The same recorded call can need a lawful basis in Dublin, everyone's consent in California, and — if it verifies a bank customer in India — storage inside the country for at least five years after the relationship ends.
Video recording compliance is not one rulebook. It is several, and they answer the same four questions differently: may you record, must you tell people, how long may or must you keep it, and where may it live. This post takes the EU, the US and India in turn, quoting the legal text itself rather than summaries of it. It describes how the rules read, not legal advice for a specific case.
Four questions every video recording compliance regime asks
Question | EU (GDPR) | US | India |
|---|---|---|---|
May you record? | Needs a lawful basis — often legitimate interest for surveillance | Federally, one party's consent; some states require all parties' | DPDP consent after a notice (or another lawful ground) |
Must you tell people? | Yes — transparency is built in | In all-party states, effectively yes | Yes — the notice comes with or before the consent request |
How long? | No longer than necessary | Mostly set by sector rules and litigation holds | Erase when the purpose ends — unless another law requires retention (e.g. RBI: 5 years) |
Where, and how protected? | Security obligations; transfer rules | No general location rule | Security safeguards; RBI V-CIP recordings stored in India |
The detail of video recording compliance is in the text. Start with the regime that is strictest about keeping things.
EU: a lawful basis, and no longer than necessary
The GDPR does not ban recording. It requires a reason and limits how long you keep what you record.
- A lawful basis. For video surveillance, the European Data Protection Board's guidelines on video devices identify legitimate interest under Article 6(1)(f), and public-interest tasks under Article 6(1)(e), as "the provisions most likely to be used." For recorded meetings and customer calls, the basis depends on the purpose and has to be chosen and documented before recording starts.
- Storage limitation. Article 5(1)(e) requires personal data to be kept "for no longer than necessary for the purposes for which the personal data are processed." For surveillance footage, the EDPB goes further: in most cases — its example is detecting vandalism — data should be "erased, ideally automatically, after a few days."
- Security. Article 5(1)(f) requires "appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing."
- Access with redaction. Under Article 15(3), "the controller shall provide a copy," and under 15(4) that copy "shall not adversely affect the rights or freedoms of others." The EDPB says controllers should use masking or scrambling rather than refuse — which is why the recording mode matters, as argued in composite vs per-track recording.
For video recording compliance, the EU's pressure is toward keeping less, for less time. The US starts from a different question entirely.
US: consent to record, set state by state
There is no general US federal privacy law for recordings. The binding question is interception: whose consent do you need to record a conversation?
The federal answer is one party. 18 U.S.C. § 2511(2)(d) says it is not unlawful to intercept a communication "where such person is a party to the communication or where one of the parties to the communication has given prior consent," unless it is done to commit a crime or tort. Some states set a higher bar — often called two-party or all-party consent:
State | The statutory text |
|---|---|
California | Penal Code § 632 applies to anyone who, "intentionally and without the consent of all parties to a confidential communication," records it — where a confidential communication is one "carried on in circumstances as may reasonably indicate that any party to the communication desires it to be confined to the parties thereto." |
Florida | § 934.03(2)(d) makes interception lawful "when all of the parties to the communication have given prior consent." |
Washington | RCW 9.73.030 prohibits recording private communications "without first obtaining the consent of all the participants" — but consent "shall be considered obtained whenever one party has announced to all other parties … that such communication or conversation is about to be recorded," and the announcement must itself be recorded. |
These three are examples, not a complete list, and the wording differs in ways that matter. The design consequence is consistent, though. A video call can include participants in several states at once, and the recording system rarely knows which. The practical approach is to meet the strictest rule on every call: announce recording to everyone, make the announcement visible and audible, and keep a record that it happened. Washington's statute is a useful template, because it treats a recorded announcement as consent.
Retention in the US is then driven by sector rules and by litigation: once a dispute is anticipated, footage has to be preserved, which is covered in evidentiary video recording.
India: DPDP notice and consent, and RBI's sector rules
For video recording compliance, India now has both a general data protection law and, for banking, detailed recording rules.
The Digital Personal Data Protection Act, 2023 applies to "personal data in digital form," which includes recorded video of identifiable people. Its core obligations for recording are:
- Notice first. Section 5(1): every request for consent "shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal," setting out the personal data and the purpose.
- Consent that means something. Section 6(1): consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action."
- Security. Section 8(5): protect personal data "by taking reasonable security safeguards to prevent personal data breach."
- Erasure — with an exception. Section 8(7): unless "retention is necessary for compliance with any law for the time being in force," erase personal data when consent is withdrawn or "as soon as it is reasonable to assume that the specified purpose is no longer being served," and make your processors erase it too.
- Transfers. Section 16(1) lets the Central Government "restrict the transfer of personal data … to such country or territory outside India as may be so notified."
Timing matters. The government notified the DPDP Rules on 14 November 2025, and they "introduce an eighteen-month period for phased compliance." Recording systems being designed now will be operating when those obligations are in force.
