
Video surveillance design in the US intersects with an expanding, state-by-state patchwork of privacy legislation rather than a single national data protection law. Roughly twenty states have now enacted comprehensive consumer privacy statutes (California's CCPA/CPRA being the first, joined by Colorado, Connecticut, Virginia, Oregon, Texas, and others, with Maryland's law taking effect October 1, 2026), and nearly all classify biometric data as "sensitive" information subject to heightened obligations. Separately, three states — Illinois, Texas, and Washington — maintain dedicated, standalone biometric privacy statutes. Illinois's Biometric Information Privacy Act (BIPA), enacted in 2008, is widely regarded as the strictest: it requires written consent before collecting a biometric identifier, mandates a published retention and destruction schedule, prohibits selling biometric data, and is the only one of these statutes with a private right of action, with statutory damages of $1,000 per negligent violation and $5,000 per reckless or intentional violation plus attorney's fees. Texas's CUBI similarly requires informed consent and destruction timelines but is enforced only by the state attorney general.
Where this becomes directly relevant to surveillance design is any camera deployment incorporating facial recognition, gait analysis, or other biometric-identifying analytics — squarely "biometric identifier" territory triggering consent, notice, retention-schedule, and deletion-request obligations a conventional, non-analytic CCTV deployment generally does not trigger in the same way.
Why this matters specifically for US projects
The applicable privacy obligations for a given surveillance system depend on which state (or states) the cameras are deployed in, and whether the system uses biometric analytics at all — meaning the same hardware and software configuration can carry materially different compliance obligations and litigation exposure depending purely on deployment location.
| Law type | Example(s) | Biometric-specific? | Private right of action? | Key surveillance implication |
|---|---|---|---|---|
| Standalone biometric statute | Illinois BIPA | Yes | Yes ($1,000–$5,000/violation) | Written consent, retention schedule, no sale — high litigation exposure |
| Standalone biometric statute | Texas CUBI | Yes | No (AG enforcement only) | Consent and destruction timeline required, lower exposure than Illinois |
| Comprehensive privacy law | California CCPA/CPRA | Biometric treated as "sensitive" | Limited (breach scenarios mainly) | Opt-in consent, access/deletion rights, notice requirements |
| Comprehensive privacy law | Colorado, Connecticut, Virginia, Oregon, and others | Biometric generally "sensitive" | Generally no broad private right of action | Similar opt-in/notice/access framework |
Practical guidance
ASDV flags, at the design stage of any US surveillance project, whether the system will include biometric-identifying analytics, since that single decision changes the applicable legal framework significantly, particularly in Illinois. We confirm the specific state privacy law landscape applicable to each deployment location for multi-site clients and recommend routing final consent-language and retention decisions through qualified US privacy counsel.
Common mistakes
Deploying facial recognition analytics in Illinois without written consent and a published retention schedule; assuming compliance in one state automatically applies everywhere in a multi-site portfolio; treating video retention policy as a purely technical/storage decision.
Future outlook
Expect the number of states with comprehensive privacy laws touching biometric and video data to keep growing. Any specific deployment involving biometric analytics should have its consent, notice, and retention approach reviewed by qualified US privacy counsel before go-live.