CCTV Privacy Law Mapper
Analytics

Is face matching on CCTV biometric data under GDPR and BIPA?

Compares faces in the picture with a stored list of faces (a watchlist, staff, known people) to identify who they are. That is biometric data processed to identify a person: special category data under GDPR and UK GDPR, a biometric identifier under BIPA, and the use the EU AI Act looks at hardest.

Biometric identification
yes: it compares faces to identify people
May infer emotion
no
May infer a sensitive characteristic
no
May be an AI system
yes
Read from words such as
face recognition

Yes, where it compares faces with stored ones to identify people. GDPR and UK GDPR Art. 9 list biometric data processed to identify a person as special category data, which needs an Art. 9 condition as well as an Art. 6 basis. BIPA treats the face template as a biometric identifier and asks for written notice, the purpose and term in writing and a written release before collection. Face detection or blurring, which does not compare faces, is not identification.

Findings it can raise, with the list

Clauses this analytics type adds

12 clauses
GDPR Art. 9Processing of special categories of personal data

Processing of special categories of personal data. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where camera lists usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
UK GDPR Art. 9Processing of special categories of personal data

Article 9 Processing of special categories of personal data. Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.

What a reviewer asks to see: Article 9 condition and, where required, the Schedule 1 condition of the 2018 Act recorded per processing; Appropriate policy document where Schedule 1 requires one; Explicit consent records where that is the condition
Where camera lists usually fall short: Biometric processing for identification without an Article 9 condition; Relying on substantial public interest without the Schedule 1 condition and policy document; Health data processed outside the professional-secrecy safeguard
Source: UK GDPR, read 29 Sep 2026
BIPA s. 15(a)Written, public retention schedule and destruction guidelines, applied

Written, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.

What a reviewer asks to see: The published retention and destruction policy (web page or posted notice) with its retention schedule and the destruction trigger of purpose satisfied or three years since last interaction; Destruction records showing the schedule is followed, including for departed employees and closed customer accounts; Any warrant or subpoena relied on to retain data past the schedule
Where camera lists usually fall short: A retention policy that exists internally but was never made available to the public; No destruction of employee templates after termination, so three-year clocks run out unnoticed; A vendor holding the templates with no policy published by the entity that uses them
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(b)(1)Written notice that a biometric identifier or information is being collected or stored

Written notice that a biometric identifier or information is being collected or stored. Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.

What a reviewer asks to see: The written notice (enrolment screen, form, employee notice) stating that a biometric identifier or information is collected or stored, dated before first collection; Evidence of delivery to each subject or representative before enrolment
Where camera lists usually fall short: Biometric timeclocks or access systems rolled out with no written notice to employees; Notice buried in a privacy policy that says nothing about biometrics specifically; Notice given at the first scan rather than before it
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and use

Written notice of the specific purpose and length of term of collection, storage and use. Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).

What a reviewer asks to see: The written notice naming the specific purpose and the length of term of collection, storage and use; Consistency between the stated term and the published retention schedule
Where camera lists usually fall short: A purpose stated as generally as security or business operations; No length of term stated at all; A stated term that contradicts the published retention policy
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(b)(3)Written release executed by the subject or representative before collection

Written release executed by the subject or representative before collection. Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.

What a reviewer asks to see: Executed written releases or electronic signature records for every enrolled subject, retained for the life of the data and the limitations period; Employment releases executed as a condition of employment where that basis is used; Parent or guardian releases for minors
Where camera lists usually fall short: Enrolment with no release at all, the most litigated BIPA violation; A release obtained from a vendor's terms rather than executed by the subject; Electronic consent with no record of who signed, when and with what intent
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(c)No sale, lease, trade or other profit from biometric identifiers or information

No sale, lease, trade or other profit from biometric identifiers or information. No private entity in possession of a biometric identifier or biometric information may sell, lease, trade or otherwise profit from a person's or a customer's biometric identifier or biometric information. The prohibition is absolute; consent does not authorise it. Courts have distinguished profiting from the data itself, which is banned, from charging for a product or service that uses biometrics, which is not.

What a reviewer asks to see: Data-use and vendor contract terms showing biometric data is never sold, licensed, leased or monetised; Revenue and data-sharing reviews confirming no consideration is received for biometric data
Where camera lists usually fall short: Licensing enrolled templates or face-geometry data sets to a third party; A vendor contract that lets the processor use templates to train or sell its own products
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(e)(1)Reasonable standard of care within the entity's industry

Reasonable standard of care within the entity's industry. A private entity in possession of biometric identifiers or biometric information shall store, transmit and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity's industry. The measure is what a reasonable entity in the same industry does for such data, which makes industry security standards and practice the yardstick.

What a reviewer asks to see: Documented security measures for biometric data (encryption in storage and transit, access control, template protection) benchmarked against the entity's industry practice; Risk assessment naming biometric data as a distinct asset
Where camera lists usually fall short: Biometric templates stored or transmitted with weaker protection than the industry uses for comparable data; No assessment of what the industry standard of care is
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
APP APP 3Collection of solicited personal information

APP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.

What a reviewer asks to see: Justification of necessity for collection; Lawful and fair collection methods; Heightened protection for sensitive information
Where camera lists usually fall short: Over-collection; Unlawful/unfair collection; Sensitive info collected without consent
Source: Australian Privacy Principles (APPs), read 29 Sep 2026
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information

Right to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.

What a reviewer asks to see: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation; Use restriction enforcement controls
Where camera lists usually fall short: No separate sensitive PI inventory; Limit mechanism not offered when uses go beyond permitted purposes; Permitted purpose claimed without documentation
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
EU AI Act Art. 4AI literacy

AI literacy. Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.

What a reviewer asks to see: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort; Evidence the literacy measures were revisited when a new AI system or a materially different use case was introduced; Material addressing the groups the system is used on, where that shapes the risks staff must be able to recognise
Where camera lists usually fall short: One generic awareness module issued to everyone regardless of role or technical starting point; Training that covers the internal AI policy but not the capabilities and limits of the systems actually in use; Contractors and outsourced operators excluded even though they operate the system on the organisation's behalf; No refresh when the system or its use case changes, so literacy reflects a version no longer running
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 6Classification rules for high-risk AI systems

Classification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.

What a reviewer asks to see: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation; A trigger that re-runs classification when Annex III is amended or the intended purpose changes; Registration of the not-high-risk conclusion in the EU database as required by Art.49(2)
Where camera lists usually fall short: Classification decided once at design time and never revisited when the intended purpose broadened; The Art.6(3) derogation relied on without the documented assessment that is the condition of using it; A profiling system routed through the derogation, which the Regulation forecloses; Only Annex III considered, so a safety component falling under Annex I legislation is missed
Source: EU AI Act, read 29 Sep 2026

See the specimen list run Map your own list