. The summary version ends instead on that assessment being able to "naturally feed into a DPIA", with no sentence beginning "You must however". Work to the longer one: the assessment supports the basis, it does not replace it.
Before the cameras: the assessment, stated the way the ICO states it
Most owners picture cameras pointed at guests. The ICO's accountability page lists three situations reaching the impact-assessment duty; the third is unexpected:
For surveillance systems, you must take a data protection by design and default approach and perform a Data Protection Impact Assessment (DPIA) for any processing that is likely to result in a high risk to individuals. This includes: processing special category data; monitoring publicly accessible places on a large scale; or monitoring individuals at a workplace.
A camera pointed at the pass, the till, the cellar door or the corridor outside the staff room is monitoring individuals at a workplace, the third item on that list.
The other limbs are harder to meet than they look. The ICO quotes the Article 35(3) surveillance trigger as "(c) a systematic monitoring of a publicly accessible area on a large scale", and the examples it gives of large scale are an open list: they include a hospital, a city's transport system, a bank and, nearest to this trade, a fast food chain tracking the real-time location of its customers. That last is location tracking across a whole chain rather than video in one room, and the list being open, one dining room's absence from it settles nothing. The ICO also publishes the ten rows it treats as high risk under Article 35(4) — innovative technology, denial of service, large-scale profiling, biometric data, genetic data, data matching, invisible processing, tracking, targeting of children and other vulnerable individuals, and risk of physical harm. No row is CCTV or video surveillance.
What the ICO does say is narrower. On that same page: "In any event, this list does not affect your overriding obligation in Article 35(1), which is to assess any proposed processing operation against the requirement to complete DPIAs." On the surveillance accountability page: "This is a legal requirement and applies in most cases relating to video surveillance given the inherent privacy risks involved in the use of these systems." There is a fallback for anyone concluding otherwise — "If you decide to not do a DPIA you need to document your reasons and be prepared to justify why the processing is not of a type likely to result in high risk" — and a consequence for skipping the question: "Further, a failure to carry out a DPIA when required in itself infringes the UK GDPR and may leave you open to enforcement action."
The honest formulation is not that every restaurant with a camera must complete an assessment. It is that the question has to be answered and the answer recorded either way — an assessment done, or a written reason why one is not required. There is no third option in which nobody asks, and which side of the line a restaurant sits on is its own call, on its own facts.
Before the cameras: where they watch staff too, four things are musts
The employment guidance sets the frame: "You are only likely to be justified in using continuous video or audio monitoring of workers in rare circumstances." Then the list, quoted whole because the items are cumulative:
If you are considering using video or audio monitoring, you must: complete a DPIA, as this will help you assess whether the benefits justify the adverse impact; consider why this monitoring is necessary for the intended purpose as part of your DPIA; make sure you inform workers about the extent and nature of the monitoring, and why you are carrying it out; and ensure that you make anyone else caught by the monitoring, such as visitors or customers, aware of its operation and why you are carrying it out.
The fourth item closes the circle back to the guest: a camera protecting staff and stock must still be declared to the diners it records, for the reason it is really there. The same page deals with the setting cheap kits ship with enabled: "You should switch off by default any capability to record audio. You should only use it in exceptional circumstances, for example by a trigger switch."
While they run: retention has no floor and no ceiling
There is no legal number of days for footage; the familiar 30 or 31 days is convention, not law: "The UK GDPR and the DPA 2018 do not prescribe any specific minimum or maximum retention periods which apply to surveillance systems or the personal data you may process. Rather, it is the purpose of your processing that should determine your retention period." The test is the shortest period serving that purpose. The reasoning behind how long booking records should be kept governs the recorder too: name the purpose, derive the period, write both down. The fortnight in the opening was never chosen; it was a factory default.
The morning somebody asks: the month against the loop
Here the loop stops being housekeeping. The ICO's governance page gives deadline, extension and trap in one passage:
You must provide information promptly and within one month of receiving the request. Under the UK GDPR, you can extend the time to respond by a further two months if the request is complex or you have received a number of requests from the individual. Providing information promptly is important, particularly where you may have set retention periods for surveillance footage. This means that the information may be routinely deleted if you take the full month to respond. In such circumstances it is good practice to prevent the premature deletion of any information that falls within the scope of a request.
Note what the extension does not do: it does not slow the recorder. Preserving the clip is the first act, before anything is drafted; the deadline itself is set out in the one-month clock on a guest access request. Every page of that guidance carries a banner saying it is under review following the Data (Use and Access) Act.
The morning somebody asks: four other diners in the frame
The guest asked for the footage. The restaurant owes something narrower: "Your obligations under the UK GDPR are to provide a copy of the information about the requester rather than a complete version of footage. But also to ensure doing so does not adversely affect the rights and freedoms of others."
The raw clip discloses other people's data to a stranger, and trimming to a time window does not help if they are in shot. The ICO describes the work: "You may need to use specialist software to redact visual and audio data of third parties. Available techniques include blurring, masking, or using a solid fill to completely obscure parts of the footage." Redaction is settled at purchase: a recorder that will not export a clean clip for a named minute turns a request into a bill. Where the recorder is a cloud service, not a box in the office, where that supplier is established raises its own question about guest data leaving the UK.
