Vendor-neutral guide · 8 min read

UK GDPR and remote session recording: lawful basis, transparency, retention

Written by the 247connect Marketing Team

Shape of the topic

A standards clause list linked to a shield of controls and an evidence file with an audit tick.A standards clause list linked to a shield of controls and an evidence file with an audit tick.
A control, the evidence for it, and a reviewer who signs it off: that chain is what an audit actually looks at.

In short

Recording remote support sessions and keeping access logs is good security practice, but the moment those recordings capture information about an identifiable person, whether the user being supported, the operator, or a third party visible on screen, they become personal data and UK GDPR applies. That does not mean recording should stop; it means the organisation needs a lawful basis for it, has to be transparent about it, and needs a sensible retention period rather than keeping everything indefinitely. This guide sets out what those requirements mean in practice for remote session recording and logging.

Key takeaways

  • Session recordings and access logs that identify a person are personal data under UK GDPR, even when the primary purpose is security.
  • Legitimate interests is the lawful basis most commonly relied on for security-related session recording, but it requires a documented balancing test.
  • Transparency means telling staff and users that sessions may be recorded, not just having a policy that exists somewhere unread.
  • Retention periods should be set deliberately and justified, not left as indefinite by default.
  • Data minimisation applies to recordings too: only capture what is needed for the stated purpose.
  • Organisations should confirm their specific lawful basis and retention decisions with their own data protection officer or adviser, since circumstances vary.

When a session recording becomes personal data

UK GDPR applies to personal data, meaning any information relating to an identified or identifiable living person. A recording of a remote support session will usually show the operator's actions, and it may also show content on the user's screen, such as their name, an email address, or other identifying detail. Even keystroke or session metadata logs, showing which named account connected to which device and when, count as personal data about the operator at minimum.

This means session recordings cannot be treated purely as a technical or security artefact sitting outside data protection law. They need the same basic groundwork as any other processing of personal data: a lawful basis, a fair and transparent explanation to the people affected, and a defined retention period.

Choosing a lawful basis

There are six lawful bases under UK GDPR, and for security-related session recording, legitimate interests is the one most commonly used, since consent is often impractical for something an organisation needs to do consistently and a contract basis rarely fits neatly. Legitimate interests requires a documented balancing exercise: identifying the interest being pursued, such as security, accountability and fraud prevention, checking that recording is necessary to achieve it, and weighing that against the impact on the individuals being recorded.

Where an employer records staff sessions for support or security purposes, the balancing test needs to take the employment context seriously, since staff have a reasonable expectation of some monitoring for legitimate business reasons but not of open-ended surveillance. Recording that is proportionate, limited to support and security purposes, and clearly communicated is far easier to justify than recording that goes beyond what those purposes need.

  • Identify the specific interest that recording serves, not a general reference to security
  • Check that recording is a necessary and proportionate way to achieve that interest
  • Document the balancing test rather than relying on an unwritten assumption

Being transparent about recording

The transparency principle requires that people are told, in clear and accessible language, that their sessions may be recorded, why, and for how long the recording is kept. For staff, this is usually done through an IT acceptable use policy or a monitoring policy referenced in the employment contract or staff handbook. For external users receiving remote support, a short, visible notice at the point a session starts is good practice and helps meet the fairness requirement, since consent to the session and awareness of recording are different things.

A policy that exists on an intranet page nobody reads does not, on its own, satisfy transparency in a meaningful sense, even if it technically ticks a box. Practical transparency measures, such as an on-screen notification when a session is being recorded, do more to meet the spirit of the requirement than a buried clause.

  • Reference session recording clearly in staff monitoring or acceptable use policies
  • Show a visible on-screen notice when an external support session is recorded
  • Keep the explanation of why sessions are recorded specific and understandable

Retention: how long is too long

UK GDPR's storage limitation principle requires personal data to be kept no longer than necessary for the purpose it was collected for. For session recordings and access logs, that purpose is usually security assurance, incident investigation and audit evidence, which suggests a retention period long enough to support those activities but not indefinite. Many organisations settle on a period in the range of a few months to a couple of years depending on sector requirements, but the right figure depends on the organisation's own risk profile and any sector-specific obligations, such as those in health or financial services.

