Setting a Video Retention Policy for Commercial Properties

Set a defensible commercial video retention period using incident discovery, privacy, legal needs, measured storage and tested deletion controls.

Illustrative security, privacy and IT leaders reviewing a commercial video retention plan

Commercial properties often inherit a familiar retention number from an old proposal, recorder default or neighbouring site. That shortcut can leave an incident undiscoverable or keep identifiable video longer than the approved purpose supports.

A defensible policy starts with the event workflow. Determine when a relevant incident could reasonably be discovered, how quickly it can be reported, who can preserve the footage, and which legal, privacy, contractual or regulatory duties apply. Configure the shortest period that reliably covers that process. Then validate it with measured bitrate, playback, overwrite and incident-hold tests.

This guide provides a decision framework for security, privacy and IT leaders. It is operational guidance, not legal advice. Identify the laws and obligations that apply to the organization, property, occupants and proposed uses with qualified advisers.

1. Identify the governing context before choosing a day count

Start by mapping who controls the system, whose images it captures and why the recordings exist. A property owner, third-party manager, tenant, security contractor and cloud provider can each have different responsibilities.

Record these inputs:

  • accountable organization and privacy contact;
  • property type, occupants and monitored zones;
  • documented purpose for each camera group;
  • applicable privacy, employment, residential, public-sector or sector-specific requirements;
  • insurer, lease, monitoring and service-contract conditions;
  • access, complaint, investigation and disclosure processes;
  • litigation, law-enforcement or regulatory preservation procedures; and
  • systems and vendors that store, replicate, export or back up video.

The Office of the Privacy Commissioner of Canada’s PIPEDA self-assessment tool says organizations subject to PIPEDA should retain personal information only as long as necessary for the identified purpose, establish minimum and maximum periods, consider applicable legislative requirements, audit holdings and use secure disposal procedures. Video can also be subject to other laws or contractual duties, so confirm applicability instead of applying one privacy framework to every property.

The OPC’s overt private-sector video-surveillance guidance recommends limited access, secure storage, documented disclosure, destruction when recordings are no longer required and periodic evaluation. It expressly excludes employee surveillance and covert surveillance. Workplace, residential, health, public-sector and regulated settings need their own analysis.

Write the governing sources beside each retention rule. A policy entry should identify whether the period comes from a legal requirement, an incident workflow, a contract, an approved risk decision or a combination.

2. Build a purpose and discovery matrix for every camera group

Group cameras only when their purposes and discovery patterns are genuinely similar. A receiving door, elevator lobby, cash room and fenced yard can generate incidents that become known at different times.

Use a matrix like this:

FieldDecision to document
Camera groupIDs and zones governed by the rule
PurposeSpecific event or risk the recording supports
People capturedTenants, visitors, employees, contractors or public passersby
Discovery sourceAlarm, complaint, patrol, audit, inventory process or tenant report
Latest reasonable discoveryEvidence-based time by which the event should become known
Intake and approval timeTime needed to route the report and authorize preservation
Routine periodConfigured automatic-overwrite or deletion period
Hold triggerIncident, access request, claim, investigation or legal instruction
Hold ownerRole authorized to preserve and release
Review dateWhen the need and period will be reassessed

Interview the people who receive incidents. Useful questions include:

  • How frequently are deliveries, damage reports, access exceptions or inventory discrepancies reviewed?
  • Can weekends, holidays, staff absence or tenant reporting extend discovery?
  • Which system first reveals the event, and does that alert reliably reach an owned queue?
  • How long does approval take after a report arrives?
  • Have prior requests failed because the relevant time or camera was unclear?
  • Can the discovery process be improved instead of retaining every recording longer?

Treat delayed discovery as an operating problem as well as a storage input. Better alarm routing, daily exception review and clear tenant reporting can reduce the period required to find relevant footage.

3. Derive the routine retention period from the workflow

Use a planning model rather than a universal recommendation:

Routine retention planning baseline = latest reasonable incident discovery + reporting and triage time + authorized preservation time + tested operational margin

This formula is a decision aid, not a legal rule. Applicable minimum or maximum periods can override the operational result. Explain every input and approve the final period through the organization’s privacy and risk process.

For example, a loading event might be reconciled on the next business day, while a tenant absence could delay discovery of damage in another zone. Those groups may justify different periods. A longer period for all cameras creates additional personal-information exposure and storage demand without automatically improving investigations.

Challenge each proposed period:

  1. Purpose: Which approved event requires this recording?
  2. Discovery: What evidence supports the latest discovery time?
  3. Workflow: Can an authorized person preserve footage before routine overwrite?
  4. Minimum: Does a law, decision, contract or valid access process require a minimum?
  5. Maximum: When does ordinary footage stop serving the identified purpose?
  6. Proportionality: Does the benefit justify the additional volume of identifiable activity retained?
  7. Technical reality: Can the system deliver the period at required image quality under busy and low-light conditions?

