GDPR video privacy best practices: a practical workflow

Video surveillance can be an essential security tool, but every camera introduces a data protection responsibility. CCTV, body-worn cameras, dashcams, drones, and other recording technologies can capture identifiable people, vehicle registrations, and other information that falls within the scope of data protection law. For organizations operating under the GDPR, protecting that information requires more than simply securing the camera system itself.

A practical privacy workflow should cover the entire lifecycle of video data, from deciding whether recording is necessary through to storage, review, redaction, disclosure, and deletion. The European Data Protection Board has specifically addressed the processing of personal data through video devices, while UK guidance also emphasizes lawfulness, transparency, data minimization, retention, security, and accountability when surveillance systems are used.

The good news is that GDPR compliance does not have to make video surveillance unmanageable. With clearly defined processes and the right combination of technical and organizational safeguards, teams can continue using valuable footage while significantly reducing unnecessary privacy exposure.


Start with a clear purpose

The first question should not be "How can we secure all this footage?" It should be "Why are we recording it?"

GDPR principles require organizations to have a defined purpose for processing personal data and avoid collecting information that is excessive or unnecessary for that purpose. Video surveillance should therefore have a documented objective, whether that involves protecting property, supporting workplace safety, preventing crime, or investigating specific incidents.

A clearly defined purpose also makes later decisions easier. If a recording is subsequently requested for a different reason, the organization can assess whether that new use is compatible with the original purpose rather than automatically assuming that existing footage can be reused.


Establish the lawful basis before recording

Video surveillance involving identifiable individuals requires a lawful basis under the GDPR. Consent is not automatically the appropriate choice simply because people appear on camera; in many surveillance environments, obtaining meaningful consent from every individual would be impractical or inappropriate.

Organizations should identify and document the relevant lawful basis before deploying the system and ensure the reasoning behind it remains appropriate as circumstances change. The ICO's surveillance guidance emphasizes that organizations need to identify and document a lawful basis for surveillance processing and consider necessity and proportionality alongside technical capability.

For more intrusive systems, a Data Protection Impact Assessment may also be necessary. This is particularly important where surveillance is likely to create a high risk to individuals' rights and freedoms.


Make people aware of surveillance

Privacy compliance is not simply about what happens to footage after it has been recorded. People should generally be able to understand when surveillance is taking place and why.

Clear signage is one practical component of transparency. Notices should be visible before people enter a monitored area and should provide enough information for individuals to understand that recording is occurring and where they can find additional details.

The exact information and communication method will depend on the circumstances, but transparency should be treated as an ongoing responsibility rather than a one-time notice placed beside a camera.


Minimize what the cameras capture

The strongest privacy workflow begins before footage reaches the storage system.

Camera positioning should be carefully considered to ensure the system captures what is genuinely needed without unnecessarily monitoring areas where people would reasonably expect greater privacy. A camera intended to protect an entrance, for example, should not automatically provide a detailed view into an adjacent private area simply because the equipment is capable of doing so.

The same principle applies to technical features. High-resolution cameras, audio recording, facial recognition, and other capabilities can make surveillance substantially more intrusive. Organizations should evaluate whether each feature is necessary and proportionate to the intended purpose rather than enabling every available function by default.


Treat audio differently

Audio is easy to overlook when designing a video privacy program, yet continuous audio recording can be significantly more intrusive than visual surveillance.

The ICO advises that organizations should not normally record conversations between members of the public through surveillance systems and recommends disabling audio capabilities unless there is a specific, evidenced need that cannot reasonably be addressed through a less intrusive method.

This makes audio a useful example of why privacy-by-design matters. A system should not collect information merely because its hardware allows it to.


Define retention periods

Keeping footage indefinitely creates unnecessary risk.

Organizations should establish retention periods based on the purpose for which recordings were collected and delete or securely dispose of footage when it is no longer required. Different categories of footage may warrant different retention periods, particularly where an incident has resulted in a formal investigation or legal requirement to preserve evidence.

Retention policies should also account for exceptional circumstances. Relevant footage may need to be preserved beyond a normal deletion schedule if it becomes part of an investigation, complaint, litigation, or other legitimate process.


Restrict access to original footage

Not everyone who needs information from a recording needs access to the original file.

