CyberCode.ph · Philippines

CCTV and the Law in the Philippines: Notice, Audio, Retention and Footage Requests

Last updated September 29, 2026 · Practical privacy, cybersecurity and technology-law guidance

Direct Answer

Operating CCTV in the Philippines is legal, but recording identifiable people is personal-data processing, and since 27 August 2024 it has been governed by NPC Circular No. 2024-02 on Closed-Circuit Television (CCTV) Systems. The circular requires a prominently displayed notice, a lawful basis that is normally not consent, cameras pointed only at the intended space, encrypted storage with access logs, a documented retention period, and a reply to a person asking for footage of themselves within five to fifteen working days. Purely household cameras sit outside it.

For connected questions on lawful processing, rights, complaints and organizational duties, see the Data Privacy Philippines hub.

Key Takeaways

  • There is a specific CCTV rule, and most people have not read it. NPC Circular No. 2024-02, signed 9 August 2024, published 12 August 2024 and effective 27 August 2024, replaced the National Privacy Commission’s earlier CCTV advisory. It is far more detailed than the advisory it repealed.
  • Consent is the wrong starting point. Section 4(A) tells personal information controllers to identify a lawful basis other than consent for CCTV. A sign saying “by entering you consent to being recorded” is not how the circular expects the question to be answered.
  • Some camera placements are flatly prohibited. Fitting rooms, rest rooms, toilets and lactation or breastfeeding rooms are named in the text as strictly off-limits. There is no balancing test for those spaces.
  • Retention has no fixed number — but it cannot be set by your hard drive. The circular says footage is kept only as long as necessary for the declared purpose, and that the period “shall not be determined based solely on the storage capacity of CCTV systems.”
  • People can ask for footage of themselves, and there is a clock. Viewing requests must be dealt with within five working days; requests for a copy within fifteen working days, extendable once by up to fifteen more.
  • The circular says nothing about audio. Microphones on a camera raise a separate question under the Anti-Wiretapping Act, which is a criminal statute, not a privacy regulation.

Jump to a Section

Decision Snapshot

The questions people actually arrive with, and the short answer to each. Every line is expanded further down the page.

Question Short answer
Is CCTV legal in the Philippines? Yes. Operating it is lawful; how you operate it is regulated.
Do I need a sign? Yes. A readily visible, prominently displayed notice is required where the circular applies.
Do I need people’s consent to record them? Normally no — and the circular asks you to find a basis other than consent.
Can I put a camera in a toilet or fitting room? No. This is strictly prohibited by name.
Can my camera face the street or my neighbour’s property? Not freely. Coverage must stay on the intended space, and pointing beyond a private residence can pull a home camera into full compliance duties.
How long can I keep footage? Only as long as the declared purpose needs. There is no fixed statutory number, and storage capacity is not a valid reason.
Can someone demand footage of themselves? Yes, subject to verification and the grounds for denial.
How fast must I answer them? Five working days to view; fifteen working days for a copy, extendable once.
Can I charge for a copy? A reasonable fee covering administrative cost is permitted.
Does the rule cover the microphone? No. Audio is a separate question under the Anti-Wiretapping Act.
Does it apply to my home CCTV? Not if the use is purely personal, family or household — see the limits below.
Does it apply to the police? Lawful surveillance by law enforcement under their own mandates is carved out.

Why CCTV Is a Data Privacy Question

A camera that records a recognisable face is collecting personal information. That single fact is what pulls CCTV out of the world of hardware choices and into the world of compliance. Under the Data Privacy Act of 2012 (Republic Act No. 10173), anyone who decides why and how personal data is processed is a personal information controller (PIC), and anyone processing it on the controller’s behalf is a personal information processor (PIP). A shop owner who installs cameras is a PIC. The security agency or cloud video provider operating the system for them is usually a PIP.

The National Privacy Commission (NPC) is the Philippine regulator that administers and implements the Data Privacy Act, and it is the body that issued the CCTV rules described on this page. That relationship matters practically: the NPC can investigate CCTV practices, act on complaints about them, and impose administrative fines for breaches of the Act it enforces.

Three things follow from treating footage as personal data rather than as a private recording you happen to own:

  • You need a reason. Processing must rest on a lawful basis and a declared, legitimate purpose. “We already had the cameras” is not a purpose.
  • The people in the footage have rights. Including a right of reasonable access to material about themselves, which the circular turns into a concrete request procedure with deadlines.
  • You are holding something you must protect. Loss of or unauthorised access to recorded footage can be a personal data breach, with its own notification questions.

The Rule That Applies: NPC Circular No. 2024-02

The governing instrument is NPC Circular No. 2024-02, titled Closed-Circuit Television (CCTV) Systems. It was signed on 9 August 2024 by Privacy Commissioner John Henry D. Naga together with Deputy Privacy Commissioners Leandro Angelo Y. Aguirre and Nerissa N. De Jesus. The NPC announced that it was published on 12 August 2024 and that it took effect fifteen days after publication, on 27 August 2024. Section 16 of the circular states that it “shall take effect fifteen (15) calendar days after its publication in the Official Gazette or a newspaper of general circulation.”

It replaced the NPC’s earlier guidance. The Commission’s own issuances index records NPC Advisory No. 2020-04, the Guidelines on the Use of Closed-circuit Television (CCTV) Systems, as having been repealed by this circular. If you are working from a CCTV policy written before late 2024, it was probably built on the repealed advisory.

