Solink's Privacy Commitment

Privacy is foundational to how we build and operate our platform. As a cloud-based video security provider, we know our customers entrust us with their data. Our commitment to privacy is built on these core principles:
Your Data Belongs To You
Our customers retain full ownership and control over their data. Solink provides robust tools that give you full control over your video footage and business data, including who can access it, how long it’s retained, and when it’s deleted. 
Customers control when and how their data is accessed or shared:
  • Admins decide who has access to their system and what they can do with that access using role-based access control
  • Audit logs track system usage for compliance, internal controls, and chain of custody purposes
  • Solink does not sell the data customers generate using our products
  • Customers choose how long camera footage is processed and stored
Privacy by Default
We design our products with privacy-protective settings enabled from the start.
  • Camera footage is stored under control and ownership of each customer
  • Analytics features are disabled by default, giving customers control over when to enable them
  • Privacy masking features allow customers to blur faces to protect privacy
Transparency
  • We communicate openly about what data we collect, why we collect it, and how we use it. Our Privacy Policy and Terms of Service provide comprehensive details about our data practices.
  • Audit logs show what actions have been taken, who has accessed data, and who is actively viewing footage
Data Minimization
  • We collect only the data necessary to provide our services effectively. We don’t sell your data or use it for purposes beyond delivering and improving our platform.
  • Privacy masking features allow customers to blur faces to protect privacy

GDPR Compliance

The General Data Protection Regulation (GDPR) is an EU regulation that grants EU citizens greater control over their personal data. It applies to all businesses that market to people in the EU or process their data, regardless of where the business is based.
At Solink, we prioritize security and privacy. We continuously validate our GDPR strategy through internal reviews and audits.
Data Hosting
We strategically determine data hosting locations based on regional privacy laws, performance needs, and access frequency. We can host all your data in the EU ensuring it remains stored and processed within EU borders in accordance with applicable data protection and residency requirements.
Individual Privacy Rights
GDPR grants individuals specific rights over their personal data, including the right to access, rectify, erase, and port their data. We are committed to providing a responsive and effective process for addressing inquiries from data subjects or regulatory authorities. To submit a data subject request, please contact us at [email protected].
Data Transfers
Solink abides by guidelines for data transfer within the European Economic Area, the UK, and Switzerland. Our Data Processing Addendum ensures that customers can securely transfer data in compliance with applicable regulations.

Solink's Compliance Features

Solink’s platform includes features specifically designed to support our customers’ compliance efforts across jurisdictions:
FeatureDescription Compliance Benefit
Configurable Retention PoliciesSet retention periods that align with local regulatory requirements Meet jurisdiction-specific retention limits
Role-Based Access Controls Granular permissions to limit who can view footage and data Demonstrate access limitation and need-to-know principles by ensuring that only authorized personnel with a legitimate business purpose can access recordings.
Comprehensive Audit Logs Detailed logging of system access, searches, and data exports Support accountability requirements and incident investigations
Data Export Tools Facilitate responses to data subject access requests Facilitate responses to data subject access requests
Privacy Masking Blur or mask faces to protect privacy Support data minimization and proportionality requirements
Signage Templates Downloadable notice templates for customer use Help meet transparency and notification requirements

Key Laws and Regulatory Guidance by Country

While the GDPR provides a baseline framework across the EU, many countries have additional laws and regulations applicable to video security systems. Below is an overview of jurisdiction-specific requirements to help our customers understand their privacy obligations.

The information on this page is provided for informational purposes only and does not constitute legal advice. Organizations should assess their specific circumstances and obligations under applicable laws.

Canada
United States
European Union
Asia-Pacific
Latin America

Our Certifications and Commitments

Solink maintains industry-recognized security certifications and undergoes regular third-party audits to validate our security and privacy controls. 
SOC 2 Type II:
Annual audit of security, availability, and confidentiality controls
Data Processing Addendum:
Standard contractual clauses for international data transfers
National Defence Authorization Act:
Our software is fully NDAA-compliant
Regular Penetration Testing:
Third-party security assessments

Visit our Security page for details on our certifications.

