Guide · Governance
Camera retention and access policies: a plain-English guide for HOA boards
Estimated reading time: 9 minutes
A camera system can collect a large amount of information about residents, visitors, vehicles, and daily activity.
Before the system is turned on, the board should decide how long that information will be kept, who can see it, and what counts as a valid reason to look at it.
These decisions should be written down. A clear policy protects residents, helps the manager respond consistently, and reduces the chance that the system will be used for personal disputes or casual browsing.
This is operational guidance, not legal advice. Have association counsel review your final policy.
Start with the purpose
Retention and access rules should begin with one question:
Why is the community collecting this information?
A policy might allow the system to be used for:
- Reviewing a reported theft or break-in
- Investigating damage to common property
- Responding to a safety incident
- Providing relevant information to law enforcement
- Reviewing a vehicle connected to a reported incident
- Checking whether a gate, camera, or access system is working correctly
The policy should also say what the system may not be used for.
Common prohibited uses include:
- Watching a particular resident without a valid safety reason
- Checking when someone leaves or returns home
- Following visitors, contractors, or household members
- Enforcing minor HOA rules that are unrelated to safety
- Looking through footage out of curiosity
- Sharing amusing, embarrassing, or personal clips
- Posting footage to a neighborhood group or social media
A narrow purpose makes the rest of the policy easier to write.
Choose a retention period
Retention is the amount of time footage or other records remain available before they are automatically deleted.
There is no single retention period that works for every community or every system.
The board should consider:
- How quickly incidents are usually reported
- Whether the system records continuously or only when activity is detected
- How much information is being collected
- Storage costs
- Vendor limitations
- Insurance requirements
- Applicable state law
- Advice from association counsel
A 30-day rolling retention period can be a reasonable starting point for discussion. It gives residents and managers some time to report an incident without keeping routine activity indefinitely.
Thirty days is a policy choice, not a universal legal requirement. Some communities may choose a shorter period. Others may have a documented reason for keeping certain information longer.
The important part is to choose a standard period and follow it consistently.
Create a process for preserving an incident
Routine information should be deleted according to the normal schedule.
When a specific incident is reported, the authorized manager may need to preserve a relevant clip or record before it disappears.
The policy should explain:
- Who may request that information be preserved
- What information the request must include
- Who decides whether the request is valid
- How much footage or data may be preserved
- Where the preserved information is stored
- When it will be deleted
- Who may receive a copy
Ask for enough detail to locate the event, such as the approximate time, general location, and type of incident.
Do not ask residents to include unnecessary personal information in an email or online form.
Preserve only the information that is reasonably connected to the reported incident. A request about a package theft at 2:00 p.m. should not become a reason to save several days of footage from every camera.
Decide who can have access
Keep the list short.
For many communities, access might be limited to:
- The community manager
- One trained backup
- An approved security provider
- The system vendor when technical access is required
- Association counsel when necessary
- Law enforcement under the conditions defined in the policy
Board membership alone should not automatically provide access.
A board member may have a legitimate role in approving the policy, budget, and vendor. That does not mean every director needs the ability to search residents' movements or watch recorded footage.
Avoid shared usernames and passwords. Each authorized person should have an individual account so their activity can be identified.
For California ALPR systems, state requirements include security procedures, a written usage and privacy policy, defined authorized users, and records of access.
Define valid uses
The policy should require a specific reason for every search, view, download, or export.
A valid reason might be:
- A resident reported a theft from the community mailroom
- A vehicle damaged a gate and left the property
- Police requested information connected to a documented investigation
- The manager is checking a reported camera failure
- Counsel instructed the association to preserve information connected to a legal claim
“Checking something” is not enough.
The person accessing the system should record:
- The date and time
- Their name
- The incident or request
- The camera, location, or plate searched
- The reason for access
- Whether anything was downloaded or shared
- Who received the information
Handle requests from residents consistently
Residents may ask to view footage for many reasons.
Examples include:
- A missing package
- Damage to a vehicle
- A disagreement with a neighbor
- Concern about a visitor
- A pet incident
- A suspected rule violation
- A request to see who entered the property
The board should not make a new decision each time.
Create a standard request process and apply it consistently.
The process might require:
- A written request
- The approximate date, time, and location
- A description of the incident
- A police report or insurance claim when appropriate
- Confirmation that the request relates to the person making it
- Review by the manager or counsel before anything is released
In many cases, the best response may be to preserve the relevant information rather than allowing the resident to browse it.
Footage may contain other residents, guests, children, license plates, unit numbers, or activity unrelated to the request. Counsel can help the association decide whether information should be withheld, redacted, shown under supervision, or provided directly to police or an insurer.
