Vehicle CCTV and in-cab cameras: who can actually watch the footage?

Cameras in HGV cabs have become routine — forward-facing for insurance and incident evidence, driver-facing for behaviour and safety, sometimes both. What's much less routine is a proper answer to three questions every operator running them should be able to answer without hesitation: who is allowed to watch that footage, what reason do they need, and who's checking that access isn't being misused. Get this wrong and the exposure isn't hypothetical — it's a live regulatory risk, separate from and in addition to anything DVSA cares about.
It's personal data the moment someone's identifiable
The starting point is simple and non-negotiable: any footage capturing an identifiable person — a driver's face, a number plate, a pedestrian caught on a forward-facing camera — is personal data under UK GDPR, and the moment you're recording, storing or reviewing it, you're processing personal data as a matter of law. That's true whether it's one van or a hundred-strong fleet, and it applies to forward-facing dashcams and driver-facing in-cab cameras alike.
The Information Commissioner's Office is direct about the threshold: you can use a camera in a business vehicle, but only if you can justify it. There's no default entitlement to record just because the technology is cheap and available.
What counts as a valid reason
You need a lawful basis under UK GDPR before a camera goes in, not after. In practice, most fleet operators rely on legitimate interests — driver safety, incident evidence, protection against fraudulent claims — but relying on that basis isn't a rubber stamp. It has to be documented, genuinely weighed against the intrusion into people's privacy, and revisited if the purpose changes.
That last point catches operators out more than any other. If cameras go in for insurance evidence, and six months later the footage starts getting pulled for driver performance reviews or disciplinary hearings, that's a different purpose — and the ICO is explicit that a change of purpose means updating your policy and telling staff before you start using it that way, not after.
Audio recording is treated as a separate, more intrusive step again. The ICO's own guidance says audio should be off by default and only switched on in genuinely exceptional circumstances, such as a specific threat to personal safety — it isn't something to leave running as standard alongside video.
In-cab, driver-facing cameras are workplace monitoring — full stop
This is where operators most often miss a step. A driver-facing camera isn't just a vehicle safety device; it's monitoring an employee doing their job, and the ICO's employee monitoring guidance applies to it in exactly the same way it would apply to keystroke logging or call recording in an office. That guidance requires a documented, proportionate justification, transparency with the people being monitored before it starts, and — where monitoring is more than occasional — a Data Protection Impact Assessment.
Consent is generally the wrong lawful basis to reach for here. Because of the imbalance of power in an employment relationship, the ICO is clear that consent is rarely appropriate as the basis for monitoring workers — an employee can't meaningfully refuse a camera their job depends on, so "they agreed to it" doesn't carry the legal weight operators sometimes assume it does. Legitimate interests, properly documented and balanced, is the more realistic route, alongside being upfront with drivers about exactly what's recorded, when, and why.
The same logic extends to personal use. If a vehicle is ever used outside work — commuting, an occasional personal errand — continuous monitoring during that time is much harder to justify, and the sensible position, reflected in ICO guidance, is that cameras should generally be switched off outside working hours where a vehicle sees any private use at all.
The personal laptop problem
Here's a scenario worth being honest about, because it's genuinely common and rarely thought through: a manager investigating an incident pulls the footage off the vehicle's hard drive onto their own personal laptop, so they can review it at their desk or take it home to write up the report. It feels harmless — they're an authorised person, investigating a real incident, for a legitimate reason.
It's still a significant gap, and worth treating as one. Being authorised to view footage for an investigation is not the same as being authorised to copy it onto a device the business doesn't control. A personal laptop sits entirely outside the company's oversight — no visibility of its security patching, its password strength, whether it automatically backs up to a personal cloud account, who else has access to it, or what happens to that copy after the investigation closes. The business can delete the original from its own system on schedule and still have no idea a second copy exists indefinitely on someone's home computer.
This directly undermines the access control a proper policy is meant to provide. A named list of authorised viewers and a logged, controlled system means very little if footage can simply be dragged onto whatever device is closest to hand. The safer route is straightforward: extracts for an investigation should go onto company-controlled, encrypted storage with its own access log and deletion date — never a personal laptop, personal email, or personal cloud account — and the policy should say so explicitly, because without that instruction, well-meaning managers will keep doing exactly this.
