How Long Should a New York Building Keep Camera Footage?
Thirty days is the usual answer. Here is the arithmetic behind it, the point at which sixty or ninety is genuinely worth paying for, and what your retention policy stops meaning the moment an incident is reported.
Published 5 August 2026 · 12 min read
Thirty days is the answer most New York buildings land on, and most of the time it is the right one. It is not a law. It is the point where two curves cross: how long it usually takes for an incident to surface, and how much disk you are willing to buy.
Retention is really two separate problems that get welded together on every quote we are asked to review. The first is engineering: how many terabytes does thirty days of your cameras actually consume? That is arithmetic, and you can check it yourself in about two minutes. The second is legal: what your retention policy stops meaning the moment somebody tells you an incident happened. That one is not arithmetic, and getting it wrong costs more than any hard drive.
The arithmetic, and the one number worth memorizing
Storage comes from bitrate. Resolution, frame rate, codec and how much the scene moves all matter, but they matter only because they change bitrate. So the whole calculation collapses to one conversion:
1 Mbps of continuous video = 10.8 GB per day = 0.0108 TB per day.
The derivation, so you can check it rather than trust it: 1 megabit per second × 86,400 seconds in a day = 86,400 megabits = 10,800 megabytes = 10.8 GB. From there, for a system recording around the clock:
Storage (TB) = Bitrate (Mbps) × 0.0108 × Days × Cameras
If a camera only records during business hours, scale it: eight hours a day is one third of the number above. Now you need realistic bitrates. These are what modern IP cameras actually produce at 15 fps with variable bitrate on a normally busy scene:
| Camera | H.264 bitrate | H.264 per day | H.265 bitrate | H.265 per day |
|---|---|---|---|---|
| 2 MP / 1080p | 3 to 4 Mbps | 32 to 43 GB | 1.5 to 2 Mbps | 16 to 22 GB |
| 4 MP / 2560×1440 | 5 to 6 Mbps | 54 to 65 GB | 2.5 to 3 Mbps | 27 to 32 GB |
| 5 MP / 2592×1944 | 6 to 8 Mbps | 65 to 86 GB | 3 to 4 Mbps | 32 to 43 GB |
| 8 MP / 4K | 10 to 16 Mbps | 108 to 173 GB | 5 to 8 Mbps | 54 to 86 GB |
| 12 MP | 16 to 24 Mbps | 173 to 259 GB | 8 to 12 Mbps | 86 to 130 GB |
Two adjustments people forget. A high-motion scene (a sidewalk, a loading dock, a lobby at 6 p.m.) runs 20 to 40% above these figures. A static back corridor runs 20 to 30% below. And going from 15 fps to 30 fps adds roughly 67 to 100% for a benefit almost nobody can see; 15 fps is the surveillance sweet spot and 10 fps is fine on a static scene.
A worked example you can check against your own quote
Take a common New York job: a twelve-camera system in a mid-size apartment building. Eight 4 MP turrets on common areas, stairs and the trash room, and four 4 MP cameras on entrances and the package room, which move more and therefore cost more bitrate. All H.265, 15 fps, recording continuously, thirty days.
- Eight common-area cameras at 3 Mbps. 3 × 0.0108 × 30 × 8 = 7.78 TB
- Four entrance cameras at 4 Mbps. 4 × 0.0108 × 30 × 4 = 5.18 TB
- Total: 12.96 TB of usable, written-to-disk video.
Then add 10 to 15% for file system overhead, database and metadata, because you never get the number on the label. Call it 14.5 TB usable. Not raw. Usable, after whatever RAID level you chose eats its share.
Now go and look at what your quote proposes. If it says “16-channel NVR with 8 TB,” that system does not hold thirty days of those twelve cameras. It holds about seventeen. If it says “4 × 6 TB in RAID 5,” that is 24 TB raw and 18 TB usable, which does hold thirty days with room to add cameras later. That single check, run in two minutes on your phone, catches more bad camera quotes than anything else we can teach you.
The same twelve cameras on H.264 instead of H.265 would need about 23.3 TB usable. Which brings us to the codec.
H.265 and smart codecs: real savings, and the caveat nobody mentions
H.265/HEVC delivers roughly the same perceived quality as H.264 at 30 to 50% lower bitrate, commonly quoted as about 45% less storage. That is genuine, it is free, and there is no reason to specify H.264 on a new system unless something downstream cannot decode it.
