Video Surveillance Compliance Guide
AegisGates Vision AI | Platinum Health Equipment Pty Ltd
Version 1.0 | Effective: April 23, 2026
CRITICAL NOTICE
YOU ARE RESPONSIBLE for compliance with video surveillance laws in your jurisdiction. This guide provides general information but is NOT legal advice. Consult a lawyer before deploying cameras.
1. General Principles
1.1 Core Requirements (Most Jurisdictions)
- ✅ Lawful Purpose: Security, safety, operational efficiency (NOT harassment, discrimination)
- ✅ Transparency: Visible signage notifying people of monitoring
- ✅ Consent: Obtain consent where legally required (varies by jurisdiction)
- ✅ Proportionality: Monitor only what's necessary for the stated purpose
- ✅ Security: Protect footage from unauthorized access
- ✅ Retention Limits: Automated narrative deletion (90-day default)
- ✅ Access Rights: Search Export tool provided for Data Portability
2. Jurisdiction-Specific Requirements
2.1 Australia
Privacy Act 1988 (Australian Privacy Principles - APPs)
Key Principles:
- APP 3 (Collection): Must notify individuals that surveillance is occurring
- APP 5 (Transparency): Publish privacy policy explaining surveillance practices
- APP 11 (Security): Implement reasonable security measures
- APP 12 (Access): Allow individuals to access footage containing their image
Signage Requirements:
- Display notice BEFORE entering monitored area
- Include: purpose, contact details, privacy policy link
State-Level Surveillance Device Acts
| State |
Act |
Key Requirements |
| New South Wales |
Surveillance Devices Act 2007 |
Generally lawful if participant or signage posted; audio recording requires all-party consent in private conversations |
| Victoria |
Surveillance Devices Act 1999 |
Similar to NSW; stricter for audio surveillance |
| Queensland |
Invasion of Privacy Act 1971 |
Prohibits surveillance of private activities; signage required |
| Western Australia |
Surveillance Devices Act 1998 |
Consent or lawful purpose required |
| South Australia |
Surveillance Devices Act 2016 |
Consent or reasonable grounds required |
Workplace Surveillance
| State |
Act |
Requirements |
| NSW |
Workplace Surveillance Act 2005 |
14-day notice to employees; restrict to work areas only |
| ACT |
Workplace Privacy Act 2011 |
Similar to NSW |
Best Practices for Australia:
- Post visible signage at all entrances
- Notify employees in writing 14 days before workplace monitoring
- Restrict cameras to work areas (not bathrooms, break rooms)
- Implement access controls (only authorized personnel)
- Delete footage after 30 days unless needed for incident investigation
2.2 European Union (GDPR)
Legal Basis (Article 6)
Must have ONE of:
- Consent: Freely given, specific, informed (difficult for public spaces)
- Legitimate Interest: Security, fraud prevention (most common for businesses)
- Legal Obligation: Compliance with laws requiring surveillance
- Vital Interests: Protect life/health (e.g., hospital monitoring)
Key GDPR Requirements
| Article |
Requirement |
Action |
| Article 5 |
Data minimization |
Limit camera coverage to necessary areas |
| Article 13 |
Transparency |
Post multilayer privacy notice (signage + detailed policy) |
| Article 35 |
DPIA (Data Protection Impact Assessment) |
Required for large-scale systematic monitoring |
| Article 15-22 |
Data subject rights |
Provide access, deletion, portability |
| Article 32 |
Security |
Encryption, access controls, breach response plan |
GDPR Signage Requirements
Layer 1 (Immediate Notice):
- Camera icon or "CCTV" symbol
- Controller name and contact
- Purpose (e.g., "Security")
Layer 2 (Detailed Notice):
- Legal basis for processing
- Retention period
- Data subject rights
- Privacy policy URL or QR code
Prohibited Cameras:
- Toilets, changing rooms, medical areas
- Public streets (unless proportionate and justified)
- Neighboring private property
Fines for Non-Compliance: Up to €20 million or 4% of global annual turnover (whichever is higher)
2.3 United States
Federal Laws
- No federal video surveillance law (patchwork of state laws)
- Wiretap Act (18 USC §2511): Audio recording requires all-party or one-party consent depending on state
- Americans with Disabilities Act (ADA): Cannot discriminate in camera placement
State Biometric Privacy Laws
| State |
Law |
Requirements |
| Illinois |
Biometric Information Privacy Act (BIPA) |
Written consent + retention policy for facial recognition |
| Texas |
Capture or Use of Biometric Identifier (CUBI) |
