CCTV Law & Data Protection
20 free practice questions with explanations
PassNova has 20 free SIA CCTV Operator practice questions on CCTV Law & Data Protection, each with a clear explanation. Practise them in the browser with instant feedback — 100% free, no sign-up, on any device. Updated for 2026.
CCTV Law & Data Protection: example questions & answers
20 worked examples with answers and explanations below. Practise them in the browser with instant feedback on every answer.
Which UK legislation is the primary framework for protecting personal data collected by CCTV systems?
- ACCTV Directive
- BUK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018✓
- CThe Human Rights Act 1998, which is the only statute governing image capture
- DPrivacy Regulation Act
Answer: UK GDPR and the Data Protection Act 2018 are the primary UK frameworks governing personal data collection and processing, including CCTV footage.
Under UK GDPR, what is the primary principle organisations must follow when processing personal data via CCTV?
- AData should be processed fairly, transparently, and lawfully✓
- BNo consent is ever needed
- CCollect as much data as possible so that nothing useful is ever missed
- DData captured on private property becomes the organisation's own property
Answer: UK GDPR requires that personal data is processed fairly, transparently, and for lawful purposes - a core UK GDPR principle.
What is the primary purpose of the Surveillance Camera Code of Practice?
- ATo ban all CCTV systems
- BTo set manufacturing standards that camera equipment must meet before sale
- CTo provide guidance on proportionate and effective CCTV use✓
- DTo require all CCTV systems to record sound alongside the video image
Answer: The Surveillance Camera Code of Practice provides guidance on using CCTV proportionately and effectively while respecting privacy rights.
Which principle of the Surveillance Camera Code of Practice states that CCTV use must be necessary and not excessive?
- ALegality
- BAccountability
- CTransparency
- DProportionality✓
Answer: Proportionality is the principle ensuring CCTV systems are necessary, not excessive, and proportionate to the identified problem.
Under UK GDPR, individuals have the right to request information about personal data held about them. What is this called?
- AA Data Access Request submitted to the ICO
- BFreedom of Information request
- CSubject Access Request (SAR)✓
- DA Privacy Notification served on the data controller
Answer: A Subject Access Request (SAR) is an individual's right under UK GDPR to access personal data an organisation holds about them.
What is the time limit for responding to a Subject Access Request under UK GDPR?
- ASeven days from receipt of the request
- BFourteen days from receipt of the request
- CForty-five days from receipt of the request
- DOne calendar month✓
Answer: Organisations must respond to a Subject Access Request (SAR) within one calendar month of receipt under UK GDPR - not a fixed 30 days. A calendar month runs to the same date in the next month, so it can actually be 28-31 days depending on when the request was received; this is a common point of confusion the ICO specifically clarifies in its guidance.
Which role within an organisation is responsible for ensuring UK GDPR compliance with CCTV systems?
- AOnly the IT department, because the system runs on the corporate network
- BData Protection Officer (DPO) and/or Senior Management✓
- CThe CCTV operator alone, as the person who views the recorded images
- DExternal contractors
Answer: The Data Protection Officer (DPO) and senior management share responsibility for ensuring UK GDPR compliance across the organisation.
Under the Data Protection Act 2018, which legal basis might justify continuous CCTV monitoring in a private business premises?
- AMarketing purposes
- BGeneral curiosity
- CPublic interest
- DLegitimate business interests (e.g., security) - if balanced against privacy rights✓
Answer: A legitimate business interest (such as protecting property and employees) can justify CCTV, provided it's balanced against privacy rights.
What must organisations display at CCTV-monitored locations under UK GDPR transparency requirements?
- ASignage at the main entrances only, with no need to name the operator
- BCCTV is optional
- CCovert monitoring is allowed with no signage, as long as footage is deleted weekly
- DA CCTV in operation notice with organisation contact details✓
Answer: UK GDPR requires visible CCTV notices with organisation details to inform individuals that monitoring is taking place.
Which type of CCTV is generally considered intrusive and requires strong justification under UK GDPR?