Section 13 gave organisations a transition: “PICs and PIPs shall be given a period of sixty (60) calendar days from the effectivity of this Circular to comply with the requirements provided herein.” That window closed in late October 2024. There is no grace period left to rely on.

The circular is short — sixteen sections — and its shape tells you what the NPC cares about. Nearly half of it is about handling requests for footage.

Section Subject What it decides for you
1 Scope Whether the circular applies to your cameras at all
2 Definition of Terms What counts as a CCTV system
3 General principles Notice, legitimate purpose, proportionality, fairness, accountability
4 Lawful basis Why consent is not your default answer
5 Safeguards Policies, placement, storage, encryption, retention, analytics, vendors
6 Data subject request for access How a person asks for footage of themselves
7 Third-party access request When someone else may obtain footage
8 Response procedure How viewing and copying are actually conducted
9 Period for complying with the request The five- and fifteen-working-day clocks
10 Denial of request The seven grounds for saying no
11 Interpretation Doubts resolved in favour of the data subject
12 Penalties Criminal, civil and administrative liability under the DPA
13 Transitory Provisions The sixty-day compliance window (now closed)
14 Separability Clause Standard severability
15 Repealing Clause Inconsistent issuances repealed or modified
16 Effectivity Fifteen days after publication

Who Is Covered and Who Is Not

Section 1 applies the circular to all PICs and PIPs processing personal data through CCTV systems, with two carve-outs: purely personal, family or household affairs, and lawful surveillance by law enforcement, intelligence and investigative agencies acting under their mandates.

The household exception is narrower than most people assume, and the circular says so in terms. Section 1(A) provides that where CCTV systems “capture images of individuals beyond the boundaries of a private and non-commercial residence or establishment, particularly where it monitors a public space, such use cannot be considered purely for personal, family, or household use. As such, the owner of the CCTV systems is a PIC and subject to the corresponding obligations under the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and all relevant issuances of the NPC.”

Read that carefully, because it is the single most consequential sentence in the document for ordinary households. A doorbell camera trained on your own porch is one thing. The same camera angled to cover the street, the sidewalk, or the neighbour’s gate is, on the face of the text, no longer purely household use — and the person who installed it has become a controller with the full set of obligations.

What the circular defines as CCTV is also worth noting: Section 2 describes “closed-circuit television or camera surveillance systems in a fixed or stationary location that can capture images of individuals or other information relating to individuals.” The emphasis on a fixed or stationary location is why body-worn cameras are dealt with in a separate instrument, NPC Circular No. 2025-01, Guidelines on the Processing of Personal Data Collected Using Body-Worn Cameras.

Situation Does the circular apply? What changes the answer
Retail store, restaurant, clinic, office, warehouse Yes Nothing — this is the core case
School, university, dormitory Yes Additional care where minors are recorded
Condominium, subdivision, homeowners’ association common areas Yes The association or its property manager is the controller
Camera inside your own home, covering only your own property Generally no Purely personal, family or household use
Home camera covering the street, sidewalk or a neighbour’s land Likely yes Section 1(A) expressly removes this from the household exception
Camera in a vehicle used for business Depends The definition centres on a fixed or stationary location; assess the actual deployment
Police or investigative agency surveillance under its mandate No Carved out as lawful surveillance
A private guard agency operating your cameras Yes — as your processor You remain the controller and stay accountable

Why Consent Is Usually the Wrong Basis

The circular tells controllers to look past consent. Section 4(A) provides that “PICs shall determine the more appropriate lawful basis other than the consent of the data subject for the processing of their personal data through the use of CCTV systems.” Section 4(B) adds that where footage includes sensitive personal information, processing must rest on the most appropriate lawful basis under Section 13 of the Data Privacy Act.

This is counterintuitive to a lot of Philippine businesses, because the reflex in privacy compliance is to collect consent for everything. For open surveillance it does not work, and the reasons are practical rather than technical:

  • Consent has to be freely given. A customer who must walk through a monitored entrance to buy groceries is not meaningfully choosing.
  • Consent can be withdrawn. If your basis is consent, a person who withdraws it has a strong argument that you must stop recording them — which is impossible to honour in a fixed camera covering a shared space.
  • A notice is not a consent form. Telling people cameras are operating discharges the duty to inform. It does not manufacture agreement.

In practice, most commercial CCTV deployments are documented against a basis such as the legitimate interests of the controller or a third party, or the protection of life and health, or compliance with a legal obligation, depending on the facts. The Data Privacy Act sets out six lawful bases for personal information in Section 12 and a narrower, closed list of exceptions for sensitive personal information in Section 13 — and there is no legitimate-interests route for sensitive personal information. Which basis fits is a judgement to make and write down before installation, not after a complaint arrives. A privacy impact assessment is the natural place to record it, and the circular expects PIAs to be run for CCTV anyway.

One practical consequence: if your CCTV signage currently says “by entering these premises you consent to video recording,” that sentence is doing no legal work and is arguably misleading about the basis you actually rely on. Replace it with a statement of purpose.

