The Office of the Australian Information Commissioner (OAIC) has kicked off 2026 with a targeted compliance sweep of business privacy policies, reviewing around 60 organisations across sectors that routinely collect personal information face-to-face. For strata committees, club operators, and facilities managers running CCTV on site, this is a useful prompt to check whether your surveillance practices actually match what your signage and privacy documentation claim — because for many sites, they don’t.
Why CCTV footage falls squarely under privacy law
CCTV footage that captures faces, movement patterns, or timestamped activity can constitute personal information under the Privacy Act once an individual becomes identifiable. The OAIC’s sweep is focused on Australian Privacy Principle (APP) 1.4 — whether published privacy policies contain the required detail — but the underlying expectations for any organisation handling recorded footage are straightforward in principle and often messy in practice: notify people before recording, secure the footage appropriately, and destroy or de-identify it once it’s no longer needed.
Enforcement isn’t hypothetical either. The OAIC has flagged infringement notices with penalties up to $66,000 for policies that don’t meet the required standard. That’s a modest figure for a large operator but a meaningful one for a strata scheme or club that hasn’t budgeted for compliance remediation.
Where sites typically fall short
A sign at the entrance stating “CCTV in operation” is a start, but APP 5 requires organisations to take reasonable steps to make people aware of why information is collected, how it’s typically disclosed, and whether it might be disclosed overseas. In our experience auditing client sites, the gap usually isn’t the absence of signage — it’s a mismatch between what the signage says and what actually happens with the footage. A sign that says “security only” doesn’t cover a scenario where footage is later pulled for staff performance review or used to resolve a customer dispute.
The practical failure points tend to cluster around three things:
- Access control — shared NVR logins, contractors with standing remote access long after a project ends, and no audit trail of who viewed what footage and when.
- Retention — footage kept indefinitely “just in case” rather than against a defined and justifiable retention period, with no automated purge.
- Storage and export — unclear whether footage or system access sits offshore (common with cloud-connected NVRs and some VMS platforms), and whether remote viewing is properly authenticated rather than a shared password on a mobile app.
Workplace surveillance adds another layer
Workplace CCTV isn’t neatly covered by the Privacy Act alone — state and territory surveillance and workplace laws also apply, and they differ by jurisdiction. Sites that have done a good job on customer-facing signage often haven’t extended the same rigour to staff areas, back-of-house zones, or consultation obligations before installing cameras where employees work. It’s also worth confirming whether any camera on site has audio recording enabled, even inadvertently, since audio surveillance frequently sits under separate and stricter rules than video alone.
Operational implications for NSW sites
For strata committees and club operators, this sweep is a low-cost early warning rather than an immediate compliance deadline. But it’s the kind of regulatory signal that tends to precede broader scrutiny, and the fix is genuinely operational rather than legal — it’s about matching documented practice to actual system configuration. That means knowing your camera coverage map, your access control list, your retention settings, and your storage location, and having it written down somewhere more durable than institutional memory.
This is exactly the kind of gap that shows up during the Mallen site audit process — we regularly find NVRs with shared admin logins still active for contractors who finished work years ago, retention settings left at manufacturer defaults, and signage that no longer describes what the system actually does. None of these are exotic problems, but they’re the ones a regulator (or a disgruntled staff member lodging a complaint) will find first.
If your site runs CCTV alongside access control or a broader VMS deployment, it’s worth reviewing both together — access logs and retention policy tend to live in the same conversation. Our CCTV and video analytics services include exactly this kind of configuration and documentation review, separate from any hardware upgrade.
A quick self-check
Before assuming this doesn’t apply to you, walk the site and ask:
- Is signage visible before someone enters camera coverage, and does it match current practice?
- Does your privacy policy mention CCTV, its purpose, and how people can ask questions or request footage?
- Do you have a defined retention period, and can you demonstrate deletion actually happens?
- Can you list everyone with current access — including contractors — and how that access gets revoked?
- Is footage or remote access hosted offshore, and if so, is that disclosed?
Any vague answer is the place to start tightening up. The OAIC sweep may only touch a small number of organisations directly, but the underlying expectations apply to every site running cameras that can identify people — which, in practice, is nearly all of them.
Original source: https://smart-wifi.com.au/the-privacy-sweep-alert-in-australia-is-your-cctv-system-compliant/