Sample policy · Reg 10

Surveillance, CCTV and Monitoring Policy

Statutory anchor: Regulation 10 (dignity and respect), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 13 (safeguarding) and Regulation 17 (good governance). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1.1, 2026-07-19

1. What the regulation says

Service users must be treated with dignity and respect. (Reg 10(1): the headline duty)

having due regard to any relevant protected characteristics (as defined in section 149(7) of the Equality Act 2010) of the service user. (Reg 10(2)(c): protected characteristics)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/10. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

Service users must be treated with dignity and respect. In particular, you have to protect their privacy, support their autonomy, independence and involvement in the community, and have due regard to any relevant protected characteristics under the Equality Act 2010. Surveillance, CCTV and monitoring can support safety, security and incident review, but they also interfere with privacy, dignity, autonomy and trust, so they must be used only where they are lawful, necessary, proportionate, transparent and properly governed under the Data Protection Act 2018, UK GDPR and ICO and CQC surveillance guidance.

3. Purpose

The purpose of this policy is to make sure that [Service Name] only uses surveillance, CCTV or monitoring systems where they are lawful, necessary, proportionate, transparent and properly governed.

Surveillance can support safety, security and incident review, but it can also interfere with privacy, dignity, autonomy and trust. It must not be used casually or as a substitute for safe staffing, supervision, care planning or good management.

4. Policy warning

The service must not install or use CCTV, audio recording, covert monitoring, vehicle cameras, body-worn cameras, remote monitoring or other surveillance without a documented lawful basis, risk assessment and governance approval.

Surveillance must not be used in bedrooms, bathrooms, treatment areas, changing areas, personal-care areas or other private spaces unless there is an exceptional, lawful, necessary and proportionate reason, supported by specialist advice.

Covert surveillance is high risk and must not be used without senior approval and legal/data protection advice.

5. Scope

This policy applies to:

6. Principles

The service will ensure surveillance is:

7. Responsibilities

The provider is responsible for approving surveillance systems and ensuring compliance.

The Registered Manager is responsible for ensuring surveillance does not compromise dignity, safety, safeguarding, confidentiality or care quality.

The Data Protection Officer or information governance lead is responsible for advising on lawful basis, transparency, DPIA, access controls, retention and data subject rights.

Managers are responsible for local use, signage, incident access and audit.

Staff must not view, copy, share, record or disclose surveillance material unless authorised.

7.1 Local decisions before adoption

Before adoption, the provider records its:

Leaving one of these decisions blank means the system is not ready to operate.

8. Surveillance approval workflow and lawful basis

No new system, material change or new use starts until the provider completes this workflow:

  1. Define the problem and purpose: describe the specific outcome sought, not a broad aim such as safety or quality.
  2. Test less intrusive options: record alternatives considered and why they would not meet the identified need.
  3. Assess lawfulness and impact: document the lawful basis, special-category condition where needed, consultation and DPIA decision.
  4. Approve controls: set coverage, access, security, signage, retention, deletion, incident response and review date.
  5. Authorise operation: record the senior approver and any conditions before activation.
  6. Review real use: check access logs, complaints, incidents and continued necessity, then change or remove the system if it is no longer justified.

Before any system is used, the provider must document:

Possible purposes may include safety, security, crime prevention, incident review or protection of people at risk, but the purpose must be specific.

9. Data Protection Impact Assessment

A Data Protection Impact Assessment must be completed where surveillance is likely to create high risk to people's rights and freedoms.

The DPIA should consider:

High-risk surveillance must not start until the DPIA has been reviewed and approved.

10. Transparency and signage

People must be told about surveillance unless there is a lawful reason not to do so.

The service must provide:

Signage must be visible before people enter monitored areas where practicable.

11. Areas where surveillance is prohibited or exceptional

Surveillance must not normally be used in:

Any exception must be individually justified, time-limited, documented, risk assessed and supported by specialist advice.

12. Audio recording

Audio recording is more intrusive than video-only monitoring and must be separately justified.

The service must not enable audio recording unless:

Call recording must be clearly explained to callers and managed under the information governance policy.