Contact Us

For any questions or concerns related to Solink’s data privacy strategy, please contact [email protected]

Federal: PIPEDA

The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities.
Key Requirements for video security:
  • Consent: Organizations must obtain meaningful consent before collecting personal information. For video security, this typically means posting clear, visible signage at all entrances and throughout monitored areas
  • Purpose Limitation: Video security must be used only for the purposes identified at the time of collection (e.g., security, loss prevention)
  • Necessity and Proportionality: The Office of the Privacy Commissioner (OPC) requires that video security be demonstrably necessary and proportionate to the identified security risk
  • Retention Limits: Footage should be retained only as long as necessary to fulfill the stated purpose. 
  • Access Rights: Individuals have the right to request access to footage containing their image, subject to limited exceptions
  • Safeguards: Organizations must implement appropriate technical and organizational measures to protect recorded footage

Quebec: Law 25 (Bill 64)

Quebec’s Law 25 significantly modernized the province’s privacy framework, creating one of the strictest regimes in North America.
Key Requirements:
  • Privacy Impact Assessments (PIAs): May be required before the collection, use, or disclosure of personal information, including video security systems
  • Privacy by Default: Systems must be configured with the highest privacy settings by default
  • Data Localization: While not strictly required, organizations must assess risks of storing data outside Quebec and implement appropriate safeguards
  • Incident Notification: Mandatory breach notification to the Commission d’accès à l’information (CAI) and affected individuals for incidents presenting a risk of serious injury
  • Designated Privacy Officer: Organizations must appoint a person responsible for personal information protection
  • Transparency: Privacy policies must be written in clear, simple language and be readily accessible

Alberta: PIPA

Alberta’s Personal Information Protection Act applies to private-sector organizations operating in Alberta.
Key Requirements:
  • Employee Monitoring: Specific provisions govern workplace security. Employers must provide notice before implementing video monitoring and can only monitor for reasonable purposes
  • Consent: Generally requires consent, but allows collection without consent for certain purposes including security and investigation of breaches
  • Reasonable Person Standard: Collection must be what a reasonable person would consider appropriate in the circumstances
  • Retention: Personal information must be destroyed when no longer needed for the purpose collected

British Columbia: PIPA

British Columbia’s Personal Information Protection Act mirrors many federal requirements but with provincial enforcement.
Key Requirements:
  • Consent: Required for collection, use, and disclosure of personal information
  • Notice: Organizations must inform individuals about the purposes for collection at or before the time of collection
  • Workplace Surveillance: Employers may collect employee personal information without consent if reasonable for establishing, managing, or terminating employment, but notice is still required
  • Access Rights: Individuals can request access to their personal information held by an organization

Federal Framework

There is no comprehensive federal privacy law in the United States. Video security is primarily governed by a patchwork of state laws, sector-specific federal regulations, and common law principles.
Sector-Specific Considerations:
  • HIPAA: Healthcare facilities must ensure video security systems don’t inadvertently capture protected health information (PHI) without appropriate safeguards
  • FERPA: Educational institutions must protect student records, which may include video footage
  • Workplace: Generally, employers may conduct video security in the workplace with notice, except in areas where employees have a reasonable expectation of privacy (restrooms, locker rooms)

California: CCPA/CPRA

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides comprehensive privacy rights to California residents.
Key Requirements:
  • Right to Know: Consumers can request disclosure of personal information collected, including video footage that identifies them
  • Right to Delete: Consumers can request deletion of their personal information, subject to exceptions for security and legal compliance
  • Right to Opt-Out: Consumers can opt out of the “sale” or “sharing” of their personal information
  • Notice at Collection: Businesses must provide notice of data collection practices at or before the point of collection
  • Data Minimization: Collection must be reasonably necessary and proportionate to the disclosed purposes

