Ask a video vendor where your footage is stored and you will usually get a clean, confident answer. Canadian data centre. Toronto, or Montreal, or Vancouver. It sounds like the end of the conversation, and for most buyers it is.

It is the end of the first conversation. There is a second one, and almost nobody starts it.

Storage location is where the recordings sit. Processing location is where the video is worked on — analyzed, transcoded, indexed, searched, matched. Those are different systems in different places, and the second one is not implied by the first. A platform can store your video in a Canadian facility and send frames somewhere else entirely to decide whether a person is in them. The reverse is just as common: a recorder in your own electrical room, holding every byte on site, feeding a cloud analytic that reads the stream from another country.

That second arrangement is the one that surprises people. An owner who chose on-premise recording specifically so the video would never leave the building will describe their system as local — and be describing only where the file sits.

This is not an argument against cloud video. Cloud and hybrid architectures are legitimate, well-engineered and often the right call; we design and support them. It is an argument that an owner should be able to answer two questions about their own system, and most can answer half of one.

The two questions, separated

Where is it stored? Which physical facilities, in which countries, hold the recordings and their backups. This includes the copies you forget about: replicas kept for redundancy, snapshots, disaster-recovery copies in a second region, and exported clips a user downloaded and emailed to an adjuster.

Where is it processed? Every place a machine somewhere reads the actual pixels. That list is longer than most people expect:

  • Transcoding — converting the camera's stream into formats a browser or phone can play, and generating the low-resolution preview you scrub through.
  • Indexing and search — building the metadata that lets you type "red vehicle, Tuesday afternoon" and get results in seconds. Something had to look at every frame to build that index.
  • Analytics — person and vehicle classification, plate reading, loitering and line-crossing detection, appearance search. Some of this runs on the camera, some on a local appliance, some in a data centre.
  • Support access — a vendor engineer opening your stream to diagnose a fault, from wherever that engineer sits.
  • Subprocessors — the third parties your vendor uses for any of the above. Your contract is with one company. The frames may pass through several.

The word "cloud" gets used for all of this interchangeably, which is exactly why the two questions collapse into one in a sales meeting. If you have not already read our comparison of the underlying models, cloud vs on-premise video recording covers the cost, retention and failure-mode trade-offs; this article is about the question that survives after you have chosen one. Where the analytics themselves should run is its own decision, covered in edge server or cloud analytics.

Why "Canadian data centre" is an incomplete answer

It is not a wrong answer. It is an answer to one of the two questions, offered in response to both.

Consider a system sold and configured as fully on-premise. The recorder is in the building. Retention is on local drives. Nothing about the architecture diagram suggests anything leaves. Then someone enables an appearance-search feature, or a licence-plate module, or an alert that fires when a person enters an area after hours. Depending on the product, enabling that feature can mean the camera or recorder begins sending frames — or short clips, or entire streams — outbound to a service that does the analysis and sends back a label. The recordings stayed home. The video did not.

Now run it the other direction. A platform stores everything in a Canadian region, and answers your residency question honestly and correctly. Its machine-learning inference runs in a different region, because that is where the hardware is. Its support organization works across several countries. Its indexing pipeline uses a subprocessor. Every one of those is a normal engineering decision, and none of them is a lie about storage.

The gap is not usually deception. It is that you asked a storage question and the vendor answered the storage question.

The question to put in writing

Ask it in an email, and ask for the reply in writing. A verbal answer from a salesperson does not survive their departure; a written one lands in your file and, if it matters later, in your contract.

Here is the substance, in the plainest form we know:

Please identify, in writing: (1) every country and region in which our recorded video and its backups are stored; (2) every country and region in which our video is processed — including transcoding, indexing, search, analytics and any machine-learning inference; (3) every subprocessor or third party that performs any of the above, and where each of them operates; (4) which product features, if enabled, cause video or images to leave our premises, and how we can see which are currently on; and (5) who within your organization and your subprocessors can access our video, under what circumstances, and whether that access is logged and available to us.

Item four is the one that earns its place. Storage and processing locations are architectural facts, and a good vendor has them documented. Which features move video off site is an operational fact that changes when someone in your organization clicks a toggle. An answer to items one through three describes the system as designed. Item four describes the system as configured, which is the one you actually own.

A vendor with a mature answer will produce it quickly, often as an existing document, because enterprise and public-sector customers have been asking for years. A vendor who becomes vague, reframes the question as a technicality, or answers item one four times, has told you something useful too.

What PIPA expects of the answer

British Columbia's Personal Information Protection Act applies to this because surveillance video of identifiable people is personal information, the same way door logs are — a point we made at length in your door logs are personal information.

We are deliberately not telling you whether any cross-border rule applies to your organization. Whether your sector, your clients' contracts or your professional obligations impose a residency requirement is a question for your counsel or privacy officer, and this article is not the place to compress it. What we can point at are two duties that apply to your video system whatever the answer to that question turns out to be.

Protection — the reasonable-security obligation. Section 34 is one sentence:

"An organization must protect personal information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks."

Read the phrase or under its control. It is doing the heavy lifting here. Handing your video to a vendor does not hand over the obligation with it. If frames leave your building for processing, the reasonable security arrangements you are expected to have made now extend to a path and a party you cannot see from your own network — which is precisely why the written answer above is not paperwork. It is the evidence that you knew where the personal information goes. You cannot make reasonable arrangements about a data flow you have never been told exists.

There is nothing in that sentence that says video may not be processed elsewhere. There is a great deal in it that says you should be able to describe the arrangement.

Retention — and the default that is not yours. Section 35 cuts both ways. Where an organization uses someone's personal information to make a decision that directly affects them, it must keep that information for at least a year afterward, so the individual has a reasonable opportunity to get access to it. And it must destroy documents containing personal information — or strip the link to particular individuals — as soon as it is reasonable to assume the purpose for collecting it is no longer served and retention is no longer required for legal or business purposes.

Both halves assume you control the clock. In a cloud or hybrid system, you often do not.

The provider's retention is a plan setting, and its default was chosen by the provider to suit the product, not chosen by you to suit your purposes. Thirty days, ninety days, whatever the tier includes. If your own policy says sixty days, and the platform keeps a hundred and eighty because that is what the plan you bought includes, your written policy and your actual holdings disagree — and the actual holdings are what exist. The awkward version runs the other way too: a plan that quietly ages footage out at thirty days can destroy the recording of an incident you used to make a decision about someone, in a window where you had reason to keep it.

Then there is what "deleted" means. Ask specifically: when video ages out or you delete it, how long do backups, replicas and snapshots retain it, and are the derived artifacts — thumbnails, index entries, extracted metadata, analytic results — deleted with the video or kept separately? Metadata that says a named person's vehicle was at your gate on a date is still information about that person after the footage it came from is gone.

What a good answer looks like

None of this makes cloud video a poor choice, and none of it makes on-premise recording automatically safer — an unmaintained recorder in an unlocked closet is not a privacy control. The point is narrower, and it is a question of ownership rather than architecture.

An owner in reasonable shape can say: our recordings sit here; they are processed here and here; these features send video off site and they are on for these cameras; the vendor's retention is set to this many days and it matches our policy; deletion propagates to backups within this window; these people can access our video and access is logged.

An owner in the more common shape can say: it's in the cloud.

The distance between those two positions is not a project. It is one email, one reply, and one afternoon reading it — and the second half of the question is the half that gets you something you did not already know.

Sources

  • Personal Information Protection Act (SBC 2003, c. 63), s.34 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • Personal Information Protection Act (SBC 2003, c. 63), s.35 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01