Protecting Client Footage: A Practical Security Checklist for Video Editors

A practical security checklist for freelance editors and small teams handling client footage: storage, encryption, sharing, AI tools, deletion and UK GDPR.

File Sharing & PrivacyBy AI Point EditorialUpdated 24 September 20268 min read

Protecting client footage comes down to a handful of habits: agree in writing how files will be handled, keep them on encrypted drives and accounts protected by two-factor authentication, share them with private, expiring links rather than public ones, and delete them when the job and any agreed retention period end. If the footage shows identifiable people, it is also personal data under UK GDPR, which adds legal duties on top of good practice.

This guide is a working checklist for freelancers and small teams. It covers the whole life of a project, from receiving rushes to deleting them.

Not legal advice. This is general guidance for creators. If you handle sensitive footage or are unsure of your obligations, check with the client, a qualified adviser or the Information Commissioner's Office (ICO).

Why raw footage needs more care than finished videos

A finished video has been reviewed and approved. Raw footage has not. It can contain unguarded comments, people who did not consent to appear, whiteboards with confidential plans, screens showing customer data, car number plates, children, or the inside of someone's home. Phone footage often also carries GPS location in its metadata.

Losing a finished video is embarrassing. Leaking the rushes can break a contract, damage your client's relationships and, where people are identifiable, become a data breach.

Before the job: agree the rules

Settle these points in writing before any footage arrives. An email confirmation is better than nothing; a short contract or data processing agreement is better still.

  • Who owns the footage and what you are allowed to do with it (for example, whether you may show excerpts in your portfolio).
  • How it will be delivered to you and how you will return it.
  • Which tools you will use, especially any cloud or AI services the footage will pass through.
  • How long you will keep it after delivery, and how you will delete it.
  • Who else will see it, such as a subcontracted colourist, captioner or voiceover artist.
  • What happens if something goes wrong, and how quickly you will tell the client.

Storage: encrypt everything that leaves the building

Laptops and portable drives get lost and stolen. Full-disk encryption means a lost device is an inconvenience, not a leak.

Where the footage lives What to do
Windows laptop or desktop Turn on BitLocker (Windows Pro) or Device Encryption where available; store the recovery key somewhere safe, away from the device
Mac Turn on FileVault
External SSD or hard drive Use BitLocker To Go (Windows) or an encrypted APFS volume (macOS), or a drive with hardware encryption
Phone used on shoots Use a strong passcode; modern iPhones and Android phones encrypt storage when a lock screen is set
Cloud storage Use a business account with two-factor authentication, not a shared personal login

Test that you can unlock an encrypted drive on the machines you actually use before a shoot, not on the day.

Backups are part of security

Security includes not losing the footage. A common rule of thumb is 3-2-1: three copies, on two different types of storage, with one kept off-site. Each copy needs the same protection as the original; an unencrypted backup drive in a bag undoes all the work above.

Accounts and access

  • Two-factor authentication on email, cloud storage, editing platforms and anything that can reset them. An authenticator app or security key is stronger than SMS.
  • A password manager with a unique password for every service.
  • One account per person. Shared logins make it impossible to remove one person's access or know who did what.
  • Least access. A captioner needs a low-resolution export, not the full rushes.
  • Remove access when the job ends, including for freelancers you brought in.

Sharing files safely

Most leaks happen at the sharing stage, not through hacking.

  1. Use private links restricted to named people where your service allows it, rather than "anyone with the link".
  2. Set an expiry date on links and a password if the service supports it.
  3. Send the password by a different channel from the link, for example the link by email and the password by phone or message.
  4. Share the smallest thing that does the job: a watermarked, lower-resolution review copy for approval, not the master.
  5. Avoid unlisted YouTube videos for confidential drafts. Unlisted means anyone with the link can watch it, and links get forwarded.

For moving files between your own devices, direct transfer is often safer than putting rushes on another cloud service. See sending large files from phone to PC and how browser file transfer works for what each method exposes.

