{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/place-video-privacy-controls-at-capture-view-and-export/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/",
        "slug": "place-video-privacy-controls-at-capture-view-and-export",
        "url": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/place-video-privacy-controls-at-capture-view-and-export/"
        },
        "title": "Place video privacy controls at capture, viewing, and export",
        "summary": "Privacy controls act at different points in the video lifecycle. Map masking, access restriction, and redaction to the disclosure risk each control is intended to reduce.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:36:13+00:00",
        "modified_at": "2026-08-25T21:36:16+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 468,
        "potentially_affected": "Organizations recording people or private areas, especially where live viewing, investigations, evidence sharing, or public disclosure create different privacy risks.",
        "dse_recommendation": "Document the intended privacy boundary at capture, recording, viewing, and export, then test that each authorized and unauthorized workflow produces the expected result.",
        "primary_source": {
            "name": "Privacy in surveillance",
            "url": "https://whitepapers.axis.com/en-us/privacy-in-surveillance",
            "published_on": null,
            "authority": "Axis Communications"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> a privacy mask at the camera, an operator permission in the VMS, and redaction applied to an exported clip solve different problems. A design should identify when information must be hidden, who may reveal it, and whether an unmasked original may exist.</p>\n<h2>Source fact: privacy controls can act at several stages</h2>\n<p>The Axis white paper <a href=\"https://whitepapers.axis.com/en-us/privacy-in-surveillance\" target=\"_blank\" rel=\"noopener noreferrer\">Privacy in surveillance</a> describes privacy options that include blocking selected image areas, masking people, using non-visual technologies, and applying controls across capture, recording, viewing, and export. It distinguishes static masking, dynamic masking, access controls, and redaction rather than presenting privacy as one camera setting.</p>\n<p>That lifecycle view matters. A permanent source mask can prevent sensitive pixels from entering a stream. A dynamic mask may permit an authorized role to reveal information. VMS permissions can restrict who sees a camera or recording. Export redaction creates a disclosure copy while leaving the evidentiary original subject to separate controls.</p>\n<h2>Source boundary and applicability</h2>\n<p>The paper describes Axis approaches and does not establish legal compliance, authorize recording, or prove that a particular third-party VMS preserves a mask. Privacy requirements depend on jurisdiction, purpose, notice, labor agreements, retention, public-record obligations, and the people or spaces captured. Product and version support must be verified.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Which areas or people must never be recorded, and which may be revealed only for an approved investigation?</li>\n<li>Does masking occur before encoding, in a parallel stream, in the client, or only during export?</li>\n<li>Who can disable a mask or retrieve an unmasked stream, and is that action logged?</li>\n<li>Do mobile clients, video walls, integrations, thumbnails, analytics, and exported stills follow the same rule?</li>\n<li>Must an evidentiary original be preserved while a redacted disclosure copy is created?</li>\n</ul>\n<h2>DSE recommendation: build a privacy-control matrix</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>Create a matrix with lifecycle stages as rows and each viewing or export workflow as columns. For every cell, name the allowed roles, expected masked state, location of any unmasked original, audit event, and approval required to reveal information. Prefer source masking when pixels have no legitimate operational purpose. Where an original is necessary, restrict the reveal path with least privilege, a documented reason, and reviewable logs.</p>\n<p>Include every stream and derivative, not just the primary desktop client. Test live and recorded video, low- and high-resolution streams, snapshots, bookmarks, evidence packages, third-party integrations, and administrative previews. Treat any unlogged bypass or unexpectedly unmasked derivative as a design defect.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the approved privacy matrix, screenshots of configured regions, role and permission exports, test clips from each workflow, redacted and original file hashes where applicable, reveal-event audit logs, and sign-off from privacy or legal owners. Re-test after camera replacement, firmware or VMS upgrades, layout changes, or integration changes.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://whitepapers.axis.com/en-us/privacy-in-surveillance\" target=\"_blank\" rel=\"noopener noreferrer\">Privacy in surveillance</a> &#8211; Axis Communications</li>\n</ul>",
