CCTV Privacy Law Mapper
Finding 1 of 18

Face matching or face recognition: biometric identification

The camera compares faces with a stored list to identify people. Every regime held here treats that as the most sensitive thing a camera does: GDPR and UK GDPR as special category data needing an Art. 9 condition as well as an Art. 6 basis and, in most cases, an assessment first; BIPA as a biometric identifier needing written notice, the purpose and term in writing and a written release before collection; the APPs as sensitive information; the CCPA as sensitive personal information.

When it is raised
Raised on every camera whose analytics read as face matching or face recognition, where a regime or a named law is placed at the site. Face detection or blurring never raises it.
The question
Which condition or written release covers each person this camera matches, and where is it recorded?
For
your lawyer
The column that settles it
written release
On the row
a numbered delta and the words "face matching" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 9Processing of special categories of personal data

Processing of special categories of personal data. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where camera lists usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 35Data protection impact assessment

Data protection impact assessment. Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What a reviewer asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
Where camera lists usually fall short: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 9Processing of special categories of personal data

Article 9 Processing of special categories of personal data. Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.

What a reviewer asks to see: Article 9 condition and, where required, the Schedule 1 condition of the 2018 Act recorded per processing; Appropriate policy document where Schedule 1 requires one; Explicit consent records where that is the condition
Where camera lists usually fall short: Biometric processing for identification without an Article 9 condition; Relying on substantial public interest without the Schedule 1 condition and policy document; Health data processed outside the professional-secrecy safeguard
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 35Data protection impact assessment

Article 35 Data protection impact assessment. Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.

What a reviewer asks to see: DPIA screening records for new processing; Completed DPIAs with the four required elements and DPO advice; Review records when processing changes
Where camera lists usually fall short: DPIA done after launch; Screening not documented; Commissioner's list of high-risk processing ignored
Source: UK GDPR, read 29 Sep 2026

Illinois Biometric Information Privacy Act (BIPA)

BIPA s. 15(a)Written, public retention schedule and destruction guidelines, applied

Written, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.

What a reviewer asks to see: The published retention and destruction policy (web page or posted notice) with its retention schedule and the destruction trigger of purpose satisfied or three years since last interaction; Destruction records showing the schedule is followed, including for departed employees and closed customer accounts; Any warrant or subpoena relied on to retain data past the schedule
Where camera lists usually fall short: A retention policy that exists internally but was never made available to the public; No destruction of employee templates after termination, so three-year clocks run out unnoticed; A vendor holding the templates with no policy published by the entity that uses them
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(b)(1)Written notice that a biometric identifier or information is being collected or stored

Written notice that a biometric identifier or information is being collected or stored. Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.

What a reviewer asks to see: The written notice (enrolment screen, form, employee notice) stating that a biometric identifier or information is collected or stored, dated before first collection; Evidence of delivery to each subject or representative before enrolment
Where camera lists usually fall short: Biometric timeclocks or access systems rolled out with no written notice to employees; Notice buried in a privacy policy that says nothing about biometrics specifically; Notice given at the first scan rather than before it
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and use

Written notice of the specific purpose and length of term of collection, storage and use. Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).

What a reviewer asks to see: The written notice naming the specific purpose and the length of term of collection, storage and use; Consistency between the stated term and the published retention schedule
Where camera lists usually fall short: A purpose stated as generally as security or business operations; No length of term stated at all; A stated term that contradicts the published retention policy
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026
BIPA s. 15(b)(3)Written release executed by the subject or representative before collection

Written release executed by the subject or representative before collection. Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.

What a reviewer asks to see: Executed written releases or electronic signature records for every enrolled subject, retained for the life of the data and the limitations period; Employment releases executed as a condition of employment where that basis is used; Parent or guardian releases for minors
Where camera lists usually fall short: Enrolment with no release at all, the most litigated BIPA violation; A release obtained from a vendor's terms rather than executed by the subject; Electronic consent with no record of who signed, when and with what intent
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026

Australian Privacy Principles (APPs)

APP APP 3Collection of solicited personal information

APP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.

What a reviewer asks to see: Justification of necessity for collection; Lawful and fair collection methods; Heightened protection for sensitive information
Where camera lists usually fall short: Over-collection; Unlawful/unfair collection; Sensitive info collected without consent
Source: Australian Privacy Principles (APPs), read 29 Sep 2026

California Consumer Privacy Act (CCPA, as amended by the CPRA)

CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information

Right to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.

What a reviewer asks to see: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation; Use restriction enforcement controls
Where camera lists usually fall short: No separate sensitive PI inventory; Limit mechanism not offered when uses go beyond permitted purposes; Permitted purpose claimed without documentation
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

Named, not quoted

See the specimen list run Map your own list