This article is general information, not legal advice. Surveillance, consent, and privacy laws vary by state and change quickly. Consult qualified counsel before making compliance decisions for your business.
Is it legal for a business to record video on its own property?
In most circumstances, yes. No single federal statute prohibits silent video surveillance on private commercial property, and courts have long allowed businesses to monitor entrances, sales floors, warehouses, yards, and parking areas for security purposes. The controlling concept is the reasonable expectation of privacy: people in a store aisle, a loading dock, or an open-plan work area generally do not have one, while people in a restroom or changing room clearly do. If that phrase is new to your team, the security glossary covers it alongside other compliance terms worth knowing.
Two qualifiers matter for operators. First, "legal by default" applies to silent video, not audio, and not biometric identification. Those are governed by stricter statutes covered below. Second, state tort law still applies even where no statute does. A camera positioned to see into a space where privacy is expected, on your property or a neighbor's, can support an intrusion-upon-seclusion claim regardless of your security intent.
For employee monitoring specifically, the same expectation-of-privacy analysis applies, but the safer practice is disclosure: tell employees in writing that video surveillance is in use in work areas, and get acknowledgment through your handbook process. Covert workplace cameras are where businesses most often lose otherwise defensible cases.
Why audio recording is the biggest legal trap
Audio is where a routine camera deployment becomes a potential wiretap violation. Federal law under 18 U.S.C. § 2511 prohibits intercepting oral communications, with one-party consent as the federal baseline: recording is permitted if at least one party to the conversation consents. Silent video is not an "interception" of oral communication, which is why the video and audio rules diverge so sharply.
States can and do go further. California's Penal Code § 632 requires all-party consent to record confidential communications, and roughly a dozen states have all-party consent rules as of this writing, per the Reporters Committee for Freedom of the Press recording guide. A camera microphone quietly capturing customer or employee conversations in one of those states can violate the statute even though the video itself is lawful.
The practical problem is that many commercial cameras ship with microphones enabled by default. For a multi-site business operating across state lines, the simplest compliant posture is usually to disable audio capture entirely unless counsel has approved a specific, disclosed use in a specific state. If you do record audio anywhere, post explicit notice that audio recording is in use, not just generic camera signage, and confirm the consent standard in that state before deployment.

Where cameras cannot point: privacy zones
Even on fully private property, some spaces are off limits. Restrooms, locker rooms, changing areas, lactation rooms, and any space used for medical care or personal hygiene carry a reasonable expectation of privacy that survives almost any business justification. Cameras do not belong in them, and neither do camera views through their doorways or windows.
Placement discipline also extends beyond your property line. Wide-angle and PTZ cameras on poles or trailers can incidentally cover neighboring residences, fence lines, or adjacent businesses. Aim coverage at your own assets and entry points, use privacy masking to block windows and neighboring parcels, and document those masks. The same discipline applies to license plate reading at your perimeter: capturing plates on your own property for security is one thing, but sharing that data broadly changes the risk picture, as the ongoing debate around plate-reader networks on private property shows.
A short placement review at each site, done once and documented, prevents most privacy-zone problems: list every camera, its field of view, any masked regions, and the business purpose for the coverage.
Signage and employee notice: what to post and why
There is no nationwide signage statute for business video surveillance, but signage is still one of the cheapest compliance tools available. Visible "video surveillance in use" notice at entrances lowers any expectation of privacy on the premises, supports implied-consent arguments in states that regulate recording, and satisfies the jurisdictions and contexts that do require posted notice. If audio is recorded anywhere on site, the signage should say so explicitly.
Employee notice deserves more than a sign. A written monitoring policy should state where cameras operate, whether audio is captured (ideally, that it is not), who can access footage, and how long recordings are kept. Distribute it through onboarding and handbook acknowledgments, and revisit it when you add analytics capabilities, because notice given for basic video does not automatically cover new uses like biometric identification. Unionized workplaces add another layer: surveillance practices can be a subject of bargaining obligations, so loop in labor counsel before changing monitoring at a covered site.
For multi-site operators, standardize the signage and the policy centrally, then verify locally. The most common failure mode is not a missing policy but an acquired or remote site running cameras that the written policy never mentioned.
