Footage almost never fails as evidence on the day it is recorded. It fails eleven months later, in a meeting nobody planned for.

The recorder clock turns out to have been seven minutes fast. The hour before the incident was deleted on schedule, three weeks after someone first mentioned a complaint. The only copy anyone can find is an MP4 exported from a phone screen, and the person who set the system up has left. Each of those is an ordinary failure of evidentiary video recording, and none of them is a technology problem. They are procedure problems that the technology either makes easy or makes impossible.

This post covers the three places footage breaks after the fact — time, retention and export — and the person who has to stand behind all three.

What makes an evidentiary video recording

An evidentiary video recording — footage meant to serve as video evidence — is one that can be produced later and shown to be what it claims to be: from this source, at this time, complete, unaltered, and handled by identifiable people since. The legal requirements behind that — a description of the process and a hash of the record — are laid out in what a video chain of custody actually requires. The engineering that produces the proof is in the recording architecture audit.

What sits between the two is the practice of evidentiary video recording. The best-designed pipeline still produces weak evidence if nobody checks the clock, the retention job deletes what should have been held, or an export leaves the building as a convenience copy. Time goes first, because every other claim depends on it.

Timestamps: record the offset, never fix the clock

Every recorder has a clock, and every clock drifts. On a surveillance estate the drift is different on every device, which is why four camera angles drift out of alignment. On a video platform, each server has its own. The question an examiner asks is not whether the clock was right. It is whether you know by how much it was wrong.

The forensic guidance is specific, and slightly counterintuitive. SWGDE's best practices for acquiring video from recorders tell examiners to "calculate if there is a time offset between real time and the DVR system clock" — and, in a footnote, "do not change the time and date on the DVR system." Correcting the clock at the moment of collection destroys the evidence of how far off it was, and makes every earlier timestamp harder to interpret.

For an operator, that turns into three habits:

  • Discipline the clocks going forward. Synchronise recorders and media servers to a reliable time source, so drift stays small.
  • Log the offset continuously, not only at collection. A periodic record of "device time vs reference time" lets anyone correct any timestamp later. A single check on the day of export only tells you about that day.
  • Never "fix" a clock as part of pulling footage. Record the offset, export, then correct the clock as a separate, logged change.

The formal paperwork expects this precision too. The certificate in the Schedule of India's Bharatiya Sakshya Adhiniyam, 2023 asks for the date and the "Time (IST): ___ hours (In 24 hours format)" at which it is signed. If the certificate is exact about its own time, the footage it certifies should be exact about its own.

For evidentiary video recording, an accurate timestamp only helps if the footage still exists when someone needs it.

Retention: the schedule deletes, the hold preserves

Two obligations pull in opposite directions, and both are real.

Data protection law pushes toward deleting. The GDPR's storage limitation principle, Article 5(1)(e), says personal data must be kept "for no longer than necessary for the purposes for which the personal data are processed." Video of identifiable people is personal data, so a retention period is not optional and "keep everything forever" is not a strategy.

Litigation pushes toward keeping. In US federal courts, Rule 37(e) covers electronically stored information "that should have been preserved in the anticipation or conduct of litigation" and is lost because a party "failed to take reasonable steps to preserve it." If the court finds intent to deprive the other side, it may presume the lost information "was unfavorable to the party." Deleting on schedule is defensible. Deleting on schedule after you had reason to expect a dispute is not.

The two are reconciled by keeping them as separate mechanisms:


Retention schedule

Legal hold

Purpose

Delete when the purpose has been served

Keep specific footage regardless of the schedule

Scope

Every recording in a class

Named recordings, cameras, sessions or date ranges

Duration

Fixed period per class of recording

Until someone with authority releases it

Triggered by

Time

A complaint, claim, incident report or request

Owner

Records / compliance lead

Legal, on notice from anyone in operations

The failure that matters is the gap between them: the incident is reported to a store manager on Monday, the footage rolls off on Thursday, and legal hears about it in a month. The fix is procedural — anyone who receives a complaint about something on camera can place a hold, immediately, without waiting for legal to decide whether it matters. A hold that turns out to be unnecessary costs some storage. A hold that was never placed costs the evidence.

The storage layer has to support this. S3 Object Lock, for example, has a legal hold that "doesn't have an associated fixed amount of time and remains in effect until removed," separate from the retention period. Whether a retention period can be cut short by an administrator is a different and more dangerous question — governance and compliance modes are not the same thing. How long each class should be kept depends on the regime; the cost side of long retention is in the compliance trap in recording at scale.

Footage that survives is still only as good as the copy that leaves the system.

Export: two copies with two jobs

The export is where evidentiary video recording most often breaks, because it is the moment convenience wins. Someone needs to see the clip, so it gets re-encoded to MP4, trimmed, emailed, and the trimmed MP4 becomes "the footage."

