Privacy Laws and Commercial Security Footage: A Maryland Compliance Guide

Commercial security footage, access logs, and biometric scans are personal data under modern privacy laws. CCPA, GDPR, and state biometric statutes apply to your camera system the same way they apply to your CRM. HS Tech Group, based in Pikesville, Maryland and serving the greater Baltimore and Maryland market and Southeastern Pennsylvania, sees commercial security clients carry risk because their systems were designed before these rules existed.

For years, commercial security was a closed system. Cameras recorded, doors logged, and the data sat on a DVR until something went wrong. That assumption is gone. Regulators now classify video of identifiable people, badge swipes, and biometric scans as personal data.

1. Why Your Security System Is Now a Privacy Concern

Three categories of data your security system collects qualify as personal data:

  • Video footage capturing identifiable faces, license plates, or other features
  • Access control logs tying a person’s name or credential to a time and location
  • Biometric identifiers: fingerprints, facial geometry, hand scans, iris patterns

Under the California Consumer Privacy Act, this data tied to a California resident triggers disclosure, deletion, and opt-out obligations. Under GDPR, the same data tied to an EU resident triggers broader rights. Illinois, Texas, and Washington have biometric-specific laws with statutory damages.

2. What CCPA Requires of Your Camera and Access System

CCPA applies to businesses meeting any of three thresholds: $25 million in annual revenue, data of 100,000 or more California residents, or 50 percent of revenue from selling personal data. If you meet one of those tests and your systems capture California residents, your obligations include:

  • Disclose collection at or before the point of collection, via signage and a published privacy notice
  • Honor consumer rights to know, delete, and opt out of sale or sharing
  • Maintain a documented retention schedule, not indefinite storage
  • Produce specific footage tied to a verified consumer request within statutory timeframes

An unlimited-retention DVR is a liability. Documented retention, role-based access, and an audit trail are what compliance looks like.

3. How GDPR Changes the Picture for Multinational Operations

If your business has European Union employees, customers, or visitors on site, GDPR likely applies. It is stricter than CCPA in three ways: you must document a lawful basis before the cameras turn on, you may need to produce footage of a specific person within 30 days of a request, and cross-border transfers to U.S. data centers require contractual safeguards. For Baltimore-area businesses with European exposure, this is not hypothetical.

4. Biometric Privacy: The Highest-Risk Category

Biometric data sits in its own legal category because it cannot be changed. A leaked password can be reset; a leaked fingerprint cannot. Illinois’s BIPA has produced settlements in the hundreds of millions of dollars, and other states are adopting the template. If your access control uses fingerprint readers, facial recognition, or hand geometry, the bar is higher:

  • Written consent before collection, with disclosures about purpose and retention
  • A published retention and destruction policy
  • Prohibition on selling or profiting from biometric data
  • A documented standard of care for storage and transmission

5. What a Compliant Commercial Security Posture Looks Like

Compliance is not about which camera you buy. It is about how the system is configured and governed. HS Tech Group builds compliance into the design phase, not as a retrofit:

  • Documented retention schedules with automated deletion after the window
  • Role-based access controls with every view recorded in an audit log
  • Visible signage and a privacy notice naming what is collected, why, and for how long
  • Encrypted storage and transmission, plus a documented incident response procedure
  • Annual review against current law in the jurisdictions where you operate

These are operational decisions that belong with camera placement.

Does CCPA apply to my Baltimore business if I do not operate in California?

CCPA applies based on whose data you collect, not where your office sits. If your cameras capture California residents on site, the law reaches you once your business crosses one of the three statutory thresholds.

How long can I legally keep commercial security camera footage?

There is no single number across jurisdictions. The defensible standard is to keep footage only as long as needed for a documented business purpose, typically 30 to 90 days, with longer retention for incidents under legal hold.

Are access control logs considered personal data under privacy law?

Yes. A log tying a name or credential to a time and location is personal data under CCPA, GDPR, and most state privacy laws, subject to the same rules as video.

What is BIPA and why does it matter outside Illinois?

BIPA is the Illinois Biometric Information Privacy Act. It matters nationally because it has produced the largest biometric settlements in U.S. legal history and become the template other states are adopting.

Who is responsible for security data privacy compliance, the integrator or the business?

The business owns the legal obligation. The integrator owns the design that makes compliance achievable. A good integrator builds compliance capability in from day one.

When a visitor or job applicant asks what your business does with their image, badge swipe, or fingerprint, will you have a clear answer? HS Tech Group helps commercial businesses across Baltimore and Southeastern Pennsylvania design security systems that protect the building and meet the law. Schedule a compliance review at hstechgroup.com/commercial.