Ontario public institutions should consult their privacy coordinator and the Information and Privacy Commissioner of Ontario’s video-surveillance guidance. The IPC says parts of that 2015 public-sector guidance are under review following 2026 legislative changes. Its statutory context and minimum-retention discussion should not be presented as a universal rule for private commercial properties.

4. Calculate storage from evidence, then measure it on site

Retention policy and storage design influence each other. Policy defines the required period. Technical design must achieve it without silently reducing recording quality or losing the oldest footage early.

For one continuously recorded stream, a simplified decimal estimate is:

Storage per day in GB = average bitrate in Mb/s × 10.8

A stream averaging 4 Mb/s therefore uses about 43.2 GB per day and about 1.30 TB over 30 days before filesystem, database, redundancy, export, growth and operating reserves. This is arithmetic for planning, not a prediction for a specific camera.

Actual bitrate varies with:

  • scene motion and detail;
  • day and night noise;
  • resolution, frame rate, codec and compression;
  • variable, maximum or average bitrate controls;
  • continuous, scheduled or event-triggered recording;
  • audio and metadata streams;
  • pre-event and post-event recording; and
  • camera model, firmware and analytics.

The current AXIS Site Designer user manual explains that its storage estimates use camera model, scene, lighting, motion, schedule, resolution, frame rate, codec and compression. It also identifies 30 days as a tool default. A design default is only a starting input. Replace it with the approved policy period and test the result against representative recordings.

Use this validation process:

  1. Configure the intended production profiles and schedules.
  2. Measure actual bitrate during representative busy, quiet, daylight and low-light periods.
  3. Include all recording locations, edge storage, central storage, replicas and cloud copies.
  4. Reserve capacity for database operation, protected incidents, degraded disks and planned camera growth.
  5. Verify the oldest available recording for every policy group.
  6. Trigger alerts before reduced capacity causes an unplanned retention shortfall.

Avoid lowering image quality solely to force video into a fixed disk budget. Return to the purpose and decide whether the period, recording schedule, camera grouping, scene design or capacity should change.

5. Separate routine overwrite from incident preservation

Routine retention governs ordinary video. Incident preservation creates a controlled exception for a defined case. Keep the two processes visibly separate in policy, permissions and storage reporting.

An incident-hold record should contain:

  • unique case or request number;
  • reason and authority;
  • requester and approving role;
  • camera IDs and exact time range, including time-zone reference;
  • date and method of preservation;
  • integrity or authenticity controls supported by the system;
  • storage location and access roles;
  • disclosures and recipients;
  • review or expiry date;
  • release authority; and
  • final deletion or transfer evidence.

Preserve the narrowest useful set. Broad exports create larger review, disclosure and safeguarding burdens. Document any expansion after investigators identify an additional camera or time window.

Define triggers for:

  • reported security or safety incidents;
  • tenant or customer complaints;
  • privacy-access requests;
  • insurance claims;
  • law-enforcement or regulator requests; and
  • instructions from legal counsel concerning anticipated or active proceedings.

Route uncertain requests to privacy or legal advisers before release or deletion. Front-line operators should know how to prevent routine overwrite temporarily while the authorized decision is made. A temporary hold also needs an owner and expiry review.

6. Translate the policy into recorder and cloud controls

For each storage platform, map the approved rule to the exact configuration object. It may be a per-camera value, recorder pool, archive tier, cloud licence, event rule or storage quota.

Document:

  • system name and version;
  • camera-to-policy-group assignment;
  • configured routine period and recording mode;
  • overwrite behaviour when storage is full;
  • edge, central, archive and cloud copy relationships;
  • failover and backfill behaviour after network loss;
  • locked or bookmarked recording behaviour;
  • deletion, export and hold permissions;
  • storage-health and capacity alerts; and
  • configuration owner and last verification date.

ONVIF Profile G supports interoperable functions for configuring, requesting and controlling recordings and for storage retrieval in conformant IP video products. The ONVIF Profile G Client Test Specification version 22.06 includes conditional tests for creating and deleting recordings when a device supports dynamic recordings.

Conformance describes supported interfaces and tested operations. The property still needs to decide the retention period, confirm which optional features the deployed device and client support, configure permissions, validate vendor-specific overwrite behaviour and prove deletion across every copy.

