The short answer
When cameras watch a public area on a large scale, a data protection impact assessment is a legal requirement before processing starts: Article 35(3)(c) GDPR treats systematic large-scale monitoring of a publicly accessible area as an automatic trigger, and analytics or biometrics only raise the bar. This guide lays out the assessment structure — scope, purposes, lawful basis, necessity and proportionality, likelihood-and-severity risk analysis, mitigations, residual risk and prior consultation — so you can document defensible decisions.
Key takeaways
- Systematic large-scale monitoring of a publicly accessible area is an automatic DPIA trigger under Article 35(3)(c) GDPR; adding analytics or facial recognition strengthens the case.
- Consent is rarely workable in public spaces; controllers typically rely on legitimate interests or, for public authorities, public task, documented through a legitimate interests assessment that feeds the DPIA.
- A defensible DPIA separates design-inherent risks from operational risks and scores each for likelihood and severity both before and after mitigation.
- If residual risk stays high, Article 36 GDPR requires prior consultation with the supervisory authority; budget for a consultation that can take up to eight weeks.
- The EDPB's 2026 common DPIA template and the WP29/EDPB nine high-risk criteria provide a regulator-endorsed structure even while that template is under consultation.
- Document a reasoned decision not to do a DPIA where no trigger clearly applies; an undocumented assumption is hard to defend in an audit.
When CCTV analytics makes the DPIA mandatory
Article 35(1) GDPR requires a controller to carry out a DPIA before processing when a type of processing, particularly using new technologies, is likely to result in a high risk to people's rights and freedoms. This is a screening test, not proof of actual harm: you are looking for features that point to possible high risk. For cameras in public places those features are usually present by default.
The direct trigger sits in Article 35(3)(c): systematic monitoring of a publicly accessible area on a large scale. Around it sit the nine WP29/EDPB criteria — systematic monitoring, data concerning vulnerable people, innovative technological solutions, large-scale collection, and others. Municipal camera networks, stations, stadiums and large retail galleries usually meet two or more criteria at once, which under the common guidance indicates a DPIA.
Analytics changes the picture. If the system does more than record — counting, event classification, or identification of individuals — you typically cross into processing of biometric data (special category under Article 9 GDPR) and the innovative-technology criterion. The DPIA then stops being a borderline question and becomes near-universal. EDPB Guidelines 3/2019 explicitly note that for the common purposes of video surveillance, an impact assessment will be needed in many cases.
Always cross-check national lists published under Article 35(4), because each EU/EEA supervisory authority has its own schedule of operations that require a DPIA. The ICO, for example, lists biometrics and tracking. Concluding that a DPIA is not required is safest after verifying against the current national list in your jurisdiction.
Scope, purpose and lawful basis before anything else
Start the DPIA with a precise description of the data and the full processing lifecycle: which cameras exist, what falls inside each frame, how long recordings are kept, whether streams go to the cloud, which analytics modules run, and who among the operators can access what. A single DPIA may cover a set of similar operations with similar risk, but it cannot blanket-cover cameras pointed at materially different situations.
Define the purpose narrowly: site security, crime prevention, crowd-flow management. Purpose limitation and data minimisation require you to fix the minimum personal data without which the purpose fails — for example, dropping recording where a counter suffices, or dropping identification where aggregate statistics are enough. Transparency follows with legible signage placed before people enter the monitored area, naming the operator, the purpose and a contact point.
Consent is rarely a realistic lawful basis in public space, because passers-by cannot refuse without changing route or behaviour, so consent is unlikely to be genuinely free. The workable bases are legitimate interests for private operators and public task for authorities acting in the public interest. Each basis needs documented reasoning; a legitimate interests assessment demonstrates the balance between the controller's interests and people's rights and feeds naturally into the DPIA.
Where biometric data is processed, an Article 6 basis alone is not enough — you also need a special-category condition under Article 9. In the UK, DPA 2018 adds further conditions and, in many cases, an appropriate policy document. Record all of this in the DPIA before deployment, not after a complaint arrives.