Notice required; consent for commercial use |
| Washington |
Biometric Privacy Law |
Notice + consent for enrollment in biometric system |
| California |
CCPA/CPRA |
Privacy policy disclosure + opt-out rights |
BIPA Example (Illinois):
- Publish written policy on biometric data retention
- Obtain written consent BEFORE collecting facial images
- Delete biometric data when purpose expires or within 3 years
- Private right of action ($1,000-$5,000 per violation)
2.4 United Kingdom (UK GDPR)
ICO CCTV Code of Practice - 12 Guiding Principles:
- Use CCTV only for specified, lawful purposes
- Assess whether CCTV is necessary and proportionate
- Be clear about your purposes
- Inform people of CCTV (signage)
- Respect privacy rights
- Ensure images are not excessive or kept longer than necessary
- Secure cameras and recordings
- Respond to access requests (within 1 month)
- Ensure staff are trained and supervised
- Conduct regular reviews
- Document compliance (DPIA if high-risk)
- Respond to complaints
Retention Period: ICO guidance: Generally 31 days unless incident investigation required
2.5 Canada (PIPEDA)
Personal Information Protection and Electronic Documents Act (PIPEDA)
- Consent: Required unless reasonable person would expect surveillance (e.g., retail store security)
- Notice: Clear signage at entrances
- Purpose Limitation: Use footage only for stated purpose
- Retention: Delete after 30 days unless incident under investigation
- Access Rights: Provide copies of footage upon request
3. High-Risk Scenarios
3.1 Biometric Recognition (Facial, Gait, License Plate)
Extra Requirements:
- GDPR: DPIA required (Article 35)
- BIPA (Illinois): Written consent + retention policy
- CCPA (California): Privacy policy disclosure + opt-out right
Recommendation: AegisGates utilizes Scene and Activity analysis. We do not maintain biometric databases or identify specific individuals by face. Ensure your AI "Special Attentions" settings comply with local privacy expectations.
3.2 Workplace Monitoring
Employee Notices Required:
- Australia: 14 days' written notice (NSW, ACT)
- EU: Worker consultation, labor union notification
- US: Varies by state; best practice is written notice
Prohibited Areas: Bathrooms, changing rooms, break rooms, union meeting spaces
4. Compliance Checklist
Pre-Deployment
- Identify legal basis for surveillance (consent, legitimate interest, etc.)
- Conduct DPIA (if GDPR applies or high-risk)
- Consult legal counsel
- Draft privacy policy and signage
- Obtain necessary consents (employees, customers, visitors)
- Configure retention periods in AegisGates dashboard
During Deployment
- Post signage at ALL entrances to monitored areas
- Restrict camera angles (avoid private areas, neighboring property)
- Test camera coverage (ensure proportionality)
- Configure access controls (who can view footage)
- Train staff on privacy responsibilities
Post-Deployment
- Log all access to footage
- Respond to data subject access requests using the **Search Export** tool
- Review narrative retention policy (System Default: 90 Days)
- Automated narrative cleanup enabled via AegisGates system
- Conduct annual privacy compliance audit
5. Signage Template
⚠️ VIDEO MONITORING IN PROGRESS
This area is monitored by AI-powered surveillance for [SECURITY / SAFETY / OPERATIONAL] purposes.
Operator: [YOUR COMPANY NAME]
Contact: [EMAIL / PHONE]
Retention: [X] days
Privacy Policy: [URL]
By entering, you consent to being recorded.
6. Resources
Regulatory Authorities
| Jurisdiction |
Authority |
Website |
| Australia |
Office of the Australian Information Commissioner (OAIC) |
oaic.gov.au |
| EU |
European Data Protection Board (EDPB) |
edpb.europa.eu |
| UK |
Information Commissioner's Office (ICO) |
ico.org.uk |
| US (Federal) |
Federal Trade Commission (FTC) |
ftc.gov |
| California |
California Privacy Protection Agency (CPPA) |
cppa.ca.gov |
| Canada |
Office of the Privacy Commissioner of Canada (OPC) |
priv.gc.ca |
7. Contact AegisGates Support
Legal/Compliance Questions: [email protected]
Privacy/GDPR Requests: [email protected]
Technical Support: [email protected]
Disclaimer: This guide is for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. Consult a licensed attorney in your jurisdiction before deploying video surveillance systems.
Document History
| Version |
Date |
Changes |
| 1.0 |
April 23, 2026 |
Initial release |
Document Owner: Legal & Compliance Team, Platinum Health Equipment Pty Ltd