Manage law-enforcement requests
The policy should explain how the association handles requests from law enforcement.
Questions to resolve include:
- Can an officer make an informal request?
- Is a case number required?
- Does the request need to be in writing?
- Who is authorized to respond?
- When should counsel be involved?
- Can police search the system directly?
- Can the vendor provide access without contacting the association?
- Does the system share information automatically with an agency?
- What record will the HOA keep of the request?
Boards should understand the difference between:
- Responding to a request for a specific incident
- Giving an agency ongoing access
- Allowing automatic information sharing
- Responding to a subpoena or court order
These are different decisions and should not be treated as one general permission.
Use audit logs
An audit log records activity inside the system.
Depending on the product, it may show:
- Who signed in
- What they searched
- Which footage they viewed
- What they downloaded
- What they shared
- What settings they changed
- When each action occurred
Ask the vendor to demonstrate the audit log before signing a contract.
The board should decide who reviews it and how often. A simple quarterly review may be enough for a small system. A system used more frequently may need monthly review.
The reviewer is looking for unusual activity, such as:
- Searches without a clear reason
- Access outside normal responsibilities
- Repeated searches involving one resident
- Downloads that were not documented
- Vendor access that was not explained
- Accounts belonging to former employees or contractors
The review does not need to include residents' personal information in open board minutes. The minutes can simply note that the required review occurred and whether any policy issues were found.
Review vendor access
The vendor may have broad technical access to the system and the information it contains.
Before signing a contract, ask:
- Which vendor employees can access the information?
- Why might they need access?
- Is access limited by job role?
- Is each access recorded?
- Can the HOA see vendor activity in the audit log?
- Does the vendor use subcontractors?
- Where is the information stored?
- Can the vendor use the information to improve other products?
- Can the vendor share information with another customer or agency?
- What happens when the contract ends?
- How quickly will HOA information be deleted?
- How will the HOA be notified of a security incident?
The answers should appear in the contract or another binding document. A verbal explanation from a salesperson is not enough.
A simple policy structure
A useful retention and access policy can be organized into ten parts:
- Purpose of the system
- Locations and information collected
- Permitted uses
- Prohibited uses
- Normal retention period
- Incident-preservation process
- Authorized roles
- Rules for sharing information
- Audit and review process
- Policy review and enforcement
Keep the language direct. The people expected to follow the policy should be able to understand it without legal training.
Board checklist
Before turning on the system, confirm that:
- The board has defined the system's purpose.
- Permitted and prohibited uses are written down.
- A normal retention period has been selected.
- Automatic deletion is enabled where available.
- There is a process for preserving incident-specific information.
- Authorized roles are named.
- Every user has an individual account.
- Shared passwords are prohibited.
- Multi-factor authentication is enabled.
- Resident requests follow a written process.
- Law-enforcement requests are documented.
- Vendor access is limited and visible.
- Searches, views, downloads, and sharing are logged.
- Someone is responsible for reviewing the audit log.
- Former employees and contractors lose access promptly.
- The policy has been reviewed by association counsel.
- Residents know where to find the policy.
FAQ
- Should every board member have access?
- Usually, no. Access should follow operational responsibility rather than board title. A small number of trained people is easier to supervise and audit.
- Is 30 days the correct retention period?
- It is a reasonable starting point for many communities, but it is not a universal rule. The board should consider reporting patterns, state law, system capabilities, insurance requirements, and counsel's advice.
- Can a resident view footage after a theft or accident?
- Possibly, but the association should follow a consistent request and review process. Footage may contain information about other people, so direct resident access should not be automatic.
- Should the HOA give police direct access?
- That is a significant policy decision. The board should understand the scope, duration, logging, and revocation of any access before approving it. Access to a specific incident is different from ongoing access to the full system.
- Can footage be used for HOA rule enforcement?
- The policy should answer this clearly. Many communities limit the system to safety, security, and protection of common property so it does not become a general tool for monitoring residents.
- What happens when the manager changes?
- The departing manager's access should be removed immediately. The replacement should receive an individual account and any required training. Shared credentials should never be passed from one manager to another.
Put this into practice
A written policy is easier to create before the first difficult request arrives.
The HOA Surveillance Starter Kit includes policy templates and a vendor-evaluation worksheet that can be adapted to your community.
Get the starter kitRelated guides
Resident Communication and Privacy
A plain-English guide to explaining a proposed safety system, answering common concerns, and giving residents a meaningful chance to respond.
California HOA Security Camera Laws
What California boards need to know about cameras and ALPR — privacy, signage, retention, and records disclosure.
This guide is operational guidance and is not legal advice. Consult association counsel for advice specific to your community.