{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/video-surveillance-privacy-operating-model-sia-code/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
        "slug": "video-surveillance-privacy-operating-model-sia-code",
        "url": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/video-surveillance-privacy-operating-model-sia-code/"
        },
        "title": "A privacy operating model for video surveillance based on SIA’s 2025 Code",
        "summary": "SIA’s 2025 Code organizes privacy responsibilities around purpose, impact assessment, minimization, accuracy, retention, security, access, transparency, and review.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:28:39+00:00",
        "modified_at": "2026-07-19T21:28:39+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 406,
        "potentially_affected": "Organizations that manufacture, design, install, own, operate, host, analyze, share, or support video surveillance and associated analytics or identifying metadata.",
        "dse_recommendation": "Create a documented privacy operating model with accountable roles and jurisdiction-specific legal review rather than treating technical configuration as compliance.",
        "primary_source": {
            "name": "Security Industry Association — Data Privacy Code of Practice: Video Surveillance",
            "url": "https://www.securityindustry.org/wp-content/uploads/2025/06/SIA-Video-Code-of-Practice-2025.pdf",
            "published_on": null,
            "authority": "Security Industry Association"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Responsibilities begin before installation</h2>\n<p><strong>Source fact:</strong> SIA&#8217;s 2025 Data Privacy Code of Practice separates responsibilities among manufacturers, integrators, and end users. Manufacturers are asked to address secure defaults and upkeep, including patching, vulnerability communication, credential changes, access control, authentication, encryption, cloud-service security, and current hardening guidance.</p>\n<p>For integrators, SIA places privacy work in design and layout. A privacy impact assessment can identify concerns involving fields of view, analytics, viewing or exclusion zones, authentication, cloud or on-premises architecture, third parties, and contractual responsibilities before installation. End users establish the system&#8217;s purpose, justification, and operating scope. SIA describes them as the data controllers who retain ultimate responsibility even when a service provider handles data.</p>\n\n<h2>Principles for ongoing operation</h2>\n<p>The Code recommends a privacy impact assessment that examines how information is collected, used, shared, maintained, and retained. It presents privacy by design, regular review, transparency and notification, purpose limitation, and data minimization as core principles. It also calls for accurate metadata such as location, date, and time, particularly where evidentiary use matters.</p>\n<p>Storage should last only as long as reasonably necessary or legally required. Access to retained images should be restricted through clear rules stating who can access them, when, and for what purpose. Integrity and confidentiality measures can include digital signatures, watermarking, and encryption in transit and at rest.</p>\n\n<h2>Legal and operational boundary</h2>\n<p>SIA explicitly states that the Code is general information and not legal advice. It does not create a universal retention period, notice format, lawful basis, biometric rule, or sector-specific compliance decision. Requirements vary by jurisdiction, workforce relationship, use case, and the type of people or information captured.</p>\n\n<h2>DSE privacy checklist</h2>\n<p><strong>DSE recommendation:</strong> This is DSE operational synthesis and should be completed with qualified counsel for applicable law.</p>\n<ol>\n<li>Name the data controller, processors, system owner, privacy contact, and technical administrators.</li>\n<li>Document each surveillance purpose, justification, location, field of view, data type, and intended user.</li>\n<li>Complete and approve a privacy impact assessment before deployment or material analytic change.</li>\n<li>Minimize collection through positioning, masks, exclusion zones, purpose-specific analytics, and disabled unnecessary audio.</li>\n<li>Define jurisdiction- and purpose-based retention, preservation holds, deletion, export, and sharing rules.</li>\n<li>Restrict and audit live view, search, export, administration, and third-party access.</li>\n<li>Verify time, location, camera identity, encryption, integrity, notices, and complaint contact information.</li>\n<li>Review the program with affected stakeholders on a stated cadence and after significant change.</li>\n</ol>\n\n<h2>Official reference</h2>\n<ul>\n<li><a href=\"https://www.securityindustry.org/wp-content/uploads/2025/06/SIA-Video-Code-of-Practice-2025.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Data Privacy Code of Practice: Video Surveillance</a> — SIA&#8217;s 2025 roles, assessment principles, operational controls, and legal disclaimer.</li>\n</ul>",