Role-based permissions can help ensure that sensitive footage is available only to people with a legitimate reason to view it. Organizations should consider access at each stage of the workflow, including live monitoring, investigation, export, disclosure, and long-term storage.

Maintaining a clear distinction between unrestricted original evidence and versions prepared for wider sharing is particularly useful. It allows organizations to preserve the integrity of source material while limiting unnecessary exposure.


Redact before sharing

This is where video privacy workflows often become operationally challenging.

A recording requested for an investigation, legal matter, insurance claim, or information disclosure may contain numerous people who have nothing to do with the underlying incident. Simply sending the original file can expose their faces, license plates, identification documents, computer screens, or other personal information unnecessarily.

Redaction creates a controlled version of the footage that can be shared for its intended purpose without revealing everything captured by the camera.

Our team at Pimloc developed Secure Redact to make this stage considerably more scalable. Our AI-powered technology can detect and anonymize privacy-sensitive information across video and other media, while automated tracking helps maintain those protections as people and objects move through a recording. This reduces the need for teams to manually follow individuals frame by frame.

Learn more about Secure Redact and what it can do for you.


Make redaction proportionate

Effective redaction is not about hiding everything.

Over-redacting footage can make it difficult to understand what happened, potentially reducing the usefulness of evidence. Under-redacting can expose personal information unnecessarily. The goal is to remove information that is irrelevant to the intended recipient while preserving the context required for the legitimate purpose.

A privacy workflow should therefore define what needs to be protected before processing begins. The answer may differ depending on whether footage is being provided to law enforcement, an insurer, a legal team, a customer, or the general public.


Keep an audit trail

Accountability is a central element of data protection.

Organizations should be able to demonstrate what information they process, why they process it, who has access to it, and how privacy risks are managed. For surveillance systems, the ICO specifically highlights the importance of maintaining records covering matters such as purposes, data-sharing arrangements, and retention periods.

Auditability should extend to the redaction process itself. Teams should be able to establish what version was created, who reviewed it, and what actions were taken before the footage was released.

Secure Redact supports this part of the workflow with detailed audit trails that record activity throughout the anonymization process. That provides organizations with a clearer record of how sensitive media moved from original evidence to an approved version for disclosure, helping privacy teams demonstrate accountability rather than relying on informal records or spreadsheets.


Secure the entire video lifecycle

Privacy protection cannot stop once footage has been redacted.

Original files, working copies, exported versions, thumbnails, metadata, and temporary files can all create potential exposure points. Organizations should therefore consider encryption, authentication, access permissions, secure transfer methods, backup controls, and deletion procedures across the entire lifecycle.

Third-party processors also need careful consideration. Contracts, responsibilities, security measures, and data-sharing arrangements should be documented appropriately so that outsourcing part of the video workflow does not create an unrecognized privacy gap.


Review the workflow regularly

A surveillance system that was appropriate when installed may not remain appropriate indefinitely.

Cameras may be repositioned, new analytics capabilities may be introduced, retention requirements may change, and organizations may begin using footage for purposes that were not originally anticipated. Regular reviews help ensure that the original privacy assessment still reflects reality.

Organizations should also revisit incidents where something went wrong. A missed redaction, inappropriate disclosure, excessive retention period, or unauthorized access attempt can reveal weaknesses that should be addressed before they recur.


Turning privacy into an everyday process

GDPR video compliance is strongest when privacy becomes part of normal operations rather than an emergency task triggered whenever somebody requests footage. A well-designed workflow gives teams clear answers to the most important questions: what should be recorded, who should see it, how long should it remain available, and what needs to be removed before sharing.

For organizations handling large volumes of footage, automation can make this approach considerably more practical. Secure Redact can be incorporated into established workflows through API integration and scalable processing capabilities, allowing privacy protection to become part of a wider video management environment instead of forcing staff to rely on disconnected manual editing tools.

Ultimately, good video privacy is about more than satisfying a regulation. It is about demonstrating that surveillance is necessary, proportionate, transparent, secure, and respectful of the people captured by it. When those principles are built into every stage of the video lifecycle, organizations can use surveillance technology confidently while reducing the privacy risks that come with it.


Frequently asked questions

Previous
Previous

How to process body camera evidence securely from upload to disclosure

Next
Next

How to combine behavioural analytics with redaction in surveillance video