CCTV Privacy Law Mapper
Retention

CCTV retention period: what the laws say

No text held here sets a number of days for CCTV footage. What they set is a test: keep it no longer than the purpose needs, write the period down, and tell people what it is. Any number of days you use is your own.

GDPR and UK GDPR
Art. 5: kept in identifiable form no longer than the purpose requires (storage limitation). No fixed number of days; the EDPB Guidelines on video devices are named, not quoted.
BIPA (face matching in Illinois)
15(a): a written retention schedule, made public, with destruction when the purpose is met or within three years of the last interaction, whichever comes first.
Australian Privacy Principles
APP 11: destroy or de-identify personal information when it is no longer needed.
CCPA
1798.100: disclose the retention period or the criteria, and keep it no longer than reasonably necessary.
In the mapper
You set your own maximum. A camera strictly above it raises finding 5, labelled "the maximum you set, not a legal limit"; exactly the maximum does not. A camera with no retention recorded raises it whether or not you set a maximum.

The clauses

GDPR Art. 5Principles relating to processing of personal data

Principles relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where camera lists usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
UK GDPR Art. 5Principles relating to processing of personal data

Article 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What a reviewer asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
Where camera lists usually fall short: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR, read 29 Sep 2026
BIPA s. 15(a)Written, public retention schedule and destruction guidelines, applied

Written, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.

What a reviewer asks to see: The published retention and destruction policy (web page or posted notice) with its retention schedule and the destruction trigger of purpose satisfied or three years since last interaction; Destruction records showing the schedule is followed, including for departed employees and closed customer accounts; Any warrant or subpoena relied on to retain data past the schedule
Where camera lists usually fall short: A retention policy that exists internally but was never made available to the public; No destruction of employee templates after termination, so three-year clocks run out unnoticed; A vendor holding the templates with no policy published by the entity that uses them
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
APP APP 11Security of personal information

APP 11 - Security of personal information. Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.

What a reviewer asks to see: Information security controls for personal information; Destruction/de-identification of redundant PI
Where camera lists usually fall short: PI not secured; Redundant PI retained
Source: Australian Privacy Principles (APPs), read 29 Sep 2026
CCPA s. 1798.100General duties of a business that collects personal information

General Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.

What a reviewer asks to see: Notice at collection text on web forms and physical points of collection; Privacy policy disclosures of categories and purposes; Data inventory mapping categories to purposes and retention periods; Information security program documentation; Retention schedule with criteria and disposal evidence
Where camera lists usually fall short: No notice at offline collection points; Purposes described vaguely (e.g. business operations); Retention periods absent or stated as indefinite; Security controls not mapped to PI categories
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

See the specimen list run Map your own list