Skip to main content
Safety Solutions TrainingSafety Solutions Training

Cameras, evidence and data

Body-worn cameras at work

A practical UK authority guide for organisations considering or using body-worn video with specialist, public-facing, security, enforcement, care, housing, lone-working or frontline staff.

Practical recommendationNo obligationUK-wide delivery

Body-worn camera used in a workplace setting

Practical recommendationNo obligationUK-wide delivery

Decision before purchase

Start with the risk and the purpose, not the camera

Record the problem you are trying to solve, the evidence for that problem and why less intrusive controls are insufficient. A vendor demonstration is not a necessity assessment.

1 · Problem

What specific harm or evidence gap exists?

Use incident data, staff consultation, complaints and risk assessments. Avoid broad aims such as “for safety”.

2 · Alternatives

Could a less intrusive control work?

Test staffing, barriers, room design, communications, fixed CCTV, alarms, supervision and withdrawal arrangements.

3 · Proportionality

Where would recording be justified?

Compare the likely benefit with intrusion, unequal impact, location, audio capture and effects on vulnerable people.

4 · Readiness

Can you control the footage from recording to deletion?

Do not deploy until policy, DPIA, privacy information, training, access, storage, redaction, deletion and incident processes work.

Do not deploy yet if:

Nobody owns the footage; the lawful basis is unclear; staff can freely replay or delete clips; the vendor cannot export an authentic original; retention is “as long as storage allows”; or the organisation cannot answer a subject access request without exposing other people.

Deployment rules

Write the operational rules before issuing devices

Activation

  • Set event-based triggers linked to an identified risk; avoid continuous recording without exceptional justification.
  • Define when recording must start, may start, must stop and must never be used.
  • Document any pre-event buffer, its length and whether it records audio.
  • Allow a wearer to explain a non-activation or early stop without permitting silent selective recording.

Audio

  • Treat audio and video as separate data streams and justify each one.
  • Prefer equipment that allows separate control where operationally workable.
  • State prominently when audio is being captured.
  • Set stronger restrictions for private, medical, welfare, legal, trade-union and safeguarding conversations.

People and places

  • Map use in public space, workplaces, vehicles and private dwellings separately.
  • Define rules for toilets, changing areas, bedrooms, treatment rooms and other high-privacy areas.
  • Plan for children, bystanders, interpreters, confidential documents and computer screens.
  • Provide an escalation route when a person objects or recording would create a safety risk.

Governance

  • Name the controller, system owner, information asset owner and authorised decision-makers.
  • Maintain a processing record, DPIA, policy, privacy notice, retention schedule and access matrix.
  • Train wearers, supervisors, evidence handlers, investigators and subject-access staff for their own roles.
  • Audit activations, missed activations, access, exports, deletions, complaints and discriminatory patterns.

What a user should say

Use a short, truthful announcement

The announcement should match the approved purpose and actual device state. It is transparency information, not a request for consent and not a threat.

Before activation, where safe and practicable
“I am switching on my body-worn camera. It records video and audio. I am using it because of [brief approved reason].”
If challenged
“The camera is used under our organisation's policy. I can tell you where to find the privacy information and how to raise a concern or request your information.”
When stopping
“I am ending the recording now because the reason for recording has ended.”

Staff should not say the footage “cannot be deleted”, “will definitely be used in court”, “proves everything”, or that a person has no data protection rights. Where an announcement would increase immediate risk, policy should permit recording without it and require the reason to be documented afterwards.

Storage, access and retention

Move footage off the camera into controlled storage

A camera should be a capture device, not the organisation's evidence archive. Secure upload should preserve the original, create an audit trail and prevent wearer deletion or informal sharing.

On-device storage

Temporary capture only

  • Encrypt the device and local storage.
  • Prevent playback, editing, copying and deletion by the wearer unless a tightly defined need is approved.
  • Use non-removable media or equivalent controls where feasible.
  • Upload promptly through an authenticated dock or managed connection.
  • Define what happens after loss, theft, damage, failed upload or a flat battery.
Cloud or managed repository

Controlled record and evidence store

  • Use role-based access, multi-factor authentication, encryption and immutable audit logs.
  • Record hosting locations, subprocessors, resilience, backups, deletion behaviour and any international transfers.
  • Require a UK GDPR-compliant processor contract and test breach reporting, export and exit arrangements.
  • Separate originals, working copies and redacted disclosure copies.
  • Ensure the organisation can retrieve footage without vendor lock-in.
Retention rule

There is no single statutory retention period for every organisation. Set the shortest justified routine period for each purpose, delete automatically when it expires, and apply a documented legal or evidence hold when footage relates to an incident, complaint, safeguarding matter, claim, disciplinary process, subject access request, police request or foreseeable litigation. Record who imposed the hold, why, its scope and when it will be reviewed.