SWGDE's guidance is unambiguous about which copy is evidence: "a native file format or proprietary file format is likely to provide best evidence for legal authenticity purposes as it is closest to the original manner of recording." Its field worksheet instructs examiners to "create a hash value for any video retrieved," and where a system records in a proprietary format, the player goes with the files — "the examiner may have to manually select this option to copy the viewer along with video files."

In practice, every export produces two things, clearly labelled:


Evidence copy

Working copy

Format

Native, as recorded

Whatever plays easily (MP4)

Scope

The full relevant period, untrimmed

Trimmed to the moment people need to see

Integrity

Hashed at export; hash recorded in the export log

Not relied on; says so in its name

Goes with it

Proprietary player if needed, clock-offset record, manifest

Nothing

Who handles it

Logged at every handover

Anyone who needs to watch

The export log matters as much as the file. Who exported it, when, what hash it had, and who it was handed to next is the custody record for the life of that copy. On a surveillance estate this is often the weakest point — the footage behind a retail loss-prevention case or a perimeter intrusion tends to be pulled in a hurry by whoever is on shift.

All of this eventually has to be put into words by a person.

Name the person who will sign

Evidence law does not accept a system on its own word. Every evidentiary video recording needs someone to describe it.

In the US, self-authenticating electronic records under Rule 902(13) and (14) depend on "a certification of a qualified person," and Rule 902(11) requires the proponent to give the other side "reasonable written notice" and make the record and certification available for inspection. In India, section 63(4) of the BSA requires a certificate "purporting to be signed by a person in charge of the computer or communication device or the management of the relevant activities" and an expert, and the Schedule's Part A asks the signatory to confirm that the device "was working properly" throughout.

That person needs to exist before the incident, not be found after it. Name the role — usually whoever owns the recording system operationally — and make sure they can explain, in plain language:

  • How recordings are captured, stored, and protected from change or deletion.
  • How clocks are synchronised and how offsets are logged.
  • What the retention schedule is, how holds are placed, and who can release them.
  • How exports are made, hashed, logged and handed over.
  • Whether the system was working properly during the period in question — and what the logs show if it was not.

If nobody in the organisation can answer those five without asking a vendor, that is the first gap to close.

An evidentiary video recording runbook

The whole practice fits on a page. Each step names who does it and what it leaves behind.

Step

Who

Evidence it produces

Clock sync and offset logging

Platform / IT

Continuous device-vs-reference time record

Retention schedule per class

Records / compliance

A written schedule and automated deletion logs

Hold on first notice

Anyone who receives a complaint

A dated hold, scoped to specific footage

Native export with hash

Designated operator

Evidence copy, hash, player, offset record

Export and handover log

Designated operator

Who had which copy, when

Certification

Named system owner (+ expert where required)

A certificate they can defend

The Bottom Line

Evidentiary video recording fails later, not on the day — through a clock nobody measured, a deletion nobody paused, or an export nobody can vouch for. Record clock offsets instead of fixing clocks, keep retention and legal holds as separate mechanisms with a hold anyone can place, and export a hashed native copy alongside the convenient one.

Then name the person who will sign, while there is still time for them to learn what they will be asked.

What's Next

For what the law actually asks of recorded footage, read what a video chain of custody requires. For the pipeline evidence underneath this procedure — manifests, chained hashes and object-lock modes — see the recording architecture audit.

Frequently Asked Questions

What makes an evidentiary video recording admissible?

It has to be shown to be what it claims to be: from a known source, at a known time, complete and unaltered, with a record of who handled it. In practice that means a known clock offset, retention that did not delete it, a hashed native export, and a person who can describe the system. Admissibility itself is decided by a court.

Should I correct the DVR time before exporting evidentiary video recording footage?

No. Forensic guidance says to calculate the offset between the recorder clock and real time, and not to change the date and time on the device. Record the offset, export, and only then correct the clock as a separate logged change.

How long should video recordings be retained for evidence?

Long enough for the purpose, and no longer — the GDPR's storage-limitation principle makes open-ended retention hard to justify. Set a fixed period per class of recording, and use legal holds to keep specific footage beyond that period when a dispute is expected. The period itself depends on the regime and sector.

What is a legal hold on video footage?

An instruction to preserve specific recordings regardless of the normal retention schedule, until someone with authority releases it. In US federal courts, failing to take reasonable steps to preserve information once litigation is anticipated can lead to sanctions under Rule 37(e).

Is an MP4 export good enough as evidence?

As a working copy, yes. As the evidence copy, it is weaker: forensic guidance treats the native format as the best evidence because it is closest to how the footage was recorded. Export both, hash the native copy, and label the MP4 as a working copy.

Who signs the certificate for a video recording in India?

Under section 63(4) of the Bharatiya Sakshya Adhiniyam, 2023, the certificate is signed by a person in charge of the device or the management of the relevant activities, and an expert. The Schedule sets out the form, including the hash value and algorithm.

Can our recordings and exports stay on our own infrastructure?

Yes, if recording processing and storage run on infrastructure you control. Samvyo works this way, so clocks, retention, holds and exports are governed by your own procedures rather than a vendor's. The runbook above still has to be yours.