Public area monitored with no assessment recorded
GDPR and UK GDPR Art. 35 ask for an assessment before systematic monitoring of a publicly accessible area on a large scale, and before processing likely to result in a high risk, which face matching usually is. Whether this is "large scale" is your call, so the line is a question.
- When it is raised
- Raised at EU, EEA and UK sites on a camera covering a public area (shop floor, entrance, car park, street, till, reception) whose assessment column is blank or no, and on any face matching camera with no assessment recorded.
- The question
- Is this monitoring of a publicly accessible area on a large scale, and if so, where is the assessment?
- For
- your privacy lead
- The column that settles it
- assessment done
- On the row
- a numbered delta and the words "no assessment" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
GDPR (the EU General Data Protection Regulation)
GDPR Art. 35Data protection impact assessmentData protection impact assessment. Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.
UK GDPR
UK GDPR Art. 35Data protection impact assessmentArticle 35 Data protection impact assessment. Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.