How Long Should Businesses Keep Security Camera Footage? A 2026 Canada and U.S. Guide

How long should businesses keep security camera footage? This guide explains practical retention periods, Canadian and U.S. privacy considerations, incident preservation, and how to create a defensible CCTV retention policy.

14 minutes read
How Long Should Businesses Keep Security Camera Footage? A 2026 Canada and U.S. Guide

Imagine discovering on Monday that a customer slipped in your parking lot on Saturday. Your cameras captured what happened clearly—but the recorder overwrote the footage overnight.

The cameras worked. The recording worked. The retention policy failed.

Keeping footage too briefly can erase critical evidence before anyone realizes it matters. Keeping every recording indefinitely creates a different set of problems: higher storage costs, greater cybersecurity exposure, unnecessary collection of personal information and potential privacy-law violations.

So, how long should a business keep security camera footage?

The short answer

For many businesses, 30 days is a reasonable starting point for routine security camera footage—but it is not a universal legal requirement.

A practical risk-based framework is:

  • 14–30 days: Lower-risk offices and locations where incidents are normally reported quickly.

  • 30–60 days: Retail stores, commercial buildings, warehouses, parking areas and multi-residential common areas.

  • 60–90 days: Higher-risk sites, locations where losses may be discovered late or environments with frequent liability and insurance claims.

  • Rule-specific retention: Regulated businesses, contractual requirements and footage governed by insurance, employment, biometric or sector-specific rules.

  • Separate incident retention: Relevant footage should be removed from the normal overwrite cycle when an incident, claim, investigation, access request or legal dispute arises.

These ranges are operational starting points, not legal safe harbours. The correct period depends on why the cameras exist, how quickly incidents are discovered, who appears in the footage, where the business operates and which laws or contracts apply.

This article provides general educational information and is not legal advice. Requirements should be confirmed with qualified counsel for the applicable jurisdiction and industry.

There is no universal “30-day CCTV law”

Many businesses configure their recorders for 30 days and assume the number came from legislation. In most situations, it did not.

Thirty days became common because it often balances storage capacity with the time businesses need to discover and investigate routine incidents. That does not make it automatically appropriate—or legally sufficient—for every organization.

A neighbourhood office, a hospital entrance, a cannabis retailer, a warehouse loading dock and a critical-infrastructure facility do not have the same risks. Applying one retention period to all of them may mean retaining too much footage in some places and losing important evidence in others.

A defensible retention period should account for:

  1. The stated purpose of the surveillance.

  2. The average delay between an incident and its discovery.

  3. The site’s theft, safety, fraud and liability exposure.

  4. Applicable privacy, employment and sector-specific laws.

  5. Insurance and customer-contract requirements.

  6. Pending investigations, claims or litigation.

  7. Whether analytics collect biometric or other sensitive information.

Routine footage and incident evidence are not the same

One of the most important distinctions in a video-retention policy is the difference between the rolling archive and preserved evidence.

Type of recording Purpose Appropriate retention approach
Routine footage General safety, deterrence and incident review Automatically overwritten after the approved baseline period
Flagged event Activity requiring review but not yet confirmed as an incident Retained temporarily until reviewed and classified
Confirmed incident Theft, injury, violence, property damage or another reportable event Exported or protected from automatic deletion
Investigation or claim evidence Footage connected to police, insurance, employment or legal action Preserved until the authorized case owner confirms the hold can end
Biometric information Face geometry or another identifier used to identify a person Managed under a separate biometric policy and applicable law
Audio recording Captured conversations or sound Subject to separate necessity, notice, consent and communications-law analysis

A business does not normally need to store every minute from every camera for several years. It needs enough routine history to discover incidents and a reliable process for preserving the footage that becomes important.

The following ranges can help an organization begin its assessment.

Environment Practical starting point Why
Low-risk office or administrative area 14–30 days Incidents are generally noticed and reported quickly
Retail store or restaurant 30–60 days Theft, transaction disputes and customer claims may be discovered later
Commercial or multi-residential property 30–60 days Complaints may involve parking areas, entrances, elevators or shared spaces
Warehouse, logistics yard or construction site 45–90 days Inventory loss and property damage may not be identified immediately
High-risk or critical site 60–90 days or requirement-specific Greater consequences may justify a longer investigation window
Confirmed incident footage Separate evidence hold The routine overwrite period should no longer apply

These periods should not be selected simply because storage is available. The organization should be able to explain why each period is necessary and proportionate to the surveillance purpose.

