Knowledge

Video Surveillance and Privacy Compliance

Recording people creates obligations, whatever the technology. This is an engineer's overview of what those obligations tend to require — not legal advice.

Not legal advice. This page describes common themes in privacy regulation as they affect video systems, to help you ask better questions. Obligations depend on jurisdiction, deployment and organisation. A qualified assessment for your own deployment is the only thing that settles it.

Video of identifiable people is personal data

This is the starting point under essentially every modern privacy regime. Footage in which a person can be recognised is personal data about them, which means someone is accountable for how it is collected, stored, shared and deleted — regardless of whether any AI is involved.

A useful early distinction: a system that detects that a person is present is doing something materially different from one that determines which individual they are. Facial recognition and re-identification are commonly treated as a heightened category with stricter conditions. Presence-based detection avoids that category entirely — it reduces sensitivity, though it does not remove the underlying obligation, because identifiable video is still being recorded.

India — the DPDP Act 2023

For deployments in India, the Digital Personal Data Protection Act 2023 is the operative law. Recurring themes relevant to video:

Europe — GDPR

GDPR applies where there is an EU establishment or EU data subjects. Its video-relevant themes overlap substantially with the above — lawful basis, transparency, minimisation, storage limitation, security, and subject rights including access and erasure. Two additional points come up repeatedly for camera systems: a Data Protection Impact Assessment is often expected for systematic monitoring of public or semi-public space, and biometric identification carries materially stricter conditions than presence detection.

Where these systems usually go wrong

In practice, non-compliance rarely looks like a dramatic misuse of data. It looks like:

Design choices that make compliance easier

Architecture can reduce obligations rather than merely documenting them:

A starting checklist

Where ManasaView fits

ManasaView is built so several of these questions have structural answers: processing and footage stay on the device, detection is presence-based rather than identity-based, retention is a configurable policy that genuinely deletes, and access requires a login. See also privacy by design in video AI. None of that constitutes compliance on your behalf — the deployment decisions and the assessment remain yours.

Frequently asked questions

Is CCTV footage personal data?

Where individuals are identifiable, yes — under GDPR, India's DPDP Act and most comparable regimes. That makes someone accountable for how it is collected, stored, shared and deleted, whether or not any analytics are applied.

Does using AI on video make compliance harder?

It depends what the AI does. Systems that identify specific individuals, such as facial recognition, are usually treated as a heightened category with stricter conditions. Systems that only detect that a person is present, without determining who, avoid that category — though the footage itself remains personal data.

Do I need signage for security cameras?

Transparency obligations generally mean people should know that recording is happening, and visible signage is the usual way to achieve that on premises. Effective signage typically also identifies who is responsible and how to contact them.

How long can I keep CCTV footage?

There is rarely a single fixed number. The principle is that personal data should not be kept longer than necessary for the stated purpose, so a documented, justified retention period that is actually enforced is what matters. Sector-specific rules may impose their own minimums or maximums.

Does keeping video on-site instead of the cloud help?

It removes a substantial class of questions about transfers, third-party processors and cross-border data flows, and reduces the number of parties who can access footage. It does not remove the underlying obligations around notice, purpose, retention and access control.

← Back to Knowledge