Other State Privacy Laws

StateLawKey requirements
ColoradoCPAApplies if: 100K+ consumers OR selling data with 25K+ consumers Retail example: Customer walks into your Denver store - they can request footage showing them; must post clear signage Workplace example: Employee can access break room footage; need privacy assessment if using facial recognition for time tracking Key requirement: Data protection assessments for AI analytics
VirginiaVCDPAApplies if:100K+ consumers OR 25K+ with 50%+ revenue from data sales Retail example: Shopper can request deletion of footage after incident investigation complete Workplace example: Must get consent before using biometric time clocks; employees have same access rights as customers Key requirement: Privacy assessments before deploying new surveillance tech
ConnecticutCTDPAApplies if: Currently 100K+ consumers; drops to 35K+ in July 2026 Retail example: Must explain in entrance signage how long you keep footage and why Workplace example: If tracking employee movements for loss prevention, need privacy assessment Key requirement: Clear opt-out for marketing analytics; cure period ended Dec 2024
UtahUCPA Applies if:$25M+ revenue AND 100K+ consumers Retail example:Most business-friendly; customers can access/delete footage but no correction right Workplace example:No privacy assessment needed for standard security cameras Good for: Smaller retailers - high revenue threshold means fewer businesses covered
OregonOCPAApplies if:100K+ consumers OR 25K+ with 25%+ revenue from data Retail example:Must provide list of third parties who received customer footage (e.g., insurance company, police) Workplace example:15-day deadline to stop processing after employee opts out Unique: Must list all business names on privacy notice
MontanaMCDPAApplies if:Originally 50K+; now 25K+ consumers (lowest threshold) Retail example:Small Montana stores likely covered; customers can access footage within 45 days Workplace example:Need consent for biometric door locks; privacy assessment required Watch out: Cure period ends April 2026; no penalty caps
DelawareDPDPA Applies if:35K+ consumers OR 10K+ with 20%+ revenue from data Retail example:Must honor browser opt-out signals by Jan 2026 for online analytics Workplace example:Applies to nonprofits and schools - even private universities must comply Key requirement: Must disclose third-party recipients in access requests
IowaICDPA Applies if:100K+ consumers OR 25K+ with 50%+ revenue from data Retail example:Customer can access and delete footage but cannot correct associated data Workplace example:No opt-out for targeted ads or profiling - more limited rights Good news: 90-day cure period with no sunset - most forgiving enforcement
New JerseyNJDPAApplies if:100K+ consumers OR 25K+ with any revenue from data sales Retail example:Must process opt-out requests within 15 days (fastest in US) Workplace example:Applies to nonprofits/universities; employees at covered entities have heightened protections Watch out: Broad "sensitive data" includes financial info; 30-day cure ends July 2026
TennesseeTIPAApplies if:$25M+ revenue AND 175K+ consumers (highest threshold) Retail example:Large retailers only; customers can access footage used in loss prevention Workplace example:Affirmative defense if you follow NIST privacy framework Unique: Treble damages for willful violations; 60-day cure period never sunsets

EU-Wide: GDPR

The General Data Protection Regulation provides the baseline framework for all EU member states.
Key Requirements for video security:
  • Lawful Basis: Most commercial video security relies on “legitimate interests”, requiring a balancing test against data subject rights
  • Transparency: Clear signage must be posted indicating security is occurring, the identity of the controller, and how to obtain more information
  • Data Protection Impact Assessment (DPIA): Required for systematic monitoring of publicly accessible areas and processing of biometric data
  • Data Minimization: Cameras should only capture what is necessary; privacy masking should be used where possible
  • Retention Limits: Footage should be retained only as long as necessary
  • Access Rights: Data subjects can request access to footage containing their image
  • Security: Appropriate technical and organizational measures must protect footage

EU AI Act

The EU AI Act, effective August 2024, imposes additional requirements on AI-powered security systems.
Key Provisions:
  • Prohibited Practices: Real-time remote biometric identification in publicly accessible spaces for law enforcement is generally prohibited, with narrow exceptions
  • High-Risk AI Systems: Biometric identification and categorization systems are classified as high-risk, requiring conformity assessments, registration, and ongoing monitoring
  • Transparency: Individuals must be informed when they are subject to emotion recognition or biometric categorization systems
  • Fundamental Rights Impact Assessment: Required for high-risk AI systems used by public bodies or private entities providing essential services

Belgium: Camera Act (Loi Caméras)