How footage-retention rules work in Canada

Canadian privacy law generally follows a purpose-based approach rather than prescribing one universal number of days.

The Office of the Privacy Commissioner of Canada advises private-sector organizations to keep recordings only as long as necessary to fulfil the purpose of the surveillance, secure them against unauthorized access and destroy them securely when they are no longer required. The Commissioner also recommends documenting minimum and maximum retention periods in a written video-surveillance policy. Office of the Privacy Commissioner of Canada

Under PIPEDA, organizations should establish retention guidelines and procedures. When personal information has been used to make a decision about an individual, it must remain available long enough to give that individual a reasonable opportunity to access it.

Provincial requirements can add more specificity. For example, British Columbia’s Personal Information Protection Act requires information used to make a decision that directly affects an individual to be retained for at least one year. It also requires organizations to destroy or de-identify personal information when its original purpose and legal or business need have ended. British Columbia Personal Information Protection Act, Section 35

That one-year requirement does not mean every British Columbia business must retain every camera recording for a year. It becomes relevant when particular footage has actually been used to make a decision directly affecting a person—for example, a documented disciplinary or access decision.

Quebec follows a similar purpose-based principle. Its private-sector privacy law requires information used for a decision about an individual to be kept for at least one year following the decision. Once the purposes for collecting or using personal information have been achieved, the information must generally be destroyed or irreversibly anonymized, subject to another legally required preservation period. Quebec Act Respecting the Protection of Personal Information in the Private Sector, Sections 11 and 23

The applicable Canadian rules can also change depending on:

  • Whether the organization is federally or provincially regulated.

  • Whether the cameras record customers, tenants, visitors or employees.

  • Whether the footage contains health or other sensitive information.

  • Whether the organization operates in more than one province.

  • Whether a public-sector, education, healthcare or industry-specific law applies.

Employee surveillance requires particular care because employment, labour and workplace-privacy rules may apply beyond the general guidance for cameras in publicly accessible areas.

How footage-retention rules work in the United States

The United States does not provide one generally applicable national retention period for ordinary business CCTV footage. The practical result is a patchwork of state privacy laws, sector requirements, biometric laws, contracts, court rules and litigation-preservation duties.

For businesses subject to the California Consumer Privacy Act, the notice at collection must disclose how long each category of personal information will be retained—or the criteria used to determine that period. Covered businesses may not retain personal information longer than reasonably necessary for the disclosed purpose. California Consumer Privacy Act, Section 1798.100

Biometric analytics can create additional obligations. Illinois law, for example, distinguishes an ordinary photograph from a scan of face geometry. When covered biometric identifiers or information are collected, a private entity must establish a public retention schedule and permanently destroy the information when its original purpose has been satisfied or within three years of the individual’s last interaction, whichever occurs first. Illinois biometric definitions and retention requirements

This does not mean every Illinois security video is automatically biometric information. The risk changes when the system extracts or uses biometric identifiers to recognize or identify individuals.

The Federal Trade Commission also encourages businesses to retain sensitive personal information only for as long as a legitimate business need exists, maintain a written retention policy and securely dispose of information that is no longer required. FTC Guide for Business

U.S. businesses should therefore review the laws of every state in which cameras operate or recorded individuals may be located, particularly when using facial recognition, employee monitoring, audio recording or analytics that profile identifiable people.

Security manager reviewing preserved surveillance footage beside a redundant video-storage system after a drive warning.

When should normal deletion stop?

Automatic deletion is useful until the organization knows—or reasonably should know—that particular footage may be evidence.

A preservation hold should be considered when the organization receives or becomes aware of:

  • A reported injury, theft, assault or property-damage incident.

  • A customer, employee, tenant or visitor complaint.

  • An insurance claim or potential claim.

  • A privacy or footage-access request.

  • A police request, subpoena or court order.

  • A disciplinary or employment investigation.

  • A demand letter or threat of legal action.

