What exactly must the camera help the pharmacy do after an incident? If the answer is only “record everything”, the project has started with equipment instead of a defined problem.
Pharmacy CCTV should be designed around specific risks, proportionate coverage, usable evidence and accountable access. It needs to protect people, medicines, information and premises without turning every available angle, microphone or analytic feature into routine surveillance.
How should a UK pharmacy choose a CCTV system?
Define the incidents the system must help prevent, investigate or evidence. Map the minimum camera coverage needed, complete the privacy assessment, specify image quality and retrieval tests, set access and retention controls, secure every connected component and test the full response before accepting the installation.
- Buy against incident scenarios, not a camera count.
- Keep consultation, staff and neighbouring spaces outside the view unless a documented, proportionate need says otherwise.
- Prove that authorised staff can retrieve, export and protect the right footage under pressure.
Start with the pharmacy’s security problem
List the events the pharmacy is trying to manage: forced entry, theft, threatening behaviour, unauthorised access to a restricted area, a disputed collection, damage at the entrance or an incident during a delivery. For each one, decide whether CCTV is intended to deter, alert, support a live response, reconstruct events or provide evidence later.
The GPhC standards for registered pharmacies require premises to safeguard health, safety and wellbeing, protect privacy and be secure from unauthorised access. They do not prescribe a universal number of cameras or a single technical design. The owner still needs a risk-based system that fits the particular premises and services.
Connect the specification to the pharmacy’s wider risk-assessment process. CCTV may support a control, but it does not repair a weak lock, an exposed key, an unsafe lone-working arrangement, a blind handover or an unclear incident procedure.
Map the places where evidence matters
Walk the site at opening, peak time, closing and after dark. Mark the public entrance, sales floor, medicines counter, dispensary boundary, consultation rooms, staff-only doors, delivery point, stock rooms and external approaches. Then mark the places a camera must not casually capture: a confidential conversation, a clinical assessment, a staff changing area, a neighbouring property or a computer screen showing patient information.
| Area | Decision to make | Acceptance evidence |
|---|---|---|
| Entrance and frontage | Can the system show approach, entry and exit without unnecessarily overlooking neighbours or the public highway? | Day and night test clips, documented field of view and privacy masking |
| Medicines counter | Can an incident be reconstructed without recording confidential conversations or readable prescriptions? | Representative counter test and privacy review |
| Restricted access points | Does coverage show the access event and the relevant route rather than a meaningless wide shot? | Simulated unauthorised-entry scenario and time alignment |
| Delivery handover | Can the system distinguish arrival, custody and departure while protecting driver and patient information? | Handover replay and export test |
| Consultation spaces | Is surveillance excluded unless there is an exceptional, documented and proportionate justification? | Camera plan, DPIA decision and physical verification |
Do not accept a drawing that shows only camera symbols. Ask for the expected field of view, pixel density at the point where identification matters, lighting assumptions, blind spots, privacy masks and the route by which footage reaches storage.
Make privacy part of the design
The ICO’s CCTV guidance for organisations says the operator should identify why surveillance is needed, consider less intrusive alternatives, document the decision, check the camera angle and tell people they are being recorded. The ICO notes that surveillance guidance is under review following the Data (Use and Access) Act, so use the current page and monitor it rather than relying on an old installer checklist.
Record the purpose, lawful basis, locations, people affected, data flows, retention period, access roles, processors and disclosure process. Connect those decisions to the pharmacy’s wider data-protection controls, and screen whether a data protection impact assessment is required. The ICO’s detailed surveillance accountability guidance explains that a DPIA is required where processing is likely to create a high risk, including relevant workplace monitoring and large-scale monitoring of public areas.
Position signs where people encounter surveillance, not behind the counter after they have already been recorded. Keep the privacy notice consistent with actual practice. If the installer changes a field of view, enables audio, adds cloud analytics or extends retention, reassess the decision before treating it as a harmless technical setting.
Treat audio and analytics as separate decisions
A camera that can record audio does not mean the pharmacy should use it. Conversations at a medicines counter can reveal health information even when a prescription or screen is not visible. Continuous audio is more intrusive than video alone and needs its own clear necessity and proportionality assessment.