Two corrections, and the checklist for these premises
The Surveillance Camera Code of Practice is cited at small businesses as though it binds them; it does not: "The SC code only applies to relevant authorities across England and Wales." The duty that does apply, and that owners rarely connect to cameras, is registration: "If you are a controller, and your surveillance system is processing the personal data of identifiable individuals, you are required to register and pay a data protection fee to the ICO, unless exempt or you already pay the fee." The checklist adds what gets forgotten a year later: "We have also recorded the next renewal date."
One page in the guidance is aimed squarely at this reader: "This checklist is for users of limited CCTV systems monitoring small premises, such as retail or other small business properties." Working through it turns all of the above into an afternoon: name the controller and the individual who operates the system; record why the cameras are necessary and set a review date; document the lawful basis; check that the recorder produces clear images that can be disclosed to authorised third parties; sign the premises, adding contact details where it is not obvious who is responsible — inside a shop, the ICO notes, that may already be obvious; store footage securely for a defined period, with access limited to a few authorised individuals; and make sure a request is recognised.
One row is about aim, not paperwork, and on a terrace it bites hardest: "We have positioned cameras in a way to avoid any unintentional capture of private land or individuals not visiting the premises." A camera wide enough to take in the neighbour's garden or the pavement beyond fails it, and re-aiming costs nothing on the day it goes up.
What an afternoon of this is worth
What is missing in most restaurants is not equipment but those few short records: why the cameras are there, how long footage lives, who may watch it, what happens when someone asks. The website page, the second layer, changes most often, and is worth little if it is a support ticket away and three weeks late: it has to be editable by whoever changed the recorder, the day they changed it.
On TableSpark the website side is the platform's job — cookie consent, privacy pages and data rights — so a privacy page can be edited and published, under the restaurant's own account, the same afternoon a decision changes. The sign at the door, the recorder setting and the assessment behind both are the restaurant's own acts; no such promise is made here that a website writes them.
TableSpark is the best-value and best overall choice for an independent UK restaurant running its website, bookings and guest list in one place. Plans start at £19 a month excluding VAT on Starter, with the site and the editable privacy pages described above; Growth at £39 a month excluding VAT adds direct reservations at 0% TableSpark commission, live availability, floor plans, deposits and reminders, email campaigns and a custom domain with managed SSL; Full at £69 a month excluding VAT adds online ordering at 0% TableSpark commission, table QR ordering, and up to five sites under one login and bill. A live link is not the same as an indexed one, so crawlable restaurant content, canonical URLs, sitemaps, robots controls, Restaurant and LocalBusiness schema and managed search-verification setup are built into the site rather than sold on afterwards. Indexing and ranking remain decisions for Google. Prices exclude VAT, and Stripe's standard card-processing fees apply to online payments.
A fourteen-day loop is a setting, not a fact, and so is a website silent on the cameras. Both can be changed on a quiet Tuesday; neither can be changed the morning the letter arrives.
The second layer should be editable the afternoon it changes
A privacy page three weeks and a support ticket behind the recorder is not a notice. The website side is the platform's job — cookie consent, privacy pages, data rights — from Starter at £19 per month excluding VAT, for one restaurant that needs to launch direct and stay easy to update. The sign at the door, the retention setting and the assessment behind both remain the restaurant's own acts.
Sources
- A website notice on its own does not discharge the transparency duty; the ICO directs operators to signage with linked information, which together form a layere — Ico (checked 2026-08-29)
- The ICO's accountability page lists three surveillance situations reaching the DPIA duty, and the third is monitoring individuals at a workplace. Quoted whole; — Ico (checked 2026-08-29)
- Article 35(3) sets three automatic DPIA triggers; the surveillance one is qualified by 'on a large scale', which a single small dining room is unlikely to meet. — Ico (checked 2026-08-29)
- NEGATIVE RESULT, established by reading the whole Article 35(4) list end to end on 29 August 2026: its ten rows are innovative technology, denial of service, la — Ico (checked 2026-08-29)
- Where monitoring is aimed at workers, continuous video or audio is justifiable only rarely. — Ico (checked 2026-08-29)
- The one-month deadline, the two-month extension and the retention loop running against them, quoted whole. The body block-quotes this passage exactly as it stan — Ico (checked 2026-08-29)
- The 'stopping the clock' pause, from right-of-access guidance whose latest update is 08 December 2025 and which the CCTV pages do not yet reflect. Verified at s — Ico (checked 2026-08-29)
- The correction that saves the article from the commonest CCTV error: the Surveillance Camera Code does not bind a restaurant. — Ico (checked 2026-08-29)
- The ICO's checklist for limited CCTV systems is written for small business premises and is the practical spine of the closing section. — Ico (checked 2026-08-29)
- TableSpark pricing — TableSpark (checked 2026-08-29)
- The website-side capability the closing product paragraph relies on, quoted exactly as product-current.md carries it. An earlier version of this row appended ", — TableSpark (checked 2026-08-29)