Belgium has specific legislation governing camera security beyond GDPR requirements.
Key Requirements:
  • Registration: Security cameras in public places must be registered with the police via the federal camera registration system
  • Notification: Pictograms must be displayed at camera locations with specific required information
  • Workplace Surveillance: Collective bargaining agreement (CBA) No. 68 requires consultation with works councils before implementing workplace security
  • Categories: Different rules apply to fixed cameras, mobile cameras, and temporary cameras
  • Public vs. Private Spaces: Stricter rules apply to cameras monitoring public spaces

Finland: Employment Contracts Act

Finland has strict rules on workplace security.
Key Requirements:
  • Employee Consultation: Employers must consult with employees or their representatives before implementing security
  • Co-determination: Works councils have co-determination rights regarding workplace monitoring
  • Purpose Limitation: Workplace security permitted only for specific purposes (security, production monitoring, safety)
  • Proportionality: Surveillance must be proportionate and the least intrusive means available
  • Transparency: Employees must be informed about security methods, purposes, and any automated decision-making

France: CNIL Guidelines

The Commission Nationale de l’Informatique et des Libertés (CNIL) has issued detailed guidance on video security.
Key Requirements:
  • Authorization: Video security of public spaces requires prefectural authorization
  • Retention: Maximum 30 days; most situations warrant shorter periods
  • Workplace: Continuous security of employees is prohibited; cameras cannot be placed in break rooms, union offices, or restrooms. However, targeted surveillance for specific security purposes (e.g., monitoring a cash register) is permitted with proper justification.
  • Access Controls: Strict limitations on who can view footage; access must be logged
  • Signage: Detailed requirements for information to be displayed on signage
  • Sound Recording: Generally prohibited without specific justification

Germany: BDSG & State Laws

Germany has one of the strictest privacy regimes in the EU, with both federal and state-level requirements.
Key Requirements:
  • Works Council Involvement: Under the Works Constitution Act (BetrVG), works councils have co-determination rights over technical monitoring equipment
  • Section 26 BDSG: Specific provisions for employee data processing, requiring necessity for employment relationship purposes
  • Proportionality: Strict proportionality requirements; security must be the least intrusive means
  • Covert Surveillance: Generally prohibited; permitted only in exceptional circumstances with documented suspicion of criminal activity
  • State Laws: Individual German states (Länder) may have additional requirements
  • Practical Considerations: German courts have been particularly protective of employee privacy rights, often invalidating security evidence obtained improperly.

Netherlands: UAVG & AP Guidance

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has issued specific guidance on camera security.
Key Requirements:
  • Legitimate Interest Assessment: Detailed balancing test required, documented in writing
  • Workplace Monitoring: Works council consent required for employee monitoring systems
  • Signage: Clear signage required with controller identity and contact information
  • Retention: Generally 4 weeks maximum; longer retention should have specific justification
  • Access Restrictions: Limited personnel should have access to footage

Sweden: Camera Surveillance Act (Kameraövervakningslag)

Sweden requires permits for certain types of camera security.
Key Requirements:
  • Permit System: Surveillance of public places generally requires a permit from the County Administrative Board
  • Exemptions: Certain security (e.g., ATMs, entrances to premises) may be exempt from permit requirements
  • Notification: Swedish Data Protection Authority (IMY) must be notified of security activities
  • Signage: Clear signage required at all monitored locations
  • Retention: Footage should be deleted when no longer needed; typically within 2 months

United Kingdom: UK GDPR & DPA 2018

Post-Brexit, the UK maintains a GDPR-equivalent framework with additional guidance from the Information Commissioner’s Office (ICO).
Key Requirements:
  • Surveillance Camera Code of Practice: Voluntary code providing guidance on security camera use
  • 12 Guiding Principles: Including necessity, proportionality, transparency, and accountability
  • DPIA Requirements: Required for systematic monitoring and biometric processing
  • Retention: ICO recommends 30 days maximum for standard security purposes
  • Subject Access Requests: Must respond within one month

