No retention period set, or retention above the maximum you set
No text held here sets a number of days for CCTV. GDPR and UK GDPR Art. 5 keep footage no longer than the purpose needs; BIPA 15(a) asks for a public retention schedule with destruction within three years of the last interaction at most; APP 11 asks for footage to be destroyed or de-identified when no longer needed; the CCPA asks for the retention period to be disclosed and no longer than reasonably necessary. The maximum used here is the maximum you set, not a legal limit.
- When it is raised
- Raised on a camera with no retention period recorded, or one strictly above the maximum you set (exactly the maximum does not raise it). With no maximum set, only a missing period raises it.
- The question
- What purpose sets this period, and where is it written down?
- For
- your privacy lead
- The column that settles it
- retention days
- On the row
- a numbered delta and the words "retention" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
GDPR (the EU General Data Protection Regulation)
GDPR Art. 5Principles relating to processing of personal dataPrinciples relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
UK GDPR
UK GDPR Art. 5Principles relating to processing of personal dataArticle 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
Illinois Biometric Information Privacy Act (BIPA)
BIPA s. 15(a)Written, public retention schedule and destruction guidelines, appliedWritten, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.
Australian Privacy Principles (APPs)
APP APP 11Security of personal informationAPP 11 - Security of personal information. Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.
California Consumer Privacy Act (CCPA, as amended by the CPRA)
CCPA s. 1798.100General duties of a business that collects personal informationGeneral Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.