"It's forward-facing" isn't always true
A forward-facing camera mounted in the cab — high near the top of the screen or low near the dash — can catch a clear reflection of the driver's face in the windscreen, depending on the angle, the glass's curve, and the cabin lighting. This isn't a rare fluke or a stretch: a US patent (US20140146152A1) describes exactly this as a deliberate design technique — a small rearward-facing mirror fitted to a forward-facing camera, positioned in the unused part of the frame, specifically to reflect the driver's face into the same recording without needing a second camera. Whether or not that exact design has made it into a specific product on the market, it confirms the underlying phenomenon is well understood and, in some cases, engineered on purpose — not something an operator can reasonably assume won't happen with their own setup.
The label on the camera doesn't change what it's actually recording. UK GDPR doesn't ask what a camera was designed to do or which way its housing points — it asks whether an identifiable person appears in the footage. If a "forward-facing, road-evidence-only" camera is reliably capturing the driver's face via a windscreen reflection, it's processing exactly the same personal data as an in-cab camera would, and it needs to be treated that way: the driver-facing justification, transparency and safeguards apply, not the lighter approach an operator might assume covers a purely outward-looking device.
This matters practically as well as legally. If drivers have been told the camera only watches the road, and it's quietly also capturing them clearly, that's a real gap between what's been disclosed and what's actually happening — exactly the kind of mismatch that undermines trust and falls foul of the transparency duty. Worth checking the actual mounting and angle during installation, not just trusting the spec sheet, and adjusting the position if a reflection is catching the driver more clearly than the system was ever meant to.
What if that footage clearly shows a driver on their phone? It's worth thinking through, because it's a genuinely realistic scenario: a company believes its forward-facing camera can't see the driver, tells staff exactly that, and then someone reviewing an incident notices the reflection shows a driver clearly holding a phone. Could that footage be used to discipline or dismiss them?
Technically, yes, the footage shows what it shows. But relying on it is legally fraught for the company on two separate fronts. First, this is undisclosed monitoring — the company said the camera couldn't see the driver, and it demonstrably could. That sits close to what the ICO treats as covert monitoring, which is only lawful in narrow circumstances: a genuine, documented suspicion of specific wrongdoing, where advance notice would defeat the investigation. A capability nobody was told about, that just happened to catch someone while being used for something else, doesn't meet that bar — it reads as routine surveillance that was never disclosed, not a targeted, justified investigation.
Second, and this is the part that catches employers out, an employment tribunal doesn't simply throw out evidence because it was obtained improperly, but it will scrutinise whether the employer acted reasonably in obtaining it — and undisclosed, disproportionate monitoring can render a dismissal procedurally unfair even where the misconduct genuinely happened. A real case bears this out: the European Court of Human Rights upheld covert-footage dismissals of supermarket staff caught stealing, but only because there was a specific, documented suspicion behind the covert monitoring in the first place — not a blanket capability operating on everyone, undisclosed, that happened to catch something useful.
The honest fix, if a company discovers its camera can see the driver, isn't to quietly start relying on it. It's to stop, update the policy to disclose the capability honestly, properly assess the driver-facing use with the same rigour as any other in-cab camera, and only then treat future footage as usable evidence — not retrofit justification onto something that was never disclosed in the first place.
Who's actually allowed to watch it
This is the part that rarely makes it into a written policy at all, and it's the one worth testing on any audit. Access to footage has to be restricted to people who genuinely need it for the stated purpose — not "anyone in the transport office who's curious," and not a blanket forward to a manager who happens to ask. The ICO's guidance on video surveillance is explicit that operators must be clear about who is responsible for footage, that access must be carefully controlled, and that only authorised personnel should be able to view it.
In practice, a defensible system has:
A named list of roles (not necessarily individuals) authorised to access footage, tied to the specific, documented purpose it was collected for
A record of who accessed which footage, when, and why — an access log, not just a locked system nobody checks
A clear route for a driver to know what's recorded, how to raise a concern, and how to make a subject access request for footage of themselves
Footage of anyone other than the person requesting it — a colleague, a member of the public — properly redacted before it's shared or disclosed, typically by blurring faces or plates
Everyone captured on camera has rights, and they can ask for the footage
Anyone identifiable in the footage — including the driver themselves — has a right of access under UK GDPR, and can submit a subject access request for a copy. The operator generally has one month to respond. This applies even to a driver requesting footage of their own shift, and it's a request operators need to be able to recognise and action properly, including deciding how to handle footage where other identifiable people also appear.