- Inventory of camera types and coverage zones mapped to purpose
- Article 6 lawful basis for each processing purpose
- Article 9 special-category condition for biometrics or offence data
- LIA outcome: why the controller's interest outweighs individual rights
- Signage and information plan placed before entering the monitored zone
Necessity, proportionality and less intrusive alternatives
The pivotal DPIA question is whether the goal can be reached by a less intrusive method. This is not rhetorical: if lighting, fencing, patrols or redesign of the space would solve the problem, cameras may fail the proportionality test. A decision not to deploy surveillance in favour of an alternative is itself a documented outcome of the assessment.
Audit the aim and field of view of every camera so recording does not capture what is irrelevant to the purpose — a neighbouring flat, a toilet, a changing room. Expectations are judged objectively: what a reasonable person would expect in that place. In high-privacy zones, recording is almost never proportionate, and 'the technology makes it possible' is not a justification.
Account for the chilling effect: constant monitoring can change how people move, interact and where they go. That is a distinct risk to rights and freedoms that must be weighed against the stated benefit. A camera capturing everything around it simply because that is convenient will usually fail the necessity check.
Retention is set by purpose, not habit. GDPR fixes no numeric limits, but you must identify the minimum necessary period and automate deletion. Unexplained long retention is a recurring finding in supervisory reviews of surveillance systems.
Structured risk scoring: likelihood and severity
The core of the DPIA is the risk assessment, and the methodology separates risks inherent in the design of the processing (such as continuous capture of faces in a stream) from risks arising through accidental or abnormal events (a breach, unauthorised access). The EDPB's 2026 common template requires exactly this separation and asks you to state whether each mitigation is planned, partially implemented or fully implemented.
Score each risk for likelihood and severity of potential harm to the affected groups: passers-by, employees, children, vulnerable people. In public space, typical risks include unjustified surveillance, disclosure of recordings, analytics errors such as false alarms or misclassification, access abuse, and people being unable to exercise their rights.
Risk is scored twice — before and after mitigation — and every risk must be linked to concrete technical and organisational measures: masking and privacy zones, access control with logging, encryption, automatic deletion at expiry, and human review of analytics alerts before any action. Assess the accuracy and bias of the analytics algorithm itself.
The output is a residual-risk level and a decision: approve, approve with conditions, reject, or refer for prior consultation. The DPIA is not one-off; review it on any material change to analytics, algorithms or camera configuration, and periodically, because practice and regulatory positions evolve.
Residual risk, prior consultation and the AI Act
If residual risk stays high after mitigation, the controller must consult the supervisory authority before starting under Article 36 GDPR. The consultation can take up to eight weeks, extendable by a further six where the intended processing is complex — a timeline that belongs in project governance. Even where consultation is not mandatory, the DPIA may be examined later in an audit or investigation.
The EDPB's common DPIA template, published for consultation in April 2026, structures the assessment across numbered sections covering data categories, lifecycle, purpose and legal basis, necessity and proportionality, granular risk analysis, mitigations with their status, residual-risk reassessment and a recorded decision. Use is currently voluntary, but national authorities are expected to align their own templates to it, so it is a sound benchmark for internal processes.
In the EU, the AI Act runs alongside the GDPR: real-time remote biometric identification in publicly accessible spaces for law enforcement is prohibited with narrow exceptions, and high-risk systems carry their own fundamental-rights impact assessment. These obligations complement rather than replace the GDPR DPIA, and biometric deployments must satisfy both layers.
The framework described here derives from the GDPR and practice in the EU/EEA, with UK GDPR applying with its own nuances. Operators outside those jurisdictions — including in the CIS with their own personal-data statutes — can treat this structure as a method, but mandatory requirements and lists must be checked against local law and its regulator.
