CCPA and video: when your footage becomes 'personal information'

California's privacy law doesn't mention cameras, but identifiable people in your video are personal information under it — with access, deletion, and disclosure duties attached. Anonymization is the lever that takes footage out of scope.

One-click alternative with BGBlur

Upload a clip and preview automatic face, plate, background, or prompt-based blur—no keyframes or nested timelines.

The CCPA (as amended by the CPRA) defines personal information broadly: information that identifies or could reasonably be linked with a particular consumer or household. A face in your store's CCTV, a customer visible in your marketing b-roll, an employee in your training library — each is personal information when the person is identifiable. California businesses over the law's thresholds owe those people the statute's rights: to know, to delete, to limit use.

Video is the hardest data type to honor those rights in. A deletion request against a database is a query; against two years of surveillance archive it's a needle-in-haystack search followed by an editing problem. The practical strategy California businesses are converging on is scope reduction: anonymize people in footage wherever identification isn't needed, so most video stops being personal information at all.

Business video processed for privacy-law compliance
Business video processed for privacy-law compliance
Automatic face blur applied for compliance workflows
Automatic face blur applied for compliance workflows

Which video is in scope

In-scope video is footage where consumers or employees are identifiable and the business meets CCPA thresholds (roughly: $25M+ revenue, or data on 100K+ consumers/households, or majority revenue from selling/sharing data). That typically covers retail CCTV, customer-facing marketing footage, recorded support calls with video, event recordings, and — since the CPRA folded employees in — workplace and training video.

Aggregate or de-identified information is expressly outside the definition. Footage where faces, plates, and other identifiers are blurred such that individuals can't reasonably be identified or re-linked stops carrying CCPA duties — which is what makes anonymization a compliance strategy rather than just a courtesy.

The rights that bite: access and deletion against video

A verified consumer request can ask what personal information you hold — including 'the footage of me' — and demand deletion of it. Exceptions exist (security, legal holds, completing a transaction), but a marketing clip or an event recording rarely qualifies. Fulfilling deletion against published video is the nightmare case: pull the asset, edit the person out or blur them, republish.

BGBlur turns that fulfillment into a processing pass: locate the requester's appearances, blur them (deletion of their personal information from the asset), and re-export — the video survives, the obligation is met. For unpublished archives, the same pass at retention-review time keeps old footage from accumulating as unaddressed personal information.

  • Deletion request against a published video → blur the requester, republish.
  • Retention policy for CCTV → anonymize or purge at the retention boundary.
  • Marketing library → blur non-released individuals at ingest, not at request time.

Anonymize-at-ingest: the strategy that scales

Handling rights requests one by one is the expensive path. The scalable posture is to stop collecting identifiable video where you don't need it: blur customer faces in marketing b-roll before it enters the asset library; anonymize training and internal footage by default; apply face blur to CCTV exports that leave the security context (insurance claims, contractor disputes, social posts).

This mirrors the CPRA's data-minimization principle — collection and retention 'reasonably necessary and proportionate' to the purpose. Identifiable faces are rarely necessary to the purpose of a b-roll shot.

CCPA vs GDPR on video, in one paragraph

If you operate in both markets: GDPR requires a lawful basis before you process identifiable footage at all; CCPA lets you collect but attaches notice, access, deletion, and (for sale/sharing) opt-out duties afterwards. Anonymization satisfies both frameworks the same way — footage without identifiable people largely exits both regimes. A single anonymize-by-default pipeline is therefore cheaper than maintaining two regional postures. For GDPR-specific workflows, see our GDPR video compliance page.

Answering a CCPA deletion request against video

  1. Verify and scope. Confirm the requester's identity per your CCPA procedure; identify which assets they appear in.
  2. Check exceptions. Security holds, legal obligations, or pending transactions may exempt specific footage — counsel decides.
  3. Blur the requester. Upload the asset, mask the requester's appearances; other people and content are untouched.
  4. Replace the asset. Republish or re-archive the anonymized version; retire the identifiable original per policy.
  5. Document fulfillment. Log the request, action, and date — the CPRA's enforcement agency expects records.

Note: Cal. Civ. Code §1798.140 defines personal information to include information reasonably capable of being associated with a particular consumer or household, and expressly excludes de-identified information (§1798.140(m)). The CPRA's data-minimization standard (§1798.100(c)) supports anonymizing identifiable video not needed for the stated purpose. This page is educational, not legal advice.

Related guides

Frequently asked questions

Is security camera footage really 'personal information' under CCPA?
When individuals are identifiable in it, yes — the definition covers information capable of being associated with a particular consumer or household, and regulators and courts have treated identifiable imagery accordingly. Security-purpose exceptions affect deletion duties, not the classification itself.
Does blurring faces take footage out of CCPA scope?
De-identified information is excluded from the personal-information definition when individuals can't reasonably be identified or re-linked. Blurring faces, plates, and other identifiers — done properly and consistently — is the standard route to de-identification for video. Edge cases (unique clothing, gait, context) deserve judgment.
Do employees have these rights too?
Yes — since January 2023 the CPRA extends CCPA rights to employees and job applicants, which pulls workplace, training, and internal-event video into scope for covered businesses.
Someone asked us to delete footage of them from a marketing video. Do we have to?
If no exception applies, a verified request generally requires it. Blurring the requester in the asset — rather than deleting the whole video — fulfills the deletion of their personal information while preserving the asset. Confirm specifics with counsel.
We're under the CCPA thresholds. Should we care?
The thresholds decide legal duty, not risk. Sub-threshold businesses still face platform complaints and reputational fallout from identifiable-footage disputes — and thresholds have trended downward. Anonymize-by-default is cheap insurance either way.

BGBlur provides privacy tooling for creators and teams; consult counsel for broadcast, evidentiary, or regulated workflows.