CCTV Notices: What Yours Must Say and Where It Goes

A CCTV notice is a privacy notice, and the circular treats it as one. Section 3(A) states that “Given that CCTV notices are a specific kind of privacy notice, the requirements for privacy notices as stated in NPC Circular No. 2023-04 or the Guidelines on Consent shall apply.” On top of that baseline it adds three requirements of its own:

  • Information about the use of CCTV “shall be made available to the data subjects in the most appropriate format and in clear, plain, and concise language.”
  • The notices “shall be readily visible and prominently displayed within the appropriate premises, such as but not limited to, points of entry or other conspicuous areas.”
  • “The nature, scope, and extent of surveillance, purpose, capabilities of the CCTV systems, and other necessary information shall be provided to the data subjects in accordance with their right to be informed under the DPA.”

That third item is the one most signs fail. A sticker reading “CCTV IN OPERATION” tells a person nothing about scope, extent, purpose or capability. The workable pattern is a layered notice: a short, highly visible sign at the point of entry, pointing to a fuller notice that is genuinely easy to obtain.

Layer Where it lives What it should carry
Layer 1 — the sign Entrances and conspicuous points within the monitored area That CCTV is operating; who operates it; the purpose in a few words; where to get more information
Layer 2 — the full notice Website privacy notice, reception copy, posted notice board, QR code on the sign Identity and contact details of the controller; the Data Protection Officer or contact route; purpose and lawful basis; what areas are covered; whether analytics or recognition are used; retention period; who footage may be disclosed to; data subject rights and how to exercise them; how to complain

Our guide to privacy notice requirements in the Philippines covers the content of the second layer in more detail. Two additions specific to cameras are worth making explicit in the full notice: whether the system records audio, and whether any form of automated analysis is applied to the images.

Placement of the sign matters as much as its wording. The purpose of a notice is to reach a person before or as they enter the monitored area. A notice visible only from inside the shop, or only on a website, does not do that.

Where Cameras May and May Not Point

Section 5(B)(1) is the placement rule, and it contains an outright prohibition. The circular states that “Use of CCTVs in areas where individuals have a heightened expectation of privacy (e.g., fitting rooms, rest rooms, toilets, lactation or breastfeeding rooms,) is strictly prohibited.” There is no proportionality test attached to that sentence and no purpose that unlocks it.

Outside those spaces, the test is coverage discipline. Cameras “shall only be used to monitor the intended spaces, taking into consideration the purpose for such monitoring,” and the circular is explicit that zoom and rotation capabilities “shall not result in surveillance of private spaces (e.g., private backyards, through windows of private residences).” A pan-tilt-zoom camera that can be swung onto a neighbour’s window is a compliance problem even when nobody has swung it, because the control over that capability is part of what you are accountable for.

Section 5(B)(2) adds a quality obligation that reads like a technical footnote and is not one: footage must be “of appropriate and suitable quality,” and controllers must “maintain the integrity and accuracy of the footage recorded and stored, including any associated metadata (e.g., time, date, and location).” Unsynchronised system clocks are the single most common way this is breached, and they are also what destroys footage as evidence later.

Placement Position under the circular
Toilets, rest rooms, fitting rooms, lactation or breastfeeding rooms Strictly prohibited — named in the text
The corridor leading to those rooms Not prohibited, but expect to justify necessity and framing
Entrances, exits, cash handling points, stockrooms, car parks Generally defensible against a stated security purpose
Employee rest areas, prayer rooms, clinic rooms Hard to justify; treat as a heightened-expectation space
A camera whose zoom can reach a neighbour’s window or backyard Capability itself must be constrained, not merely unused
Framing that captures a public street beyond your premises Minimise; for a residence it can remove the household exception entirely

Storage, Encryption, Access Logs and Live Monitoring

Section 5(B)(3) sets the storage obligations, and encryption is among them. Footage “shall be stored in a secure manner, whereby its confidentiality, integrity, and availability are ensured,” and “the recorded footage shall be encrypted pursuant to the applicable issuances of the NPC.” That is a stronger statement than the general duty to adopt reasonable and appropriate security measures, and it is one that a great many installed systems in the Philippines do not currently meet.

Three more obligations sit alongside it:

  • Physical access control. “Access to the area where the CCTV footage is stored shall be restricted to authorized personnel only.” The recorder in an unlocked cupboard behind the counter is the archetypal failure here.
  • Access logging. “Access logs for the CCTV footage, including access requests, reproductions, and transfers, shall be updated on a regular basis as determined by the PIC.” Note the scope — not just viewing, but every copy made and every transfer out.
  • Live feed discipline. “PICs and PIPs shall restrict monitoring of live CCTV feeds to authorized personnel only.” A live view on a mobile app shared among staff, or a monitor visible to customers, is inconsistent with this.

Section 5(A) requires the whole arrangement to be written down. The policy it describes must cover the legitimate purpose, the lawful basis, the regular conduct of privacy impact assessments and regular review of the use of the systems, the notice and its placement, operational detail from procurement and installation through operation, monitoring, maintenance and incident response, the designation of authorised personnel responsible for handling access requests and monitoring live feeds, procedures for access requests, complaint handling and breach management, a documented retention policy, the security measures protecting footage “against any accidental, unauthorized, or unlawful processing, including access (e.g. copying or viewing), alteration, destruction, or disclosure,” and regular review and audit.