On top of that, manufacturers layer proprietary “smart” codecs: H.265+, Smart H.265+, Axis Zipstream, Hanwha WiseStream. They stretch the interval between full reference frames, drop frame rate dynamically when nothing moves, and spend fewer bits on the parts of the scene you told them not to care about. On a quiet stairwell they can cut another 50 to 70%.
Here is what does not go in the brochure. Stretching the group-of-pictures interval means the recorder has fewer complete frames to cut on, so frame-accurate export and forensic seeking get less precise. The clip you hand over may start a second or two early or late. Some smart-codec streams are not fully standards-compliant and will not decode properly in a third-party video management system or a browser player, which matters enormously if you ever want to move off that manufacturer. And H.265 is expensive to decode: a workstation showing thirty-two 4K H.265 streams live needs hardware decoding, which is why we lay out live walls on sub-streams and reserve the main stream for recording and export.
The honest position: use H.265 everywhere, use smart codecs on low-motion interior cameras, and leave them off entrances, registers and anywhere the footage is likely to become evidence.
Why thirty days is the common answer
Because that is roughly how long it takes for most building incidents to surface. A slip-and-fall gets reported to the managing agent a week or two after the fact. Package theft gets noticed when the resident finally chases the delivery. A payroll or harassment complaint arrives after the employee has spoken to someone. A police follow-up on a burglary a block away comes ten days later. Thirty days catches nearly all of that. Seven days catches almost none of it, which is why the bargain systems that ship with a single 2 TB drive are worse than useless: they produce the confidence of having cameras and none of the evidence.
There is also an argument on the other side that rarely gets made to boards: video you hold is video that can be subpoenaed, and every additional day of retention is additional exposure and additional data to secure. Keeping five years of footage “just in case” is not a conservative choice. It is a different risk.
When sixty or ninety days is worth paying for
Longer retention earns its money where the discovery of the problem is structurally delayed:
- Cash handling and point of sale. Internal theft is usually found at a reconciliation, not on the day. Ninety days on the register and back office is standard practice in retail and restaurants for exactly this reason.
- Inventory and warehousing. Shrink surfaces at a cycle count. If your count runs quarterly, thirty-day retention guarantees the footage is gone before you know to look.
- Buildings already in litigation or with an open claim. Different problem, different answer. See preservation below.
- Insurance or lease requirements. Some carriers and many commercial leases name a retention period. Read yours before you buy the recorder, not after.
The design that usually wins a competitive bid is tiered retention: ninety days on entrances, registers and cash areas, thirty days on general common areas, and business-hours-only recording where the space is genuinely empty overnight. That typically cuts total storage by 30 to 40% against flat ninety-day retention while keeping the long window exactly where it matters. It costs nothing but the ten minutes it takes to configure schedules properly, and almost nobody does it.
The drive matters more than the box
A surveillance recorder is not a desktop. It is many simultaneous streams writing sequentially, without pause, forever. Desktop drives (WD Blue, Seagate BarraCuda and the like) are specified for something like eight to ten hours of duty a day. Put one in an NVR and it will typically develop bad sectors and fail within six to eighteen months. We have pulled dead consumer drives out of two-year-old systems in buildings that were paying for “thirty-day retention” the whole time.
Surveillance-grade drives are firmware-tuned for this pattern. WD Purple supports the ATA Streaming Command Set and TLER (time-limited error recovery), meaning the drive returns an error instead of freezing the array for thirty seconds while it retries a bad sector, which is what causes dropped frames. Seagate SkyHawk does the same thing under a different name and adds predictive health alerts. Workload ratings tell you what the manufacturer will actually stand behind: WD Purple is rated to 180 TB per year up to 6 TB and 360 TB per year at 8 TB and above; SkyHawk is 180 TB per year, and SkyHawk AI is 550 TB per year for systems running analytics with heavy concurrent read-back.
Two things to verify on any drive before it goes in: it must be CMR, not SMR (shingled recording is catastrophic for sustained writes), and in a multi-bay array it should be a Pro or AI tier with rotational vibration sensors, because drives in the same chassis shake each other.
RAID, and the rebuild window nobody quotes
Usable capacity is simple. RAID 5 gives you (N−1) × drive size and survives one drive failure. RAID 6 gives you (N−2) × drive size and survives two. RAID 10 gives you half your raw capacity and the best write performance. A hot spare costs one more drive.
