Last updated: 7 September 2026
Body worn camera rules security industry: the UK compliance guide for 2026
Body worn camera rules in the UK security industry require operators to treat footage as personal data under UK GDPR, run a Data Protection Impact Assessment, licence the wearer correctly with the SIA, and follow Home Office and ICO guidance on retention, signage and access. As of 2026, 82.1% of security operatives already wear one, according to Working the Doors (2026).
Key Takeaways
- 82.1% of surveyed security operatives use a body-worn camera at work, and 96.7% of the same 184-person sample held an active SIA licence, according to Working the Doors (2026).
- The Information Commissioner's Office (ICO) treats body-worn video as personal data processing, meaning UK GDPR and the Data Protection Act 2018 both apply in full.
- A Cardiff University study cited by Radiocoms found that 90% of the public believe surveillance improves security, despite holding privacy concerns, according to Radiocoms (2026).
- The Security Industry Authority (SIA) does not issue a separate licence purely for wearing a body-worn camera — the requirement sits within the operative's existing Door Supervisor or Security Guard licence conditions.
- Pulse Operations's photo-verified patrol model captures 96.2% of checkpoints with a watermarked photo across live operations (trailing 90 days to July 2026), a different but complementary evidence layer to video — see the benchmark.
What are body worn camera rules in the security industry?
Body worn camera rules in the security industry are the combined set of legal, regulatory and licensing obligations that govern how SIA-licensed operatives — Door Supervisors and Security Guards regulated under the Private Security Industry Act 2001 — record, store and share video and audio footage captured while on duty. These rules draw on UK GDPR, the Data Protection Act 2018, the Surveillance Camera Code of Practice, and SIA licensing conditions, rather than sitting in a single dedicated statute.
There is no single "Body Worn Camera Act" in the UK. Instead, a security firm deploying cameras on Aldgate door staff or a Manchester retail park patrol team is stitching together several existing frameworks: data protection law, employment law, and sector licensing. Getting any one of these wrong — no Data Protection Impact Assessment (DPIA), no signage, footage kept too long — creates real liability, not a theoretical risk.
This is also where the security industry's evidence problem sits more broadly. A camera captures an incident. It doesn't, by itself, prove a patrol happened, a checkpoint was checked, or a contract was delivered. That's a separate evidence gap Pulse Operations addresses through photo-verified patrols — more on how the two systems complement each other below.
Do security guards need SIA approval to wear a body-worn camera?
Security guards do not need a separate SIA licence to wear a body-worn camera, but the Security Industry Authority treats camera use as something that must sit within an operative's existing licensed role and conduct standards. The SIA's own guidance on body-worn video systems confirms that cameras are a tool an already-licensed Door Supervisor or Security Guard may use, not a licensable activity in its own right.
That said, "no extra licence needed" doesn't mean "no rules apply." The SIA expects licence holders to behave professionally and lawfully at all times, and misuse of a camera — filming someone in a way that breaches data protection law, or using footage to harass rather than to evidence an incident — can still trigger licence review action. The regulator's guidance sits alongside, not instead of, the ICO's data protection requirements.
Two SIA licence categories are relevant here: the Door Supervisor licence, which covers pubs, clubs and licensed premises, and the Security Guard licence, which covers static and mobile guarding roles. Neither licence category currently has a distinct body-worn video endorsement, which is why firms need to build their own policy layer on top of licensing rather than relying on the SIA to specify camera procedure in detail.
CCTV and Public Space Surveillance (PSS) licences: when do they apply?
The SIA's CCTV (Public Space Surveillance) licence — a distinct SIA category covering the remote monitoring of surveillance systems — typically applies to control room operators watching fixed or mobile CCTV feeds live, not to the individual wearing a body camera on patrol. Where a security firm's control room actively monitors live body-worn video feeds in real time — rather than simply reviewing footage after the fact — that monitoring function may fall within PSS licensing scope, and firms should check their specific setup against current SIA guidance rather than assume either way.
What data protection law applies to body-worn cameras?
UK GDPR and the Data Protection Act 2018 apply to any body-worn camera that captures identifiable individuals, because that footage is personal data the moment a face, number plate or other identifying detail is recorded. The ICO's guidance on body worn video sets out specific expectations that sit alongside its general CCTV and video surveillance guidance.