For banking video KYC, the Reserve Bank of India is specific. Its Master Direction on KYC (updated 14 August 2025) requires for video-based customer identification that "the entire data and recordings of V-CIP shall be stored in a system / systems located in India," that "the video recording is stored in a safe and secure manner and bears the date and time stamp that affords easy historical data search," and that the Direction's record-management rules apply — under which "records shall be maintained for a minimum period of five years after the business relationship is ended or the account is closed."
The DPDP exception in section 8(7) is what reconciles the two: the RBI retention requirement is a law that makes retention necessary, so it overrides the general duty to erase for those recordings. Proving those recordings later falls under the Bharatiya Sakshya Adhiniyam's certificate, covered in what a video chain of custody requires.
Where the regimes pull in different directions
Put side by side, the video recording compliance rules conflict in two predictable places.
- Retention. The GDPR and DPDP push toward deleting as soon as the purpose is served; sector rules like RBI's require years. Both regimes resolve it the same way — a legal obligation to retain is itself a valid purpose — so the answer is retention by class: short by default, long only where a specific rule requires it, and legal holds for disputes. The cost side of that choice is in the storage bill for 24/7 recording.
- Consent. The US varies by state, the EU asks for a lawful basis that may not be consent at all, and India's DPDP centres on notice and consent. Designing for the strictest reading — announce to everyone, capture the acknowledgement — satisfies all three far more easily than designing per jurisdiction.
Location is the third tension, and the largest. Where recordings are allowed to live, and what storing them in-country does and does not achieve, is the subject of where your media legally has to live.
What video recording compliance asks of the architecture
Every requirement above lands on a specific capability in the recording system.
Requirement | What the system has to do |
|---|---|
Tell people, and in some states get everyone's consent | Announce recording to all participants, and record that the announcement was made |
Provide a copy while protecting others | Keep tracks separable so others can be masked — composite vs per-track recording |
Keep no longer than necessary, but years where required | Retention by class, automated deletion, and legal holds |
Store in a specific country | Pin the recorder, storage and relays — not just the bucket — to that country |
Protect against unauthorised access | Encryption, access control and an access log that is itself tamper-evident |
Prove it later | Completeness, timing and integrity evidence produced at capture |
The last row is where the engineering begins. How a pipeline produces that evidence stage by stage is laid out in the technical companion, the recording architecture audit.
The Bottom Line
Video recording compliance asks four questions — may you record, must you tell, how long, and where — and the EU, US and India answer each differently. The GDPR limits purpose and duration; US law turns on consent, with some states requiring every party's; India combines DPDP notice-and-consent with sector rules such as RBI's five-year, in-country V-CIP storage.
Design for the strictest reading of each question, keep retention by class, and make sure the architecture can prove what the law asks you to claim.
What's Next
The technical companion, the recording architecture audit, walks the evidence a recording pipeline has to produce to meet these obligations. For where media is allowed to live and why in-country storage is not the whole answer, read where your media legally has to live.
Frequently Asked Questions
What are the main video recording compliance requirements in the EU?
Under the GDPR you need a lawful basis for recording, must keep recordings no longer than necessary, must secure them, and must provide people a copy of their data while protecting others in it. EDPB guidance names legitimate interest as a likely basis for surveillance and says such footage should usually be erased after a few days.
Is it legal to record a video call in the US without telling everyone?
Under federal law, one party's consent is enough. Some states, including California, Florida and Washington, require the consent of all parties, and Washington treats a recorded announcement as consent. Because participants may be in several states, announcing recording to everyone is the practical default.
Does India's DPDP Act apply to video recordings?
Yes. The DPDP Act covers personal data in digital form, which includes recordings of identifiable people. It requires a notice with or before any consent request, valid consent, reasonable security safeguards and erasure once the purpose ends — unless another law requires retention. The DPDP Rules were notified on 14 November 2025 with an eighteen-month phased compliance period.
How long must RBI video KYC recordings be kept?
The RBI Master Direction applies its record-management rules to V-CIP, under which records are maintained for a minimum of five years after the business relationship ends or the account is closed. V-CIP recordings must also be stored in systems located in India, securely, with a date and time stamp.
How do GDPR storage limits and sector retention rules fit together?
A legal obligation to retain is a valid purpose in its own right, so sector rules can require longer retention for specific recordings. India's DPDP Act makes this explicit: the duty to erase applies unless retention is necessary for compliance with another law. Use retention by class rather than one period for everything.
Does video recording compliance require keeping recordings in-country?
Not generally — but specific rules can. RBI requires V-CIP recordings to be stored in India, and India's DPDP Act lets the government restrict transfers to notified countries. Location rules are covered in depth in the post on video data residency.
Can our recordings stay on infrastructure we control?
Yes, if the platform keeps recording processing and storage on your side. Samvyo works this way, which lets you pin recordings, relays and storage to the jurisdiction your rules require. The retention schedule, notices and consent flow remain your decisions.