Is ANPR Legal in the UK? GDPR, the ICO and Keeper Data
A council run multi storey and a retail park a mile down the road can run the same camera, over the same kind of barrier, doing the same job. Ask each site's manager whether their ANPR is legal and both are likely to reach for the same document, the Surveillance Camera Code of Practice. Only one of them is required to open it. That is the mix up hiding inside a common question. The code binds the council because Parliament named it as a relevant authority in the act that created the code. It was never written to bind the retail operator, and the reason is not that private car parks fall outside privacy law. A separate set of rules governs them, and those rules, not the camera code, decide whether a private site's cameras are lawful. Two of the checks inside that separate rulebook changed during 2026, and the change does not show up in a summary of the law. It shows up in the documents themselves. What follows comes from those documents: four questions an operator can put to their own site's paperwork this week, and the exact wording each answer has to stand up against.
1 September 2026 / 9 min read
By Tim Marting, Head of International Business Development

Which rulebook applies to your cameras?
The Surveillance Camera Code of Practice binds a named list of public bodies under the Protection of Freedoms Act, not private operators. A private car park's cameras are governed instead by UK GDPR, which sets specific, checkable requirements on lawful basis, signage, retention and access requests that a court or the ICO can test directly.
The Protection of Freedoms Act, passed in 2012, puts the duty in exact words at section 33(1): a relevant authority 'must have regard to the surveillance camera code when exercising any functions to which the code relates.' The obligation falls on a relevant authority, a defined term, not on anyone who happens to run a car park with a camera over the barrier.
Section 33(5) then defines relevant authority as a closed list, not an illustrative one. It covers local government, London's own authorities, ancient offices tied to the Inner and Middle Temple, parish meetings, police and crime commissioners and chief police officers in England and Wales, plus whoever the Secretary of State later adds by order. The list runs to 11 lettered categories. Not one of them is a private company, a landowner or a car park operator.
The code says so itself. Its own text tells operators outside that list exactly where they stand: 'Other operators of surveillance camera systems who are not defined as relevant authorities are encouraged to adopt this code and its guiding principles voluntarily and make a public commitment to doing so. Such system operators do not have to have regard to this code but it is still considered best practice.' Adopting it is a choice for a private operator. It has never been a legal duty.
There is a second limit too. Sections 29 to 33, the part of the act that creates the code, are marked E and W, England and Wales only. A site outside those two countries is not reachable by this code at all, whoever runs it.
A private car park's cameras still answer to law, and to a law nobody adopts by choice. UK GDPR applies to any organisation processing personal data, numberplates included, and it sets out things an operator can check line by line: a lawful basis on file, signage that names who is watching, a retention period with an owner, and a route for someone to ask what has been kept about their plate. That is where a private site is exposed. An operator can follow the camera code to the letter and still have no written lawful basis, no owned retention period and a DPIA nobody has opened since installation, because the code was never the document those things live in. The three questions below decide it.
Who wrote down your lawful basis, and when?
The lawful basis a private car park relies on is legitimate interests under Article 6(1)(f) of UK GDPR, the basis the ICO's own surveillance guidance is written around. It has to be worked through in writing before the cameras start recording. A new class of recognised legitimate interest took effect in February 2026, but it excludes routine parking charge enforcement.
Every use of a camera to identify someone needs a lawful basis under Article 6 of UK GDPR, and a private car park cannot lean on consent the way a website login might. The ICO says as much directly: gathering genuine consent from someone driving into a car park is, in its own words, often difficult in practice. Driving past a sign is not agreement, because agreement is not the basis being claimed.
The basis that guidance is written around is legitimate interests, Article 6(1)(f) of UK GDPR, which permits processing 'necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.' The ICO does not accept a bare assertion of that. It sets what it calls the three part test, worked through in writing before the system goes live: a genuine purpose, a use of the footage necessary for it, and a balancing check against the driver's own rights. Its own words are blunt: 'It's not enough for you to simply say that using personal information is in your legitimate interests.'
