CCTV and POPIA: Signage, Retention, and Who Can Ask for Footage
Your signage, how long you may keep footage, who may request a copy, and why recording audio is a separate offence under RICA. What POPIA requires of CCTV.
Cameras are legal. Most installations are not compliant.
There is a persistent rumour that POPIA made CCTV illegal. It did not. Surveillance for security is one of the more defensible things a business can do with personal information.
What POPIA did was attach conditions, and the conditions are where installations fail. The camera is fine. The sign is usually wrong, the retention period is usually undefined, nobody has a process for when someone asks for footage of themselves, and a surprising number of systems are recording audio, which is a separate problem under a different Act entirely.
Recorded images of identifiable people are personal information. The moment your camera captures someone who can be recognised, you are processing their personal information and POPIA applies.
When POPIA applies to your cameras, and when it does not
Section 6(1)(a) excludes processing in the course of a purely personal or household activity. A camera on your own home, pointed at your own property, watching your own gate, falls outside the Act.
That exemption is narrower than people assume. It strains as soon as the camera does more than protect your household:
- A camera covering the pavement, the street, or a neighbour's property is no longer purely household.
- Footage shared into a neighbourhood WhatsApp group is no longer purely household.
- Any camera operated by a business, a body corporate, a homeowners association or an estate is never household. Those are all responsible parties.
And the exemption only removes POPIA. It does not remove the ordinary law. A camera trained permanently on a neighbour's living room window is a privacy and nuisance problem whether or not POPIA applies to it.
Your lawful ground is legitimate interests, not consent
Section 11 requires a lawful ground for processing. Businesses instinctively reach for consent, and for CCTV that is the wrong choice. You cannot obtain meaningful consent from everyone who walks past a camera, and consent under POPIA must be voluntary, specific and informed, and can be withdrawn.
Nearly all CCTV rests instead on section 11(1)(f): processing necessary for pursuing the legitimate interests of the responsible party. Crime prevention, protecting staff and stock, and evidence after an incident are legitimate interests in the ordinary sense.
Relying on that ground carries obligations of its own. Section 10 requires processing to be adequate, relevant and not excessive, which means:
- Cameras placed where there is a real security reason, not simply everywhere.
- No cameras in bathrooms, changing rooms, or anywhere a person is entitled to expect privacy. There is no security justification that survives this.
- Coverage limited to your own premises and immediate approaches, rather than sweeping the whole street.
Section 13 also requires a specific, explicitly defined purpose. "Security" is enough if you actually mean it. Using security footage to monitor how long staff spend on tea breaks is a different purpose, and one you did not tell anyone about. Monitoring staff also engages RICA, which is criminal legislation: see employee monitoring under POPIA and RICA.
What your signage must actually say
Section 18 requires you to notify people when you collect their personal information, and signage is how that is done for CCTV. This is the requirement most sites fail, usually with a small sign reading "Smile, you're on camera" or nothing at all.
Section 18 expects the data subject to be told a substantial list of things: what is being collected, who is collecting it, why, whether supply is voluntary or mandatory, the recipients, whether it goes outside the country, and their rights of access, correction, objection and complaint. No sign can carry all of that legibly.
The workable approach, and the one that reflects how the requirement is met in practice, is a two layer notice. The sign carries the essentials and points to the full notice.
A compliant sign should be visible before a person enters the monitored area, and should state:
- That CCTV is in operation and recording
- The purpose, stated specifically, for example crime prevention and the safety of staff and customers
- Who is operating it, meaning the name of the responsible party rather than only the security company's logo
- Contact details for queries and requests
- Where to find the full privacy notice
Something like: CCTV in operation. This area is monitored and recorded by [Business Name] for crime prevention and the safety of staff and customers. For access requests or queries contact [email or number]. Full privacy notice at [website address].
Then carry a CCTV section in your website privacy notice covering retention, who footage is shared with, and how to make a request. If you need the wider notification requirements, how to write a POPIA privacy policy covers section 18 in full.
How long you may keep footage
Section 14 says records may not be kept longer than is necessary for the purpose they were collected for. POPIA sets no number of days for CCTV, which is exactly why so many systems simply keep everything until the drive fills.
The test is what you actually need. For most businesses, the purpose is served once enough time has passed for an incident to be noticed and reported. Common practice sits around 30 days, with shorter periods for low risk sites and longer where there is a specific justification.
What matters more than the exact number is that you can defend it:
- Write the retention period down, in your privacy notice and in an internal policy.
- Make deletion automatic. A system that overwrites on a cycle is easier to defend than one relying on someone remembering.
- If you preserve a clip for an investigation, insurance claim or criminal matter, treat that as a separate record with its own justification and its own end date, rather than extending retention across the whole system.
- Do not keep footage indefinitely because it might be useful one day. That is precisely what section 14 prohibits.
Someone asks for footage of themselves
Section 23 gives data subjects the right to access their personal information. Footage of an identifiable person is their personal information, so a request for CCTV footage is a data subject access request and runs on the same rules as any other, including the response timeframe.
This catches businesses unprepared, and it is worth deciding in advance how you will handle it.
- Verify who is asking. Handing footage to the wrong person is itself a breach.
