California Video Surveillance Compliance: CCPA, Penal Code 632, and Camera Placement Law
California doesn't regulate security cameras as a single category of technology -- it regulates them through at least three separate, independently enforceable legal frameworks that layer on top of each other every time a lens goes up and a microphone gets left on. The California Consumer Privacy Act and its CPRA amendments treat identifiable camera footage as personal information subject to the same notice, access, and deletion machinery as a customer database. Penal Code Section 632, part of the California Invasion of Privacy Act (CIPA), governs the audio channel and predates CCPA by more than fifty years, having been enacted in 1967 to police wiretapping and eavesdropping. Penal Code Section 647(j) governs where a camera is physically allowed to point, criminalizing recording in spaces where someone has a reasonable expectation of privacy regardless of who owns the building. Most property owners -- and more than a few of the low-voltage integrators who install their systems -- treat a camera purchase as a hardware decision. In California, it's also three overlapping legal exposures, each with its own penalty structure, each triggered independently of whether the system was ever intended to identify, record, or surveil anyone in particular.
Start with the data-privacy layer, because it's the one most businesses assume doesn't apply to them. Civil Code Section 1798.140(v) defines personal information broadly enough to explicitly include 'audio, electronic, visual...information' that identifies or could reasonably be linked to a particular consumer -- a definition that captures identifiable camera footage as a matter of statutory text, not interpretation. A business crosses into CCPA/CPRA coverage for the 2026 compliance year if it has annual gross revenue above $26,625,000, buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year, or derives half its revenue from selling personal information -- and a single camera at a retail entrance, apartment lobby, or parking structure can rack up 100,000 individual 'consumer' captures in a matter of months from foot traffic alone, without a single purchase or account ever being created. Once that threshold is crossed, footage-holding businesses owe the same notice-at-collection, right-to-know, and right-to-delete obligations that apply to any other personal information -- and if a camera's AI analytics engine measures gait, extracts a faceprint, or supports a 'search by person' feature, that footage is reclassified as sensitive personal information under CPRA's biometric-information category the moment it's processed to uniquely identify someone, even if facial recognition was never the system's advertised purpose.
The audio channel is where the criminal exposure lives, and it has nothing to do with CCPA. Penal Code 632 makes California one of roughly a dozen all-party-consent states: intentionally using an electronic recording device to eavesdrop on or record a 'confidential communication' -- one where the circumstances reasonably indicate a party wanted it confined to those present -- without the consent of every party is a crime, regardless of whether the camera's owner is also a participant in the conversation. A first violation carries a fine of up to $2,500 and up to a year in county jail or state prison; a repeat offense following a prior conviction under Sections 631, 632.5, 632.6, 632.7, or 636 raises the fine ceiling to $10,000. Separately, Penal Code 637.2 gives anyone whose confidential communication was recorded a private civil right of action for the greater of $5,000 per violation or three times actual damages -- recoverable without proving any actual harm occurred. The practical problem: most consumer- and commercial-grade cameras with built-in microphones -- video doorbells, two-way-audio dome cameras, intercom-integrated gate stations -- ship with audio recording enabled by default, turning a routine security purchase into a live CIPA exposure the moment it captures a conversation at a front door, in a breakroom, or across a shared walkway.
This exposure is not theoretical or rare. The California Lawyers Association reported hundreds of CIPA cases filed in California state and federal courts over the past two years alone, and one industry tracking analysis counted 3,847 privacy claims tied to recording and tracking technology filed nationwide since March 2023 -- 2,935 of them, or 76%, in California specifically, with 37% of the California total targeting retail businesses. Most of that current wave targets website and app tracking tools -- pixels, session-replay scripts, chat SDKs -- rather than physical cameras, which is precisely why Senate Bill 690, amended July 2, 2026 and still moving through the Legislature toward an August 31, 2026 deadline, narrows only the pen-register and trap-and-trace provisions of Penal Code 638.51 as applied to websites and apps, handing the Attorney General exclusive enforcement of that narrow slice. Sections 631 and 632 -- the sections that actually govern a camera or doorbell's microphone -- are untouched by the reform. If SB 690 passes in anything close to its current form, plaintiffs' firms that have built a business around digital-tracking CIPA claims have an obvious incentive to redirect toward the physical-recording-device claims the bill doesn't touch.

Video-only surveillance in the workplace sits in a different bucket than either exposure above: California doesn't require employee consent to be recorded on camera at work, but the Labor Commissioner has consistently advised that employers provide clear, advance written notice of what's being recorded and why, paired with visible signage in monitored areas -- disclosure, not permission, is the operative standard. That notice obligation gets sharper the more sensitive the space: restrooms, locker rooms, and any area requiring a key or badge for access are treated as carrying a reasonable expectation of privacy regardless of how the space is labeled, while open floor areas, sales counters, and entrances generally are not. Break rooms and other employee-only common areas currently sit in a genuine gray zone that depends heavily on how the space is actually used -- which is exactly the gap Assembly Bill 1331 was written to close, by explicitly prohibiting surveillance in break rooms, designated smoking areas, cafeterias, and lounges. AB 1331 was ordered to the inactive file in the Senate in late 2025 but remains eligible for reconsideration in the 2026 session, and its language is a reasonably reliable preview of where enforcement expectations are heading even before it becomes law.
Penal Code 647(j) is the statute that actually governs where a lens can point, and it's a misdemeanor charge, not a civil one -- a first offense carries up to six months in county jail and a $1,000 fine, rising to a year and $2,000 for a second or subsequent offense. It prohibits using a camera, phone, or other device to view or record the interior of a bedroom, bathroom, changing room, fitting room, dressing room, tanning booth, or any other space where the occupant has a reasonable expectation of privacy, with intent to invade that privacy. In a commercial low-voltage deployment, that reaches further than most owners assume: employee locker rooms and changing areas in retail and gym facilities, single-occupant restrooms, medical exam and treatment rooms in clinics and senior living communities, and any office or storage area a business chooses to lock specifically to keep it private. What's clearly fine under 647(j): cameras aimed at a sales floor, a building entrance, a parking lot, or a public sidewalk, where no one has a reasonable expectation that they can't be seen. The dividing line the statute draws isn't who owns the property -- it's whether the space, by its function and access controls, carries an expectation of privacy.
The California Supreme Court's framework for judging exactly that question comes from Hernandez v. Hillsides, Inc. (2009) 47 Cal.4th 272, in which a residential facility's director hid a camera in a shared office to catch after-hours misuse of a work computer. The camera was never operated during business hours and never actually recorded the plaintiffs, and the Court held that its narrow scope, limited duration, and specific investigative purpose kept the intrusion from being 'highly offensive' -- but the opinion is still cited today for the balancing approach it applies to camera-placement disputes, weighing the nature and degree of the intrusion against its justification, the context in which it occurs, and the safeguards surrounding it. What makes California distinctive is that this right to privacy runs directly from Article I, Section 1 of the state constitution, which -- unlike the Fourth Amendment -- restrains private parties and businesses, not just government action. A California employee, tenant, or customer can sue a private business directly over camera placement without any government actor needing to be involved at all, a materially broader exposure than most other states carry.
Multifamily and common-interest-development properties carry a version of this exposure that's specific to shared space. Under the Davis-Stirling Act, an HOA can install cameras in common areas but not in locations carrying a reasonable expectation of privacy, and while an association generally can't flatly prohibit an individual owner's video doorbell, it can regulate that camera's placement and appearance through its CC&Rs and architectural guidelines. The recurring practical issue is audio: because a doorbell or common-area camera routinely captures conversations between neighbors at a shared walkway, mailbox bank, or parking area, many associations disable microphones on these devices specifically to stay clear of Penal Code 632 exposure, rather than relying on residents to manage consent in the moment. Gated multifamily and commercial properties running license-plate-reader systems at entry gates carry an additional, separate obligation under Civil Code Section 1798.90.5: a written usage-and-privacy policy, publicly posted if the property has a website, covering authorized purposes, which job titles can access the data, retention and purge timelines, and restrictions on selling or sharing plate data -- a distinct statute that stacks directly on top of whatever CCPA/CPRA obligations the same footage already carries.
None of this exposure stays confined to the property owner. Security industry attorney Ken Kirschenbaum, writing in Security Sales & Integration, has warned installers directly that 'if a lawsuit gets started it's more than likely that the alarm company who installed the cameras, maybe monitors them, will get sued or dragged into the case' -- regardless of whether the final placement decision was actually the property owner's call -- and that modern jury verdicts in these disputes run into the millions, not the thousands, a figure that can exceed the value of the integrator's own company. His recommended defenses are contractual and documentary: signed agreements with indemnity provisions, written and signed placement disclaimers, and conservative camera and microphone choices in any situation with neighbor-dispute potential. For a low-voltage contractor, that means the installer who specs a camera's field of view and decides whether its microphone stays on isn't just executing a design -- they're making a legal determination the property owner will lean on if a complaint or lawsuit ever follows, which is exactly why that decision needs to be documented at design time rather than reconstructed after the fact.
A genuine compliance review of an existing camera system checks all of this at once, not one statute at a time. It maps every camera's field of view against property lines, neighboring units, and public right-of-way to flag 647(j) exposure; audits microphone status device by device, since most consumer-grade doorbell and two-way-audio cameras ship with audio recording on by default; confirms signage and notice-at-collection language actually match what's being recorded and why; documents a defensible process for responding to a CCPA right-to-know or right-to-delete request tied to camera footage; flags any AI analytics feature -- gait measurement, faceprinting, license-plate matching, 'search by person' -- for sensitive-personal-information treatment regardless of the system's original purpose; and confirms a current, CPRA-compliant service provider agreement is on file with whatever cloud VMS or NVR vendor is storing the footage. None of these findings typically require replacing hardware -- most resolve with a configuration change, a signage update, or a documented placement decision -- but none of them get caught without someone actually looking.
This is the exact gap Mytek Pros' compliance audit practice is built to close, and it's a natural extension of the same work our low-voltage team already does. As a licensed California low-voltage contractor (License #1116987) with DIR public-works registration (PW-LR-1001158430), BICSI certification, and DBE/DVBE/MBE certification, based in Carlsbad and serving businesses, multifamily properties, and affordable housing developments across San Diego County and statewide, Mytek Pros both designs and installs the surveillance systems this article covers and audits the ones already in place -- mapping every camera's field of view against Penal Code 647(j), auditing microphone status against Penal Code 632, and reviewing footage-handling practices against CCPA/CPRA obligations, then implementing the fix directly, whether that's a signage update, a documented placement change, or a microphone disabled at the head end. Our compliance audit services extend across HIPAA, SOC 2, CMMC, and NIST frameworks as well, and our managed IT and managed security services -- typically $125 to $250 per user per month -- keep the footage-storage and access-control side of the same system audit-ready on an ongoing basis. If your business, HOA, or multifamily property has never run its camera system through a CA Compliance Camera Audit, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com.
Questions about audits? Get in touch or explore our Audits services.