        "content_text": "Responsibilities begin before installation\nSource fact: SIA’s 2025 Data Privacy Code of Practice separates responsibilities among manufacturers, integrators, and end users. Manufacturers are asked to address secure defaults and upkeep, including patching, vulnerability communication, credential changes, access control, authentication, encryption, cloud-service security, and current hardening guidance.\nFor integrators, SIA places privacy work in design and layout. A privacy impact assessment can identify concerns involving fields of view, analytics, viewing or exclusion zones, authentication, cloud or on-premises architecture, third parties, and contractual responsibilities before installation. End users establish the system’s purpose, justification, and operating scope. SIA describes them as the data controllers who retain ultimate responsibility even when a service provider handles data.\n\nPrinciples for ongoing operation\nThe Code recommends a privacy impact assessment that examines how information is collected, used, shared, maintained, and retained. It presents privacy by design, regular review, transparency and notification, purpose limitation, and data minimization as core principles. It also calls for accurate metadata such as location, date, and time, particularly where evidentiary use matters.\nStorage should last only as long as reasonably necessary or legally required. Access to retained images should be restricted through clear rules stating who can access them, when, and for what purpose. Integrity and confidentiality measures can include digital signatures, watermarking, and encryption in transit and at rest.\n\nLegal and operational boundary\nSIA explicitly states that the Code is general information and not legal advice. It does not create a universal retention period, notice format, lawful basis, biometric rule, or sector-specific compliance decision. Requirements vary by jurisdiction, workforce relationship, use case, and the type of people or information captured.\n\nDSE privacy checklist\nDSE recommendation: This is DSE operational synthesis and should be completed with qualified counsel for applicable law.\n\nName the data controller, processors, system owner, privacy contact, and technical administrators.\nDocument each surveillance purpose, justification, location, field of view, data type, and intended user.\nComplete and approve a privacy impact assessment before deployment or material analytic change.\nMinimize collection through positioning, masks, exclusion zones, purpose-specific analytics, and disabled unnecessary audio.\nDefine jurisdiction- and purpose-based retention, preservation holds, deletion, export, and sharing rules.\nRestrict and audit live view, search, export, administration, and third-party access.\nVerify time, location, camera identity, encryption, integrity, notices, and complaint contact information.\nReview the program with affected stakeholders on a stated cadence and after significant change.\n\nOfficial reference\n\nData Privacy Code of Practice: Video Surveillance — SIA’s 2025 roles, assessment principles, operational controls, and legal disclaimer.",
        "content_markdown": "## Responsibilities begin before installation\n\nSource fact: SIA’s 2025 Data Privacy Code of Practice separates responsibilities among manufacturers, integrators, and end users. Manufacturers are asked to address secure defaults and upkeep, including patching, vulnerability communication, credential changes, access control, authentication, encryption, cloud-service security, and current hardening guidance.\n\nFor integrators, SIA places privacy work in design and layout. A privacy impact assessment can identify concerns involving fields of view, analytics, viewing or exclusion zones, authentication, cloud or on-premises architecture, third parties, and contractual responsibilities before installation. End users establish the system’s purpose, justification, and operating scope. SIA describes them as the data controllers who retain ultimate responsibility even when a service provider handles data.\n\n## Principles for ongoing operation\n\nThe Code recommends a privacy impact assessment that examines how information is collected, used, shared, maintained, and retained. It presents privacy by design, regular review, transparency and notification, purpose limitation, and data minimization as core principles. It also calls for accurate metadata such as location, date, and time, particularly where evidentiary use matters.\n\nStorage should last only as long as reasonably necessary or legally required. Access to retained images should be restricted through clear rules stating who can access them, when, and for what purpose. Integrity and confidentiality measures can include digital signatures, watermarking, and encryption in transit and at rest.\n\n## Legal and operational boundary\n\nSIA explicitly states that the Code is general information and not legal advice. It does not create a universal retention period, notice format, lawful basis, biometric rule, or sector-specific compliance decision. Requirements vary by jurisdiction, workforce relationship, use case, and the type of people or information captured.\n\n## DSE privacy checklist\n\nDSE recommendation: This is DSE operational synthesis and should be completed with qualified counsel for applicable law.\n\n- Name the data controller, processors, system owner, privacy contact, and technical administrators.\n\n- Document each surveillance purpose, justification, location, field of view, data type, and intended user.\n\n- Complete and approve a privacy impact assessment before deployment or material analytic change.\n\n- Minimize collection through positioning, masks, exclusion zones, purpose-specific analytics, and disabled unnecessary audio.\n\n- Define jurisdiction- and purpose-based retention, preservation holds, deletion, export, and sharing rules.\n\n- Restrict and audit live view, search, export, administration, and third-party access.\n\n- Verify time, location, camera identity, encryption, integrity, notices, and complaint contact information.\n\n- Review the program with affected stakeholders on a stated cadence and after significant change.\n\n## Official reference\n\n- [Data Privacy Code of Practice: Video Surveillance](https://www.securityindustry.org/wp-content/uploads/2025/06/SIA-Video-Code-of-Practice-2025.pdf) — SIA’s 2025 roles, assessment principles, operational controls, and legal disclaimer."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
