CCTV Privacy Law Mapper
Regimes

California Consumer Privacy Act (CCPA, as amended by the CPRA)

For CCTV at a California site: notice at or before the point of collection with the categories, purposes and retention (1798.100 and 1798.130(a)(5)(C)), collection and retention reasonably necessary and proportionate (1798.100(c)), a written contract with a service provider or contractor that receives the footage (1798.100(d)) and the right to limit the use of sensitive personal information (1798.121). Whether a face template is sensitive personal information is decided by the Act's definitions, which are named here and not stated.

Where it is placed
Placed for sites in California, and only when you say the business meets the CCPA thresholds; on "not sure" its lines read as questions.
Date last read
29 Sep 2026
Clauses cited
5 of 30 held
The standard itself
California Consumer Privacy Act (CCPA, as amended by the CPRA) on compliance.theartofservice.com
Places
California

Clauses cited, and the findings that cite them

ClauseTitleFindings
CCPA s. 1798.100General duties of a business that collects personal information5, 6
CCPA s. 1798.100(c)Data minimisation, necessity and proportionality10, 11
CCPA s. 1798.100(d)Contractual Requirements for Third Parties, Service Providers, and Contractors8
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information1
CCPA s. 1798.130(a)(5)(C)Notice at Collection6
CCPA s. 1798.100General duties of a business that collects personal information

General Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.

What a reviewer asks to see: Notice at collection text on web forms and physical points of collection; Privacy policy disclosures of categories and purposes; Data inventory mapping categories to purposes and retention periods; Information security program documentation; Retention schedule with criteria and disposal evidence
Where camera lists usually fall short: No notice at offline collection points; Purposes described vaguely (e.g. business operations); Retention periods absent or stated as indefinite; Security controls not mapped to PI categories
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.100(c)Data minimisation, necessity and proportionality

Data Minimisation, Necessity and Proportionality. A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.

What a reviewer asks to see: Record of processing showing, per data element, the purpose it was collected for; Documented necessity and proportionality assessment for each collection purpose; Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds; Compatibility analysis for any secondary use, referencing the context of collection; Approval record showing a new use was assessed before it went live
Where camera lists usually fall short: A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose; Necessity assessed once at launch and never revisited as the product changed; Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner; Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected; Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.100(d)Contractual Requirements for Third Parties, Service Providers, and Contractors

Contractual Requirements for Third Parties, Service Providers, and Contractors. A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.

What a reviewer asks to see: Service provider/contractor agreements containing all required CCPA clauses; Third party data sharing agreements; Vendor inventory classifying each recipient (service provider, contractor, third party); Audit/inspection records; Subcontractor flow-down clauses
Where camera lists usually fall short: Legacy vendor contracts missing CPRA-required clauses; No classification of recipient role; No audit rights exercised; Combining-data prohibitions absent
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information

Right to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.

What a reviewer asks to see: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation; Use restriction enforcement controls
Where camera lists usually fall short: No separate sensitive PI inventory; Limit mechanism not offered when uses go beyond permitted purposes; Permitted purpose claimed without documentation
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.130(a)(5)(C)Notice at Collection

Notice at Collection. At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.

What a reviewer asks to see: Notice text displayed on forms, mobile app onboarding, point-of-sale, telephone scripts; Offline notice via signage or printed handout; Retention disclosures per category; Sale/share disclosure
Where camera lists usually fall short: Notice exists only in main privacy policy; Offline collection (call centers, in-store) lacks notice; Retention disclosed only as 'as long as necessary'
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

See the specimen list run Map your own list