CCTV retention period: what the laws say
No text held here sets a number of days for CCTV footage. What they set is a test: keep it no longer than the purpose needs, write the period down, and tell people what it is. Any number of days you use is your own.
- GDPR and UK GDPR
- Art. 5: kept in identifiable form no longer than the purpose requires (storage limitation). No fixed number of days; the EDPB Guidelines on video devices are named, not quoted.
- BIPA (face matching in Illinois)
- 15(a): a written retention schedule, made public, with destruction when the purpose is met or within three years of the last interaction, whichever comes first.
- Australian Privacy Principles
- APP 11: destroy or de-identify personal information when it is no longer needed.
- CCPA
- 1798.100: disclose the retention period or the criteria, and keep it no longer than reasonably necessary.
- In the mapper
- You set your own maximum. A camera strictly above it raises finding 5, labelled "the maximum you set, not a legal limit"; exactly the maximum does not. A camera with no retention recorded raises it whether or not you set a maximum.
The clauses
GDPR Art. 5Principles relating to processing of personal dataPrinciples relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
UK GDPR Art. 5Principles relating to processing of personal dataArticle 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
BIPA s. 15(a)Written, public retention schedule and destruction guidelines, appliedWritten, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.
APP APP 11Security of personal informationAPP 11 - Security of personal information. Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.
CCPA s. 1798.100General duties of a business that collects personal informationGeneral Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.