CCTV and Video Surveillance Compliance in the US: State Privacy Laws (CCPA/CPRA and Others)
CCTV Design — ASDV Consultant

Video surveillance design in the US intersects with an expanding, state-by-state patchwork of privacy legislation rather than a single national data protection law. Roughly twenty states have now enacted comprehensive consumer privacy statutes (California's CCPA/CPRA being the first, joined by Colorado, Connecticut, Virginia, Oregon, Texas, and others, with Maryland's law taking effect October 1, 2026), and nearly all classify biometric data as "sensitive" information subject to heightened obligations. Separately, three states — Illinois, Texas, and Washington — maintain dedicated, standalone biometric privacy statutes. Illinois's Biometric Information Privacy Act (BIPA), enacted in 2008, is widely regarded as the strictest: it requires written consent before collecting a biometric identifier, mandates a published retention and destruction schedule, prohibits selling biometric data, and is the only one of these statutes with a private right of action, with statutory damages of $1,000 per negligent violation and $5,000 per reckless or intentional violation plus attorney's fees. Texas's CUBI similarly requires informed consent and destruction timelines but is enforced only by the state attorney general.

Where this becomes directly relevant to surveillance design is any camera deployment incorporating facial recognition, gait analysis, or other biometric-identifying analytics — squarely "biometric identifier" territory triggering consent, notice, retention-schedule, and deletion-request obligations a conventional, non-analytic CCTV deployment generally does not trigger in the same way.

Why this matters specifically for US projects

The applicable privacy obligations for a given surveillance system depend on which state (or states) the cameras are deployed in, and whether the system uses biometric analytics at all — meaning the same hardware and software configuration can carry materially different compliance obligations and litigation exposure depending purely on deployment location.

Law typeExample(s)Biometric-specific?Private right of action?Key surveillance implication
Standalone biometric statuteIllinois BIPAYesYes ($1,000–$5,000/violation)Written consent, retention schedule, no sale — high litigation exposure
Standalone biometric statuteTexas CUBIYesNo (AG enforcement only)Consent and destruction timeline required, lower exposure than Illinois
Comprehensive privacy lawCalifornia CCPA/CPRABiometric treated as "sensitive"Limited (breach scenarios mainly)Opt-in consent, access/deletion rights, notice requirements
Comprehensive privacy lawColorado, Connecticut, Virginia, Oregon, and othersBiometric generally "sensitive"Generally no broad private right of actionSimilar opt-in/notice/access framework

Practical guidance

ASDV flags, at the design stage of any US surveillance project, whether the system will include biometric-identifying analytics, since that single decision changes the applicable legal framework significantly, particularly in Illinois. We confirm the specific state privacy law landscape applicable to each deployment location for multi-site clients and recommend routing final consent-language and retention decisions through qualified US privacy counsel.

Common mistakes

Deploying facial recognition analytics in Illinois without written consent and a published retention schedule; assuming compliance in one state automatically applies everywhere in a multi-site portfolio; treating video retention policy as a purely technical/storage decision.

Future outlook

Expect the number of states with comprehensive privacy laws touching biometric and video data to keep growing. Any specific deployment involving biometric analytics should have its consent, notice, and retention approach reviewed by qualified US privacy counsel before go-live.

Frequently Asked Questions

No. Compliance obligations come from a growing, state-by-state patchwork of comprehensive privacy statutes and standalone biometric privacy laws in three states.
BIPA is the only standalone biometric statute with a private right of action, with statutory damages of $1,000-$5,000 per violation plus attorney's fees.
Not necessarily to the same degree — heightened obligations under BIPA-type statutes are specifically triggered by biometric identification capability.
Roughly twenty states as of 2026, with Maryland's law set to take effect October 1, 2026.
Yes, particularly where biometric analytics are involved or a project spans multiple states.