A security firm operating body-worn cameras is a data controller. That status brings direct obligations: a lawful basis for processing (typically legitimate interests, given the security purpose), a documented retention schedule, and the ability to respond to a Subject Access Request (SAR) — a formal request under UK GDPR for an individual to see what personal data an organisation holds about them — if a member of the public asks what footage exists of them.
The Home Office, working with the ICO and the Surveillance Camera Commissioner, published national guidance specifically on this point. As Andy Marsh, Chief Constable and NPCC Lead for Body Worn Video, put it: "As the national lead for body worn video I have been working with the Home Office, the Information Commissioner and the Surveillance Camera Commissioner to produce this document on safeguarding data for BWV cameras." That document — Safeguarding Body Worn Video Data — was written primarily for policing, but the ICO applies the same underlying data protection principles to private security operators.
Is a Data Protection Impact Assessment (DPIA) mandatory?
A Data Protection Impact Assessment (DPIA) — a structured risk assessment required under UK GDPR Article 35 for processing likely to result in high risk to individuals — is strongly expected for body-worn camera deployments, because systematic monitoring of publicly accessible areas is exactly the kind of processing the ICO flags as high-risk. Most security firms deploying cameras across multiple sites should treat a DPIA as a practical necessity, not an optional extra, and document it before rollout rather than retrospectively.
The Surveillance Camera Code of Practice and the 12 guiding principles
The Home Office's Surveillance Camera Code of Practice, issued under the Protection of Freedoms Act 2012, sets out twelve guiding principles covering necessity, proportionality, transparency, and data security. It is statutory guidance for public authorities like the police, but private security operators are increasingly expected — by clients, insurers and in tender evaluations — to demonstrate they follow the same principles voluntarily.
What retention and access rules apply to body-worn footage?
Retention periods for body-worn video are not fixed by a single statute; instead, the ICO expects firms to set and justify their own retention schedule based on purpose, and to delete footage once that purpose has passed. A common approach among UK security contractors is a short default retention window — often 30 to 31 days — with footage flagged for an incident held separately and for longer, under a documented exception.
Access control matters just as much as retention length. Footage should be viewable only by authorised staff, ideally logged and auditable, because the ICO's expectation is that personal data is only accessed by those who genuinely need it. A firm that can't show who viewed a piece of footage, or when, is exposed if that footage is later disputed or subject to a SAR.
| Retention approach | Typical period | When it applies |
|---|---|---|
| Standard/non-incident footage | Short default, commonly 30–31 days | Routine patrol or shift footage with no flagged event |
| Incident-related footage | Extended, case-by-case | Assault, theft, ejection, or any footage likely needed as evidence |
| Footage requested via SAR | Retained until request resolved | Individual has requested footage of themselves under UK GDPR |
| Footage under legal hold | Retained until matter concludes | Police investigation, insurance claim, employment tribunal |
Signage and transparency obligations
Transparency is one of the ICO's core expectations for video surveillance: people in the area being recorded should generally know that recording is happening, unless a narrow lawful exception applies. For static sites this usually means visible signage at entry points; for a mobile or door supervisor role, some firms use lanyard notices, uniform patches, or a verbal notice at point of engagement where practical. Covert recording without a specific, documented justification is a high-risk approach the ICO treats with particular scrutiny.
Audio recording: a separate consideration
Recording audio alongside video raises its own privacy considerations, because continuous audio capture picks up private conversations that go well beyond the security purpose the camera exists for. Many UK security firms configure cameras to record video continuously but only activate audio at the point an incident begins, precisely to keep the processing proportionate — a principle straight out of the Surveillance Camera Code of Practice.
Body-worn cameras vs photo-verified patrols: two different evidence problems
Body-worn cameras solve one problem well: capturing what happened during an incident, in the moment, with audio and motion. They do not solve a different, equally common problem: proving that a patrol actually happened at all, that every checkpoint on a route was walked, and that a client can see delivered-vs-contracted performance without ringing the control room.
Per Pulse Operations's guide, How to prove patrols actually happened, a tag scan — NFC or QR — only tells you a phone was held near a fixed point at a moment in time. It doesn't tell you a person was genuinely present and alert, or what the area actually looked like. Tags also fail physically: painted over, ripped off, or sat somewhere with no signal. Firms comparing dedicated security patrol apps will find this proof-of-presence question sits at the centre of most buying decisions in 2026.
