CCTV Privacy Law Mapper
Finding 4 of 18

Public area monitored with no assessment recorded

GDPR and UK GDPR Art. 35 ask for an assessment before systematic monitoring of a publicly accessible area on a large scale, and before processing likely to result in a high risk, which face matching usually is. Whether this is "large scale" is your call, so the line is a question.

When it is raised
Raised at EU, EEA and UK sites on a camera covering a public area (shop floor, entrance, car park, street, till, reception) whose assessment column is blank or no, and on any face matching camera with no assessment recorded.
The question
Is this monitoring of a publicly accessible area on a large scale, and if so, where is the assessment?
For
your privacy lead
The column that settles it
assessment done
On the row
a numbered delta and the words "no assessment" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 35Data protection impact assessment

Data protection impact assessment. Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What a reviewer asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
Where camera lists usually fall short: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 35Data protection impact assessment

Article 35 Data protection impact assessment. Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.

What a reviewer asks to see: DPIA screening records for new processing; Completed DPIAs with the four required elements and DPO advice; Review records when processing changes
Where camera lists usually fall short: DPIA done after launch; Screening not documented; Commissioner's list of high-risk processing ignored
Source: UK GDPR, read 29 Sep 2026

See the specimen list run Map your own list