The part that belongs in the conversation and almost never is: with 16 TB and 20 TB surveillance drives, a RAID 5 rebuild can run for many hours to several days at full write load while the cameras keep recording into the same array. For that entire window the array has no redundancy left. A second drive failure or a single unrecoverable read error during the rebuild loses the whole volume: all of it, not the last day. That is the real argument for RAID 6 on any array large enough to matter, and it is the argument we make whenever retention is contractually or legally required.
And the line that has to be said plainly: RAID is not backup. It protects against a drive dying. It does not protect against the recorder being stolen (the first thing a competent burglar looks for), or a fire, or ransomware, or somebody with the admin password deciding a clip should not exist. If footage genuinely matters, the recorder belongs in a locked closet with the door alarmed, and critical cameras should also push events off-site.
Retention on paper versus retention in fact
The single most common failure we find on service calls is not undersized storage. It is a system that has not been recording at all for weeks. A drive drops out of the array, the recorder logs it, nobody is watching the log, and the building discovers the gap the week it needs the footage.
Three things prevent it, and none of them are expensive. Configure the recorder to email a named person on disk failure, video loss and recording failure, then test it by pulling a drive. Have somebody physically confirm quarterly that the oldest available recording is actually as old as your policy says. And check the recorder’s clock against a real time source: an NVR whose clock has drifted forty minutes is producing exports that a prosecutor or an insurer will not be able to line up against a door log, a 911 call or a credit card timestamp. Set NTP at commissioning and verify it annually.
Also understand what motion-only recording does to your number. If a camera records only on motion, “thirty days” means thirty days of motion events, which on a quiet stairwell may span four months and on a sidewalk may span nine days. Both are defensible. Neither is what the client thinks they bought unless somebody said it out loud.
The legal half: the day retention stops being your policy
Everything above describes normal operation, where old footage rolls off automatically and that is fine. That changes the moment you know, or reasonably should know, that footage is relevant to a claim, an investigation or litigation. From that point, letting the system overwrite it is not routine housekeeping. It is destruction of evidence, and courts can respond with sanctions including an instruction to the jury that the missing footage would have been unfavorable to you.
We are not attorneys and this is not legal advice. Talk to counsel about your specific situation. But the practical steps are the same in every building, and they are all things the building does, not the vendor:
- Export immediately, do not rely on the retention window. Overwriting is automatic and silent. “We had thirty days” means nothing on day thirty-one.
- Export generously. Take the hours before and after, and every camera that might have caught the person walking in or out, not just the ten seconds of the incident itself.
- Export the native file, plus the manufacturer’s player. A phone video of the monitor is worth very little. A native export usually carries a checksum or watermark that supports authenticity.
- Write down the recorder’s clock offset against a known accurate time at the moment of export, and who exported it.
- Keep the original untouched and work from a copy. Enhancing, cropping or re-encoding the only file you have creates an argument you do not want to have.
- Have a written retention policy and follow it consistently. An inconsistent practice (ninety days when it helps, seven when it does not) is far more damaging than a short policy applied uniformly.
New York also constrains what you can record in the first place. Cameras are prohibited in fitting rooms, restrooms, showers and hotel guest rooms under General Business Law §395-b, and Labor Law §203-c separately bars video recording of employees in restrooms, locker rooms and changing rooms. And camera audio is a genuine trap: New York is a one-party consent state under Penal Law §250.05, but an unattended microphone recording a conversation between two other people has no consenting party present. That is a class E felony. We ship camera systems with audio disabled by default and will only enable it where there is a documented reason and posted notice.
What to put in the scope
A camera quote that does not contain these five things is not a specification, it is a shopping list:
- The bitrate assumed per camera, the codec, and the frame rate. Not “4 MP” but the actual Mbps the design is based on.
- The retention target in days, and whether it is continuous or motion-based, per camera group.
- The usable storage after RAID, not the raw drive total, with the overhead allowance stated.
- The drive model and workload rating, and confirmation it is CMR surveillance-grade.
- Who receives the health alerts, and how the system will be verified as still recording six months from now.
Get those five in writing and the rest of the argument mostly takes care of itself. If you would like us to check an existing quote against your camera list, send it over. The arithmetic takes us about the same two minutes it takes you.