How long you're allowed to keep it
There's no fixed legal retention period, but "just in case" isn't a lawful basis for holding footage indefinitely. The ICO's own guidance for small businesses is blunt: several weeks of footage kept on the off-chance it might be useful is probably too long. Where a business genuinely uses footage to evidence incidents for insurance purposes, and nothing has happened, the sensible default is deletion within roughly a week unless there's a specific reason — an incident, a claim, a complaint — to retain it longer. Retention periods should be set deliberately and documented, not left to whatever the hardware happens to do by default.
The fee you probably need to be paying
If any vehicle in the fleet carries a dashcam or CCTV system, the business needs to be registered with the ICO and paying the data protection fee — commonly £52 a year for most small operators. It's a business responsibility, not something that falls on an individual driver, and it's a quick, cheap thing to overlook entirely.
What this looks like on audit
None of this sits neatly under a single line in the DVSA framework, because it's fundamentally a data protection matter rather than a roadworthiness one — but it consistently comes up alongside driver management and health and safety policy areas, because a camera system without a proper access and retention policy behind it is exactly the kind of gap that looks fine until someone actually asks the operator to produce one. On audit, the questions worth being able to answer without hesitation are: what's the documented lawful basis, who specifically can access footage and how is that controlled, how long is it kept and why, and could the business produce a subject access response inside a month if a driver asked for their own footage tomorrow.
Operators who can answer all of that cleanly have nothing to worry about. Operators who've simply had cameras fitted because "everyone's got them now" usually can't — and that's a genuine, separate regulatory exposure sitting alongside the DVSA side of the business.
If you'd like your vehicle camera policy reviewed as part of a full compliance audit, that's exactly what we do. Get in touch at enquiries@ukfleetaudit.co.uk.
References
Astrid Data Protection (2022) GDPR and CCTV cameras in vehicles. Available at: https://weareastrid.co.uk/gdpr-and-cctv-cameras-in-vehicles/ (Accessed: 19 August 2026).
Bryan Cave Leighton Paisner (2023) Watching employers watching their workers: UK data protection authority issues updated workplace monitoring guidance. Available at: https://www.bclplaw.com/en-US/events-insights-news/watching-employers-watching-their-workers.html (Accessed: 19 August 2026).
DavidsonMorris (2026) Using CCTV as Evidence at a Disciplinary. Available at: https://www.davidsonmorris.com/using-cctv-evidence-at-a-disciplinary-uk/ (Accessed: 19 August 2026).
DPO Centre (2026) Bring Your Own Device (BYOD) risk management guide. Available at: https://www.dpocentre.com/blog/bring-your-own-device-byod-risk-guide/ (Accessed: 19 August 2026).
Google Patents (2014) US20140146152A1 — Driver View Adapter for Forward Looking Camera. Available at: https://patents.google.com/patent/US20140146152 (Accessed: 19 August 2026).
Local Government Lawyer (2018) Covert surveillance of employees. Available at: https://www.localgovernmentlawyer.co.uk/employment/312-employment-features/37137-covert-surveillance-of-employees (Accessed: 19 August 2026).
Information Commissioner's Office (2025) Dashcams and UK GDPR: what small businesses need to know. Available at: https://ico.org.uk/for-organisations/advice-for-small-organisations/cctv-and-dashcams/dashcams-and-uk-gdpr-what-small-businesses-need-to-know/ (Accessed: 19 August 2026).
Information Commissioner's Office (no date) Surveillance in vehicles. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/cctv-and-video-surveillance/guidance-on-video-surveillance-including-cctv/additional-considerations-for-technologies-other-than-cctv/surveillance-in-vehicles/ (Accessed: 19 August 2026).
Information Commissioner's Office (2023) Data protection and monitoring workers. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/data-protection-and-monitoring-workers/ (Accessed: 19 August 2026).
URM Consulting (2024) Data protection considerations for monitoring employees. Available at: https://www.urmconsulting.com/blog/data-protection-considerations-for-monitoring-employees (Accessed: 19 August 2026).





Comments