Pulse takes a different approach for patrol proof specifically. Every checkpoint is completed only by a mandatory watermarked photo — officer, site, GPS, time — with no tag scan step at all. As the guide puts it, the checklist for tightening patrol proof includes deciding what "proof" means per site, making photos the backbone of each patrol, watermarking every photo, capturing the state of the area rather than just a scan, logging patrols against the contract, recording incident times precisely, giving clients a live window into delivery, and being honest about gaps rather than showing a portal that always reads 100%.
| Evidence type | What it proves | What it doesn't prove | Typical use case |
|---|---|---|---|
| Body-worn camera footage | What happened during an incident | Whether routine checkpoints were walked | Incident evidence, conflict, use-of-force review |
| NFC/QR tag scan | A phone was near a tag at a given time | Presence, alertness, or area condition | Legacy patrol tracking (declining in credibility) |
| Watermarked checkpoint photo | Officer, site, GPS and time, plus the actual condition observed | Continuous coverage between checkpoints | Contract delivery proof, client reporting |
These aren't competing systems — most sites benefit from both. A body-worn camera captures the confrontation at the gate; a photo-verified checkpoint five minutes earlier proves the officer was on the correct route, at the correct time, before it happened.
This is exactly the gap the founding team hit before Pulse existed. Priority First — the London security and FM operation Pulse was built inside, always disclosed rather than presented as an arm's-length customer — ran patrols on paper sign-in sheets, jobs passed around by message, and no way to answer a client's 7am "was everything OK last night?" call with anything better than a promise. Since going live in February 2026, Priority First has run 24 sites on one login, logged more than 4,900 patrols against production data (as of July 2026), and moved from 0% to 100% of checkpoints backed by a watermarked photo. Mo Hassan, Managing Director at Priority First, put it plainly: "We used to take everyone's word for it. Now every checkpoint has a photo and the client can see it before we've finished the shift — it's changed how we win work."
How do body-worn camera rules affect tenders and client contracts?
Clients increasingly ask about body-worn camera policy at tender stage, alongside — not instead of — SIA licensing and BS 7858 vetting evidence, because buyers now expect proof of governance, not just a claim that policies exist. Per Pulse Operations's guide, How to win your next security tender, most formal tenders are decided on a published price/quality split, commonly somewhere between 60/40 and 30/70, and public-sector buyers now operate under the Procurement Act 2023 regime with its emphasis on transparency.
Screening should be evidenced to BS 7858 — the British Standard for security screening of personnel — with records that show it per person, not a policy that merely asserts it. A body-worn camera policy sits in the same category: a paragraph in a method statement claiming "all officers are camera-equipped and GDPR compliant" scores nothing against an evaluator who has seen that exact sentence in every other bid. As Mo Hassan, Founder of Pulse, puts it: "Every bid says professional, SIA-licensed, 24/7 control room — so none of it scores. Walk in with evidence instead: photo-verified patrols, delivered-vs-contract numbers, and a portal login the evaluators can open themselves. Proof the incumbent can't match changes the conversation."
For publicly accessible venues, buyers may also ask about readiness under the Terrorism (Protection of Premises) Act 2026 — commonly known as Martyn's Law — which is a separate but related compliance thread. Pulse's compliance runway tracks SIA licensing, BS 7858, DBS checks, right-to-work status, training records and Martyn's Law readiness on one expiries timeline, so a tender response can point to a live system rather than a static spreadsheet.
Your body-worn camera rules checklist
- Confirm every camera-wearing operative holds the correct SIA licence — Door Supervisor or Security Guard — for their role, before deployment.
- Run a Data Protection Impact Assessment (DPIA) covering the specific sites and use cases, and document it before rollout.
- Set a documented retention schedule — a common default is 30–31 days for non-incident footage, with a separate extended-retention path for flagged incidents.
- Install clear signage or notices at fixed sites, and brief mobile officers on verbal notice practice where signage isn't feasible.
- Restrict and log footage access to named, authorised staff only, and be ready to respond to a Subject Access Request.
- Decide the audio policy explicitly — continuous audio versus incident-triggered audio — and write it into the same policy document as video.
- Cross-reference camera policy against the Surveillance Camera Code of Practice's 12 principles, even though compliance is currently voluntary for private operators.
- Separate the incident-evidence question (cameras) from the patrol-proof question (checkpoints) — and consider whether watermarked, photo-verified checkpoints via Pulse Operations's mobile patrol service close the second gap cameras were never designed to solve.