Common questions
Is there a law in New York that says how long I have to keep camera footage?
For an ordinary private apartment building, office or store, no. There is no general New York statute setting a retention period for private CCTV. The thirty-day convention comes from practice, insurance expectations and storage economics, not from a code section.
Specific situations do carry requirements. Some commercial leases specify a retention period, some carriers write it into a policy condition, and certain regulated premises and operations have their own rules. Buildings receiving particular kinds of public funding may inherit conditions through their grant or contract terms. Read those documents before you size the recorder, because retrofitting more storage later means either replacing the array or living with a shorter window than you promised.
Separately, once you know footage relates to an incident or a claim, the duty to preserve that specific footage attaches regardless of your normal policy. That is a legal question for your counsel, but the practical answer is always the same: export it that day.
My installer quoted a 16-channel NVR with 8 TB. Is that enough for thirty days?
Run the numbers. Multiply your assumed bitrate per camera by 0.0108, then by 30, then by the number of cameras. For eight 4 MP H.265 cameras at 3 Mbps that is 7.78 TB; add four busier entrance cameras at 4 Mbps and you are at 12.96 TB before overhead.
So 8 TB gets you somewhere around seventeen days on that camera list, not thirty. It is not that the installer is dishonest. Recorders are often quoted with whatever drive capacity the distributor had in the box. The fix is to make retention a written line item rather than an assumption, and to state it as usable capacity after RAID.
Should we record continuously or only on motion?
Continuous on anything that could become evidence: entrances, vestibules, registers, package rooms, loading doors, elevator lobbies. Motion-triggered recording depends on the camera correctly deciding something happened, and the moment it matters most is often the moment a person moves slowly at the edge of frame in poor light.
Motion-only recording is genuinely useful on low-traffic interior spaces (a mechanical room, a rear stair, a storage corridor) where it can cut storage by around 80%. Modern cameras with object classification are much better at this than the old pixel-difference detection, because they discard rain, headlight sweep, shadows and insects on the lens rather than recording them.
The mixed approach is usually right: continuous where it counts, motion elsewhere, and a longer retention window on the continuous group.
Is cloud recording a better answer than a recorder in the basement?
It solves real problems. There is no recorder for a burglar to carry out, firmware updates happen without a truck roll, and remote access works without opening any inbound ports on the building network. Those are genuine advantages and we install cloud systems where they fit.
The two things that must be disclosed before anyone signs are bandwidth and five-year cost. Continuous cloud recording needs roughly 1 to 2 Mbps of sustained upload per 1080p camera; some platforms specify 4 Mbps guaranteed per camera. Twenty cameras is 20 to 40 Mbps of upload, around the clock, which most New York commercial circuits cannot supply without a fiber upgrade and which will flatten the building’s VoIP if it is not shaped. On cost, business plans commonly run $10 to $30 per camera per month; forty cameras at $20 is roughly $48,000 over five years before any circuit upgrade. Those are typical market figures, subject to survey.
The design that usually wins is hybrid: record locally at full rate for retention, push events and clips to the cloud for redundancy and remote viewing.
How do we know the system is still actually recording?
Configure alerts and then test them. Every professional recorder can email a named person on disk failure, recording failure and video loss. Almost nobody sets this up, and of the ones who do, almost nobody pulls a drive to check the email actually arrives.
On top of that, put a five-minute quarterly task on the super or the managing agent: open the playback timeline on three cameras, scroll to the oldest available recording, and confirm the date is as old as the policy says. That single check catches a failed drive, a camera that has been offline since a power event, and a schedule somebody changed and forgot about.
Work that usually comes with this
Security Camera Installation
New IP camera systems for buildings, storefronts, offices and homes.
Commercial Security Cameras
Retail, restaurant, warehouse and office systems, including NDAA-compliant hardware.
Security Camera Repair & Upgrades
Systems that stopped recording, cameras that went dark, analogue-to-IP migration.
Structured Cabling
Cat6/6A and fibre backbones, racks, patch panels, certified and labelled.
Property Management
Portfolio work: one vendor, consistent hardware, COIs on file, documented every time.
Send us the camera list and the quote.
We will run the retention math against your specific cameras and tell you in writing what the proposed storage actually holds.
Sun to Thu 9am to 5pm · Fri 9am to 12pm · Sat closed