What matters most is that the retention period is a deliberate decision, written down, and applied consistently, with recordings deleted or anonymised once the period expires rather than accumulating by default because nobody set a limit. Retaining logs for a specific, justified minimum period to support incident investigation, then reviewing whether a longer commercial or contractual need exists, is a defensible approach.

Minimisation and access to recordings

Data minimisation means capturing only what the stated purpose requires. If session metadata, such as operator, device, time and duration, is enough to satisfy the audit and security purpose, full video recording of every session may go further than necessary, particularly for routine, low-risk support activity. Where full recording is used, restricting who can view the content of recordings, separate from who can see that a session simply took place, keeps access proportionate.

Tools that separate session audit logs from full session recording, such as 247connect's session logging, give organisations a way to meet the audit and accountability purpose with less personal data than full video capture would require, though the right balance always depends on the specific risk being addressed.

Best-practice checklist

  1. 1. Decide what is actually being captured

    Distinguish between session metadata logs and full video or content recording, since they carry different privacy weight.

  2. 2. Document the lawful basis

    Write a legitimate interests assessment, or identify another applicable basis, and keep the record on file.

  3. 3. Update monitoring and acceptable use policies

    Make sure staff-facing policies clearly describe that remote sessions may be recorded or logged, and why.

  4. 4. Add a visible notice for external users

    Show an on-screen indication that a support session is being recorded before or as it begins.

  5. 5. Set and document a retention period

    Agree a specific retention period for recordings and logs, justified against the security and audit purpose, and write it down.

  6. 6. Restrict access to recording content

    Limit who can view full session recordings separately from who can see that a session occurred, based on role.

  7. 7. Build in deletion at the end of the retention period

    Confirm recordings are actually deleted or anonymised once the retention period ends, rather than accumulating indefinitely.

Common pitfalls

  • Recording every session in full when metadata logging would meet the same purpose
  • Relying on an unwritten assumption of legitimate interests rather than a documented assessment
  • Burying the recording notice in a policy nobody reads, rather than making it visible in practice
  • Keeping recordings indefinitely because no retention period was ever agreed
  • Giving broad access to session recording content rather than restricting it to those who need it

What to measure

Metrics for UK GDPR & session recording
Retention period defined and documentedYes or no, with a specific figure
Legitimate interests assessment on fileShould exist and be reviewed periodically
Recordings deleted after retention periodTrack compliance against the documented schedule
Staff aware of monitoring policyConfirm through induction or periodic communication

Select any column heading to sort.

Frequently asked questions

Do we need consent to record a remote support session?
Not necessarily. Consent is one lawful basis among six under UK GDPR, but for routine security-related recording, legitimate interests is often more practical and appropriate, provided a documented balancing test supports it. Consent may still be relevant for the separate question of a user agreeing to the support session itself.
How long should we keep remote support session recordings?
There is no single fixed figure in UK GDPR; the storage limitation principle requires keeping data no longer than necessary for its purpose. Many organisations set a period of a few months to a couple of years based on their security and audit needs, but the right figure should be documented and justified against your own circumstances, ideally with input from your data protection officer.
Is a session access log the same thing as personal data?
Yes, if it identifies who connected, since a log showing a named operator account, the device accessed, and the time and duration relates to an identifiable person and falls within UK GDPR even without any screen content being recorded.
Do we have to tell staff their remote sessions might be recorded?
Yes, transparency is a core UK GDPR principle, so staff should be told through a clear monitoring or acceptable use policy, ideally reinforced with practical measures such as an on-screen indicator, rather than left to infer it from small print.
Can session recordings be used for something other than security, such as performance management?
Only if that further use is compatible with the original purpose and has been communicated, since UK GDPR's purpose limitation principle restricts using data collected for one purpose for an unrelated one without proper justification and transparency.

Sources

Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.

Putting it into practice

This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.

More best-practice guides