CCTV Privacy Law Mapper
Laws

CCTV privacy laws in California: what we map and name

What CCTV Privacy Law Mapper maps for a camera at a site in California, what it names without mapping, and what it leaves out. This is not every law that applies there.

Jurisdiction
California, United States
Laws placed
California Consumer Privacy Act (CCPA, as amended by the CPRA), when you say the business meets the CCPA thresholds; on "not sure" its lines read as questions
Date last read
Held and read 29 Sep 2026
Named, not quoted
California Penal Code, section 632; CCPA definition of sensitive personal information, 1798.140
Read from a list as
ca us, ca usa, cal, calif, california, us ca

Coverage here

Laws mapped and checked
Mapped
California Consumer Privacy Act (CCPA, as amended by the CPRA)
Named, not mapped
California Penal Code, section 632; CCPA definition of sensitive personal information, 1798.140
The national or state layer
State biometric, eavesdropping, wiretap and consumer privacy laws sit here; only those named on this page are named, and only BIPA and the CCPA are mapped anywhere in the United States.

Findings a camera here can raise

6 of the 18 can arise here

Named, not quoted

These are named so you know to open them. We do not hold their text in full and the page does not state what they require beyond the one line above.

The clauses cited here

5 clauses
CCPA s. 1798.100General duties of a business that collects personal information

General Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.

What a reviewer asks to see: Notice at collection text on web forms and physical points of collection; Privacy policy disclosures of categories and purposes; Data inventory mapping categories to purposes and retention periods; Information security program documentation; Retention schedule with criteria and disposal evidence
Where camera lists usually fall short: No notice at offline collection points; Purposes described vaguely (e.g. business operations); Retention periods absent or stated as indefinite; Security controls not mapped to PI categories
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.100(c)Data minimisation, necessity and proportionality

Data Minimisation, Necessity and Proportionality. A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.

What a reviewer asks to see: Record of processing showing, per data element, the purpose it was collected for; Documented necessity and proportionality assessment for each collection purpose; Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds; Compatibility analysis for any secondary use, referencing the context of collection; Approval record showing a new use was assessed before it went live
Where camera lists usually fall short: A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose; Necessity assessed once at launch and never revisited as the product changed; Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner; Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected; Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.100(d)Contractual Requirements for Third Parties, Service Providers, and Contractors

Contractual Requirements for Third Parties, Service Providers, and Contractors. A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.

What a reviewer asks to see: Service provider/contractor agreements containing all required CCPA clauses; Third party data sharing agreements; Vendor inventory classifying each recipient (service provider, contractor, third party); Audit/inspection records; Subcontractor flow-down clauses
Where camera lists usually fall short: Legacy vendor contracts missing CPRA-required clauses; No classification of recipient role; No audit rights exercised; Combining-data prohibitions absent
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information

Right to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.

What a reviewer asks to see: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation; Use restriction enforcement controls
Where camera lists usually fall short: No separate sensitive PI inventory; Limit mechanism not offered when uses go beyond permitted purposes; Permitted purpose claimed without documentation
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.130(a)(5)(C)Notice at Collection

Notice at Collection. At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.

What a reviewer asks to see: Notice text displayed on forms, mobile app onboarding, point-of-sale, telephone scripts; Offline notice via signage or printed handout; Retention disclosures per category; Sale/share disclosure
Where camera lists usually fall short: Notice exists only in main privacy policy; Offline collection (call centers, in-store) lacks notice; Retention disclosed only as 'as long as necessary'
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

See the specimen list run Map your own list