Data & privacy

GDPR: what it actually says, and why half the internet has it wrong

A camera, a visible screen or an objection to being filmed does not automatically create a UK GDPR breach. Here is the test the law actually applies, and where both online claims and nervous organisations go wrong.

In this article

GDPR has become a buzzword

Watch enough videos from self-appointed public-space auditors and a familiar scene appears. Someone films through an office window, catches a glimpse of a monitor and announces a major GDPR breach. Elsewhere, a person objects to being filmed in the street and says that the camera itself breaks data protection law.

Both claims can be wrong. They can also hide a real issue if everyone argues from slogans instead of facts. UK GDPR does not ban cameras, make every visible screen a breach or require consent for every use of personal data. It regulates the processing of personal data through defined principles, lawful bases, rights, duties and exemptions.

The short version

  • UK GDPR applies to information relating to an identified or identifiable living person, not to every piece of information.
  • A code or case reference may still be personal data if it can reasonably be linked to a person.
  • Seeing personal data on a screen can amount to unauthorised disclosure, but the facts must show that personal data was exposed and that security failed.
  • Filming in public is not automatically unlawful, but the purpose, scale and later use of the footage matter.
  • Consent is only one lawful basis. Legitimate interests and public task are commonly considered for surveillance.

First question: is it personal data?

That definition is the gateway to UK GDPR. Information about a limited company, an anonymous stock total or a generic departmental label is not personal data merely because it appears on a computer. Information about named employees, customers, patients, tenants or complainants usually is. Business information can also contain personal data, particularly where it identifies a director, employee, sole trader or customer.

The test is not limited to what a stranger can identify at first glance. A customer number, case reference or pseudonym can remain personal data where the organisation, or another person using means reasonably likely to be used, can link it to an individual. Removing a name may reduce risk, but it does not necessarily anonymise the record.

A case reference on a council screen

A video captures a council department name and a case reference, but no name or other readable details. That clip alone may not establish that a passer-by could identify anyone. The reference may still be personal data in the council's hands because the council can link it to a person. Whether there has been a breach then depends on what was actually disclosed, to whom and whether the exposure resulted from a failure of security.

A visible screen is not automatically a breach

Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. That is wider than data being downloaded, emailed or removed from an organisation. An unauthorised person reading personal data on a badly positioned screen can engage the definition.

It still does not follow that every monitor visible through glass proves a breach. The footage may be unreadable, may show only non-personal business information, or may not demonstrate that anyone obtained meaningful access. A sensible assessment separates what can actually be seen from what the person filming assumes the system contains.

Whether a breach must be reported is a separate question. An organisation should record and assess a suspected incident. Notification to the ICO is required when the breach is likely to result in a risk to people's rights and freedoms, normally within 72 hours of becoming aware of it. A breach does not become reportable merely because somebody labels it serious on camera.

Filming people in public

A recognisable image of a person can be personal data. That does not make all public filming unlawful. Data protection law regulates processing; it does not create a general right never to appear in another person's photograph or video.

UK GDPR sits outside processing carried out by an individual in the course of a purely personal or household activity, with no connection to a professional or commercial activity. Holiday photographs and pictures taken for personal enjoyment are straightforward examples. The exemption is fact-sensitive. A regular monetised channel, a commercial purpose, systematic targeting or publication to a broad audience may require a different analysis.

Public place does not mean no rights

Even where a GDPR objection is misplaced, other law may matter. Harassment, misuse of private information, breach of confidence, safeguarding, trespass rules and restrictions applying to particular locations can all be relevant. The facts, conduct and use of the footage matter more than the slogan used in the argument.

Journalism is not a magic word

The Data Protection Act 2018 contains an exemption for processing carried out for journalistic, academic, artistic or literary purposes. It protects freedom of expression and can disapply specified data protection requirements where its conditions are met. It is not an automatic licence for anyone holding a camera to ignore data protection law.

In outline, the controller must be processing with a view to publication, must reasonably believe publication would be in the public interest, and must reasonably believe compliance with the relevant provision would be incompatible with the special purpose. The exemption applies only to the extent those conditions are satisfied. Calling a video journalism does not settle those questions.

Another common claim is that nobody may film or record a person without permission. Consent is one lawful basis under Article 6, but it is not the only one. The correct basis depends on who is processing the footage and for what purpose.

Lawful bases commonly considered for surveillance

Lawful basisWhere it may fitWhat must be shown
Legitimate interestsOften considered by private organisationsThe purpose must be legitimate, the processing necessary and the balance must not override the person's rights.
Public taskOften relevant to public authoritiesThe processing must be necessary for a task in the public interest or under official authority.
Legal obligationRelevant where the law requires processingThe obligation must be grounded in UK law.
ConsentPossible, but often unsuitable for general CCTVConsent must be freely given and capable of being withdrawn, which is difficult in many monitored spaces.

A shop using CCTV for security may rely on legitimate interests after documenting why the system is necessary and proportionate. A public authority may rely on public task where the legal conditions are met. Neither route removes the need for transparency, appropriate signs, data minimisation, security, controlled access, suitable retention periods and respect for individual rights.

More intrusive technology requires closer scrutiny. Facial recognition or another system actively processing biometric data to uniquely identify people can involve special-category data and additional conditions under Article 9. A sign on the wall does not fix a surveillance system that is unnecessary or disproportionate.

Businesses can get it wrong in the other direction

Overconfidence is not the only problem. Organisations sometimes refuse reasonable requests, withhold information that could lawfully be supplied, or treat any internal query as too risky because somebody mentions GDPR. That is not good compliance. Data protection law requires decisions, reasons and safeguards, not reflexive secrecy.

A subject access request, for example, may require an organisation to provide a person with their own personal data. Third-party information, legal privilege and other exemptions may affect what can be disclosed, but the organisation should apply the relevant test rather than use GDPR as a blanket refusal. Accurate compliance sits between careless disclosure and needless obstruction.

A better three-question test

Test the claim in this order

  1. Identify the data. What exactly was recorded, displayed, shared or accessed, and does it relate to an identified or identifiable living person?

  2. Identify the processing and the person responsible. Who collected, used, published or disclosed the data, for what purpose, and does the purely personal or household exemption apply?

  3. Identify the legal issue. Is there a lawful basis and fair process, or is there evidence of unauthorised access, disclosure, excessive collection, unfair use or another specific failure?

The bottom line

UK GDPR is specific, but its application can be fact-heavy. It protects personal data about identifiable living people and regulates how that data is processed. It does not switch on merely because a camera is present, a screen is visible or somebody says the word breach.

The strongest data protection complaints identify the information involved, the processing that occurred, the rule that may have been broken and the harm or risk created. That protects genuine complainants from having serious issues lost in the background noise of confident but inaccurate claims.

Official sources

ConsumerWisehttps://consumerwise.org.uk/news/gdpr-what-it-is-and-why-the-internet-is-wrong/