        "content_text": "Bottom line: a privacy mask at the camera, an operator permission in the VMS, and redaction applied to an exported clip solve different problems. A design should identify when information must be hidden, who may reveal it, and whether an unmasked original may exist.\nSource fact: privacy controls can act at several stages\nThe Axis white paper Privacy in surveillance describes privacy options that include blocking selected image areas, masking people, using non-visual technologies, and applying controls across capture, recording, viewing, and export. It distinguishes static masking, dynamic masking, access controls, and redaction rather than presenting privacy as one camera setting.\nThat lifecycle view matters. A permanent source mask can prevent sensitive pixels from entering a stream. A dynamic mask may permit an authorized role to reveal information. VMS permissions can restrict who sees a camera or recording. Export redaction creates a disclosure copy while leaving the evidentiary original subject to separate controls.\nSource boundary and applicability\nThe paper describes Axis approaches and does not establish legal compliance, authorize recording, or prove that a particular third-party VMS preserves a mask. Privacy requirements depend on jurisdiction, purpose, notice, labor agreements, retention, public-record obligations, and the people or spaces captured. Product and version support must be verified.\nApplicability questions\n\nWhich areas or people must never be recorded, and which may be revealed only for an approved investigation?\nDoes masking occur before encoding, in a parallel stream, in the client, or only during export?\nWho can disable a mask or retrieve an unmasked stream, and is that action logged?\nDo mobile clients, video walls, integrations, thumbnails, analytics, and exported stills follow the same rule?\nMust an evidentiary original be preserved while a redacted disclosure copy is created?\n\nDSE recommendation: build a privacy-control matrix\nThe following steps are DSE recommendations based on the cited source.\nCreate a matrix with lifecycle stages as rows and each viewing or export workflow as columns. For every cell, name the allowed roles, expected masked state, location of any unmasked original, audit event, and approval required to reveal information. Prefer source masking when pixels have no legitimate operational purpose. Where an original is necessary, restrict the reveal path with least privilege, a documented reason, and reviewable logs.\nInclude every stream and derivative, not just the primary desktop client. Test live and recorded video, low- and high-resolution streams, snapshots, bookmarks, evidence packages, third-party integrations, and administrative previews. Treat any unlogged bypass or unexpectedly unmasked derivative as a design defect.\nVerification and evidence\nRetain the approved privacy matrix, screenshots of configured regions, role and permission exports, test clips from each workflow, redacted and original file hashes where applicable, reveal-event audit logs, and sign-off from privacy or legal owners. Re-test after camera replacement, firmware or VMS upgrades, layout changes, or integration changes.\nOfficial references\n\nPrivacy in surveillance – Axis Communications",
        "content_markdown": "Bottom line: a privacy mask at the camera, an operator permission in the VMS, and redaction applied to an exported clip solve different problems. A design should identify when information must be hidden, who may reveal it, and whether an unmasked original may exist.\n\n## Source fact: privacy controls can act at several stages\n\nThe Axis white paper [Privacy in surveillance](https://whitepapers.axis.com/en-us/privacy-in-surveillance) describes privacy options that include blocking selected image areas, masking people, using non-visual technologies, and applying controls across capture, recording, viewing, and export. It distinguishes static masking, dynamic masking, access controls, and redaction rather than presenting privacy as one camera setting.\n\nThat lifecycle view matters. A permanent source mask can prevent sensitive pixels from entering a stream. A dynamic mask may permit an authorized role to reveal information. VMS permissions can restrict who sees a camera or recording. Export redaction creates a disclosure copy while leaving the evidentiary original subject to separate controls.\n\n## Source boundary and applicability\n\nThe paper describes Axis approaches and does not establish legal compliance, authorize recording, or prove that a particular third-party VMS preserves a mask. Privacy requirements depend on jurisdiction, purpose, notice, labor agreements, retention, public-record obligations, and the people or spaces captured. Product and version support must be verified.\n\n## Applicability questions\n\n- Which areas or people must never be recorded, and which may be revealed only for an approved investigation?\n\n- Does masking occur before encoding, in a parallel stream, in the client, or only during export?\n\n- Who can disable a mask or retrieve an unmasked stream, and is that action logged?\n\n- Do mobile clients, video walls, integrations, thumbnails, analytics, and exported stills follow the same rule?\n\n- Must an evidentiary original be preserved while a redacted disclosure copy is created?\n\n## DSE recommendation: build a privacy-control matrix\n\nThe following steps are DSE recommendations based on the cited source.\n\nCreate a matrix with lifecycle stages as rows and each viewing or export workflow as columns. For every cell, name the allowed roles, expected masked state, location of any unmasked original, audit event, and approval required to reveal information. Prefer source masking when pixels have no legitimate operational purpose. Where an original is necessary, restrict the reveal path with least privilege, a documented reason, and reviewable logs.\n\nInclude every stream and derivative, not just the primary desktop client. Test live and recorded video, low- and high-resolution streams, snapshots, bookmarks, evidence packages, third-party integrations, and administrative previews. Treat any unlogged bypass or unexpectedly unmasked derivative as a design defect.\n\n## Verification and evidence\n\nRetain the approved privacy matrix, screenshots of configured regions, role and permission exports, test clips from each workflow, redacted and original file hashes where applicable, reveal-event audit logs, and sign-off from privacy or legal owners. Re-test after camera replacement, firmware or VMS upgrades, layout changes, or integration changes.\n\n## Official references\n\n- [Privacy in surveillance](https://whitepapers.axis.com/en-us/privacy-in-surveillance) – Axis Communications"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/",
