CCTV Privacy Law Mapper
Analytics

Is CCTV age and gender estimation biometric categorisation under the EU AI Act?

Estimates characteristics of the people in the picture, most often an age band and a gender. Estimating age alone is not one of the special categories GDPR Art. 9 lists; a feature that infers a special category is a different matter, and the question is which characteristics it estimates.

Biometric identification
no
May infer emotion
no
May infer a sensitive characteristic
it may, depending on which characteristics it estimates
May be an AI system
yes
Read from words such as
age and gender estimation

Art. 5 of the EU AI Act lists biometric categorisation inferring sensitive attributes. Estimating age alone is not one of the categories GDPR Art. 9 lists; the question is which characteristics the feature estimates.

Findings it can raise, with the list

Clauses this analytics type adds

4 clauses
EU AI Act Art. 4AI literacy

AI literacy. Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.

What a reviewer asks to see: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort; Evidence the literacy measures were revisited when a new AI system or a materially different use case was introduced; Material addressing the groups the system is used on, where that shapes the risks staff must be able to recognise
Where camera lists usually fall short: One generic awareness module issued to everyone regardless of role or technical starting point; Training that covers the internal AI policy but not the capabilities and limits of the systems actually in use; Contractors and outsourced operators excluded even though they operate the system on the organisation's behalf; No refresh when the system or its use case changes, so literacy reflects a version no longer running
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 5The practices listed in Article 5

Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education, biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).

What a reviewer asks to see: Pre-deployment screening against the Art.5 prohibition list; Documented assessment that the system does not fall under a prohibited category
Where camera lists usually fall short: Deploying an Art.5-prohibited practice; Treating exceptions as routine basis
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systems

Transparency obligations for providers and deployers of certain AI systems. Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interacting with AI, label synthetic content in a machine-readable format, and disclose deepfakes and AI-generated public-interest text (subject to free-expression and artistic exceptions).

What a reviewer asks to see: User-facing AI-interaction notification; Machine-readable labelling of synthetic content; Deepfake/AI-text disclosure
Where camera lists usually fall short: No disclosure that the user is interacting with AI; Synthetic content not machine-readably labelled
Source: EU AI Act, read 29 Sep 2026
GDPR Art. 9Processing of special categories of personal data

Processing of special categories of personal data. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where camera lists usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

See the specimen list run Map your own list