- Ask them to narrow it. A date, a time window and a location. You are not obliged to search weeks of footage on a vague request.
- Consider other people in the frame. Their personal information is in the same footage, and their rights do not disappear because someone else asked. In practice this means blurring or masking third parties, or providing a still rather than a clip.
- Know your grounds for refusal, and that a refusal must be explained. Footage held as evidence in a live criminal investigation is a different situation to footage of a customer at a till.
- Log the request and your response. If you release footage to anyone, that release is a disclosure and you should be able to account for it.
The requests that cause the most trouble are the ones nobody planned for: a former employee, an insurance investigator, an attorney acting for someone who fell in your car park, or the police without a warrant. Decide the policy before the request arrives.
The audio problem almost nobody mentions
Many modern cameras record sound, and it is frequently enabled by default. This is not simply another POPIA consideration. It engages the Regulation of Interception of Communications and Provision of Communication-related Information Act, usually called RICA.
RICA prohibits the intentional interception of communications. Recording a conversation you are not a party to, without the consent of a party to it, is unlawful and can be a criminal offence, quite separate from any POPIA analysis. A camera in a waiting room capturing what two customers say to each other is recording a conversation the business is not part of.
The safe position for almost every business is to disable audio recording unless you have a specific, advised reason to have it and consent from the people being recorded. Video with no sound is a POPIA question you can answer. Audio adds a criminal statute to the analysis for very little security benefit.
If you do keep audio, say so on the signage. A sign mentioning cameras while the system quietly records conversations is a notification failure on top of everything else.
Facial recognition changes the analysis entirely
Ordinary CCTV records images. A system that identifies people by face, gait or other physical characteristics is processing biometric information, which POPIA treats as special personal information under section 26.
Special personal information may not be processed at all unless a section 27 exception applies, the most common being the data subject's consent. The legitimate interests ground that carries ordinary CCTV does not carry facial recognition.
This matters increasingly because the feature ships enabled on consumer and small business systems, and because number plate recognition at estate and complex entrances raises related questions. If your system identifies individuals rather than merely recording them, it needs its own assessment. Do not assume the sign at the gate covers it.
Your security company is an operator
Most businesses do not manage their own footage. A security company monitors it, an installer has remote access for maintenance, or the recorder uploads to a cloud service.
Each of those is an operator under POPIA, processing personal information on your behalf. Section 21 requires a written contract with each of them, obliging them to maintain the security safeguards in section 19 and to notify you immediately if footage is accessed by an unauthorised person. Very few CCTV installation agreements contain any of this.
Two further points follow:
- You remain the responsible party. If the monitoring company leaks footage, the obligation and the exposure are yours. Outsourcing the work does not outsource the accountability.
- Cloud storage is often offshore. If your recorder uploads to servers outside South Africa, section 72 governs that transfer and you need a basis for it. Ask your provider where footage is stored before you need to know.
POPIA section 21 and operator agreements covers what those contracts have to contain.
Cameras pointed at staff
Workplace surveillance is lawful but constrained, and it is where the purpose limitation bites hardest.
Cameras at a till, a stockroom or an entrance are straightforward security. Cameras positioned to watch how hard people work are performance monitoring, which is a different purpose that employees were not told about and would not reasonably expect. Section 13 does not let you quietly repurpose a security system.
Practical guidance: tell staff in writing where the cameras are and why, put it in a policy rather than an announcement, never place cameras in bathrooms or rest areas, and be careful about using security footage in a disciplinary process when the stated purpose was crime prevention. POPIA and employee data covers the wider employment picture.
Cameras pointed at the street or a neighbour
This is the most common domestic dispute and the answer is more nuanced than either side usually wants.
A home camera covering your own property is outside POPIA under the household exemption. Once it covers a public pavement or a neighbour's yard, the exemption weakens, and the ordinary law of privacy applies regardless of POPIA. Deliberately recording into a neighbour's home is very difficult to defend on any basis.
Practical steps: angle cameras down and inward so they cover your boundary rather than the street beyond it, use privacy masking if your system supports it to black out areas you should not record, and be cautious about circulating footage of identifiable people to community groups. Estates and bodies corporate should note that they are responsible parties in their own right, with full obligations including a written notice, defined retention, and contracts with their guarding company.
A short checklist
- Is there a visible sign before every entrance to a monitored area?
- Does the sign name your business, state the purpose, and give a contact?
- Does your privacy notice have a CCTV section covering retention and disclosure?
- Have you written down a retention period, and does deletion happen automatically?
- Is audio recording switched off?
- Do you know what you would do if someone requested footage of themselves tomorrow?
- Do you have a written contract with your monitoring company and your installer?
- Do you know whether your footage is stored outside South Africa?
- Are any cameras covering bathrooms, changing areas or rest rooms? Move them today.
- Does the system do facial recognition, and if so, have you assessed it separately?
POPIA Ready generates a privacy policy covering CCTV, a PAIA manual and five other documents customised to your business, free to preview. The free checklist will show you what else is missing.
General guidance on South African law as at August 2026, not legal advice. CCTV also touches employment law, RICA and the ordinary law of privacy, and a specific installation deserves a professional opinion.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview