4 CCTV footage retention is one of those decisions that looks simple, “keep it for 30 days”, until someone asks why 30 and not 7, or 90, or a year. The answer shapes privacy compliance, investigative capability and storage cost all at once. Keep footage too briefly and incidents reported late cannot be investigated. Keep it too long and an organization may be holding personal data without justification while paying for storage it does not need. This article explains what drives CCTV footage retention, how European privacy guidance approaches it, how sector rules and evidence needs fit in, who should own the decision and what retention means for surveillance storage. It is general information, not legal advice. For the storage architecture side, see our hub on video surveillance storage. There is rarely a single legal number In most jurisdictions, general CCTV use is not governed by a fixed retention period. Instead, data protection law sets principles, and organizations must choose a period they can justify. Sector-specific rules sometimes set minimums, and evidence requirements can extend retention for specific footage. The result is that retention is usually a policy decision, documented and defended by the organization itself. European data protection: storage limitation In the EU and the UK, footage that identifies people is personal data. GDPR requires that personal data be kept no longer than necessary for the purposes for which it is processed, which is the storage limitation principle. For CCTV, that means the retention period must be linked to the purpose of the cameras. The European Data Protection Board’s guidelines on processing personal data through video devices, adopted in 2019, state that in most cases footage should be erased after a few days, for example where the purpose is detecting vandalism. The final guidelines also indicate that the longer the storage period, especially beyond 72 hours, the more justification is needed for its legitimacy and necessity. Some EU member states have national rules on storage periods that add to this guidance. In the UK, the Information Commissioner’s Office takes a similar principle-based approach: there is no fixed period, and organizations should keep footage only as long as needed for their purpose, review retention regularly and delete footage securely. Public authorities in England and Wales also have the Surveillance Camera Code of Practice, which emphasizes storing no more than is strictly required. Elsewhere In the United States, there is generally no federal retention period for private or municipal CCTV. Retention may be set by state or local public records laws for government agencies, by sector regulators for certain industries (for example, gaming and some licensed businesses in certain states set minimum retention for surveillance video) and by contracts, insurance requirements or litigation risk. Other countries mix privacy principles with sector rules in their own ways. What drives a sensible retention period Purpose Cameras for detecting vandalism in a car park may justify a short period. Cameras in a transit system, prison, hospital or high-security facility may justify longer periods because incidents are reported later or investigations take longer. Time to discover and report incidents If incidents are typically reported within a few days, a short period may be enough. If complaints or claims commonly arrive weeks later, such as slip-and-fall claims or complaints about staff conduct, a longer period may be justified. Sector rules Some regulators set minimum periods for specific sectors. Where they apply, they set the floor. Investigation and evidence needs Footage relevant to an incident should be preserved beyond normal retention, separately from the routine cycle, for as long as the investigation, prosecution or claim requires. Public records obligations For government bodies, records laws may classify some footage as public records with their own schedules. Cost and capacity Storage cost should not drive retention below what the purpose requires, but it is a legitimate consideration when choosing between two justifiable periods. Routine retention vs preserved footage Good practice separates two categories: Routine footage, recorded continuously and deleted automatically when the retention period expires. Preserved footage, clips identified as relevant to an incident, request or legal matter, exported or protected and kept for as long as needed. This approach allows short routine retention, which supports privacy, while ensuring evidence is not lost. Preserved footage should be logged, access-controlled and protected from alteration. The principles overlap with digital evidence chain of custody. Who decides Retention is not purely an IT or security decision. Responsibilities typically sit with: The data controller, usually the organization operating the cameras, which is accountable for justifying the period. The data protection officer, where one exists, who advises on compliance and reviews the justification. Security operations, who understand how footage is used and how quickly incidents are reported. Legal counsel, who advise on claims, litigation holds and sector rules. Records management, for public bodies subject to records laws. IT and storage teams, who implement retention in the VMS and storage and report on capacity. A data protection impact assessment is often required for large-scale surveillance and is a natural place to document the retention decision. Documenting the decision A defensible retention policy usually records: The purpose of each camera group. The retention period for routine footage and the reasoning behind it. The process for preserving footage for incidents, requests and legal holds. Who can access footage and how access is logged. How deletion is carried out and verified. When the policy will be reviewed. Subject access and disclosure requests Under GDPR, individuals can request copies of footage in which they appear. Short retention reduces the volume of such requests that can be fulfilled, which is acceptable as long as retention is justified. When a request arrives, relevant footage should be preserved until the request is handled. Requests from police or courts follow their own procedures, and disclosed footage should be logged. What retention means for storage Retention multiplies storage capacity directly. Doubling retention doubles capacity for routine footage. Practical implications include: Capacity planning must use the retention period for each camera group. Automated deletion at scale must be reliable, with capacity reclaimed efficiently. Preserved footage needs separate, protected storage, ideally immutable for the preservation period. Secure deletion should be verifiable. data deletion verification covers how to evidence it. Different retention per group requires storage and VMS configuration that support multiple policies. Reviewing retention over time Retention decisions should not be set once and forgotten. Useful triggers for review include changes in camera purpose, new sites, new regulations or guidance, a pattern of incidents reported after footage was deleted and changes in storage platforms. Reviewing how often preserved footage is requested, and how long after the event, gives evidence for whether the routine period is right. If almost all requests arrive within a week, a 90-day routine period is hard to justify; if many arrive after a month, a very short period may be undermining investigations. Common mistakes Choosing a period by habit, such as 30 days, without documenting why. Keeping footage indefinitely because deletion was never configured. Failing to preserve footage when an incident is reported, so it is overwritten. Extending retention for all cameras because of a few high-risk locations. Storing preserved evidence on the same rolling storage as routine footage. Checklist: CCTV footage retention Define the purpose of each camera group. Check applicable data protection law, guidance and sector rules. Set routine retention per group, as short as the purpose allows, and document the reasoning. Establish a preservation process for incidents, requests and legal holds. Assign ownership across controller, DPO, security, legal and IT. Configure automated deletion and verify it works. Protect preserved footage with immutability and logged access. Size storage for retention per group plus preserved footage. Review the policy at least annually. Putting it together CCTV footage retention is usually a justified policy choice rather than a fixed legal number. European guidance points toward short periods, often days, with longer retention needing stronger justification; sector rules and evidence needs can set floors or extend specific footage. Separate routine footage from preserved evidence, document the reasoning, involve the right people and configure storage to delete reliably and protect what must be kept. That approach balances privacy, investigations and cost. Frequently asked questions How long should CCTV footage be kept? There is usually no single legal period. Under GDPR, footage should be kept no longer than necessary for its purpose, and EDPB guidance suggests a few days in most cases, with longer periods needing more justification. Is 30 days a legal requirement for CCTV? Not generally. Thirty days is a common practice in some places, but organizations must justify whatever period they choose. Who decides CCTV retention? The organization operating the cameras, as data controller, with input from its DPO, security, legal, records and IT teams. What happens to footage needed as evidence? It should be preserved separately from routine footage, protected from alteration and kept as long as the investigation or legal matter requires. Does longer retention increase storage costs? Yes, routine footage storage scales directly with retention, so doubling retention roughly doubles capacity for those cameras. Further reading Video surveillance storage CCTV storage calculation VMS archive to S3 object storage NVRs vs centralized storage GDPR data storage requirements