Handling Access Requests for Commercial Surveillance Video
A practical Ontario procedure for receiving, preserving, verifying, reviewing, redacting and securely disclosing commercial surveillance video.
A request for surveillance footage often arrives with urgency: an incident occurred, routine overwrite is approaching, and the requester believes the video will resolve what happened. Property, privacy and legal teams should preserve the narrow potentially responsive recording promptly, then verify identity and authority before deciding what can be disclosed.
Use one documented workflow for intake, jurisdiction, preservation, search, review, severing, decision and secure delivery. This keeps unrelated tenants, employees, visitors and passersby from being exposed while giving a valid requester a clear, timely response.
This article provides an operational procedure for commercial properties. It does not determine which law applies to a specific organization or request. Start with the broader Ontario video-surveillance privacy guide, then have the organization’s privacy lead or qualified counsel resolve jurisdiction, exceptions, litigation, employment, health, residential and law-enforcement issues.
Classify the request before anyone searches or exports
Reception, security and property staff should route every request to one owned intake channel. They should avoid promising release, showing live playback, forwarding a phone recording or deciding that the requester has no right of access.
Classify the request into a defined workflow:
| Request type | Initial question | Typical owner |
|---|---|---|
| Individual access request | Is the person seeking personal information about themselves under an applicable privacy law? | Privacy lead |
| Law-enforcement or regulator request | What legal authority, production instrument or voluntary-disclosure provision is being relied on? | Legal or privacy lead |
| Litigation, claim or insurer request | Does a hold, legal process, consent or contractual authority apply? | Legal or risk lead |
| Tenant, employer or internal investigation | Does the proposed use fit the original purpose and approved authority? | Privacy, HR, legal or security lead |
| Preservation request | Which recording could be overwritten before authority is resolved? | Records owner with privacy oversight |
| Informal viewing request | Does the request need to be converted into a formal access or incident process? | Privacy lead |
These categories can overlap. A tenant may ask the property manager to preserve a clip for police while also requesting access to video showing the tenant. Record each purpose separately because the legal basis, review and recipient may differ.
The Office of the Privacy Commissioner of Canada’s PIPEDA overview explains that the federal private-sector law applies to organizations handling personal information in commercial activities, subject to jurisdictional and sector-specific rules. It also distinguishes employee information at federally regulated businesses. Public institutions, health information custodians, provincially regulated employment and other settings require their own analysis.
Use an intake form that starts the clock and the search
Record the request as soon as it reaches any organizational channel. A complete intake record should contain:
- received date, time, channel and staff member;
- requester name, contact route and preferred accessible format;
- request type and claimed authority;
- incident date, approximate time and location;
- description of the requester, vehicle or object needed to locate the scene;
- cameras or areas believed to be relevant, if known;
- police occurrence, claim, case or work-order number, if applicable;
- reason for urgency, including expected overwrite;
- identity-verification status and method;
- privacy, legal, HR, insurer or law-enforcement contacts involved;
- acknowledgement, deadline and extension dates; and
- preservation, decision and final-disposition status.
Ask only for identity evidence proportionate to the disclosure risk. Store identity documents in a restricted location and avoid placing copies into an ordinary maintenance ticket. The OPC’s current guide on responding to access requests under PIPEDA says organizations may need more information to verify identity or locate records, should record the received date, clarify unclear requests and identify every source that may contain responsive information.
For PIPEDA-governed requests, section 8 requires a written request, assistance where needed and a response with due diligence within 30 days. It permits extensions only in specified circumstances and requires notice within the original period. The statute also requires information that is the subject of the request to be retained long enough for the individual to exhaust applicable recourse. See PIPEDA section 8.
Create deadline alerts at intake, several business days before the response deadline, and before any permitted extension-notice deadline. An acknowledgement alone does not complete a PIPEDA response.
Preserve a narrow segment without deciding disclosure
Preservation protects the decision process from routine overwrite. It does not confirm that video exists, prove the requester’s account or authorize release.
An approved operator should:
- record the recorder’s current time, time zone and observed drift from a trusted reference;
- identify the smallest camera set and time range reasonably connected to the request;
- protect that range from routine overwrite using the system’s approved hold method;
- retain an unaltered controlled export where policy requires a separate copy;
- calculate or record an integrity hash when the workflow and tools support it;
- place the copy in restricted case storage with a unique identifier;
- record operator, date, source system, camera IDs, export settings and every transfer; and
- define who may release the hold and when the case must be reviewed.
Preserve enough context to understand the event while limiting unrelated activity. If a loading-dock event occurred at 14:10, a justified window around the event may be appropriate. Exporting an entire day from every camera creates additional review, privacy and security burden.
If the recording has already been overwritten under the approved routine policy, document the search, the configured and observed retention, and the result. Do not recreate certainty with screenshots from another incident or a staff member’s recollection. The OPC’s access interpretation bulletin notes that a requester should be advised when requested personal information was destroyed according to the organization’s retention policy.
Search every plausible repository and document the result
The search plan should be repeatable by another authorized reviewer. List each place where responsive video or related personal information could exist:
- central recorder or video management system;
- camera edge storage and network-recovery recording;
- cloud archive or replicated storage;
- incident-management platform;
- prior exports held by security, property, legal or an insurer;
- approved evidence-sharing portal;
- service-provider or monitoring records; and
- access-control, intercom or alarm events needed to locate the video.
For each source, record the custodian, search terms, camera IDs, time range, system time correction, result and reviewer. Check whether camera names changed, daylight-saving settings shifted, a recorder was replaced or a view was offline. A “no footage” response should be supported by a documented search and known system condition.
Keep the search focused on the requester’s personal information and the stated incident. Expansion should require a reason and approval. Discovery of a separate security, safety or privacy incident should enter its own case rather than quietly broadening the access request.