13. Covert surveillance

Covert surveillance is not routine governance.

It may only be considered where there is a serious concern, a clear lawful basis, no less intrusive way to investigate, senior approval and specialist advice.

Before covert surveillance is used, the provider must document:

Covert surveillance must never be used for general staff performance monitoring or convenience.

14. Staff monitoring

Where surveillance may monitor staff, the provider must be transparent and fair.

Staff must be told:

Surveillance must not be used to replace supervision, management, staffing review or disciplinary processes.

15. Access to recordings

Access must be restricted to authorised people.

The access log must record:

Staff must not download, photograph, copy, share or send footage using personal devices or unauthorised systems.

16. Disclosure to police, safeguarding or regulators

Recordings may be shared where there is a lawful basis.

Potential recipients include:

The decision must be recorded, including what was shared, why, with whom and under what lawful basis.

17. Retention and deletion

Recordings must be kept only as long as necessary.

The provider must set and document retention periods for each system.

Longer retention may be justified where footage is linked to:

Footage not needed must be deleted securely.

18. Subject access requests

People may request access to their personal data captured by surveillance.

The service must handle requests under the Subject Access Request process.

Before disclosure, the service must consider:

Requests must be escalated to the information governance lead.

19. Surveillance in vehicles

Vehicle cameras or dashcams must be assessed separately.

The assessment must consider:

Patient transport services must consider dignity, confidentiality and safeguarding.

20. Remote monitoring and sensors

Remote monitoring, falls sensors or environmental sensors must be used only where lawful, necessary and proportionate.

The record must show:

Remote monitoring must not become an unjustified restriction or substitute for safe care.

Where surveillance or remote monitoring touches a person who may lack capacity to consent to it, follow the Mental Capacity Act best-interests process. Any question of whether the monitoring amounts to a deprivation of liberty is a separate legal matter; take specialist advice rather than treating it as decided by this policy.

21. Incidents and breaches

The following must be reported:

The Data Breach Policy and Incident Reporting Policy must be followed.

21.1 Register and action tracking

22. Audit

The Registered Manager and information governance lead must audit surveillance at least annually.

The audit must check:

Systems must be removed or changed where they are no longer justified.

22.1 Related policies

23. Review

This policy will be reviewed annually, or sooner following a surveillance incident, data breach, complaint, safeguarding concern, system change, new technology, ICO guidance update, legal change or CQC finding.

24. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

25. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement. In particular, seek specialist advice before using covert surveillance, audio recording, bedroom or private-area monitoring, facial recognition, continuous monitoring, staff disciplinary surveillance, monitoring of children, monitoring of people who may lack capacity, or sharing footage with external bodies.

26. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Conformed new cross-cutting draft to the Verivius policy standard.
v1.1 2026-07-19 Verivius (sample) Added local adoption decisions, approval workflow, register tracking and linked companion policies.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

Surveillance is the rare control that can make a service safer and less kind at the same moment. A camera in a lounge, a microphone at a reception desk, a sensor by a bed or a lens in a patient transport vehicle changes how people behave: someone who has been incontinent, who paces at night, who is distressed in a waiting area, or who wants a private word with a partner now does all of it knowing they are watched. So the evidence trail here is not paperwork about equipment, it is the record of a judgement that a specific loss of privacy bought a specific gain in safety, reached with the people affected rather than about them. Where that record is thin, the pattern is always drift: a system installed to deter break-ins quietly starts answering staffing, disciplinary and family-reassurance questions instead, and nobody notices until footage surfaces in an investigation. Staff feel it too, because a camera pointed at a corridor is also pointed at the person working in it. A well-led service keeps asking whether each system is still earning its place, and takes it out when the honest answer is no.

  1. Each surveillance system has a documented specific purpose, lawful basis and, where high risk, an approved Data Protection Impact Assessment (DPIA) completed before it went live, not a broad aim such as 'safety' recorded afterwards.

    Strong evidence: The approval-workflow record (section 8) and DPIA (section 9) documenting purpose, lawful basis, special-category condition where needed, alternatives considered and the senior approver, held in the surveillance-system register (section 7.1).