That test used to be the whole story. Since 5 February 2026 there is a second basis to weigh, because the Data (Use and Access) Act 2025 inserted Article 6(1)(ea), covering a narrow, defined list the act calls recognised legitimate interests: a public task, national security, public security and defence, emergencies, crime, and safeguarding vulnerable people. Routine enforcement of a parking charge sits on none of those six heads. So the practical answer for a private car park has not moved: Article 6(1)(f) is still the ground, with the three part test written down before enforcement starts, not drafted afterwards to justify what already happened.
Writing the basis down is not the only paperwork that has to exist before the cameras start. Article 5(1)(a) requires processing to be transparent, and Article 13 sets out what a controller must tell the data subject when their data is collected: who is behind it, why, and how long it is kept. On a car park that duty is met, or missed, at the signs on the way in. The ICO's checklist calls for clear, prominent signage naming the organisation running the system and giving at least one way to contact it. A sign with only a logo leaves a lawful basis nobody driving past can verify.
Every ICO surveillance page currently carries the same banner: due to changes made by the Data (Use and Access) Act, the guidance is under review and may be subject to change. That warning applies to the regulator's own text, not to the law underneath it, which is why writing the three part test down now, against a real site, beats waiting for a rewritten page. A basis that lives only in someone's head is not written down, and a regulator or a challenged driver can establish that in minutes.

How long does a read live on your site, and who decided that?
There is no legal maximum or minimum retention period for ANPR data. UK GDPR requires only that the period matches the actual purpose, is written down, and can be defended if asked. Storage capacity and 'it might be useful one day' are both explicitly ruled out by the ICO as reasons to keep a read.
Article 5(1)(e) of UK GDPR calls this storage limitation: personal data must be kept, in the regulation's own words, 'in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.' There is no schedule attached to that line, no table that says a car park read equals 90 days. The ICO is explicit that none exists: the UK GDPR and the DPA 2018 do not prescribe any specific minimum or maximum retention periods which apply to surveillance systems, and no fixed number is offered, because the purpose of the processing is what should set the period.
That freedom comes with a limit. The same ICO guidance rules out the two justifications operators reach for first: 'you should also not determine your retention period simply by the storage capacity of any surveillance system, or just in case you think the data may be useful in the future.' Article 5(2) then adds accountability: the controller must be able to demonstrate compliance, not just claim it. A retention period nobody wrote down and nobody can explain is a weak position when a read from four months ago is questioned.
That gap is not hypothetical. A retail outlet park we put the question to could not tell us how heavily its EV charging bays were used, or whether petrol cars ended up occupying them. What came back described intentions for the site and contained no figures at all, because none were being gathered. Nobody had decided what to keep, so nobody could say what was happening on their own bays. A retention schedule fixes nothing when the data was never collected to begin with.
The same blind spot applies to a retention period nobody has written down. If a site does not know how long it keeps a read, why, or who signed off on that number, it does not have a documented retention policy, it has whatever the software happened to ship with. That is both a compliance gap and an operational one: a site that cannot see its own data clearly cannot tell a genuine repeat visitor from a one off, cannot answer an access request without guessing what still exists, and cannot show a regulator anything beyond a shrug. The paperwork gap and the visibility gap are, on most sites, the same gap. Access requests run on a clock of their own, and the ICO makes a practical point about it: take the full response period and a site's own retention rule may have deleted the footage in the meantime. Preventing that deletion is possible for a site that knows what it holds. It is guesswork for a site that does not.
See what your own site records
A walkthrough of a working site is the quickest way to see what a documented read looks like before a retention period is written.
Book a demo →What happens on day 14, and on day 30?
Camera only enforcement runs on a 14 day clock, counted from the day after parking ended, when a driver was told nothing at the time; a prior windscreen notice extends that period. A second clock now governs complaints: since 19 June 2026, a controller must acknowledge one within 30 days and give the person a real answer.
Recovering an unpaid charge from the registered keeper only works if the notice reaches them inside a window Parliament fixed. Paragraph 9(5) of Schedule 4 to that same 2012 act covers the scenario most ANPR only sites rely on, where nothing was handed to the driver at the time: 'The relevant period for the purposes of sub paragraph (4) is the period of 14 days beginning with the day after that on which the specified period of parking ended.' Miss that window and the route the law provides for that parking event is the one that closes.