If you use a cloud video provider or an outsourced guard force, Section 3(E) and Section 5(B)(6) put the burden back on you: controllers must “use contractual or other reasonable means to ensure proper safeguards are in place when the processing is subcontracted to PIPs,” and “should put in place contractual or other reasonable means to ensure the cooperation and assistance of PIPs they have engaged.” That cooperation clause is not decorative — when a data subject asks you for footage and your vendor holds it, the five-working-day clock is still yours. Our guide to the legal requirements for cloud computing in the Philippines covers the contract side.

How Long You May Keep Footage

There is no fixed retention period for CCTV footage in Philippine law, and anyone who tells you the rule is thirty days is quoting a habit, not a regulation. Section 5(B)(4) sets a standard rather than a number:

  • “CCTV footage shall be retained only for as long as necessary to fulfill the purpose for which the CCTV footage was obtained.”
  • “Retention periods shall not be determined based solely on the storage capacity of CCTV systems.”
  • “The retention period shall be clearly documented and form part of the CCTV policy.”
  • “CCTV footage shall be destroyed once it is no longer needed for its declared and specified purpose.”

The second bullet is the one with teeth, and it is genuine information gain over almost every CCTV page you will find. The overwhelmingly common Philippine practice is to let the recorder overwrite itself when the disk fills — which means the retention period is whatever the hardware happens to produce, typically somewhere between a week and a couple of months, and it drifts as cameras or resolution change. The circular rules that out as a method. You must decide the period from the purpose, document it, and then configure the system to match.

Declared purpose What sets the period Practical shape
Deterring and investigating theft in a shop How long it typically takes for a loss to be noticed and reviewed Usually short — days to a few weeks
Investigating workplace incidents and accidents Internal reporting windows and any applicable claim periods Longer, but still bounded and written down
Building access and perimeter security Security review cycle Short by default, with a documented hold process
Footage relevant to a live complaint, case or investigation The matter itself Place a documented legal hold on that clip and let the rest expire on schedule
“In case we ever need it” Nothing Not a purpose; will not support any retention period

The legal-hold row is the piece most policies miss. The right pattern is a short default period plus a defined mechanism to preserve a specific clip when something happens — not a long default period to cover the rare case. Do not delete footage you know is relevant to a pending dispute or investigation simply because the schedule says so; export and preserve it, then record why.

Video Analytics and Facial Recognition

The circular brings analytics inside the same rules and asks for a risk assessment on top. Section 5(B)(5) states that “The same requirements shall apply when processing personal data derived from CCTV systems that utilize video analytics,” and that “PICs shall utilize PIAs to assess and minimize potential privacy risks.”

The reason analytics deserve separate attention is that they change what the system produces. A recording of a corridor is footage. The same corridor with face matching applied produces an identification, a timestamped record of who was where, and potentially a profile built over time. Where a system extracts biometric identifiers, the output is likely to be sensitive personal information, and the narrower Section 13 basis list applies rather than the six general bases — a materially harder test to satisfy.

Before switching on any recognition, counting, dwell-time, behaviour-flagging or number-plate-reading feature, run the privacy impact assessment and answer plainly: what does the feature decide, what happens to a person the system flags, what is the error rate and who bears the cost of an error, and is there a less intrusive way to reach the same purpose. The related questions about faces, voices and identity in automated systems are covered in our guide to digital likeness rights in the Philippines and in our coverage of the NPC’s guidance on data scraping.

Does the Circular Cover Audio?

No. NPC Circular No. 2024-02 contains no provision addressing audio capture, and that silence is the most misunderstood point on this topic. The circular regulates images. Whether your camera may also record sound is answered by a different and much older instrument: the Anti-Wiretapping Act, Republic Act No. 4200, which is a criminal statute rather than a privacy regulation.

The distinction matters because the consequences differ in kind. Getting the image rules wrong exposes you to the NPC’s administrative and enforcement processes. Recording a private conversation you are not entitled to record is a criminal question, and it is answered without reference to whether you displayed a notice or documented a lawful basis.

Point of comparison Video Audio
Governing instrument NPC Circular No. 2024-02, under RA 10173 RA 4200, the Anti-Wiretapping Act
Nature of the rule Regulatory, administered by the NPC Criminal statute
Does a visible notice help? Yes — it is required A notice does not by itself answer the question
Is a lawful basis other than consent available? Yes, and preferred Do not assume so; the analysis is different
Who to read next This page What RA 4200 prohibits

The practical advice is simple: unless you have a specific, considered reason to capture audio and have taken advice on it, disable the microphones. Most CCTV systems ship with audio enabled, most operators never notice, and the recording serves no purpose that the video does not already serve. For the wider question of recording conversations, see can you record someone without their consent in the Philippines.

A second statute worth naming: the Anti-Photo and Video Voyeurism Act (Republic Act No. 9995) sits behind the circular’s absolute prohibition on cameras in fitting rooms, toilets and similar spaces. A camera placed there is not merely a regulatory failure; it moves the conversation into criminal territory.

How to Ask for CCTV Footage of Yourself

Any person whose personal data is recorded on a CCTV system has a right to reasonable access to it, and Section 6 of the circular turns that right into a procedure with deadlines. The right itself comes from Section 16 of the Data Privacy Act; the circular supplies the mechanics that were previously missing.