Incident-to-evidence process

Preserve first, then investigate

  1. Make safeDeal with injury, immediate danger, safeguarding and emergency escalation. Do not delay urgent care to manage footage.
  2. Secure the deviceDo not replay, rename, trim, enhance, message or upload through a personal account. Follow the approved docking or transfer route.
  3. Preserve the originalApply an incident flag or hold before routine deletion. Keep the native file and metadata unchanged.
  4. Record the first accountObtain the wearer's own factual account promptly, using open prompts and distinguishing what they remember from what the camera may show.
  5. Log handlingRecord device ID, wearer, date, time, location, file identifier, upload, access, exports, copies and every transfer of control.
  6. Notify the right ownersInform the manager and evidence or data owner; involve police, safeguarding, insurers, HR, legal or the DPO according to the event.
  7. Assess disclosureShare only what is necessary, through a secure route, with authority and lawful basis recorded. Preserve unused relevant material.
  8. Review and closeDocument outcomes, learning, retention status and final authorised deletion. Keep the audit record required by policy.

Viewing footage and giving statements

When should staff view body-worn footage?

In most cases, staff should give their own factual account before viewing the footage. Preserve the recording first, then follow any different sequence required by the police, a regulator or the organisation's approved investigation procedure.

This keeps personal recollection separate from what was learned later from the recording. It also reduces the risk of witnesses aligning their accounts after shared viewing. A statement should describe what the person remembers, not simply narrate the video.

Before viewing

  • Write what the person saw, heard, said, did and decided in their own words.
  • Record uncertainty honestly; do not fill gaps from assumption.
  • State device ID, activation and anything unusual about operation.
  • Keep witnesses separate where accounts could influence each other.

If viewing is later authorised

  • Limit viewing to material necessary for the person's account and welfare.
  • Log who authorised it, what was viewed, when, where and who was present.
  • State clearly in any supplementary account that footage was viewed.
  • Separate corrections or additions from the original recollection.

Exhibits, authenticity and continuity

Show what the file is and how it was handled

The CPS states that video evidence must be shown to be the original or an authentic copy and not tampered with. Statements should be available to produce the video and cover continuity and security where these are in issue.

Identify

Use a unique exhibit or asset reference linked to the incident, device and capturing person. Do not rely on a descriptive filename alone.

Preserve

Keep the native original, original metadata and system audit history. Create a verified working copy for review and a separately labelled redacted copy for disclosure.

Explain

Be ready to describe the system, activation, time settings, buffering, upload, encryption, export method and any apparent gap or failure.

Account

Record every access, transfer, download, conversion, redaction and disclosure. Hash values can support integrity but do not replace witness and continuity evidence.

Do not alter silently

Never overwrite the source. Document clipping, transcoding, enhancement, muting or redaction and retain the original plus the reason and method.

Disclose lawfully

Use secure transfer, disclose the minimum necessary, preserve relevant unused material and follow police, prosecutor, court, regulator or legal instructions.

Procurement and assurance checklist

Questions the supplier must answer

  • Can audio and video be controlled separately?
  • What does pre-event buffering capture and retain?
  • Can wearers play, copy, edit or delete footage?
  • Is storage encrypted on the device and in transit?
  • How are device identity and time synchronised?
  • What happens when upload or connectivity fails?
  • Can originals and metadata be exported in a usable native format?
  • Where are live data, backups and disaster-recovery copies hosted?
  • Which subprocessors and international transfers are involved?
  • Can retention rules, holds and final deletion be independently audited?
  • Are access, viewing, export and deletion events immutable and reportable?
  • Can third parties be blurred and audio redacted for subject access?
  • What security certifications, penetration tests and incident timescales apply?
  • How will all footage and audit data be returned or deleted at contract end?
Board or senior ownerApproves purpose, risk appetite, policy and resources.
Data protection leadOwns DPIA, lawful basis, rights, sharing and breach assessment.
Operational leadOwns activation rules, training, supervision and incident learning.
Evidence custodianOwns preservation, continuity, export, disclosure and deletion holds.
IT and securityOwns device management, access, encryption, resilience and supplier assurance.
HR and workforceOwns consultation, fair worker monitoring, discipline boundaries and welfare.

Official sources

Primary guidance used for this page

Related resources

Return to the start of this guide

Discuss your requirements

Ready to equip your team with practical safety skills?

Contact our team to discuss your training needs, review course options, or request a clear, no-obligation proposal.

Practical recommendationNo obligationUK-wide delivery