The same applies to facial recognition, behavioural analytics, demographic classification and automated alerts. These functions can change the data, risks and legal analysis materially. Keep them disabled unless the pharmacy has defined a justified use, completed the required assessment and obtained appropriate specialist advice. A supplier calling a feature “AI security” is not evidence that it is necessary or suitable.
Specify the footage the pharmacy must recover
Image resolution on a quotation is not an outcome. Build several acceptance scenarios and state what must be visible. Can an authorised user follow a person from entrance to counter? Can they distinguish the relevant handover? Can they see the direction of travel and sequence of events? Does the image remain useful under reflections, backlighting, winter darkness or a changed shop display?
Synchronise the recorder, cameras, alarm and any access-control system to a dependable time source. A five-minute difference between systems can turn a clear event into an argument about sequence. Test search by date and time, playback, still export and video export. Confirm that exported footage can be opened on a controlled device without giving the recipient access to the live system.
Document the evidential route: who may preserve footage, how they record the reason, where the copy is stored, how integrity is protected, how disclosure is approved and when the copy is deleted. The ICO’s post-deployment governance guidance also covers access, rights requests and third-party disclosure.
Set retention from the purpose, not the disk size
There is no universal CCTV retention period that every pharmacy should copy. The ICO’s surveillance principles state that the purpose should determine what is necessary. Define an ordinary rolling period, explain why it is long enough for incidents to be recognised and reported, and create a separate controlled process for preserving a relevant clip.
Do not let a larger hard drive silently extend retention. Configure overwrite behaviour, monitor storage health and include the actual setting in the periodic review. If different cameras genuinely need different periods, record why; convenience alone is not a strong reason.
Control live view, playback and export
List the roles that need each capability. A colleague who needs to view the entrance may not need permission to search months of footage, export clips or change camera settings. Use named accounts where the product allows them, remove default credentials, enable multi-factor authentication for remote or cloud access where available and review accounts when people change role or leave.
Place monitors so the public cannot watch staff, patients or restricted areas. Avoid using a shared reception display as an uncontrolled live feed. Keep an access log or equivalent record for playback, export and administration, and train authorised users to recognise a subject access request or a request from the police, insurer, solicitor or another organisation.
Secure the cameras as networked devices
IP cameras, recorders, cloud portals and mobile apps are part of the pharmacy’s technology estate. Put them on an appropriate network segment, change default credentials, restrict administrative access, disable unneeded remote services and confirm how security updates are delivered. Record the models, serial numbers, firmware, support dates and supplier contacts in the asset register.
The NCSC’s smart-camera guidance is written for domestic users, but its warnings about default passwords, firmware and unnecessary remote access remain useful technical prompts. Apply them within the pharmacy’s professional IT and information-governance controls. Our pharmacy cybersecurity guide explains how connected devices fit a wider owner-level security programme.
Compare suppliers on the whole operating model
Give every bidder the same incident scenarios and site plan. Ask each one to state what is included in the camera, recorder, cabling, networking, power protection, cloud subscription, mobile access, monitoring, maintenance, export support and end-of-support arrangements.
- Who is the data processor for hosted footage, and where is it stored?
- What happens to recordings and administrator access when the contract ends?
- Which functions require an ongoing licence, and what stops working if it lapses?
- How quickly can a failed camera, disk or recorder be diagnosed and replaced?
- Who can remotely administer the system, and how is that access authenticated and logged?
- Can footage be exported in a usable format without proprietary software or watermark confusion?
Compare whole-life cost over the expected service period: survey, equipment, installation, network work, storage, licences, monitoring, maintenance, replacement, training and secure decommissioning. A low installation price can conceal a system that is hard to operate or expensive to leave.
Test the response before accepting the system
Run a tabletop and a live retrieval exercise. Give an authorised colleague a time window and incident description. Observe whether they can find the correct view, preserve the relevant period, export it, record the action and follow the escalation path without calling the installer for every step.
Then test failure: one camera offline, the recorder full, the network unavailable, an administrator absent and a request arriving outside normal hours. Record defects, assign owners and repeat the test after correction. Add the system to the pharmacy’s change control so refits, new services, counter moves and network upgrades trigger review.
Pharmacy Mentor helps owners connect premises, digital systems and service growth into one operating model. Explore our pharmacy business strategy support or speak to the team about your next growth decision.