Put it into practice
DPIA screening checklist and risk matrix for public-space CCTV and analytics
Complete before launch and on any material change. Two or more 'yes' answers in block A make a DPIA mandatory; block B ties each risk to a mitigation and its status; block C records the decision and the review date.
- A1. Systematic monitoring of a publicly accessible area on a large scale (Art. 35(3)(c))?
- A2. Processing of biometric data, facial recognition or identification of individuals?
- A3. Analytics, event classification, profiling or novel application of technology?
- A4. Do vulnerable people or high-privacy zones (children, staff, changing rooms) fall within scope?
- B1. Each risk named and scored for likelihood and severity before mitigation?
- B2. Every risk linked to a measure with status: planned / partially implemented / implemented?
- B3. Privacy zones, masking and field of view calibrated to purpose, not maximum coverage?
- B4. Access to recordings restricted and logged; streams and storage encrypted?
- B5. Retention set by purpose with automated deletion in place?
- B6. Do people review analytics alerts before any action, with algorithm accuracy assessed?
- C1. Residual risk after mitigation: acceptable / conditional / high (Article 36 consultation)?
- C2. Decision recorded with DPIA version and scheduled review date?
Questions people ask
Do I always need a DPIA for public-space cameras even with no analytics layer?
Not for every single camera, but in most meaningful deployments. Article 35(3)(c) GDPR makes systematic monitoring of a publicly accessible area on a large scale an automatic trigger. Where a camera network covers an extensive area or systematically captures large numbers of people, the DPIA is mandatory. Even a single camera can fall in through the nine WP29/EDPB high-risk criteria, such as monitoring of vulnerable people. When in doubt, regulators recommend doing a DPIA and documenting the outcome, including a reasoned decision that one is not needed.
Why is consent a poor lawful basis for street-level cameras?
Consent under Article 6(1)(a) GDPR must be freely given, specific, informed and unambiguous. A pedestrian entering a monitored zone can rarely refuse without changing route or behaviour, so consent is unlikely to be genuinely free. In practice controllers rely on legitimate interests (private operators) or public task (authorities acting in the public interest). You should support the choice with a legitimate interests assessment that weighs the controller's interests against people's rights and feeds directly into the DPIA.
What happens if residual risk stays high after all mitigations?
Article 36 GDPR requires you to consult the supervisory authority before starting the processing. The consultation can take up to eight weeks, extendable by six more depending on complexity. You should build this into the project plan and not launch before the process concludes. If consultation is not mandatory, the DPIA remains a record the authority can request during an audit or investigation, so keep it accurate and current.
How do design-inherent risks differ from operational risks in a DPIA?
Design-inherent risks flow from the processing design itself, such as continuous capture of faces or collecting more than the purpose needs. Operational risks arise from accidental or abnormal events, such as a data breach, unauthorised access or system failure. The EDPB's 2026 common template requires this separation and asks you to record each measure's status. Both classes are scored for likelihood and severity before and after mitigation, after which you record the residual risk and the decision.
How does the EU AI Act interact with a GDPR DPIA for video analytics?
In the EU the two regimes run in parallel. The AI Act prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions, and requires high-risk systems to carry out a separate fundamental-rights impact assessment (FRIA). A GDPR DPIA does not substitute for that assessment; both must coexist. Outside the EU/EEA, requirements should be verified against local personal-data law rather than assumed from GDPR practice.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Guidelines 3/2019 on processing of personal data through video devicesEuropean Data Protection Board (EDPB)
- When do we need to do a DPIA?Information Commissioner's Office (ICO)
- How can we comply with the data protection principles when using surveillance systems?Information Commissioner's Office (ICO)
- Should a data protection impact assessment ('DPIA') be carried out in relation to video surveillance?Commission nationale pour la protection des données (CNPD Luxembourg)
- EDPB publishes draft DPIA template for public consultationA&O Shearman
- Analysis: EDPB adopts common DPIA templateIrish Legal News (Matheson LLP authors)