Video Surveillance and Privacy in Ontario: A Practical Guide

A practical governance guide for purposeful camera use, limited collection, notice, retention, access, disclosure, security, and regular review.

Privacy-aware video surveillance used discreetly in a commercial lobby

Privacy is not a sign installed after the cameras. It is a set of decisions about whether surveillance is necessary, what it captures, who may use it, how long it exists, and how the organization remains accountable.

This article is operational guidance, not legal advice. Organizations should identify the law that applies to their sector and activity and involve their privacy, legal, labour, and security stakeholders where appropriate.

Begin With Necessity and Purpose

Write a specific purpose for each surveillance zone. “For security” is usually too broad to guide design. Better statements connect a defined risk to a defined area and use, such as investigating unauthorized entry at a controlled receiving door.

The Office of the Privacy Commissioner of Canada’s private-sector guidelines recommend considering less privacy-invasive alternatives, establishing the business reason, using surveillance only for that reason, limiting viewing range, providing notice, restricting access, and destroying recordings when no longer required.

Create a camera-purpose schedule with:

  • camera ID and accountable business owner;
  • risk or event addressed;
  • exact field of view and operating hours;
  • recording, monitoring, analytics, and audio status;
  • people or adjacent areas incidentally captured;
  • retention rule;
  • authorized user roles;
  • disclosures and integrations;
  • review date.

Minimize Collection in the Design

Minimization is a physical and technical exercise. During the survey:

  • point cameras at the required threshold or asset, not the widest possible area;
  • avoid windows, neighbouring properties, public sidewalks, desks, or screens unless necessary for the purpose;
  • use privacy masks where stable geometry permits;
  • choose a tighter lens or different mounting point before relying on digital masking;
  • disable unused microphones and analytics;
  • restrict PTZ presets and operator freedom near sensitive areas;
  • avoid spaces with heightened expectations of privacy.

Re-check the view after construction, furniture, foliage, and tenant changes. A previously acceptable view can become excessive when the environment changes.

Provide Meaningful Notice

Notice should reach people before they enter the monitored area and explain who is collecting images, the purpose, and how to ask questions. The federal guidance recommends clear and understandable notice with contact information.

The sign is one layer. A public-facing privacy notice can explain categories of surveillance, purpose, access or inquiry process, and contact. Internal procedures should tell reception and security staff how to route a question rather than improvise an answer.

Set Retention From the Business Process

Avoid choosing retention only because a recorder can hold a familiar number of days. Determine:

  1. how incidents are detected;
  2. how long discovery can reasonably take;
  3. who decides to preserve a clip;
  4. how preservation is recorded;
  5. when a protected clip is reviewed and deleted;
  6. how routine footage is automatically overwritten or destroyed.

The retention rule should be technically configured and periodically verified. If different zones require different periods, document why.

Restrict Access and Exports

Separate live viewing, playback, administration, export, and audit permissions. Give users the minimum role needed for their duties and review high-risk access periodically.

Exports need stronger handling because they leave the recorder’s normal controls. Use an incident or case number, record requester and approver, limit the time window, protect the file, verify the recipient, and document disclosure. When responding to an individual, consider whether other people must be masked or otherwise protected.

Secure the System

Privacy depends on cybersecurity and physical security. Protect recorders and network equipment, use unique administrator identities, segment device networks, encrypt supported connections, patch through a controlled process, back up configuration, monitor failures, and log administrative actions.

Service providers should have defined access, confidentiality, remote-support, incident-notification, return or deletion, and subcontractor terms. Remove temporary installer accounts after handover.

Treat Analytics as a New Use Decision

Adding face search, behavioural classification, demographic inference, or cross-site tracking is not merely a software upgrade. It can materially change the information collected and how people are evaluated.

Before enabling new analytics, repeat the necessity, proportionality, accuracy, bias, notice, access, retention, security, and human-review analysis. Pilot with measurable objectives and a stop condition. Do not let a feature become permanent only because it was easy to enable.

Public-Sector Organizations Need Their Own Review

Ontario public institutions have specific obligations under provincial access and privacy statutes. The Information and Privacy Commissioner of Ontario’s video-surveillance guidance addresses authority, notice, retention, access, disclosure, audit, and other controls. The IPC notes that parts of its guidance are under review following 2026 legislative changes, so institutions should check the current guidance and consult their privacy coordinator or counsel.

Private-sector, health, education, residential, employment, and regulated contexts can differ. Do not copy a policy from another sector without determining which rules and expectations apply.

Run a Periodic Surveillance Review

At least on a defined schedule and after material change, ask:

  • Does the original problem still exist?
  • Is the camera effective for that purpose?
  • Could a less intrusive measure now work?
  • Is the field of view still limited?
  • Are signs and notices accurate?
  • Are user roles, exports, and disclosures appropriate?
  • Does deletion work as documented?
  • Have analytics, integrations, or vendor access changed?
  • Can the organization answer a request or incident confidently?

Good surveillance governance is visible in the drawings, settings, roles, logs, training, and review records. That is what turns a privacy principle into daily practice.

Frequently Asked Questions

A documented purpose supports necessity, field-of-view, access, and retention decisions. Avoid installing a camera first and inventing a broad purpose later. Applicable law and context should be reviewed with qualified privacy or legal advisers.

Use the shortest period that supports the documented purpose and incident-discovery workflow, subject to applicable obligations. Define automatic deletion, preservation for an incident, approval, and final secure disposal.

Audio creates additional privacy and legal concerns. The federal private-sector guidance says sound should not be recorded unless there is a specific need. Organizations should obtain qualified advice before enabling it.