Resources 7 min read

Recording, Privacy and the Law

Surveillance creates a record of where identifiable people were and when. Which obligations attach depends on whether you record audio, whether you identify individuals, and which sector rules apply to you. The questions that decide it, and the three places organizations most often get it wrong.

Blurred conference room with professionals and holographic data network overlays depicting global security analytics.

Video surveillance creates a record of where identifiable people were and when. That record is useful, which is the point, and it also carries obligations that vary by what you record, where you operate and who appears in the footage. This page sets out the questions that decide those obligations, and the three places organizations most often get them wrong.

It is general information about a complicated area, not legal advice. The specifics for your organization are a question for your counsel.

What the obligation is

Audio is a different question from video

The most common and most avoidable mistake is enabling microphones without thinking about it. Federal wiretap law addresses the interception of oral communications. 18 U.S.C. 2511 provides that it is not unlawful for a person not acting under color of law to intercept an oral communication where that person is a party to the communication, or "where one of the parties to the communication has given prior consent to such interception," unless the interception is for the purpose of committing a criminal or tortious act. State law is not identical to federal law, and several states are stricter about consent. Recording audio therefore raises a question that recording video alone does not, and it is a question to answer before installation rather than after a complaint.

The practical consequence: most organizations turn microphones off, and record video only.

Footage of identifiable people can be regulated personal information

Where a consumer privacy statute applies, footage may fall within it. The California Consumer Privacy Act, as amended by Proposition 24, gives consumers rights over the personal information a business collects about them, including the right to know what is collected and how it is used and shared, the right to delete it with exceptions, the right to correct inaccurate information, and the right to limit the use and disclosure of sensitive personal information.

That last category matters here, because the California Attorney General lists "biometric information processed to identify a consumer" as sensitive personal information. Ordinary recorded video is not automatically biometric information; running face recognition against it to identify individuals is a different activity with a different footing. Some states also regulate biometric identifiers through statutes of their own, with their own notice and consent requirements. If face recognition is under discussion, that is the point at which counsel should be involved rather than after deployment.

Sector rules add their own requirements

Regulated organizations frequently have obligations that surveillance touches directly. The HIPAA Security Rule requires covered entities to implement facility access controls, that is "policies and procedures to limit physical access to its electronic information systems and the facility or facilities in which they are housed, while ensuring that properly authorized access is allowed." Surveillance is one way organizations evidence that, and footage of clinical areas simultaneously creates a record that has to be protected. Schools have their own position, covered in video surveillance for schools and campuses.

What it means in practice

  • Record video, not audio, unless you have a specific reason and specific advice. Confirm microphones are disabled in the camera configuration rather than assuming the model has none.
  • Put cameras where the security purpose is, and not elsewhere. Restrooms, changing areas and similar spaces are not defensible locations under any reading, and the argument that a camera merely covers the corridor outside should be made deliberately rather than discovered later.
  • Tell people. Signage at entrances is standard practice, cheap, and often relevant to whether an expectation of privacy existed. It also reduces the number of conversations you will have about it.
  • Treat face recognition as a separate decision. It is not a feature you enable, it is a category of processing. Beyond the legal position, the accuracy question is real: NIST evaluated 189 algorithms from 99 developers against 18.27 million images and found that "across demographics, false positives rates often vary by factors of 10 to beyond 100 times," while false negatives "tend to be more algorithm-specific" and vary by smaller factors. That study was published in December 2019 and algorithms have moved since, but the finding that error rates are not uniform across demographic groups is the reason a false match carries a fairness problem as well as an operational one.
  • Keep footage for a defined period and then let it go. Indefinite retention increases what a breach or a subpoena reaches, with no security benefit after the point at which incidents are reported.
  • Control export as tightly as viewing. An exported clip leaves your systems and your controls. Viewing and exporting should be separate permissions and export should be logged.

Who is accountable

Surveillance sits across four functions, and the gaps between them are where the problems occur.

  • Legal or compliance decide what may be recorded, for how long, and under what notice, and are the only people who can answer the audio and face recognition questions for your jurisdictions.
  • Security or facilities own camera placement and the purpose of each view.
  • IT own access, retention enforcement and the security of the footage itself, covered in video surveillance security and risk.
  • HR own the employee-facing side, since staff appear in the footage more than anyone else and monitoring of employees carries its own considerations.

One person should own the policy as a document, even though no single function owns the subject.

How to evidence it

  1. Write a surveillance policy stating purpose, camera locations by area, retention period, who may view, who may export, and how requests for footage are handled.
  2. Keep the camera purpose list. A stated reason per camera is the clearest evidence that placement was considered rather than incidental.
  3. Log access and export so that any disclosure of footage is attributable after the fact.
  4. Enforce retention technically, not by intention. If the policy says 30 days, the system should overwrite at 30 days.
  5. Document the signage, including where it is and when it was put up.
  6. Record the decisions you took about audio and about face recognition, including the decision not to use them. A decision not taken looks identical to a decision never considered.
  7. Review annually, and whenever you add cameras, add a site, or change what the system does.

LABUSA can document what your current system records, where and for how long, as part of a site assessment, which is usually the missing input to a policy. Request a free site security assessment. See also what video surveillance is for the components involved, and our video surveillance solutions. The hospitality case, where the notice question is sharpest and the audio question is easiest to get wrong, is treated in video surveillance for hotels and hospitality.

Sources

  • Legal Information Institute, Cornell Law School, 18 U.S.C. 2511. Establishes the quoted federal consent provision for the interception of oral communications, the basis for treating audio separately from video. law.cornell.edu. Accessed 18 August 2026.
  • California Attorney General, California Consumer Privacy Act (CCPA). Establishes the consumer rights listed and the classification of biometric information processed to identify a consumer as sensitive personal information. oag.ca.gov. Accessed 18 August 2026.
  • Electronic Code of Federal Regulations, 45 CFR 164.310, Physical safeguards. Establishes the quoted facility access controls standard under the HIPAA Security Rule. ecfr.gov. Accessed 18 August 2026.
  • National Institute of Standards and Technology, IR 8280, Face Recognition Vendor Test Part 3: Demographic Effects, December 2019. Establishes the quoted finding on demographic variation in false positive rates, and the scale of the evaluation. nvlpubs.nist.gov. Accessed 18 August 2026.

About LABUSA

LABUSA is a managed service provider that enables organizations to build a robust digital business model. We provide managed services through an open hybrid cloud strategy integrating public, private, and on-premises computing systems with intelligent edge devices. The company is ISO 9001:2015 certified and our solution extends the information technology environment's efficiency, security, reliability, and cost-effectiveness.

For more Information Contact LABUSA at

+1-281-393-8003