                "url": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "A privacy operating model for video surveillance based on SIA’s 2025 Code",
                        "item": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/#article",
                "identifier": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
                "url": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
                "headline": "A privacy operating model for video surveillance based on SIA’s 2025 Code",
                "description": "SIA’s 2025 Code organizes privacy responsibilities around purpose, impact assessment, minimization, accuracy, retention, security, access…",
                "abstract": "SIA’s 2025 Code organizes privacy responsibilities around purpose, impact assessment, minimization, accuracy, retention, security, access, transparency, and review.",
                "articleBody": "Responsibilities begin before installation\nSource fact: SIA’s 2025 Data Privacy Code of Practice separates responsibilities among manufacturers, integrators, and end users. Manufacturers are asked to address secure defaults and upkeep, including patching, vulnerability communication, credential changes, access control, authentication, encryption, cloud-service security, and current hardening guidance.\nFor integrators, SIA places privacy work in design and layout. A privacy impact assessment can identify concerns involving fields of view, analytics, viewing or exclusion zones, authentication, cloud or on-premises architecture, third parties, and contractual responsibilities before installation. End users establish the system’s purpose, justification, and operating scope. SIA describes them as the data controllers who retain ultimate responsibility even when a service provider handles data.\n\nPrinciples for ongoing operation\nThe Code recommends a privacy impact assessment that examines how information is collected, used, shared, maintained, and retained. It presents privacy by design, regular review, transparency and notification, purpose limitation, and data minimization as core principles. It also calls for accurate metadata such as location, date, and time, particularly where evidentiary use matters.\nStorage should last only as long as reasonably necessary or legally required. Access to retained images should be restricted through clear rules stating who can access them, when, and for what purpose. Integrity and confidentiality measures can include digital signatures, watermarking, and encryption in transit and at rest.\n\nLegal and operational boundary\nSIA explicitly states that the Code is general information and not legal advice. It does not create a universal retention period, notice format, lawful basis, biometric rule, or sector-specific compliance decision. Requirements vary by jurisdiction, workforce relationship, use case, and the type of people or information captured.\n\nDSE privacy checklist\nDSE recommendation: This is DSE operational synthesis and should be completed with qualified counsel for applicable law.\n\nName the data controller, processors, system owner, privacy contact, and technical administrators.\nDocument each surveillance purpose, justification, location, field of view, data type, and intended user.\nComplete and approve a privacy impact assessment before deployment or material analytic change.\nMinimize collection through positioning, masks, exclusion zones, purpose-specific analytics, and disabled unnecessary audio.\nDefine jurisdiction- and purpose-based retention, preservation holds, deletion, export, and sharing rules.\nRestrict and audit live view, search, export, administration, and third-party access.\nVerify time, location, camera identity, encryption, integrity, notices, and complaint contact information.\nReview the program with affected stakeholders on a stated cadence and after significant change.\n\nOfficial reference\n\nData Privacy Code of Practice: Video Surveillance — SIA’s 2025 roles, assessment principles, operational controls, and legal disclaimer.",
                "datePublished": "2026-07-19T21:28:39+00:00",
                "dateModified": "2026-07-19T21:28:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Cybersecurity",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Video Surveillance",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 406,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Security Industry Association — Data Privacy Code of Practice: Video Surveillance",
                    "url": "https://www.securityindustry.org/wp-content/uploads/2025/06/SIA-Video-Code-of-Practice-2025.pdf"
                }
            }
        ]
    }
}