What the controller must do: provide a simple, accessible process for viewing footage or obtaining a copy. What you must supply as the requester:

  1. Proof of who you are. The circular refers to “IDs or other similar documents.” Identity verification is legitimate and is not an obstruction.
  2. Authority, if you are acting for someone else. A representative must show “evidence of proper authorization and other supporting documents.”
  3. Enough detail to find the footage. Specifically, “sufficient details on the requested footage such as the specific date, approximate time, and location.” Vagueness here is a ground for refusal, so narrow it as far as you honestly can.

A point that frequently derails these requests: other people will usually appear in the same frames. The circular addresses this rather than treating it as a dead end, contemplating that disclosure involving images of persons other than the requester may proceed on the lawful-processing grounds in the Data Privacy Act relating to identification. In other words, the presence of bystanders is a factor to manage, not an automatic bar.

The clock

Section 9 sets the deadlines, and they are the most quotable numbers in the whole circular.

Request type Deadline Extension
Viewing the footage Not exceeding five (5) working days from receipt Not stated
Obtaining a copy Not exceeding fifteen (15) working days from receipt May be extended by a further period not exceeding fifteen (15) working days, with written notification
Notifying a denial Within five (5) working days, with reasons Not stated

These are working days, not calendar days, and they run from receipt. For an operator, the compliance implication is unavoidable: you cannot meet a five-working-day viewing deadline if nobody has been designated to handle requests, which is exactly why Section 5(A) requires that designation in writing.

How the viewing itself is conducted

Section 8 governs the mechanics, and it protects the other people in the frame. Viewing takes place in “an authorized and secure area” with “only the requesting party and the authorized personnel” present. Controllers may impose safeguards including “non-disclosure agreements or prohibiting capture via mobile phones.” Where a copy is provided, PICs or their PIPs “may charge…a reasonable fee to cover administrative costs” — a fee is permitted, but it is a cost-recovery fee, not a deterrent.

If you are the one making the request

  1. Put it in writing and keep a copy. Email is fine and creates the timestamp that starts the clock.
  2. State the date, the approximate time window and the exact location or camera area.
  3. Say whether you want to view the footage or receive a copy — the deadlines differ, and asking to view is faster.
  4. Attach your ID, or your authorisation if you are acting for someone else.
  5. Ask for written confirmation of receipt, and diarise the deadline.
  6. If the answer is a refusal, ask for the ground relied on. The grounds are a closed list, set out below.
  7. If you get no response at all, or a refusal you believe is unfounded, the route is a complaint to the NPC. Our guide to the National Privacy Commission sets out how complaints work and what must happen before you file one.

Act quickly. The single most common reason a request fails is that the footage was already overwritten — and a controller that deleted it on schedule under a documented retention policy has a valid ground for saying so.

When a Third Party or the Media Asks for Footage

Section 7 deals with requests from someone who is not in the footage. A third party must satisfy the lawful-processing criteria in the Data Privacy Act, which is a higher hurdle than a data subject’s own access request — it is not enough to be curious, related to someone involved, or acting for an insurer without a basis.

The circular gives explicit attention to the press. Where a journalist’s request “involves images of individuals other than the specific person sought to be identified for news reporting, the requesting media personnel or journalist must mask the images of those other individuals before making the footage public.” The masking duty is placed on the requester, which is a notable allocation of responsibility — though a controller handing over unmasked footage has still made a disclosure it must be able to justify.

Law enforcement is the other common requester. The circular contemplates disclosure for law enforcement purposes, criminal investigations, court orders and administrative inquiries. Practical handling for an operator:

  • Get the request in writing, identifying the requesting officer, the unit, the matter and the legal basis invoked.
  • Log it. Section 5(B)(3) requires access logs covering requests, reproductions and transfers — a police disclosure is all three.
  • Release the narrowest clip that answers the request, not the whole day.
  • Keep a record of what you handed over, to whom, when and in what format. If the footage later matters as electronic evidence, that record is part of what makes it usable.

The Seven Grounds for Refusing a Request

Section 10 lists when a request may be denied. It is a closed list, and a refusal that does not rest on one of these is difficult to defend.

# Ground What it means in practice
1 Incomplete information regarding the requested footage The date, time window or location is too vague to locate the material
2 The request is frivolous or vexatious Repetitive or abusive requests; a high bar, not a convenience
3 The purpose is contrary to law, morals or public policy For example, obtaining footage to locate or harass a person
4 A request for a copy is disproportional to the purpose Viewing would achieve the same end; weeks of footage sought for a single incident
5 The burden or expense would be unreasonable Genuine disproportion, evidenced — not simple inconvenience
6 The footage has already been deleted under the documented retention policy Only available if you actually have a documented policy and followed it
7 Disclosure could put an ongoing criminal investigation at risk Coordinate with the investigating unit and record the position

Two observations worth carrying away. First, ground 6 rewards the operator who documented a retention period and punishes the one who did not — a controller with no policy cannot cleanly explain why the footage is gone. Second, Section 11 provides that “Any doubt…shall be interpreted in a manner mindful of the rights and interests of the data subject.” Where a ground is arguable either way, that interpretive rule points one direction.

CCTV in the Workplace

Workplace CCTV is lawful in the Philippines, but the employment relationship makes two things harder: consent, and proportionality. The circular does not create a separate employee regime — the same sections apply — yet the way they apply changes.

On basis, the reasoning in the lawful-basis section above is at its strongest here. An employee who must pass a monitored entrance to earn a living is the textbook case of consent that is not freely given, which is precisely why Section 4(A) directs controllers to another basis.