Australia: Privacy Act & State Workplace Surveillance Laws

Australia has a federal privacy framework supplemented by state-specific workplace security laws.
Federal Privacy Act:
  • Australian Privacy Principles (APPs): 13 principles governing personal information handling
  • APP 3 (Collection): Personal information must only be collected if reasonably necessary
  • APP 5 (Notification): Individuals must be notified of collection at or before the time of collection
  • APP 11 (Security): Reasonable steps must be taken to protect personal information

New Zealand: Privacy Act 2020

New Zealand’s updated Privacy Act modernized the country’s privacy framework.
Key Requirements:
  • Information Privacy Principles (IPPs): 13 principles similar to Australia’s APPs
  • Purpose Limitation: Personal information collected for one purpose cannot be used for another without consent
  • Retention: Information must not be kept longer than necessary
  • Mandatory Breach Notification: Privacy breaches causing serious harm must be reported to the Privacy Commissioner and affected individuals
  • Cross-Border Transfers: Restrictions on transferring personal information overseas
  • Privacy Commissioner Guidance: The Office of the Privacy Commissioner has issued guidance on CCTV use, emphasizing proportionality and transparency.

South Korea: PIPA

South Korea’s Personal Information Protection Act is one of the strictest in Asia.
Key Requirements:
  • Consent: Explicit consent required for collection of personal information, including video footage
  • Mandatory Signage: Detailed signage requirements including operator information, purpose, retention period, and contact details
  • CCTV-Specific Rules: Article 25 of PIPA specifically addresses CCTV installation and operation
  • Data Localization: Certain categories of data must be stored domestically
  • Retention Limits: Footage must be deleted when the purpose is achieved
  • Access Rights: Individuals can request access to footage containing their image

Japan: APPI

Japan’s Act on the Protection of Personal Information was significantly amended in 2020.
Key Requirements:
  • Utilization Purpose: Purpose of use must be specified and disclosed
  • Facial Recognition: Guidelines from the Personal Information Protection Commission address facial recognition, requiring clear notice and purpose limitation
  • Opt-Out: Individuals must be able to opt out of certain data uses
  • Cross-Border Transfers: Restrictions on international data transfers; adequacy decisions or consent required

Singapore: PDPA

Singapore’s Personal Data Protection Act provides a comprehensive framework for data protection.
Key Requirements:
  • Consent: Generally required for collection, use, and disclosure of personal data
  • Notification: Organizations must inform individuals of purposes for collection
  • Purpose Limitation: Personal data can only be used for purposes for which consent was given
  • Retention Limitation: Personal data must be deleted when no longer needed
  • Access and Correction: Individuals can request access to and correction of their personal data
  • PDPC Guidance: The Personal Data Protection Commission has issued guidance on the use of CCTV and video analytics.

Brazil: LGPD

Brazil’s Lei Geral de Proteção de Dados closely mirrors the GDPR.
Key Requirements:
  • Legal Bases: 10 legal bases for processing personal data, including consent and legitimate interests
  • Consent: Must be free, informed, and unambiguous; separate consent required for sensitive data
  • Sensitive Data: Biometric data is classified as sensitive, requiring explicit consent or other specific legal basis
  • Data Subject Rights: Access, correction, deletion, portability, and information about sharing
  • DPO Requirement: Organizations must appoint a Data Protection Officer
  • DPIA: Required for processing that may result in risks to data subjects

Mexico: LFPDPPP

Mexico’s Federal Law on Protection of Personal Data Held by Private Parties governs private-sector data processing.
Key Requirements:
  • Privacy Notice: Comprehensive privacy notice required, including purposes, transfers, and data subject rights
  • Consent: Required for processing; tacit consent may be sufficient for non-sensitive data
  • Sensitive Data: Biometric data is sensitive, requiring express written consent
  • ARCO Rights: Access, Rectification, Cancellation, and Opposition rights
  • Data Transfers: Consent required for international transfers unless exceptions apply

Argentina: PDPA

Argentina’s Personal Data Protection Act provides GDPR-like protections and has an EU adequacy decision.
Key Requirements:
  • Consent: Generally required; exceptions for security and public interest
  • Sensitive Data: Biometric data is sensitive, requiring explicit consent
  • Data Subject Rights: Access, rectification, deletion, and opposition
  • Cross-Border Transfers: Permitted to countries with adequate protection or with consent