Biometric and AI analytics rules: what changed for 2025 and 2026
Video analytics is where the law has moved fastest, and the dividing line regulators care about is identification. Detecting that a person entered a fenced yard at 2 a.m. is object and behavior detection. Determining who that person is by scanning their face creates biometric data, and a growing set of states treats that as a regulated act. Our overview of AI video analytics for security cameras explains the technical difference; here is the legal one, as of August 2026.
| Law | Jurisdiction | Core obligation | Exposure / status |
|---|---|---|---|
| BIPA, 740 ILCS 14 | Illinois | Written notice and release before collecting biometric identifiers | $1,000 per negligent and $5,000 per intentional violation, private right of action |
| CUBI, Bus. & Com. Code § 503.001 | Texas | Notice and consent before capturing biometric identifiers for a commercial purpose | Up to $25,000 per violation, enforced by the attorney general |
| HB24-1130 | Colorado | Biometric-data obligations added to the Colorado Privacy Act | Effective July 1, 2025 |
| Colorado AI Act, SB 24-205 | Colorado | Duties for developers and deployers of high-risk AI systems | Took effect June 30, 2026, after a delay |
BIPA remains the headline risk because private plaintiffs can sue directly and statutory damages accrue per violation. Texas puts enforcement with the attorney general but at up to $25,000 per violation. Colorado now layers two regimes: biometric obligations that took effect July 1, 2025 under HB24-1130, and the Colorado AI Act, which took effect June 30, 2026 and reaches high-risk AI systems that influence consequential decisions about people. Beyond those, roughly 20 states now have comprehensive privacy laws that treat biometric data as sensitive, per the IAPP state privacy legislation tracker, typically requiring opt-in consent before collection.
The operational takeaway: if your security program relies on knowing that something happened, a person present after hours, a vehicle dwelling at a gate, you can usually stay outside the biometric statutes entirely. If it relies on knowing who someone is by face or other biometric identifiers, budget for consent workflows, retention schedules, and state-by-state legal review before turning the feature on.
Retention hygiene: how long to keep footage and how to handle it
Retention is less about a magic number and more about consistency. For ordinary commercial footage, no universal statute dictates a retention period, so the defensible approach is a written schedule: how long each site keeps recordings, where they are stored, who can access them, and when they are overwritten. Our guides on how long security cameras should keep footage and video retention for businesses walk through how industry, insurer requirements, and incident patterns should shape that schedule.
Two habits keep retention defensible. First, apply the schedule uniformly across sites; a company that keeps footage twice as long at one location invites questions about why. Second, build a legal-hold reflex: the moment an incident, claim, or dispute surfaces, suspend automatic deletion for the relevant cameras and preserve exports with documented chain of custody. Footage that was overwritten on schedule before any dispute arose is rarely a problem; footage deleted after you knew it mattered can become a spoliation issue. When recordings may end up in front of an insurer, prosecutor, or court, the handling standards in our guide to security camera footage as evidence apply from the first export.
Biometric data, where you collect it at all, follows stricter rules: several of the statutes above impose their own destruction timelines, which is one more reason to keep identification features off unless you have a specific, counsel-reviewed need.
A practical compliance checklist for multi-site operators
Compliance across many sites comes down to a repeatable review, not a one-time project:
- Inventory every camera at every site, with field of view, audio capability, and analytics features actually enabled.
- Disable audio capture fleet-wide unless counsel has approved a disclosed, state-specific use.
- Verify privacy zones: no coverage of restrooms, changing areas, or neighboring private spaces, with masks documented.
- Standardize signage and written employee notice, including explicit disclosure anywhere audio or biometric features are in use.
- Confirm analytics stay on the detection side of the line, object, vehicle, and behavior detection rather than biometric identification, unless a reviewed consent program is in place.
- Document a retention schedule and a legal-hold procedure, and apply both identically at every location.
- Recheck annually, because as Colorado's 2025 and 2026 effective dates show, the rules are still moving.
This is also where deployment choices matter. VDS mobile surveillance units are built for this posture by default: silent video, analytics configured for object and behavior detection rather than biometric identification, and 24/7 human monitoring that verifies events before anyone is dispatched, so people, yours or your security partner's, handle verified incidents instead of chasing raw alerts. A system designed around detection and verification gives you the security outcome without stepping into the consent regimes that identification triggers.
The bottom line for 2026: silent, well-placed, well-signed video remains squarely legal for businesses. Audio, biometrics, and sloppy retention are where the liability lives, and all three are controllable with a written policy and an annual review. When in doubt about a specific state or feature, ask counsel first and enable second.