On proportionality, Section 3(C) requires that the use of CCTV “remains necessary and proportional to the specified and declared legitimate purpose,” and Section 3(D) requires that processing not be “manipulative, oppressive, nor discriminatory.” Cameras at a cash-handling point serve a purpose that is easy to state. Cameras trained continuously on individual desks, or on a rest area, are much harder to defend, and the fairness language gives an affected employee something concrete to point at.

Workplace question Position
Can we install CCTV without asking staff to sign a consent form? Yes — and a consent form is not the right instrument
Do employees need to be told? Yes. The right to be informed applies to staff as much as to customers
Can footage be used in a disciplinary case? Generally yes, if the purpose was declared and the footage is authentic and intact
Can we point a camera at one employee we suspect? Targeted covert monitoring is a materially different and higher-risk proposition; take advice before doing it
Cameras in the pantry, prayer room or locker area? Treat as heightened-expectation spaces; expect to justify or remove
Can supervisors watch the live feed from their phones? Only if they are designated authorised personnel and the access is controlled and logged
Do we need to write a CCTV policy? Yes. Section 5(A) requires it, and it should sit alongside your employee technology policies

A note on scope discipline: CCTV is one strand of workplace monitoring, and the analysis for screen monitoring, email review or location tracking is not identical. This page deals with cameras.

CCTV at Home, in Condominiums and Subdivisions

A camera covering only your own home is outside the circular. A camera covering the street, the corridor or the neighbour’s door probably is not. This is the practical edge of Section 1(A), and it is where most household disputes in the Philippines actually sit.

If your camera reaches beyond your boundary, the text says the household exception does not apply and you are a controller with obligations under the Act, its IRR and NPC issuances. That does not mean a doorbell camera is unlawful. It means the ordinary discipline applies: a purpose you can state, framing limited to what that purpose needs, a period after which recordings are deleted, and care about who you show footage to. Posting a neighbour’s comings and goings online is a separate and more serious problem — see our guide to doxxing in the Philippines.

Condominiums, villages and homeowners’ associations are squarely inside the circular. The association or its property manager is the controller for cameras in lobbies, corridors, car parks and gates, and it owes unit owners and visitors the same notice, retention, security and access obligations as any business. In practice this is where the circular most often goes unimplemented:

  • Guards viewing live feeds without being designated in writing as authorised personnel.
  • Footage released to a unit owner who asks the guard on duty, with no verification, no log and no consideration of who else appears in it.
  • No retention policy, with the recorder simply overwriting when full — the method Section 5(B)(4) rules out.
  • Notices at the lobby entrance only, with nothing covering the car park or perimeter.

If you are a unit owner who wants footage — of a delivery theft, a vehicle scrape, a corridor incident — make the request in writing to the association or property manager rather than asking the guard, give the date, time window and camera location, and note the five-working-day viewing deadline. If the association simply does not respond, the NPC complaint route is available.

Practical Scenarios

1. A shop owner is asked for footage of a customer slip-and-fall

A customer slipped near the entrance on a Tuesday afternoon and, three weeks later, her lawyer asks for the footage. The shop’s recorder holds about fourteen days before overwriting.

Where this lands: the footage is gone, and under Section 10(6) that is a valid ground for denial — but only if the shop can point to a documented retention policy it actually followed. With no policy, the shop is explaining a deletion it never decided on, having also breached Section 5(B)(4) by letting storage capacity set the period. The fix, before an incident: write the retention period down, and build a hold mechanism so that when someone falls over in your doorway, that clip is exported the same week.

2. An employee asks to see footage of an argument in the stockroom

She asks HR on a Monday to view the footage from the previous Friday afternoon.

Where this lands: this is a data subject access request under Section 6, and the viewing clock is five working days. HR should verify her identity, confirm the date, time window and camera, arrange viewing in a secure area with only her and the designated authorised person present, and log the access. It may require her not to film the screen. It should not refuse simply because a colleague also appears in the frames.

3. A condominium refuses to give a unit owner corridor footage

A unit owner asks for footage showing who took a package outside his door. The property manager refuses, saying the footage contains other residents.

Where this lands: “other people are in it” is not one of the seven grounds in Section 10. The presence of third parties is something the circular expects to be managed, not a refusal in itself, and Section 11 directs that doubt be resolved mindful of the data subject’s rights and interests. A defensible response is a supervised viewing limited to the relevant minutes — not a blanket no.

4. A restaurant installs a camera covering the pavement outside

The owner wants to deter people loitering at the entrance, so the camera is framed to take in a stretch of public sidewalk.

Where this lands: a commercial operator is already inside the circular, so the question is proportionality under Section 3(C) rather than scope. Covering the immediate entrance against a stated security purpose is arguable. Covering the length of the street is surveillance of people with no relationship to the business at all, and will be hard to justify. Narrow the framing, or use privacy masking on the parts of the view you cannot justify.

5. A homeowner’s doorbell camera faces the neighbour’s gate

A doorbell camera at a private residence takes in the neighbour’s gate and part of their front yard. The neighbour objects.

Where this lands: on the face of Section 1(A), the household exception no longer covers this, because the camera captures individuals beyond the boundaries of the residence. The homeowner has become a controller. The practical resolution is nearly always the same — re-aim the camera or apply a privacy mask — and it is considerably cheaper than the alternative.

