Unlock the full potential of Wavestore v6.50 -view our launch presentation today and explore the latest innovations in video management.
A client read a headline about automated licence plate readers and mass surveillance, and now they're asking a question that has nothing to do with number plates: "Where does our footage actually go?"
That's the pattern integrators are starting to see. The Security Industry Association's new recommendations on automated licence plate reader (ALPR) data — retention limits, encryption and access controls, documented data sharing between agencies — weren't written about CCTV or access control generally. But clients don't read trade press that precisely. What they take away is a general anxiety about security data, and the question lands on whoever specified their system.
This guide is the plain-English answer. Not a technical spec sheet, and not SIA's document reworded — a script for the conversation you're actually going to have, translating security data governance into terms a nervous, non-technical client can follow.
SIA's language was unusually direct. Its recommendations warn that ALPR "must never become a tool for mass surveillance," alongside specific guidance on how long data should be kept, how it should be encrypted and access-controlled, and how sharing between organisations should be documented. That's a strong form of self-regulation for a trade body to publish, and Security Info Watch's coverage of it has already reached beyond the ALPR-specific audience.
Security Info Watch coverage of SIA's ALPR oversight recommendations
The result is that "security data" has become a phrase clients now associate with regulatory scrutiny, whether or not their own deployment includes a single licence plate reader. If you specified their video management or access control system, you are the person they'll ask.
There are three broad places security data can sit, and the honest answer to "where does it live" usually involves more than one of them.
Footage and event data are stored on servers or NVRs physically located at the client's premises. Nothing leaves the building unless someone deliberately exports it. This is the simplest answer to give a nervous client: the data stays where the camera is.
Some processing and short-term storage happens on the camera or device itself, before anything reaches a central server. This reduces what has to move across the network at all, which matters for both bandwidth and exposure.
Some platforms replicate full video to a cloud provider. Others sync only metadata — timestamps, event flags, system health information — while the video itself stays on-site. This distinction matters enormously to a client asking a data question, and it's the one most likely to get glossed over in a sales conversation. "Cloud-connected" can mean either, and a client is entitled to know which.
SIA's recommendations map onto three plain questions any client can understand, regardless of whether their system involves ALPR at all.
When a client raises this, the honest, plain-English answer looks something like this:
"Your footage is stored on-site, on hardware we specified and you control. It's retained for [X] days, which is set to match your operational needs, not left open-ended. Access is limited to the people your organisation has authorised, and the system encrypts data both while it's moving and while it's stored. Nothing is shared outside your organisation unless you've explicitly set that up, and if you have, it's documented."
If any part of that sentence isn't true for a specific deployment, that's worth knowing before the client asks, not after.
If you're specifying a platform now, rather than defending one already installed, this is a specification question, not just a talking point. Retention limits, encryption, and access control should be configurable and documented in the platform's own material, not something you have to infer or promise on the vendor's behalf.
As one example: WaveFusion keeps full video on-site by design, syncing only metadata to the cloud rather than replicating footage off-premises — which gives integrators a straightforward answer to the "where does it actually go" question without qualification. That's one way to answer it; the point of this guide isn't that it's the only way, but that whichever platform you're specifying, you should be able to give the same plain answer with confidence.
Not directly — the recommendations are specific to ALPR. But the underlying principles (retention limits, encryption and access control, documented sharing) are reasonable standards for any security data system, and clients are increasingly applying that logic generally rather than narrowly.
"Cloud-connected" can mean the full video is replicated to a cloud provider, or it can mean only metadata (timestamps, events, system health) is synced while video stays on-site. These have very different implications for data exposure, and the phrase alone doesn't tell you which one you're getting.
There's no universal answer — it depends on the client's operational and regulatory context. The important part is that a retention period is deliberately set and can be explained, rather than left indefinite by default.
Only what's true and documented. If sharing arrangements exist (with law enforcement, a monitoring company, or another organisation), they should already be written down somewhere the client can see. If they aren't, that's worth fixing before the question is asked by someone less friendly than a curious client.
Not automatically — either can be well or poorly secured. On-site storage does mean the data physically stays under the client's control, which simplifies some governance questions, but encryption, access control, and retention discipline matter regardless of where the data sits.
SIA's ALPR recommendations were written for one category of device, but the questions they've put into clients' heads are general ones: where does my data go, who can see it, and is any of it shared without my knowledge. Integrators who can answer those three questions plainly, for whatever system they've specified, turn a moment of client anxiety into a moment of trust. Integrators who can't are the ones fielding the harder follow-up question later.
Know the honest answer for your own deployments before a client asks — it's a far better position than working it out in front of them.

Solutions for a world we can't yet see. Discover v6.50 features helping people and businesses.