CCTV Privacy Law Mapper
Finding 6 of 18

No signage or notice recorded

The notice at the point of capture is what a sign starts: GDPR and UK GDPR Art. 13, APP 5 and APP 1, CCPA notice at or before collection, and for face matching in Illinois the written notice of BIPA 15(b)(1). No held text prescribes the wording of a sign.

When it is raised
Raised on a camera whose signage column is blank or no.
The question
What notice do people get before they enter this camera's view, and what does it say?
For
your privacy lead
The column that settles it
signage
On the row
a numbered delta and the words "no signage" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 13Information to be provided where personal data are collected

Information to be provided where personal data are collected. Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What a reviewer asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
Where camera lists usually fall short: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 13Information to be provided where personal data are collected from the data subject

Article 13 Information to be provided where personal data are collected from the data subject. At the time of collection the controller must give its identity and contact details (and any representative's), the data protection officer's contact details, the purposes and lawful basis, the legitimate interests where Article 6(1)(f) is relied on, the recipients, and any intended transfer abroad with whether transfer regulations under Article 45A cover it or which safeguards are relied on and how to get a copy. It must also give the retention period or criteria, the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent, the right to complain to the controller and to the Commissioner, whether provision of the data is required and the consequences of not providing it, and the existence of automated decision-making subject to Article 22C safeguards with meaningful information about the logic and consequences. Before further processing for a new purpose the data subject must be told of it, unless the further processing is for research, archiving or statistics under Article 84B and telling them is impossible or disproportionate, in which case the controller must protect their interests, including by publishing the information.

What a reviewer asks to see: Privacy notices at each collection point with every Article 13 item; Version history of notices; Assessment and public statement where the Article 13(5) research exception is used
Where camera lists usually fall short: Notice missing the right to complain to the controller; Transfer information still citing adequacy decisions instead of transfer regulations; No notice update before a new purpose starts
Source: UK GDPR, read 29 Sep 2026

Australian Privacy Principles (APPs)

APP APP 5Notification of the collection of personal information

APP 5 - Notification of the collection of personal information. Notify individuals of the collection of their personal information and the matters set out in APP 5.

What a reviewer asks to see: Collection notices (APP 5 matters); Timing of notification
Where camera lists usually fall short: No collection notice; Notice missing APP 5 matters
Source: Australian Privacy Principles (APPs), read 29 Sep 2026
APP APP 1Open and transparent management of personal information

APP 1 - Open and transparent management of personal information. Manage personal information in an open and transparent way, including having a clearly expressed and up-to-date APP privacy policy.

What a reviewer asks to see: Published APP privacy policy; Evidence of open data-handling practices; Policy review records
Where camera lists usually fall short: No APP privacy policy; Policy out of date; Practices not transparent
Source: Australian Privacy Principles (APPs), read 29 Sep 2026

California Consumer Privacy Act (CCPA, as amended by the CPRA)

CCPA s. 1798.100General duties of a business that collects personal information

General Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.

What a reviewer asks to see: Notice at collection text on web forms and physical points of collection; Privacy policy disclosures of categories and purposes; Data inventory mapping categories to purposes and retention periods; Information security program documentation; Retention schedule with criteria and disposal evidence
Where camera lists usually fall short: No notice at offline collection points; Purposes described vaguely (e.g. business operations); Retention periods absent or stated as indefinite; Security controls not mapped to PI categories
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026
CCPA s. 1798.130(a)(5)(C)Notice at Collection

Notice at Collection. At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.

What a reviewer asks to see: Notice text displayed on forms, mobile app onboarding, point-of-sale, telephone scripts; Offline notice via signage or printed handout; Retention disclosures per category; Sale/share disclosure
Where camera lists usually fall short: Notice exists only in main privacy policy; Offline collection (call centers, in-store) lacks notice; Retention disclosed only as 'as long as necessary'
Source: California Consumer Privacy Act (CCPA, as amended by the CPRA), read 29 Sep 2026

Illinois Biometric Information Privacy Act (BIPA)

BIPA s. 15(b)(1)Written notice that a biometric identifier or information is being collected or stored

Written notice that a biometric identifier or information is being collected or stored. Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.

What a reviewer asks to see: The written notice (enrolment screen, form, employee notice) stating that a biometric identifier or information is collected or stored, dated before first collection; Evidence of delivery to each subject or representative before enrolment
Where camera lists usually fall short: Biometric timeclocks or access systems rolled out with no written notice to employees; Notice buried in a privacy policy that says nothing about biometrics specifically; Notice given at the first scan rather than before it
Source: Illinois Biometric Information Privacy Act (BIPA), read 29 Sep 2026

Named, not quoted

See the specimen list run Map your own list