  • An internal investigation involving the recorded area.

  • A cybersecurity incident affecting the video system.

In the United States, Rule 37 of the Federal Rules of Civil Procedure addresses electronically stored information that should have been preserved when litigation was anticipated or underway. Federal Rules of Civil Procedure

Once a hold is triggered, the organization should identify the relevant cameras and time range, protect the original recording from being overwritten, preserve associated timestamps and system information, control copies and document who accessed or exported the evidence.

The hold should include reasonable footage before and after the reported time. A witness may report that an event happened at 2:00 p.m. when the relevant activity actually began several minutes earlier or occurred in another camera’s field of view.

A practical formula for choosing a retention period

A business can begin with the following decision rule:

Baseline retention = the longest applicable period among the normal incident-discovery window, legal minimum, contractual obligation and insurance requirement—subject to privacy necessity and proportionality.

For example, if most incidents are discovered within 12 days, but inventory discrepancies may take 35 days to identify, a 14-day archive is clearly inadequate. A 45- or 60-day period may be more defensible for the relevant warehouse cameras.

The calculation should be performed by site or camera category, rather than across the entire organization.

Step 1: Measure how late incidents are discovered

Review the previous 12 months of incident reports. Calculate the number of days between when each incident happened and when someone requested the footage.

The retention period should cover most legitimate discovery delays while leaving a reasonable investigation buffer.

Step 2: Identify legal, insurance and contractual obligations

Check applicable privacy laws, sector regulations, collective agreements, customer contracts, insurance requirements and lease obligations.

If the business operates across jurisdictions, one default policy may not be sufficient.

Step 3: Classify cameras by purpose and risk

An indoor office camera, warehouse loading dock, cash-handling area and perimeter camera may justify different retention periods.

Document the purpose of each category so the business can explain why its retention choice is reasonable.

Step 4: Separate routine recordings from incidents

Configure routine footage for automatic expiration. Create a controlled process for protecting confirmed incidents from deletion without extending the entire archive.

Step 5: Define who can place and release a hold

A video export should not remain indefinitely because an employee once marked it as important. Each preserved incident should have:

  • A case or incident number.

  • A reason for preservation.

  • An accountable owner.

  • The date the hold began.

  • A review date.

  • A documented authorization for final disposal.

Step 6: Protect what the business retains

Longer retention increases the consequences of unauthorized access. Appropriate controls may include encryption, role-based permissions, multifactor authentication, access logging, controlled evidence exports and secure deletion.

Step 7: Test the policy

A written policy is not enough if the recorder overwrites footage sooner than expected or if deleted cloud recordings remain in unmanaged backups.

Periodically verify:

  • The actual number of retrievable days.

  • Time and timezone accuracy.

  • Export quality.

  • User permissions.

  • Automatic-deletion settings.

  • Incident-hold functionality.

  • Backup expiration.

  • Secure disposal procedures.

Moving footage from an NVR to cloud storage does not remove the organization’s privacy or preservation responsibilities.

Cloud, edge and hybrid platforms can make retention easier to control because they may support different rules by camera, site or event type. However, unlimited technical capacity is not the same as unlimited legal justification.

A well-designed system should allow an organization to:

  • Automatically expire routine footage.

  • Protect selected incidents from deletion.

  • Apply different retention periods to different sites.

  • Restrict access according to user responsibilities.

  • Track evidence exports and disclosures.

  • Delete recordings and related backups securely.

  • Adjust capacity without replacing the entire recording system.

The objective is not to store the greatest possible amount of video. It is to keep the right footage for the right period—and dispose of it responsibly when that period ends.

Sample security-camera retention policy language

The following language can be adapted after legal and operational review:

Routine video-surveillance recordings will be retained for [X days] and then automatically overwritten or securely deleted unless a recording has been identified as relevant to a reported incident, investigation, access request, insurance claim, legal obligation or anticipated proceeding.

Authorized personnel may place relevant recordings on preservation hold. Each hold must include a documented purpose, accountable owner and review date. Preserved recordings will be retained only for as long as the investigation, claim, decision, legal obligation or proceeding reasonably requires.