                "url": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Place video privacy controls at capture, viewing, and export",
                        "item": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/#article",
                "identifier": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/",
                "url": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/",
                "headline": "Place video privacy controls at capture, viewing, and export",
                "description": "Privacy controls act at different points in the video lifecycle. Map masking, access restriction, and redaction to the disclosure risk each control is…",
                "abstract": "Privacy controls act at different points in the video lifecycle. Map masking, access restriction, and redaction to the disclosure risk each control is intended to reduce.",
                "articleBody": "Bottom line: a privacy mask at the camera, an operator permission in the VMS, and redaction applied to an exported clip solve different problems. A design should identify when information must be hidden, who may reveal it, and whether an unmasked original may exist.\nSource fact: privacy controls can act at several stages\nThe Axis white paper Privacy in surveillance describes privacy options that include blocking selected image areas, masking people, using non-visual technologies, and applying controls across capture, recording, viewing, and export. It distinguishes static masking, dynamic masking, access controls, and redaction rather than presenting privacy as one camera setting.\nThat lifecycle view matters. A permanent source mask can prevent sensitive pixels from entering a stream. A dynamic mask may permit an authorized role to reveal information. VMS permissions can restrict who sees a camera or recording. Export redaction creates a disclosure copy while leaving the evidentiary original subject to separate controls.\nSource boundary and applicability\nThe paper describes Axis approaches and does not establish legal compliance, authorize recording, or prove that a particular third-party VMS preserves a mask. Privacy requirements depend on jurisdiction, purpose, notice, labor agreements, retention, public-record obligations, and the people or spaces captured. Product and version support must be verified.\nApplicability questions\n\nWhich areas or people must never be recorded, and which may be revealed only for an approved investigation?\nDoes masking occur before encoding, in a parallel stream, in the client, or only during export?\nWho can disable a mask or retrieve an unmasked stream, and is that action logged?\nDo mobile clients, video walls, integrations, thumbnails, analytics, and exported stills follow the same rule?\nMust an evidentiary original be preserved while a redacted disclosure copy is created?\n\nDSE recommendation: build a privacy-control matrix\nThe following steps are DSE recommendations based on the cited source.\nCreate a matrix with lifecycle stages as rows and each viewing or export workflow as columns. For every cell, name the allowed roles, expected masked state, location of any unmasked original, audit event, and approval required to reveal information. Prefer source masking when pixels have no legitimate operational purpose. Where an original is necessary, restrict the reveal path with least privilege, a documented reason, and reviewable logs.\nInclude every stream and derivative, not just the primary desktop client. Test live and recorded video, low- and high-resolution streams, snapshots, bookmarks, evidence packages, third-party integrations, and administrative previews. Treat any unlogged bypass or unexpectedly unmasked derivative as a design defect.\nVerification and evidence\nRetain the approved privacy matrix, screenshots of configured regions, role and permission exports, test clips from each workflow, redacted and original file hashes where applicable, reveal-event audit logs, and sign-off from privacy or legal owners. Re-test after camera replacement, firmware or VMS upgrades, layout changes, or integration changes.\nOfficial references\n\nPrivacy in surveillance – Axis Communications",
                "datePublished": "2026-08-25T21:36:13+00:00",
                "dateModified": "2026-08-25T21:36:16+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/place-video-privacy-controls-at-capture-view-and-export/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Place video privacy controls at capture, viewing, and export"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Video Surveillance",
                    "Guide",
                    "Important priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 468,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Privacy in surveillance",
                    "url": "https://whitepapers.axis.com/en-us/privacy-in-surveillance"
                }
            }
        ]
    }
}