← Back to Regulatory Updates

Regulatory Update • July 2026

ICO Publishes Guidance on Using Data to Protect Businesses from Crime

Published: 3 July 2026 Topic: Business Crime / CCTV / UK GDPR Source: ICO Guidance

The ICO has published practical guidance explaining how businesses can use personal information to help protect staff, customers and premises from crime.

The guidance is especially relevant for organisations using CCTV, incident records or information sharing to manage risks such as theft, abuse, anti-social behaviour and staff safety concerns.

Reading time 2 minutes

What changed

The ICO has published practical guidance explaining how businesses can use personal information to help protect staff, customers and premises from crime.

The guidance is aimed particularly at small businesses dealing with issues such as theft, violence towards staff, aggressive behaviour and other crime-related risks. It explains how data protection law can support the lawful use of information, including CCTV footage, incident records and information sharing, where this is done fairly, proportionately and with appropriate safeguards.

Can businesses use personal data to prevent crime?

Yes. Data protection law does not stop businesses from using personal information to protect people, premises or property. The key is to be clear about the purpose, use only what is necessary, keep information secure, limit access and avoid using intrusive measures where a less intrusive option would work.

Why this matters

Many small businesses worry that data protection law prevents them from taking practical steps to protect their premises or staff. The ICO’s guidance makes clear that the law can give businesses a structured way to use information for crime prevention, rather than acting as a barrier.

This is relevant for any organisation using CCTV, keeping incident logs, sharing information about crime risks, or considering more intrusive tools such as facial recognition. Businesses still need to think carefully about fairness, transparency, retention, access controls and whether the level of monitoring is proportionate. For wider updates across privacy, data protection and compliance, see our Regulatory Updates page.

What organisations should do

Organisations should review whether their crime-prevention data use is clear, proportionate and properly documented.

  • Check whether CCTV, incident records or other monitoring tools have a clear purpose.
  • Use clear signage and privacy information where CCTV or similar monitoring is in place.
  • Limit access to footage, incident logs and crime-related records to people who need it.
  • Set retention periods so information is not kept for longer than necessary.
  • Review when information can be shared with staff, police, insurers, landlords or neighbouring businesses.
  • Be cautious with intrusive tools such as facial recognition, which are likely to require stronger justification and safeguards.
  • Keep simple records explaining why information is used, who can access it and how long it is kept.

Practical takeaway

Data protection law does not prevent businesses from protecting staff, customers and premises from crime. It does mean that CCTV, incident records and information sharing should be purposeful, proportionate, secure and explained clearly.

Grounded in

ICO guidance on how data protection law can help businesses protect themselves from crime, including the lawful use of personal information, CCTV footage, information sharing and the careful use of more intrusive technologies such as facial recognition.

Sources

Future Implementation Support Waitlist