    Weak evidence: The register lists the system but the purpose column reads "safety and security", the lawful basis is blank or simply says "legitimate interests" with nothing to show the balancing that was done, and where a Data Protection Impact Assessment exists at all it is dated after the cameras were switched on. There is no note of which less intrusive option was tried first, and the approver is unnamed or is the same person who chose and bought the kit, so nothing shows an independent judgement was ever made.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 35(1) and 35(3)(c) (DPIA prior to processing), with Article 5(1)(b), Article 6(1) and Article 9(2)

  2. No camera, microphone or sensor covers bedrooms, bathrooms, toilets, changing areas or treatment areas during intimate care unless an individually justified, time-limited, specialist-advised exception exists.

    Strong evidence: The camera, sensor and microphone location map (section 7.1) checked against the prohibited-areas list (section 11), with the documented, risk-assessed and specialist-advised justification for any exception.

    Weak evidence: The location map is a sketch that has not kept pace with cameras moved during refurbishment or repositioned by a contractor, so a lens now takes in a bedroom doorway, a shower-room entrance or a couch used for examinations. Where an exception exists, the justification is a single line such as "falls risk" with no end date, no review point and no record of the specialist advice that was supposed to support it.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  3. Covert surveillance is used only for a serious concern with recorded legal and data-protection advice and senior authorisation, never for routine staff performance monitoring or convenience.

    Strong evidence: The covert-surveillance record (section 13) documenting the serious concern, alternatives considered, legal and data-protection advice, authorisation, scope, duration, areas covered and when surveillance will stop.

    Weak evidence: The only record is an email thread agreeing to "put a camera up for a while", with the serious concern described loosely, nothing on what else was tried, no legal or data-protection advice attached and no stated point at which the surveillance stops. Covert footage then appears in a staff disciplinary or attendance file that the original authorisation never contemplated.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  4. Access to recordings is restricted to authorised roles and every viewing or export is logged, with no footage copied onto personal devices.

    Strong evidence: The access log (section 15) recording date, person accessing, reason, footage reviewed, whether copied or exported, recipient, outcome and the retention or deletion decision.

    Weak evidence: The access log runs for the first fortnight after go-live and then stops, or every row reads "incident review" with no note of what was actually viewed, whether it was exported, who received it or what happened to the copy afterwards. Leavers still know the viewing password, and footage for a safeguarding or police matter was shared by someone photographing the monitor on a personal phone.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  5. People are told about overt surveillance through clear signage and privacy-notice information before entering monitored areas, not recorded without notice.

    Strong evidence: Signage and privacy-notice provision (section 10) naming the purpose, data controller identity, retention, how to request access and how to complain, with missing signage logged as a reportable incident (section 21).

    Weak evidence: Signs are faded, fixed behind a propped-open door, or sited inside the monitored area rather than before people reach it, and they show a camera symbol with no controller name, no stated purpose, no retention period and nothing telling a person how to ask for a copy or how to complain. Nobody can point to a single occasion when missing or damaged signage was logged as an incident rather than quietly replaced.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 13(1), read with Article 12(1) and Article 5(1)(a)

  6. Remote monitoring or sensors affecting a person who may lack capacity have a recorded capacity assessment and best-interests decision under the Mental Capacity Act 2005, not a blanket install, with any deprivation-of-liberty question taken as a separate legal matter.

    Strong evidence: The remote-monitoring record (section 20) capturing consent or lawful basis, capacity assessment and best-interests decision where needed, the risk addressed, who responds and the impact on privacy and autonomy.

    Weak evidence: A sensor was fitted after a family member or a night-shift colleague asked for it, and the person's record holds no capacity assessment for this specific decision and no best-interests entry naming who was consulted. The write-up describes the alerts the device sends but is silent on the risk it is meant to address, who responds when it fires, what it costs the person in privacy and autonomy, and when the arrangement will be looked at again.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Mental Capacity Act 2005 s.4 (with ss.2-3 and s.5), and Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 11(3)

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026