What you need to know
SIA’s 2025 Code organizes privacy responsibilities around purpose, impact assessment, minimization, accuracy, retention, security, access, transparency, and review.
Potentially affected
Organizations that manufacture, design, install, own, operate, host, analyze, share, or support video surveillance and associated analytics or identifying metadata.
DSE recommendation
Create a documented privacy operating model with accountable roles and jurisdiction-specific legal review rather than treating technical configuration as compliance.
Responsibilities begin before installation
Source fact: SIA’s 2025 Data Privacy Code of Practice separates responsibilities among manufacturers, integrators, and end users. Manufacturers are asked to address secure defaults and upkeep, including patching, vulnerability communication, credential changes, access control, authentication, encryption, cloud-service security, and current hardening guidance.
For integrators, SIA places privacy work in design and layout. A privacy impact assessment can identify concerns involving fields of view, analytics, viewing or exclusion zones, authentication, cloud or on-premises architecture, third parties, and contractual responsibilities before installation. End users establish the system’s purpose, justification, and operating scope. SIA describes them as the data controllers who retain ultimate responsibility even when a service provider handles data.
Principles for ongoing operation
The Code recommends a privacy impact assessment that examines how information is collected, used, shared, maintained, and retained. It presents privacy by design, regular review, transparency and notification, purpose limitation, and data minimization as core principles. It also calls for accurate metadata such as location, date, and time, particularly where evidentiary use matters.
Storage should last only as long as reasonably necessary or legally required. Access to retained images should be restricted through clear rules stating who can access them, when, and for what purpose. Integrity and confidentiality measures can include digital signatures, watermarking, and encryption in transit and at rest.
Legal and operational boundary
SIA explicitly states that the Code is general information and not legal advice. It does not create a universal retention period, notice format, lawful basis, biometric rule, or sector-specific compliance decision. Requirements vary by jurisdiction, workforce relationship, use case, and the type of people or information captured.
DSE privacy checklist
DSE recommendation: This is DSE operational synthesis and should be completed with qualified counsel for applicable law.
- Name the data controller, processors, system owner, privacy contact, and technical administrators.
- Document each surveillance purpose, justification, location, field of view, data type, and intended user.
- Complete and approve a privacy impact assessment before deployment or material analytic change.
- Minimize collection through positioning, masks, exclusion zones, purpose-specific analytics, and disabled unnecessary audio.
- Define jurisdiction- and purpose-based retention, preservation holds, deletion, export, and sharing rules.
- Restrict and audit live view, search, export, administration, and third-party access.
- Verify time, location, camera identity, encryption, integrity, notices, and complaint contact information.
- Review the program with affected stakeholders on a stated cadence and after significant change.
Official reference
- Data Privacy Code of Practice: Video Surveillance — SIA’s 2025 roles, assessment principles, operational controls, and legal disclaimer.
Review the official source
Security Industry Association — Data Privacy Code of Practice: Video Surveillance · Verified July 19, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE