CCTV sits in a legal patchwork most customers have never read: state surveillance devices legislation, workplace surveillance rules, the Privacy Act for larger businesses, and much stricter treatment of audio than video. This guide maps the framework for security contractors — what to advise, what to avoid, and how the Hikvision/Dahua procurement story fits in.
Australia has no single CCTV statute. The operative layers: each state and territory’s surveillance devices (or listening devices) legislation governs the use of optical and listening devices — with real differences between jurisdictions; workplace surveillance rules (notably NSW’s Workplace Surveillance Act and the ACT’s equivalent) add notice and policy requirements for monitoring employees; the Commonwealth Privacy Act and its APPs bind businesses with turnover above $3 million (and some others) in how they collect, store and disclose footage of identifiable people; and general law (trespass, nuisance, stalking provisions) polices the edges. The installer’s role isn’t legal advice — it’s designing systems that make lawful operation easy and flagging the configurations that invite trouble.
The state acts share architecture but differ in scope and consent rules: some regulate optical surveillance devices on private activities generally, others focus on listening devices with optical provisions added later; party-consent rules for recording conversations vary meaningfully between jurisdictions. The practical consequences for installers are stable though: audio capture is the high-risk feature everywhere, covert surveillance of private activity is restricted everywhere, and the client operating cameras — not the installer — carries the use obligations, which is exactly why handover documentation matters.
Businesses covered by the Privacy Act (generally $3M+ turnover, plus certain sectors regardless of size) treat identifiable footage as personal information: collection must be reasonably necessary and notified (signage and privacy policies), storage secured, access controlled, and disclosure managed — with individuals holding access rights to footage of themselves in many circumstances. For installers this converts to design features: retention aligned to policy, role-based access on the VMS, export logging, and secure remote access rather than port-forwarded recorders with default passwords — which are a privacy breach and a cybersecurity incident waiting to share a headline.
Distinct from privacy law but part of every CCTV conversation since 2023: following a government review, Australian departments removed Hikvision and Dahua devices from government buildings, aligning with US NDAA Section 889 restrictions and similar UK moves. No general Australian ban exists — private-sector use remains lawful and widespread — but the professional obligations are clear: for government, defence-adjacent and policy-sensitive corporate clients, verify procurement requirements before specifying; for all clients, disclose the context honestly and document their informed choice; and for every install regardless of brand, harden the devices (credentials, segmentation, firmware) so the cybersecurity dimension is managed, not assumed.
traqR gives CCTV contractors the documentation layer this legal patchwork rewards: per-camera asset registers with fields of view photographed at handover, configuration records (retention settings, audio disabled, masking applied), signage installation evidence, hardening checklists captured per device, and service histories showing firmware currency — the record set that protects the client operationally and the installer professionally.
Yes — cameras covering your own property are broadly lawful. The boundaries: don’t aim into neighbours’ private areas or anywhere with a reasonable expectation of privacy, be very cautious with audio (heavily restricted in every state), and expect surveillance-devices legislation to differ by jurisdiction on the details.
Recording private conversations is heavily restricted under state listening/surveillance devices laws, with consent requirements that vary by state. The professional default is audio off unless the client has taken specific legal advice for their jurisdiction and use case.
In NSW and the ACT, explicitly yes — workplace surveillance legislation requires advance written notice, visible cameras and policy disclosure, with covert monitoring requiring special authority. Elsewhere, notice remains best practice and supports Privacy Act compliance for covered businesses.
No universal statutory period applies — 30 to 90 days is common commercial practice, balancing investigative usefulness against storage and privacy exposure. Privacy Act-covered businesses should set retention in policy and stick to it; specific sectors and incidents (e.g. known claims) can require longer holds.
traqR does quoting, scheduling, invoicing, timesheets and compliance — built for Australian trades. Try it free for 14 days, no credit card required.