- AMonitoring toilet facilities or private dressing areas✓
- BMonitoring public parking areas
- CMonitoring building entrances used by staff and visitors during opening hours
- DMonitoring shops
Answer: CCTV in private areas like toilets and dressing rooms is considered highly intrusive and rarely justifiable.
Under the Surveillance Camera Code of Practice, what should organisations do before installing a CCTV system?
- AInstall the system immediately and deal with any privacy concerns afterwards
- BOnly notify the ICO
- CObtain written permission from the local police before any camera is fitted
- DConduct a Privacy Impact Assessment (PIA)✓
Answer: A Privacy Impact Assessment should be conducted to justify CCTV necessity and assess privacy implications.
What is the Information Commissioner's Office (ICO) role regarding CCTV systems?
- AOperates all CCTV systems
- BApproves and licenses every CCTV installation before it may be switched on
- CEnforces data protection law and provides guidance on CCTV compliance✓
- DDeletes CCTV footage
Answer: The ICO is the UK's independent authority for data protection and enforces UK GDPR and DPA 2018 compliance.
Can CCTV operators access and view footage containing personal data of others outside their duties?
- AIt depends on the shift time, with wider access permitted at night
- BNo - access must be limited to lawful, job-related purposes✓
- CYes, freely
- DOnly with verbal permission from a colleague in the same control room
Answer: CCTV operators must only access footage for legitimate work purposes; unauthorised access is a data protection breach.
How long should CCTV footage typically be retained before deletion?
- AAs determined by a retention policy based on legitimate purpose✓
- BOne week for every system, regardless of the purpose of the recording
- CForever
- DOnly while incidents are still occurring on site, then deleted at once
Answer: Retention periods should be set according to a documented policy reflecting the purpose of monitoring - not indefinitely.
Under UK GDPR, if CCTV footage inadvertently captures an individual's sensitive personal data, what must occur?
- AIt must be deleted within 24 hours
- BThe data can be used freely
- CPolice must be notified immediately
- DAppropriate measures should be in place to minimise capture and secure the data✓
Answer: Data minimisation and security measures should prevent or minimise capture of sensitive personal data.
A CCTV recording containing personal data is lost. What does UK GDPR require?
- ATell the ICO within 72 hours, and tell those affected only if the risk to them is high✓
- BTell the ICO only if the risk is high, and tell those affected in every case
- CTell the ICO within 30 days, and tell those affected at the same time
- DTell those affected within 72 hours; the ICO only needs an annual summary
Answer: Two different tests, and they are easy to get the wrong way round. The ICO must be told within 72 hours of you becoming aware, unless the breach is unlikely to result in any risk — a low threshold, so most breaches are reportable. The people affected are told without undue delay only where there is a HIGH risk to their rights and freedoms, which is a higher bar. If the recording was securely encrypted you may not need to tell them at all.
When can CCTV footage be shared with third parties such as the police?
- AAlways, without restriction, because footage is the operator's own record
- BOnly for legitimate legal purposes and with appropriate safeguards✓
- CNever
- DOnly if they pay for it
Answer: CCTV footage can be shared with third parties (including police) for legitimate purposes like criminal investigations, with appropriate safeguards.
Under the Surveillance Camera Code of Practice, which principle requires that CCTV operators be trained and accountable?
- ANecessity
- BLegality
- CAccountability and Competency✓
- DTransparency
Answer: Accountability and Competency is the principle ensuring operators are properly trained and their actions are documented and reviewable.
What must an organisation document to demonstrate UK GDPR compliance with CCTV systems?
- ANothing is required
- BOnly camera locations
- CA Records of Processing Activities (RoPA) documenting purpose, data, retention, and safeguards✓
- DEquipment brand only
Answer: Organisations must maintain Records of Processing Activities documenting CCTV purpose, data processed, retention, and security measures.
Under UK law, can CCTV systems legitimately monitor employees in break rooms or toilets?
- ANo - these are private areas where monitoring is rarely justified✓
- BYes, always
- COnly in retail settings
- DOnly if secret cameras are used and the recordings reviewed by managers
Answer: CCTV in private areas like break rooms and toilets cannot be justified as they breach reasonable privacy expectations.