6. A recorder is stolen during a break-in

Burglars take the DVR along with the cash box. It held three weeks of footage of staff and customers, unencrypted.

Where this lands: this is a personal data breach, not merely a theft. The loss of unencrypted footage of identifiable people is exactly the scenario Section 5(B)(3)’s encryption requirement is aimed at. The operator must now assess whether the incident meets the notification threshold — see when the NPC must be notified of a data breach — and will have to explain why the footage was not encrypted.

7. A journalist asks for footage of an incident in a mall

A reporter requests footage of an altercation for a news story.

Where this lands: this is a Section 7 third-party request, and the reporter must meet the lawful-processing criteria. If footage is released, the circular places the masking duty on the journalist for individuals other than the person sought to be identified. The mall should still release the narrowest clip, log the disclosure, and record the basis on which it decided to release at all.

What Happens If You Get This Wrong

Section 12 does not create new penalties; it routes you back to the Data Privacy Act. It provides that “Processing of personal data in violation of this Circular shall carry criminal, civil, and administrative liability pursuant to the provisions of the DPA, its IRR, and related issuances.” Three distinct exposures follow.

Exposure What it looks like
Administrative NPC investigation, orders, and administrative fines. Under NPC Circular No. 2022-01, grave infractions attract 0.5% to 3% of the immediately preceding year’s annual gross income and major infractions 0.25% to 2%, with a cap of ₱5,000,000 per single act or omission. Security-measure failures and breach-notification failures sit in the major band.
Criminal Chapter VIII of RA 10173 creates offences including unauthorized processing, processing for unauthorized purposes, negligent access, improper disposal, unauthorized disclosure and malicious disclosure, carrying imprisonment and fines that run into millions of pesos depending on the offence and whether the data is sensitive. Where a camera is placed in a private space, separate criminal statutes can also be engaged.
Civil Claims by individuals for damages arising from the processing.

Worth being precise about what usually triggers scrutiny, because it is rarely the camera itself. It is a refused access request, a leaked clip, a stolen recorder, or a dispute where someone discovers there was never a policy. Our guide to what counts as a data privacy violation in the Philippines covers how these matters typically surface.

CCTV Compliance Checklist

Work through this against your own installation. Every item maps to a section of the circular.

# Item Source
1 A written purpose for the CCTV system, stated before installation Sec. 3(B)
2 A documented lawful basis that is not consent Sec. 4(A)
3 A written CCTV policy covering operation, access, complaints, breaches and review Sec. 5(A)
4 A privacy impact assessment, repeated on a regular cycle Sec. 5(A)(3)
5 Visible notices at entry points and other conspicuous areas Sec. 3(A)
6 A fuller privacy notice, readily available, covering scope, capability and rights Sec. 3(A)
7 No cameras in toilets, fitting rooms, rest rooms or lactation rooms Sec. 5(B)(1)
8 Coverage limited to the intended space; zoom and rotation constrained Sec. 5(B)(1)
9 Accurate system clocks and preserved metadata Sec. 5(B)(2)
10 Footage encrypted Sec. 5(B)(3)
11 Physical access to the recorder restricted to authorised personnel Sec. 5(B)(3)
12 Access logs covering requests, reproductions and transfers, kept current Sec. 5(B)(3)
13 Live feed viewing restricted to authorised personnel Sec. 5(B)(3)
14 A retention period set by purpose, documented, and configured on the system Sec. 5(B)(4)
15 A legal-hold mechanism for footage relevant to an incident Sec. 5(B)(4)
16 A PIA before enabling any video analytics or recognition feature Sec. 5(B)(5)
17 Written contracts with guard agencies and cloud video vendors, including cooperation on requests Secs. 3(E), 5(B)(6)
18 Named personnel designated to handle access requests Sec. 5(A)(6)
19 A request procedure that can meet five and fifteen working days Secs. 6, 9
20 A secure viewing area and a process for supervised viewing Sec. 8
21 A documented position on audio — and microphones disabled unless justified RA 4200
22 Breach procedure covering loss or theft of footage or recorders Sec. 5(A)(7)

If most of these are missing, start with items 1, 2, 3, 5, 14 and 18. Those six carry the largest share of the risk and cost the least to fix. Our broader data privacy compliance checklist puts CCTV in the context of the rest of your obligations, and the cybersecurity duties page covers the technical measures the Act requires more generally.

Common Mistakes

  • Relying on a consent sign. The circular asks for a basis other than consent, and a notice is not a consent mechanism.
  • Letting the hard drive set the retention period. Expressly ruled out by Section 5(B)(4), and it is the most widespread failure in the country.
  • Treating a request for footage as a favour. It is a right with a five- or fifteen-working-day deadline attached.
  • Refusing because third parties appear in the frame. Not one of the seven grounds in Section 10.
  • Handing footage to whoever asks at the guardhouse. No verification, no log, no basis — three breaches in one gesture.
  • Leaving the recorder unencrypted and unlocked. Section 5(B)(3) requires both encryption and restricted physical access.
  • Leaving audio on by default. A separate statute, and an unnecessary risk in most deployments.
  • Enabling facial recognition because the system offers it. Section 5(B)(5) requires a PIA, and biometric output raises the legal test.
  • Working from a policy written before late 2024. It was almost certainly built on the repealed 2020 advisory.
  • Assuming home cameras are always exempt. Section 1(A) says otherwise once the camera looks past your boundary.

