Video Surveillance Compliance Guide

AegisGates Vision AI | Platinum Health Equipment Pty Ltd
Version 1.0 | Effective: April 23, 2026

CRITICAL NOTICE

YOU ARE RESPONSIBLE for compliance with video surveillance laws in your jurisdiction. This guide provides general information but is NOT legal advice. Consult a lawyer before deploying cameras.

1. General Principles

1.1 Core Requirements (Most Jurisdictions)

2. Jurisdiction-Specific Requirements

2.1 Australia

Privacy Act 1988 (Australian Privacy Principles - APPs)

Key Principles:

Signage Requirements:

State-Level Surveillance Device Acts

State Act Key Requirements
New South Wales Surveillance Devices Act 2007 Generally lawful if participant or signage posted; audio recording requires all-party consent in private conversations
Victoria Surveillance Devices Act 1999 Similar to NSW; stricter for audio surveillance
Queensland Invasion of Privacy Act 1971 Prohibits surveillance of private activities; signage required
Western Australia Surveillance Devices Act 1998 Consent or lawful purpose required
South Australia Surveillance Devices Act 2016 Consent or reasonable grounds required

Workplace Surveillance

State Act Requirements
NSW Workplace Surveillance Act 2005 14-day notice to employees; restrict to work areas only
ACT Workplace Privacy Act 2011 Similar to NSW
Best Practices for Australia:
  1. Post visible signage at all entrances
  2. Notify employees in writing 14 days before workplace monitoring
  3. Restrict cameras to work areas (not bathrooms, break rooms)
  4. Implement access controls (only authorized personnel)
  5. Delete footage after 30 days unless needed for incident investigation

2.2 European Union (GDPR)

Legal Basis (Article 6)

Must have ONE of:

Key GDPR Requirements

Article Requirement Action
Article 5 Data minimization Limit camera coverage to necessary areas
Article 13 Transparency Post multilayer privacy notice (signage + detailed policy)
Article 35 DPIA (Data Protection Impact Assessment) Required for large-scale systematic monitoring
Article 15-22 Data subject rights Provide access, deletion, portability
Article 32 Security Encryption, access controls, breach response plan

GDPR Signage Requirements

Layer 1 (Immediate Notice):

Layer 2 (Detailed Notice):

Prohibited Cameras:

Fines for Non-Compliance: Up to €20 million or 4% of global annual turnover (whichever is higher)

2.3 United States

Federal Laws

State Biometric Privacy Laws

State Law Requirements
Illinois Biometric Information Privacy Act (BIPA) Written consent + retention policy for facial recognition
Texas Capture or Use of Biometric Identifier (CUBI) Notice required; consent for commercial use
Washington Biometric Privacy Law Notice + consent for enrollment in biometric system
California CCPA/CPRA Privacy policy disclosure + opt-out rights
BIPA Example (Illinois):
  1. Publish written policy on biometric data retention
  2. Obtain written consent BEFORE collecting facial images
  3. Delete biometric data when purpose expires or within 3 years
  4. Private right of action ($1,000-$5,000 per violation)

2.4 United Kingdom (UK GDPR)

ICO CCTV Code of Practice - 12 Guiding Principles:

  1. Use CCTV only for specified, lawful purposes
  2. Assess whether CCTV is necessary and proportionate
  3. Be clear about your purposes
  4. Inform people of CCTV (signage)
  5. Respect privacy rights
  6. Ensure images are not excessive or kept longer than necessary
  7. Secure cameras and recordings
  8. Respond to access requests (within 1 month)
  9. Ensure staff are trained and supervised
  10. Conduct regular reviews
  11. Document compliance (DPIA if high-risk)
  12. Respond to complaints

Retention Period: ICO guidance: Generally 31 days unless incident investigation required

2.5 Canada (PIPEDA)

Personal Information Protection and Electronic Documents Act (PIPEDA)

3. High-Risk Scenarios

3.1 Biometric Recognition (Facial, Gait, License Plate)

Extra Requirements:

Recommendation: AegisGates utilizes Scene and Activity analysis. We do not maintain biometric databases or identify specific individuals by face. Ensure your AI "Special Attentions" settings comply with local privacy expectations.

3.2 Workplace Monitoring

Employee Notices Required:

Prohibited Areas: Bathrooms, changing rooms, break rooms, union meeting spaces

4. Compliance Checklist

Pre-Deployment

During Deployment

Post-Deployment

5. Signage Template

⚠️ VIDEO MONITORING IN PROGRESS

This area is monitored by AI-powered surveillance for [SECURITY / SAFETY / OPERATIONAL] purposes.

Operator: [YOUR COMPANY NAME]
Contact: [EMAIL / PHONE]
Retention: [X] days
Privacy Policy: [URL]

By entering, you consent to being recorded.

6. Resources

Regulatory Authorities

Jurisdiction Authority Website
Australia Office of the Australian Information Commissioner (OAIC) oaic.gov.au
EU European Data Protection Board (EDPB) edpb.europa.eu
UK Information Commissioner's Office (ICO) ico.org.uk
US (Federal) Federal Trade Commission (FTC) ftc.gov
California California Privacy Protection Agency (CPPA) cppa.ca.gov
Canada Office of the Privacy Commissioner of Canada (OPC) priv.gc.ca

7. Contact AegisGates Support

Legal/Compliance Questions: [email protected]
Privacy/GDPR Requests: [email protected]
Technical Support: [email protected]

Disclaimer: This guide is for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. Consult a licensed attorney in your jurisdiction before deploying video surveillance systems.

Document History

Version Date Changes
1.0 April 23, 2026 Initial release

Document Owner: Legal & Compliance Team, Platinum Health Equipment Pty Ltd