Review authority, exemptions and third-party information
Place a decision checklist beside the recording. The reviewer should answer:
- Which law, policy, contract or legal instrument governs this request?
- Has the requester’s identity and right of access been verified?
- Which portions contain the requester’s personal information?
- Which portions identify other people, vehicles, credentials, screens or conversations?
- Does an applicable mandatory or discretionary exception apply?
- Can protected information be severed while giving meaningful access to the remainder?
- Has the video been disclosed previously, and must that use or disclosure be explained?
- Does a government-institution consultation or special notice rule apply?
- Which delivery method gives understandable access with the least additional exposure?
- Who has authority to approve the decision letter and release?
The OPC’s PIPEDA access guide says exempt information should be identified and severed where possible, with access provided to the remainder. It also requires a written explanation and recourse information when an applicable exemption is used. The OPC’s interpretation bulletin explains that third-party personal information must be severed when it can be separated from the requester’s information.
Avoid a blanket practice that refuses every video containing another person. Video frequently includes bystanders. Review whether blurring, cropping, masking, muting, still images, a shorter segment or supervised viewing can protect others while providing meaningful access under the governing rules. Preserve the unaltered controlled original and create a separate disclosure copy.
Choose and test the least-exposing access method
Access can take different forms depending on the law, the request, available severing tools and the sensitivity of the scene. Options may include:
- an encrypted redacted video export;
- selected still frames with unrelated people obscured;
- a cropped segment limited to the requester’s activity;
- supervised viewing in a controlled room;
- an understandable log or alternate format where permitted; or
- a written decision explaining that no responsive recording was found or that access is refused under a stated provision.
The OPC’s interpretation bulletin notes that PIPEDA does not guarantee access in a particular format in every case. The organization remains responsible for providing access in an understandable form when the right applies.
Test the disclosure copy before release:
- confirm the correct requester, site, cameras and time range;
- view the entire file from beginning to end;
- check every frame for unmasked third parties and reflections;
- verify that muted audio cannot be recovered from an alternate track;
- confirm file metadata does not expose unnecessary system or location details;
- scan the transfer package for unrelated files;
- open the export on a separate approved workstation; and
- compare the disclosure copy with the decision record.
Use identity verification at delivery, an encrypted transfer, a separate key channel where appropriate, an expiry date and receipt confirmation. Avoid ordinary email attachments, public links and personal messaging accounts for surveillance video.
Give a complete response and preserve the audit trail
The response should state:
- the request received and governing process;
- whether responsive personal information was found;
- the sources and date ranges searched at an appropriate level of detail;
- how access is being provided;
- any information severed or withheld and the applicable reasons;
- any approved fee and prior estimate, where legally permitted;
- the contact for questions or accessible formats;
- correction or challenge options where applicable; and
- available complaint, appeal or other recourse.
Retain the request, identity-verification record, search log, preservation record, decision analysis, approvals, disclosure copy, transfer evidence and final disposition according to the approved case schedule. Keep high-risk exports separate from routine video and restrict access to the case team.
The OPC’s private-sector video-surveillance guidelines recommend secure storage, limited access, documented disclosures, destruction when recordings are no longer required and readiness to provide individuals access to information about themselves. The guidance addresses overt surveillance of the public and dates from 2008, so employee, covert, residential, health and other specialized contexts need separate review.
Ontario public institutions should follow their statutory freedom-of-information and privacy procedures. The Information and Privacy Commissioner of Ontario’s video-surveillance guidelines address access, disclosure, retention and law-enforcement requests for institutions governed by Ontario public-sector privacy laws. The IPC states that parts of the 2015 guidance are under review following 2026 legislative amendments. Check the current page and involve the institution’s freedom-of-information or privacy coordinator.
Test the procedure before a real request arrives
Run a tabletop exercise using fictional information and a test recording. The team should prove that it can:
- recognize a request received by reception or security;
- route it to the accountable privacy owner;
- start the correct deadline and escalation alerts;
- preserve a narrow segment before overwrite;
- search edge, central, cloud and prior-export locations;
- verify identity without overcollecting documents;
- create and quality-check a severed disclosure copy;
- send a complete decision through an approved channel;
- record recipient verification and receipt; and
- release the hold and dispose of copies when authorized.
Record every failed step, owner, correction and retest date. Repeat the exercise after recorder replacement, retention changes, cloud migration, privacy-law updates, staffing changes or adoption of new analytics.
The commercial security camera system should support narrow preservation, role-based playback and export, useful audit logs, privacy masking, reliable time synchronization and controlled deletion. The organization still owns the request, legal decision and disclosure. Securitron Canada can help GTA property teams configure and test the technical controls that support an approved privacy procedure.
Frequently Asked Questions
An individual may have an access right under the privacy law governing the organization and activity. Confirm jurisdiction, obtain a written request where required, verify identity, locate responsive video, review applicable exceptions and protect other people before granting or refusing access.
Route the request through the organization's approved privacy and disclosure procedure. Verify the requester's identity and authority, preserve the narrow relevant segment, assess the governing law and review unrelated personal information before deciding how access can be provided.
For an organization and request governed by PIPEDA, section 8 generally requires a response within 30 days. Specific extension rules and notice requirements apply. Confirm when the request became complete and involve the privacy lead or counsel when applicability or timing is uncertain.
Assess whether their personal information can be severed. Depending on the governing law and circumstances, controls may include blurring, cropping, muting audio, limiting the time window, providing stills or arranging supervised access. Document the legal basis and preserve an unaltered controlled original.
Preserve the narrow potentially responsive recording promptly under an approved hold, without changing the original recording. Record the cameras, time range, system time, operator, reason, storage location and integrity evidence. Preservation does not decide whether disclosure is authorized.