AI and cloud tools: read before you upload

Transcription, captioning, upscaling and AI editing tools are useful, but every upload is another place the client's footage lives. Before using one on client material, check:

  • Where the service stores the data and for how long.
  • Whether uploads may be used to train or improve its models, and whether you can opt out.
  • Whether the client has agreed to that tool being used.

Running tools locally avoids most of these questions. For transcription, open-source models such as Whisper can run entirely on your own computer; we compare the trade-offs in local vs cloud transcription.

Strip metadata from files you share

Phone and camera files can include GPS coordinates, device names and creation dates. Before sending clips to anyone beyond the client, check and strip container metadata. You can inspect it with FFmpeg's ffprobe:

ffprobe -v error -show_entries format_tags -of default=nw=1 input.mov

And remove global metadata without re-encoding:

ffmpeg -i input.mov -map_metadata -1 -c copy output.mov

Run ffprobe again afterwards to confirm, as some metadata can be stored per stream. There are more useful commands in FFmpeg commands for creators.

Footage of identifiable people and UK GDPR

If footage shows or records people who can be identified, by face, voice, name or context, it is personal data under UK GDPR and the Data Protection Act 2018. That covers most interviews, events and workplace filming.

In a typical client job, the client decides why and how the footage is used, making them the controller, whilst you as the editor act on their instructions as a processor. In broad terms, UK GDPR expects:

  • A written contract between controller and processor setting out what the processor may do with the data.
  • Appropriate security measures, such as the encryption and access controls above.
  • A processor to tell the controller without undue delay about a personal data breach. The controller then decides whether to report it to the ICO; where reporting is required, it must normally be done within 72 hours of becoming aware of it.
  • No extra use of the data beyond what the client instructed, such as putting it in your showreel without permission.

Take extra care with footage revealing health, ethnicity, religion, sexual orientation or other special category data, and with footage of children. If you run your own productions, you are likely to be the controller yourself, and you may need to pay the ICO's data protection fee unless an exemption applies. The ICO's guidance for small organisations at >ico.org.uk explains these roles and the fee.

After the job: deletion and retention

  1. Confirm with the client that the final delivery is accepted.
  2. Return or hand over the masters and project files if agreed.
  3. Delete working copies, cache and proxy folders, exports and review links after the agreed retention period.
  4. Remember backups, cloud trash folders and old shared links.
  5. Tell the client in writing that deletion is complete.

A consistent project folder structure makes this far easier, because every file for a job lives in one predictable place.

Quick checklist

  • Written agreement on use, tools, retention and deletion.
  • Full-disk encryption on every laptop and external drive.
  • Two-factor authentication and unique passwords on every account.
  • Private, expiring, password-protected share links; no public or unlisted drafts.
  • Only approved AI and cloud tools; local processing where possible.
  • Metadata stripped from shared clips.
  • UK GDPR roles understood if people are identifiable.
  • Verified deletion, including backups and trash, at the end.

FAQ

Do I need permission to use client footage in my showreel?

Yes, get it in writing. Unless your agreement says otherwise, the footage belongs to the client, and it may include people who agreed to appear only in the client's video.

Is unlisted YouTube private enough for client drafts?

Not for confidential material. Anyone who has the link can watch an unlisted video. Use a restricted, expiring share link instead.

Am I responsible under UK GDPR if I only edit the video?

Usually as a processor, yes. You must follow the client's instructions, keep the data secure and tell them promptly about any breach. Check the ICO's guidance for your situation.

What should I do if I lose a drive with client footage?

Tell the client straight away, explain whether the drive was encrypted and what it contained, and follow any agreed incident process. If people in the footage are identifiable, the client may need to assess whether it is a reportable breach.

Software, platform rules and settings change. We review our guides regularly, but always check the official documentation for the tools you use. Found an error? Email soubickdas@gmail.com. See our editorial policy.
A

AI Point Editorial

We build caption, transcription and video-workflow tools and write about what we learn doing it — practical, tested and free of hype.