Access to recordings is limited to authorized personnel with a legitimate business need. Viewing, exporting, sharing and disposal must follow the organization’s privacy, information-security and evidence-handling procedures.

Recordings or analytics containing biometric information, audio or other sensitive data will be managed under any additional policies and laws applicable to that information.

The placeholders should be supported by a documented risk assessment, not selected arbitrarily.

Seven common retention mistakes

1. Assuming 30 days is legally required

Thirty days may be reasonable, but the business should understand and document why it is appropriate.

2. Keeping everything indefinitely

Indefinite retention can conflict with privacy-minimization principles and increases the impact of a breach.

3. Using the same period for every camera

Different cameras serve different purposes and create different levels of risk.

4. Treating exported clips casually

Evidence copied to laptops, email attachments and shared drives may escape the normal retention and security controls.

5. Deleting footage after receiving notice of a claim

Routine deletion should stop when relevant evidence must reasonably be preserved.

6. Ignoring backups and vendor copies

The policy should cover NVRs, cloud systems, edge devices, exported files, mobile downloads and backup environments.

7. Failing to reassess AI and audio features

Facial recognition, biometric identification, behavioural profiling and audio capture may change the privacy analysis even when the camera itself has not changed.

The real question is not “How much can we store?”

Modern video systems can make years of storage technically possible. That does not mean years of routine surveillance are necessary, proportionate or strategically useful.

The stronger question is:

How long do we genuinely need routine footage, and how reliably can we protect important incidents when they occur?

A defensible security camera retention policy protects the organization in both directions. It reduces the chance that valuable evidence disappears too soon, while limiting the privacy, cybersecurity and operational risks created by keeping recordings for too long.

ArcadianAI supports camera-agnostic cloud, edge and hybrid video environments, allowing organizations to modernize how existing cameras are connected, monitored and managed without automatically replacing their current infrastructure.

If your organization is reviewing its camera architecture, storage strategy or incident workflow, use retention as a design requirement—not an afterthought added after the recorder is installed.

Frequently asked questions

Is a business legally required to keep security camera footage for 30 days?

Not generally. Thirty days is a practical baseline used by many organizations, but applicable privacy laws, sector regulations, contracts, insurance requirements or investigations may require a shorter or longer period.

Is 30 or 90 days better for CCTV footage?

The better period depends on how long it takes the business to discover incidents. Thirty days may be sufficient for a lower-risk location, while 60–90 days may be more appropriate for warehouses, parking facilities or locations where losses and claims are reported late.

Can a business automatically delete old security footage?

Yes, routine automatic deletion can support a consistent retention policy. The system must also provide a way to stop deletion and preserve relevant footage when an incident, access request, claim or legal matter arises.

How long should incident footage be retained?

Incident footage should be separated from the routine archive and retained for as long as the related investigation, claim, decision, legal requirement or anticipated proceeding reasonably requires. The release of a preservation hold should be documented.

Does the one-year decision rule mean all footage must be kept for one year?

No. Rules requiring information used to make a decision about an individual to be retained for at least one year apply to the information used for that decision. They do not automatically require every routine camera recording to be stored for a year.

Can businesses retain security footage forever?

Indefinite retention is difficult to justify when footage is no longer needed for its stated purpose. Privacy laws may require deletion, destruction or de-identification when the legitimate purpose and legal need have ended.

Does using facial recognition change the retention requirements?

Potentially. Ordinary video and biometric identifiers may be treated differently. Systems that extract face geometry or identify people can trigger additional notice, consent, policy, security and deletion requirements.

Does cloud video storage allow a business to retain footage longer?

Cloud storage may make longer retention technically easier, but it does not remove legal or privacy limitations. Retention must still be necessary, proportionate, secure and consistent with the organization’s disclosed purpose.

Security is like insurance—until you need it, you don’t think about it.

But when something goes wrong? Break-ins, theft, liability claims—suddenly, it’s all you think about.

ArcadianAI upgrades your security to the AI era—no new hardware, no sky-high costs, just smart protection that works.
→ Stop security incidents before they happen 
→ Cut security costs without cutting corners 
→ Run your business without the worry
Because the best security isn’t reactive—it’s proactive. 

Is your security keeping up with the AI era? Book a free demo today.