News & Events

Where Does Your Security Data Actually Live? A Plain-English Answer for Nervous Clients

Unlock the full potential of Wavestore v6.50 -view our launch presentation today and explore the latest innovations in video management.

VIEW PRESENTATION

A client read a headline about automated licence plate readers and mass surveillance, and now they're asking a question that has nothing to do with number plates: "Where does our footage actually go?"

That's the pattern integrators are starting to see. The Security Industry Association's new recommendations on automated licence plate reader (ALPR) data — retention limits, encryption and access controls, documented data sharing between agencies — weren't written about CCTV or access control generally. But clients don't read trade press that precisely. What they take away is a general anxiety about security data, and the question lands on whoever specified their system.

This guide is the plain-English answer. Not a technical spec sheet, and not SIA's document reworded — a script for the conversation you're actually going to have, translating security data governance into terms a nervous, non-technical client can follow.

Why Clients Are Asking This Now

SIA's language was unusually direct. Its recommendations warn that ALPR "must never become a tool for mass surveillance," alongside specific guidance on how long data should be kept, how it should be encrypted and access-controlled, and how sharing between organisations should be documented. That's a strong form of self-regulation for a trade body to publish, and Security Info Watch's coverage of it has already reached beyond the ALPR-specific audience.

Security Info Watch coverage of SIA's ALPR oversight recommendations

The result is that "security data" has become a phrase clients now associate with regulatory scrutiny, whether or not their own deployment includes a single licence plate reader. If you specified their video management or access control system, you are the person they'll ask.

Where Data Actually Lives: The Short Version

There are three broad places security data can sit, and the honest answer to "where does it live" usually involves more than one of them.

On-Site

Footage and event data are stored on servers or NVRs physically located at the client's premises. Nothing leaves the building unless someone deliberately exports it. This is the simplest answer to give a nervous client: the data stays where the camera is.

Edge

Some processing and short-term storage happens on the camera or device itself, before anything reaches a central server. This reduces what has to move across the network at all, which matters for both bandwidth and exposure.

Cloud (Full or Metadata-Only)

Some platforms replicate full video to a cloud provider. Others sync only metadata — timestamps, event flags, system health information — while the video itself stays on-site. This distinction matters enormously to a client asking a data question, and it's the one most likely to get glossed over in a sales conversation. "Cloud-connected" can mean either, and a client is entitled to know which.

The Three Things SIA Actually Asked For — Translated

SIA's recommendations map onto three plain questions any client can understand, regardless of whether their system involves ALPR at all.

  1. How long is data kept, and who decided that? Retention shouldn't be indefinite by default. A client should be able to say, in one sentence, how long their footage is retained and why that period was chosen.
  2. who can access it, and is it encrypted? This is really two questions clients often merge into one. Encryption protects data in transit and at rest; access control determines who within the organisation, and outside it, can actually view it.
  3. Is any of it shared with anyone else, and is that documented? This is the question with the most reputational weight. A client who can't answer it — or worse, doesn't know the answer — is exposed if it's ever asked by a regulator, a journalist, or their own board.

A Script for the Conversation

When a client raises this, the honest, plain-English answer looks something like this:

"Your footage is stored on-site, on hardware we specified and you control. It's retained for [X] days, which is set to match your operational needs, not left open-ended. Access is limited to the people your organisation has authorised, and the system encrypts data both while it's moving and while it's stored. Nothing is shared outside your organisation unless you've explicitly set that up, and if you have, it's documented."

If any part of that sentence isn't true for a specific deployment, that's worth knowing before the client asks, not after.

Where This Sits for Integrators Specifying a New System

If you're specifying a platform now, rather than defending one already installed, this is a specification question, not just a talking point. Retention limits, encryption, and access control should be configurable and documented in the platform's own material, not something you have to infer or promise on the vendor's behalf.

As one example: WaveFusion keeps full video on-site by design, syncing only metadata to the cloud rather than replicating footage off-premises — which gives integrators a straightforward answer to the "where does it actually go" question without qualification. That's one way to answer it; the point of this guide isn't that it's the only way, but that whichever platform you're specifying, you should be able to give the same plain answer with confidence.

FAQ

Does SIA's ALPR guidance apply to my client's CCTV system if they don't use licence plate readers?

Not directly — the recommendations are specific to ALPR. But the underlying principles (retention limits, encryption and access control, documented sharing) are reasonable standards for any security data system, and clients are increasingly applying that logic generally rather than narrowly.

What's the difference between "cloud-connected" and full cloud storage?

"Cloud-connected" can mean the full video is replicated to a cloud provider, or it can mean only metadata (timestamps, events, system health) is synced while video stays on-site. These have very different implications for data exposure, and the phrase alone doesn't tell you which one you're getting.

How long should security footage actually be retained?

There's no universal answer — it depends on the client's operational and regulatory context. The important part is that a retention period is deliberately set and can be explained, rather than left indefinite by default.

What should I tell a client who asks if their data has ever been shared with anyone else?

Only what's true and documented. If sharing arrangements exist (with law enforcement, a monitoring company, or another organisation), they should already be written down somewhere the client can see. If they aren't, that's worth fixing before the question is asked by someone less friendly than a curious client.

Is on-site storage automatically more secure than cloud storage?

Not automatically — either can be well or poorly secured. On-site storage does mean the data physically stays under the client's control, which simplifies some governance questions, but encryption, access control, and retention discipline matter regardless of where the data sits.

Conclusion

SIA's ALPR recommendations were written for one category of device, but the questions they've put into clients' heads are general ones: where does my data go, who can see it, and is any of it shared without my knowledge. Integrators who can answer those three questions plainly, for whatever system they've specified, turn a moment of client anxiety into a moment of trust. Integrators who can't are the ones fielding the harder follow-up question later.

Know the honest answer for your own deployments before a client asks — it's a far better position than working it out in front of them.

A group of five diverse business professionals smiling and engaging in a lively meeting around a table with laptops.

View Wavestore v6.50 presentation

Solutions for a world we can't yet see. Discover v6.50 features helping people and businesses.