Frequently Asked Questions

Is CCTV legal in the Philippines?

Yes. Installing and operating CCTV is lawful. What is regulated is how you operate it — the notice you display, the basis you rely on, where the cameras point, how the footage is secured, how long you keep it, and how you handle a request from someone recorded on it. Those requirements come from NPC Circular No. 2024-02, issued under the Data Privacy Act of 2012.

Do I need people’s consent to record them on CCTV?

Normally no, and the circular actively steers you away from consent. Section 4(A) directs controllers to identify “the more appropriate lawful basis other than the consent of the data subject.” Consent is difficult to obtain freely in an open, monitored space and can be withdrawn, which makes it unworkable for a fixed camera. You still must tell people that cameras are operating — that is the right to be informed, not consent.

How long can CCTV footage be kept in the Philippines?

There is no fixed number in the rules. Footage is kept “only for as long as necessary to fulfill the purpose for which the CCTV footage was obtained,” the period must be documented in your CCTV policy, and footage must be destroyed once it is no longer needed. Critically, the period cannot be determined solely by the storage capacity of your system — so letting the recorder overwrite itself when the disk fills is not a compliant retention method.

Can I ask a shop, office or condominium for CCTV footage of myself?

Yes. A person recorded on CCTV has a right to reasonable access, which flows from Section 16 of the Data Privacy Act and is given a procedure by Section 6 of the circular. Make the request in writing, prove your identity, and give the specific date, approximate time and location so the footage can actually be found.

How long does a business have to respond to a request for footage?

Under Section 9, a request to view footage must be dealt with within five working days of receipt. A request for a copy must be dealt with within fifteen working days, extendable once by a further period of up to fifteen working days with written notice. A denial must be communicated with reasons within five working days.

Can a business charge me for a copy of CCTV footage?

Yes, but only a reasonable fee to cover administrative costs. Section 8 permits cost recovery; it does not permit a charge set high enough to discourage the request.

Can a business refuse to give me footage because other people appear in it?

Not on that basis alone. The presence of third parties is not among the seven grounds for denial in Section 10, and the circular expressly contemplates disclosure where others appear in the frame. A controller should manage the issue — for example through a supervised viewing limited to the relevant minutes — rather than refuse outright. Section 11 also requires that doubt be interpreted mindful of the data subject’s rights and interests.

Can CCTV record audio?

NPC Circular No. 2024-02 contains no provision on audio at all. The question is governed instead by Republic Act No. 4200, the Anti-Wiretapping Act, which is a criminal statute and is analysed differently from the privacy rules on this page. Unless you have a specific, considered reason to capture sound, the safe default is to disable the microphones.

Is CCTV allowed in the workplace?

Yes, subject to the same rules. Employees must be informed, the basis should not be consent, and placement must be necessary and proportionate to a declared purpose. Cameras in toilets, changing areas and lactation rooms are strictly prohibited. Targeted covert monitoring of an individual employee is a materially different proposition and should not be undertaken without advice.

Does the circular apply to my home CCTV?

Not if the use is purely personal, family or household. But Section 1(A) states that where the cameras capture individuals beyond the boundaries of a private and non-commercial residence — particularly where they monitor a public space — the use cannot be treated as purely household, and the owner becomes a personal information controller with the corresponding obligations. A doorbell camera covering only your own porch is fine; one framed across the street is a different question.

Does a CCTV system have to be registered with the NPC?

There is no separate CCTV registration. The ordinary registration rules apply to the organisation as a whole: under NPC Circular No. 2022-04, registration is required where a controller has 250 or more employees, or processes sensitive personal information of 1,000 or more individuals, or where processing is likely to pose a risk to rights and freedoms, involves automated decision-making or profiling, or is not occasional. Whether CCTV pushes you over a threshold depends on your wider processing, not on the cameras alone.

Verification Note

This page is built from primary government sources retrieved and read on 17 September 2026. Specifically: the full text of NPC Circular No. 2024-02 as published by the National Privacy Commission; the NPC’s own announcement of the circular, which supplies the publication and effectivity dates; the NPC’s index of advisories and circulars, which records the repeal of NPC Advisory No. 2020-04; the text of Republic Act No. 10173 as published by the NPC; and NPC Circular No. 2022-01 on administrative fines.

Two limits are worth stating openly. First, this page cites no Philippine court decisions on CCTV. Supreme Court sources were not retrievable when this guide was prepared, and we would rather say so than paraphrase a case from memory. Where a point below turns on how a court would view a particular deployment, we have said that it is a judgement rather than a settled rule. Second, the full text of Republic Act No. 9995 could not be retrieved from an official source on this date, so this page refers to that statute by name and does not summarise its elements; see our dedicated guide for that.

Where the circular is silent — audio being the clearest example — we say it is silent rather than filling the gap with an inference.

Official Sources

About This Guide

Author: Cybercode.ph Editorial Team.
Last materially reviewed: 17 September 2026.

This guide has not been reviewed by a named external legal reviewer. We state that plainly rather than attach credentials the page does not have. Every legal proposition on this page is traceable to one of the official sources listed above, and where a source could not be retrieved we have said so in the verification note rather than write around the gap.

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

Found something out of date? Philippine privacy issuances change, and this page carries a review date for that reason. If a circular referenced here has been amended or repealed, we want to know.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.