When Home Business CCTV Stops Being “Purely Personal or Household”

05/07/2026

Have you noticed the increase of “cake sheds” in your area? It seems every week another one pops up on local social media groups.

Home businesses are booming. Whether it’s a side hustle or the start of something much bigger, garden bakeries, honesty shops, home salons and dog grooming cabins are becoming an increasingly familiar sight in communities across the UK.

As someone who loves seeing small businesses succeed, I think it’s fantastic.

Many of these businesses have invested in CCTV to protect themselves, their property and their livelihoods.

This week’s Facebook post…

This week I came across a Facebook post from a home business owner explaining that they were going to review their CCTV after cakes had allegedly gone missing.

The owner explained that they trusted their customers but simply weren’t breaking even and needed to identify who was responsible.

It made me stop and think.

To identify one suspected cake thief, they would potentially need to review footage containing hundreds of other customers, passers-by and perhaps even children accompanying their parents.

That raises a much bigger question than simply…

“Who took the cake?”

It raises the question:

At what point does home CCTV stop being a purely personal or household activity and become subject to UK GDPR?

“Privacy gone mad? Surely GDPR doesn’t apply to a cake shed…”

At first glance, it might seem that way.

After all, we’re talking about someone selling a few cakes from a shed in their garden.

Surely UK GDPR wasn’t written with that in mind?

The answer is… probably not.

However, UK GDPR wasn’t written specifically for cake sheds, beauty cabins or home dog grooming businesses. It was written to protect people’s personal data wherever it is processed.

The real question therefore isn’t what you’re selling.

It’s how you’re processing other people’s personal data whilst doing it.

One of the most common assumptions I hear is:

“It’s my house, so GDPR doesn’t apply.”

Sometimes that’s true.

Sometimes it isn’t.

The household exemption

Article 2(2)(c) UK GDPR provides that the legislation does not apply to:

“…the processing of personal data by a natural person in the course of a purely personal or household activity.”

This is commonly referred to as the household exemption.

If your CCTV genuinely records only activity within your own domestic environment for purely personal purposes, UK GDPR is unlikely to apply.

But the exemption isn’t unlimited.

What do the Courts say?

One of the most significant decisions on the household exemption is the pre-Brexit Court of Justice decision in Case C-212/13, Ryneš.

The Court of Justice considered a homeowner who had installed CCTV following repeated attacks on his property. Although the camera was installed at his home, it also captured part of the public street outside.

The Court held that because the camera recorded beyond the boundaries of the private property, the processing was no longer carried out “in the course of a purely personal or household activity.” As a result, the household exemption did not apply.

More recently, principles discussed in Ryneš have subsequently been reflected in England and Wales in cases such as Fairhurst v Woodard [2021] 10 WLUK 151, where the Court considered the application of UK GDPR to domestic CCTV and smart doorbell systems.

This case involved a domestic CCTV system and smart doorbell which recorded areas beyond the owner’s property, including neighbouring land and shared spaces. The court found that the surveillance fell within the scope of UK GDPR and considered issues such as transparency, proportionality and the extent of the recording.

Neither case says that homeowners cannot install CCTV.

Instead, they demonstrate that whether UK GDPR applies depends on how the system is used and what it records.

The rise of the cake shed

The principles established in Ryneš and Fairhurst are becoming increasingly relevant as home businesses continue to grow.

The line between home and business is becoming increasingly blurred.

That doesn’t mean every home business is automatically subject to UK GDPR. Equally, it doesn’t mean every CCTV system installed at a residential property benefits from the household exemption.

The answer will always depend on the facts.

The key question is whether the processing remains “purely personal or household”, or whether the CCTV is now being used in connection with commercial activities involving identifiable individuals.

So what should home business owners think about?

If your CCTV falls within the scope of UK GDPR, there are several practical questions worth considering.

These aren’t designed to discourage home businesses from using CCTV. They’re intended to help ensure surveillance is used responsibly and proportionately.

Final thoughts

The rise of the cake shed is something to celebrate. It’s fantastic to see so many people turning skills and hobbies into successful businesses.

But as the line between home and business becomes increasingly blurred, so too can the legal position.

If you’re using CCTV to support your business, whether that’s monitoring customer collections, deliveries or protecting stock, it may be time to consider whether your CCTV has moved beyond purely domestic use and whether UK GDPR now applies.

Because sometimes the most important question isn’t who took the cake.

It’s whether your CCTV is still being used as a purely personal or household activity.

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…