FAQ
Is it legal for security guards to wear body cameras in the UK?
Yes, it is legal for SIA-licensed security guards to wear body cameras in the UK, provided the deployment complies with UK GDPR, the Data Protection Act 2018 and, where relevant, the principles in the Home Office's Surveillance Camera Code of Practice. There is no law banning the equipment; the legal obligations sit in how footage is captured, stored and accessed, not in the wearing of the camera itself.
Do security guards need an SIA licence to use body-worn cameras?
Security guards need their existing Door Supervisor or Security Guard SIA licence to be valid and current, but there is no separate SIA licence specifically for wearing a body-worn camera. The SIA's guidance on body-worn video systems confirms this sits within the operative's existing licensed conduct, not as a distinct licensable activity.
What SIA licence is required to monitor body-worn camera footage remotely?
Real-time remote monitoring of live body-worn video feeds may fall within the scope of the SIA's CCTV (Public Space Surveillance) licence, which is a distinct category from Door Supervisor or Security Guard licensing. Firms operating a control room that actively watches live camera feeds, rather than reviewing recorded footage after the event, should check their specific setup against current SIA guidance.
What data protection laws apply to body-worn cameras in the security industry?
UK GDPR and the Data Protection Act 2018 both apply, because footage capturing identifiable individuals counts as personal data from the moment of recording. The ICO's dedicated body worn video guidance sets out how these obligations apply specifically to camera-based recording, alongside the ICO's general CCTV and surveillance guidance.
Do security operatives need a DPIA before using body cameras?
A Data Protection Impact Assessment is strongly expected, though not automatically mandatory in every single case, because systematic body-worn recording in publicly accessible areas typically meets the UK GDPR threshold for "likely high risk" processing. Most multi-site security operators should complete and document a DPIA before rollout as standard practice.
How long can body-worn camera footage be legally retained?
There is no single legally fixed retention period; the ICO expects firms to set and justify their own schedule based on purpose. A common industry approach uses a short default window, often around 30–31 days, for routine footage, with a separate, longer, documented retention path for footage relating to a flagged incident, legal hold, or Subject Access Request.
Do businesses need to display signage when security staff wear body cameras?
Transparency is a core ICO expectation for video surveillance, so visible signage at fixed sites, or clear verbal notice for mobile roles where signage isn't practical, is generally required unless a specific, documented lawful exception for covert recording applies. Covert use without justification carries significant compliance risk.
What is the Surveillance Camera Code of Practice, and does it apply to private security firms?
The Surveillance Camera Code of Practice is Home Office statutory guidance, issued under the Protection of Freedoms Act 2012, setting out 12 guiding principles for surveillance camera use including necessity, proportionality and data security. It is legally binding on public authorities like the police rather than private security firms directly, but many clients and tender evaluators now expect private operators to demonstrate voluntary alignment with the same principles.
Securing your patrol evidence alongside body-worn camera policy with Pulse Operations
Getting body-worn camera rules right solves the incident-evidence problem — but it leaves the separate question of proving routine patrols actually happened, which is where most client disputes and lost tenders actually originate. Pulse Operations builds that second layer: every checkpoint on a route is completed only by a mandatory watermarked photo — officer, site, GPS, time — with no tag scans by design, so a client can see delivered-vs-contract performance in their own branded portal rather than taking a control room's word for it.
Across live operations on Pulse, 96.2% of checkpoints carry a watermarked photo, tracked over a trailing 90-day window to July 2026 — see the full benchmark for methodology. The same architecture that built this — a hash-chained (SHA-256), tamper-evident audit log with a built-in integrity check, an offline-first officer app with self-healing sync, and UK-built, UK-hosted infrastructure with enforced tenant isolation — grew out of running Priority First's own 24-site London operation, not a product roadmap built in isolation from real shifts.
If your firm is reviewing camera policy, patrol proof, or both ahead of a tender or client audit, book a look at Pulse's photo-verified patrol system, see published pricing at pulse-operations.co.uk/pricing, or compare Pulse against TrackTik, Silvertrac and Guardhouse at /compare.
Related Reading
- Security Site Induction Checklist UK: Full 2026 Guide
- Guardhouse Alternative 2026: Best UK Options Compared
- SmartTask Alternative 2026: Best Options Compared
- Integrated Security & FM Software UK | Pulse Operations
