Phone: (202) 833-1460 Washington DC Farragut North Metro

Data Retention Policies for Public Safety Drone Programs in Australia

Small unmanned aircraft systems (UAS) are becoming practical tools for Australian police, fire and emergency services. A drone may capture video above a bushfire, map flood damage near Brisbane, locate a missing person outside Hobart, or support a search along the Perth coastline. Each flight can produce valuable evidence, operational records and personal information that require disciplined handling after the aircraft lands.

A sound retention policy explains what data is collected, why it is needed, where it is stored, who may access it and when it must be deleted. It should cover live-streamed footage, recorded video, photographs, telemetry, flight logs, still images, maintenance records and reports. The policy must support public safety while aligning with privacy obligations, evidence rules and community expectations.

Define The Data Before Setting Retention Periods

A UAS program should create a data inventory before choosing retention periods. Operational footage may include identifiable faces, vehicle registration plates, private homes, backyards and conversations captured incidentally. Metadata can reveal exact locations, timestamps, aircraft identifiers, pilot details and patterns of police activity.

Separate data into practical categories. Incident evidence, routine training footage, unsuccessful searches, mapping products and aircraft health records do not have the same value or legal status. A flight supporting a suspected offence may need to follow an evidence hold, while an uneventful training flight can usually be deleted under a shorter schedule.

Retention rules should also distinguish original files from working copies. Editing, stabilising or compressing footage can create a derivative file, but the original should remain protected when it may be used in court or reviewed during an investigation.

Link Retention To Purpose And Risk

The central rule should be purpose limitation: retain information for a defined operational, legal or administrative reason, and do not keep it indefinitely merely because storage is inexpensive. Footage collected to assess a bushfire perimeter should not quietly become a permanent surveillance archive.

A risk-based schedule can give agencies a defensible structure. For example, non-incident footage might be automatically deleted after 30 or 90 days, subject to a review hold. Footage linked to an incident can be retained for the period required by investigation, prosecution, coronial review, insurance or records legislation. Training and testing material should have a separate expiry date and should be de-identified where possible.

Australian agencies should check Commonwealth, state and territory requirements before adopting these periods. The Privacy Act 1988 and Australian Privacy Principles may apply to some organisations, while state privacy laws, public records obligations, freedom of information rules and evidence procedures can create additional duties.

Build In Legal And Evidentiary Holds

A legal hold suspends normal deletion when data may be relevant to a complaint, investigation, court proceeding, coronial matter, inquest, access request or internal review. The hold should identify the relevant files, responsible officer, reason for preservation and date of the next review.

Evidence handling must protect authenticity and continuity. Agencies should record when footage was downloaded, who accessed it, whether it was converted into another format and where the master copy is stored. Hash values, audit logs and read-only master files can help demonstrate that a recording has not been altered.

The policy should address requests from prosecutors, courts, oversight bodies and information-access applicants. In New South Wales, Queensland, Victoria and other jurisdictions, public records and information-access frameworks differ. A local legal and records-management review is essential before a UAS team changes an automated deletion rule.

Match Data Types To Retention Actions

A useful schedule makes decisions visible to pilots, dispatchers, investigators, records officers and information-technology staff. The following model is a starting point rather than a universal legal timetable.

Data category Typical use Suggested default action Additional control
Routine flight video with no incident Navigation, situational awareness Delete within 30–90 days Automatic review and deletion
Incident footage Response record or investigation Retain under the incident file schedule Apply legal hold when required
Evidence-quality original Court or prosecution material Preserve until authorised disposal Access log, integrity check and master copy
Search-and-rescue imagery Locate people or assess terrain Delete after operational need ends Restrict access to the response team
Training footage Pilot assessment and exercises Delete after training cycle or de-identify Avoid unnecessary personal information
Flight and maintenance logs Safety, compliance and audit Retain under aviation and records rules Protect pilot and location details
Mapping or analytical outputs Planning and recovery Retain according to project purpose Record source data and version history

The schedule should state who can approve an exception and how disposal is documented. Deletion may involve secure erasure, destruction of removable media or an approved cloud-retention control. Simply removing a file from a user interface may not remove copies from backups, caches or synchronised devices.

Control Cloud Storage And Australian Access

Many Australian public-safety organisations use commercial drone platforms, software-as-a-service applications or cloud storage hosted in Australia. A local data centre can support sovereignty and procurement requirements, but it does not automatically make a service compliant. Agencies still need to understand subcontractors, administrator access, overseas support, backups, encryption and breach-notification processes.

Contracts should specify ownership, permitted processing, retention settings, deletion certification, audit rights and the provider’s response to subpoenas or access requests. They should also prevent a vendor from using public-safety imagery for product development or artificial-intelligence training without express authority.

Access should follow role-based permissions and least privilege. A pilot may need to upload a flight, while an investigator may need the incident file and a records officer may need disposal reports. Multifactor authentication, encryption in transit and at rest, device controls and regular access reviews reduce the consequences of a lost tablet or compromised account.

Respect Privacy In Australian Communities

Australian communities expect emergency agencies to use drones proportionately, particularly in suburban areas where aircraft can overlook homes, schools, sporting grounds and apartment balconies. A flight over a flooded street in Cairns may be plainly justified, while repeated recording of private gardens without a clear operational purpose can damage trust.

Privacy impact assessments should examine collection, retention, disclosure and disposal together. Agencies should consider whether the aircraft can use a narrower field of view, avoid unnecessary recording, blur faces or plates, and stop collecting once the task is complete. The Office of the Australian Information Commissioner’s privacy guidance can assist agencies covered by the federal privacy framework, while state and territory rules may apply to police and emergency services.

Transparency also matters. Public-facing policies can explain the types of missions supported, broad retention categories, complaint pathways and oversight arrangements without revealing sensitive tactics. Community engagement through local councils, multicultural groups and neighbourhood forums is particularly valuable when drone operations become routine rather than exceptional.

Make Deletion Auditable And Operational

A retention policy works only when it is built into the UAS workflow. The flight application should capture the mission purpose and incident number at upload. The records system should apply a retention category, trigger a legal hold when instructed and produce an audit trail when a file is viewed, exported or deleted.

Supervisors should review exceptions, failed deletions and overdue holds at set intervals. Periodic audits can compare aircraft logs with stored media, identify orphaned files and confirm that contractors follow the same rules. Staff training should cover privacy, evidence integrity, secure transfer and the consequences of unauthorised copying.

Before deployment, agencies can test the policy using realistic Australian scenarios: a Melbourne search in a dense neighbourhood, a regional Queensland flood, a Western Australian bushfire and a training flight at an approved CASA operating location. Those exercises reveal whether retention decisions are clear under pressure and whether technology supports the policy rather than undermining it.

Turn The Policy Into Everyday Practice

A public-safety UAS program should publish an approved retention schedule, assign ownership to a records or information-governance lead and configure deletion controls before routine missions begin. Review the schedule with legal counsel, privacy officers, prosecutors, information-technology teams and frontline operators so operational needs are balanced with accountability.

Use each flight’s purpose to determine its data pathway, preserve material that becomes evidence, delete what no longer has a lawful purpose and document every exception. A clear, auditable approach helps Australian agencies gain the benefits of drone technology while protecting privacy, evidentiary value and public confidence.