| Feature | Description | Compliance Benefit |
|---|---|---|
| Configurable Retention Policies | Set retention periods that align with local regulatory requirements | Meet jurisdiction-specific retention limits |
| Role-Based Access Controls | Granular permissions to limit who can view footage and data | Demonstrate access limitation and need-to-know principles by ensuring that only authorized personnel with a legitimate business purpose can access recordings. |
| Comprehensive Audit Logs | Detailed logging of system access, searches, and data exports | Support accountability requirements and incident investigations |
| Data Export Tools | Facilitate responses to data subject access requests | Facilitate responses to data subject access requests |
| Privacy Masking | Blur or mask faces to protect privacy | Support data minimization and proportionality requirements |
| Signage Templates | Downloadable notice templates for customer use | Help meet transparency and notification requirements |
The information on this page is provided for informational purposes only and does not constitute legal advice. Organizations should assess their specific circumstances and obligations under applicable laws.
Visit our Security page for details on our certifications.
| State | Law | Key requirements |
|---|---|---|
| Colorado | CPA | Applies if: 100K+ consumers OR selling data with 25K+ consumers Retail example: Customer walks into your Denver store - they can request footage showing them; must post clear signage Workplace example: Employee can access break room footage; need privacy assessment if using facial recognition for time tracking Key requirement: Data protection assessments for AI analytics |
| Virginia | VCDPA | Applies if:100K+ consumers OR 25K+ with 50%+ revenue from data sales Retail example: Shopper can request deletion of footage after incident investigation complete Workplace example: Must get consent before using biometric time clocks; employees have same access rights as customers Key requirement: Privacy assessments before deploying new surveillance tech |
| Connecticut | CTDPA | Applies if: Currently 100K+ consumers; drops to 35K+ in July 2026 Retail example: Must explain in entrance signage how long you keep footage and why Workplace example: If tracking employee movements for loss prevention, need privacy assessment Key requirement: Clear opt-out for marketing analytics; cure period ended Dec 2024 |
| Utah | UCPA | Applies if:$25M+ revenue AND 100K+ consumers Retail example:Most business-friendly; customers can access/delete footage but no correction right Workplace example:No privacy assessment needed for standard security cameras Good for: Smaller retailers - high revenue threshold means fewer businesses covered |
| Oregon | OCPA | Applies if:100K+ consumers OR 25K+ with 25%+ revenue from data Retail example:Must provide list of third parties who received customer footage (e.g., insurance company, police) Workplace example:15-day deadline to stop processing after employee opts out Unique: Must list all business names on privacy notice |
| Montana | MCDPA | Applies if:Originally 50K+; now 25K+ consumers (lowest threshold) Retail example:Small Montana stores likely covered; customers can access footage within 45 days Workplace example:Need consent for biometric door locks; privacy assessment required Watch out: Cure period ends April 2026; no penalty caps |
| Delaware | DPDPA | Applies if:35K+ consumers OR 10K+ with 20%+ revenue from data Retail example:Must honor browser opt-out signals by Jan 2026 for online analytics Workplace example:Applies to nonprofits and schools - even private universities must comply Key requirement: Must disclose third-party recipients in access requests |
| Iowa | ICDPA | Applies if:100K+ consumers OR 25K+ with 50%+ revenue from data Retail example:Customer can access and delete footage but cannot correct associated data Workplace example:No opt-out for targeted ads or profiling - more limited rights Good news: 90-day cure period with no sunset - most forgiving enforcement |
| New Jersey | NJDPA | Applies if:100K+ consumers OR 25K+ with any revenue from data sales Retail example:Must process opt-out requests within 15 days (fastest in US) Workplace example:Applies to nonprofits/universities; employees at covered entities have heightened protections Watch out: Broad "sensitive data" includes financial info; 30-day cure ends July 2026 |
| Tennessee | TIPA | Applies if:$25M+ revenue AND 175K+ consumers (highest threshold) Retail example:Large retailers only; customers can access footage used in loss prevention Workplace example:Affirmative defense if you follow NIST privacy framework Unique: Treble damages for willful violations; 60-day cure period never sunsets |