Treat these conditions explicitly:

  • Edge plus central recording: determine which copy governs recovery during a network interruption and when backfilled video expires.
  • Cloud replication: confirm data location, subcontractors, return or deletion at contract end and whether provider backups follow the same schedule.
  • Protected incidents: monitor reserved capacity because locked clips may remain outside routine overwrite.
  • Decommissioning: securely erase recordings and configuration from drives, appliances, memory cards and vendor services according to approved procedures.

7. Define access, disclosure and deletion controls

Separate live view, playback, export, hold, deletion, administration and audit privileges. Use named accounts and retain enough activity evidence to review high-risk actions.

The retention policy should identify:

  • who can search routine video;
  • who can approve an export or disclosure;
  • who can create, extend and release a hold;
  • who can change the configured period;
  • who reviews access and configuration logs;
  • how exported files are protected and transferred; and
  • how copies held by vendors, investigators or internal teams reach final disposition.

Exports can outlive the recorder policy because they sit in case folders, email, portable media or cloud collaboration tools. Put every approved copy under a case schedule and prohibit informal downloads. A routine recorder overwrite does not delete an exported copy.

If video is used to make a decision about an individual, obtain advice on access and minimum-retention requirements. The OPC self-assessment tool cited above instructs organizations subject to PIPEDA to keep information used for a decision long enough to allow access after that decision. Other governing laws can impose different rules.

8. Test retention, holds and deletion as acceptance criteria

Require observable pass or fail results before commissioning and after material change.

Routine retention tests

  • Retrieve the oldest expected recording from each policy group.
  • Confirm that a clip immediately inside the boundary is available and a routine clip beyond it follows the approved deletion behaviour.
  • Verify timestamps, time zone and synchronization across camera, recorder and exported file.
  • Review busy and low-light periods for usable quality and actual bitrate.
  • Confirm that a failed disk, offline camera or storage threshold generates an owned alert.

Preservation tests

  • Create a fictional case with a narrow camera and time range.
  • Preserve the clip using the approved role.
  • Confirm that routine overwrite does not remove the protected material.
  • Verify access logging, export protection and recipient workflow.
  • Release the test hold and confirm final disposition at the expected time.

Change tests

  • Add a camera or higher-resolution stream and recalculate capacity.
  • Change a policy group and verify every associated camera.
  • Test backfill after a controlled network interruption where supported.
  • Confirm that cloud, archive and exported copies follow their documented schedules.
  • Review notices and internal procedures when the purpose or period changes.

Run these tests periodically and after storage replacement, recorder updates, camera changes, firmware work, cloud migration or policy revision. Keep evidence with the approved retention schedule.

9. Approve a concise policy and ask better vendor questions

The final policy should state:

  1. scope and accountable owner;
  2. purpose and camera groups;
  3. governing requirements and review contacts;
  4. routine periods with documented rationale;
  5. recording, storage, replication and overwrite rules;
  6. access, export and disclosure roles;
  7. incident preservation, expiry and release process;
  8. secure deletion and equipment-disposal process;
  9. monitoring, testing and audit requirements; and
  10. review triggers and approval history.

Ask vendors:

  • Can retention be configured and reported by camera group?
  • Which copies, replicas, backups and exports exist outside the primary recorder?
  • What happens when protected incidents consume reserved capacity?
  • How does the system prove the oldest available date without manually opening every camera?
  • Which alerts identify lost recording, failed storage, reduced retention or time drift?
  • How are edge recordings reconciled after connectivity returns?
  • Which ONVIF Profile G functions are supported by the exact client and device models?
  • How are tenant access requests, redaction, disclosure and secure export handled?
  • How is data deleted from cloud services and retired storage media?
  • What acceptance evidence will prove the approved period and hold workflow?

Connect this schedule to the technical design for commercial security cameras and the broader Ontario video-surveillance privacy program. If your property needs a documented storage and preservation baseline, request a retention and system review covering camera purposes, real discovery timelines, deployed architecture and applicable obligations.

Frequently Asked Questions

Choose the shortest justified period that covers the documented incident-discovery and preservation workflow, subject to applicable legal, regulatory, contractual and access requirements. Different camera groups may need different periods. Avoid adopting a universal day count without evidence.

A universal 30-day requirement should not be assumed. Requirements depend on the organization, sector, purpose and applicable law. Some design tools use 30 days as a default planning value, which does not create a legal rule. Confirm the governing context with qualified privacy or legal advisers.

Routine retention governs automatic overwrite or deletion of ordinary recordings. An incident hold preserves a narrowly selected time range and camera set for an approved case until an authorized reviewer releases it under a documented schedule.

Test the oldest expected recording, playback across the retention boundary, automatic overwrite, time accuracy, incident preservation, hold release, access logs and capacity alerts. Repeat after camera, bitrate, storage, firmware or policy changes.