Sites that leave a notice on the windscreen first work to a different clock. Paragraph 8(5) covers that route: 'The relevant period for the purposes of sub paragraph (4) is the period of 28 days following the period of 28 days beginning with the day after that on which the notice to driver was given.' Same schedule, same act, a longer window, because the two routes start from different first steps.
Side by side, the two routes look like this.
A newer clock now runs beside those two, and it governs a different moment: what a site does once someone complains, not how long it can wait to enforce. Section 103 of the Data (Use and Access) Act 2025, in force since 19 June 2026, inserts a complaints duty into the Data Protection Act 2018. A controller must 'acknowledge receipt of the complaint within the period of 30 days beginning when the complaint is received' and then, without undue delay, respond to it and tell the complainant the outcome. Thirty days to confirm it has landed, then a duty to move without delay and say what happened, instead of leaving it unanswered.
Parka's ANPR cameras log every read against a site's own retention and lawful basis settings, not a generic default, so the 14 day and 30 day clocks above start from evidence a site can pull up on request rather than reconstruct from memory. When a driver disputes a read, whether a genuine misread or a straightforward keeper query, the same record settles it without a manager guessing. This does not replace the paperwork an operator has to own. It only means that paperwork has something real behind it on day 14, day 30, or when a complaint arrives.
Two clocks are already running on every site with a camera over the barrier: one on how long a keeper request stays open, the other on how fast a complaint gets answered, whether or not the paperwork behind them exists yet. Whether the 14 days apply to a given site is easy to answer. The harder question, and the one that decides an outcome, is what day the counting started and what the site could put in front of someone who asked.
| Route | What the driver had at the time | Relevant period | Where it is set |
|---|---|---|---|
| ANPR only | Nothing given on site | 14 days, from the day after parking ended | Schedule 4, paragraph 9(5) |
| Notice to driver | A notice left on the vehicle | 28 days, after a first 28 day period from the day the notice was given | Schedule 4, paragraph 8(5) |
Common questions
If a council owns the freehold but a private company runs the car park day to day, who carries the duty?
The duty follows the body exercising the function, so it stays with the council and does not travel down a lease to the operator. A landowner can still require code style commitments in the contract itself. That is a commercial choice made between two parties, and it binds the operator through the agreement, not through the act.
Does adopting the Surveillance Camera Code voluntarily give a private operator any legal protection?
It gives no legal defence, because nothing in the act attaches a consequence to a voluntary adopter either way. What it gives is a public commitment a landowner or a tenant can point to during a procurement. It shortens none of the UK GDPR duties, and those are what a regulator assesses if a complaint arrives.
What does a written three part test actually look like on a real site?
Three short written answers, dated, with a named person behind them: the purpose the cameras serve on that specific site, why recognition is a proportionate way to achieve it, and how the driver's interests were weighed against it. The ICO's position is that claiming a legitimate interest is not enough on its own, so the point of the document is that somebody can produce it.
What happens if a site misses the 14 day window for serving a notice on the keeper?
The right to hold the registered keeper liable for that particular parking event does not arise. It is a deadline attached to one event and one vehicle, not a bar on ever contacting that keeper again about a different day. Sites that miss it usually miss it because nobody owned the date, not because the law was unclear.
Is the new complaints duty the same thing as answering a subject access request?
No, and they run on separate clocks. A complaint is about how a site handled someone's data and now carries its own acknowledgment deadline. An access request is for a copy of the data itself. The same driver can trigger both in a single email, and a site that treats them as one thing has answered half of it.
Does a private car park have to pay a data protection fee on top of any camera system costs?
Yes, normally. Any organisation processing personal data, numberplate reads included, pays the ICO's data protection fee unless it is exempt. The current tiers, set in February 2025, run from £52 for the smallest organisations to £3,763 for the largest, with a £5 reduction for paying by direct debit.
More insights
Have a closer look when you are ready
Book a 30 minute demo and we will walk your team through the platform at your pace.
