PONOPT FIELD NOTES · Страхование и риск

Can Video Analytics Support a Claim Without Compromising Privacy?

How to lawfully use video analytics in claims: legal basis, data minimisation, retention, and the biometric red lines under GDPR and the EU AI Act.

Yes — if video analytics is framed as bounded decision support, not covert surveillance. You can lawfully verify the who, when and where of an incident when you can show a lawful basis, capture only what you need, set short retention, tell people what is recorded and keep a human in the loop. Treat any identifiable person as personal data, and steer clear of facial and emotion recognition, which push a system into high-risk or prohibited territory.

Key takeaways

  • Under the GDPR and UK GDPR an identifiable person on camera is personal data; footage that is merely blurred or 'anonymised' is often still re-identifiable, so the full data-protection duties apply.
  • Legitimate interest can justify analytics for claim verification or fraud prevention, but only after a necessity and proportionality test: prefer less intrusive alternatives and document why they fall short.
  • Build in minimisation from the start: narrow angles, no audio, no emotion or physical profiling, on-device analysis, and deletion as soon as the analytical purpose is met.
  • Retention is the weakest link: set a written period tied to the claim lifecycle, and treat footage that becomes evidence under a separate documented legal-hold decision, not 'just in case' archiving.
  • Some uses are off-limits: the EU AI Act bans untargeted scraping of CCTV to build facial-recognition databases and bans emotion recognition in workplaces; biometric identification and categorisation are high-risk.
  • Evidence integrity matters as much as privacy: footage from covert or disproportionate surveillance may be challenged or excluded, so document purpose, legal basis, capture parameters and an unbroken chain of custody.
  • Run a data-protection impact assessment and a real-world pilot before rollout, and keep final decisions with a person — analytics flags and triages; it does not adjudicate.

What video analytics can and cannot prove in a claim

Video analytics answers narrow verifiable questions about a claim: did the incident occur, when and where, was an item scanned at a checkout before an alleged injury or theft, how did the claimant move, does the reported damage match the scene? It turns raw footage into structured event records — motion, zones, sequence of actions — that let an adjuster compare the policyholder's account against observable facts and flag staged or exaggerated losses. Virtual inspections driven by the policyholder's own phone video add a remote, documented view of property or vehicle damage.

The tool has hard limits. Analytics establishes observable facts, not intent, causation or the value of a loss — those conclusions remain with a human and need corroborating documents. False positives are unavoidable, and if error rates are too high the system stops being a proportionate response and can even undermine the legal basis for processing, because the measure must actually work for the stated purpose. Treat analytics as triage and verification, never as an automatic denial engine.

Start from the legal baseline, not the technology

The GDPR and UK GDPR treat any identifiable person on camera as personal data, and regulators are explicit that a system is not 'anonymised' just because faces are blurred or masked — people often remain re-identifiable through the wider CCTV estate or because staff intervene with them (CNIL). From that starting point follow the whole duty chain: lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, security and transparency.

Regulation is layered. Beyond the GDPR you may rely on the UK 'crime compatibility condition' when reusing personal information to detect, investigate or prevent crime, including scams and fraud — an option that sits alongside recognised legitimate interest for insurers that are not public or competent authorities. In the EU, the AI Act adds a risk tiering that determines which analytics uses carry extra obligations or are banned. Sector codes and national guidance can tighten the picture further, so check your own regulator before rollout.

The lawful basis and the proportionality test

Legitimate interest is the common starting point for claim verification and fraud prevention, but it only holds if processing is necessary and not disproportionate. State a specific aim — verifying a slip-and-fall at a checkout, detecting a staged theft — and show why less intrusive checks (weighing scanned goods, RFID, random staff inspection, document review) are insufficient. CNIL recommends experimenting in real conditions to confirm the device is genuinely effective, lawful and low-impact before full deployment.

Where analytics detects criminal offences and the output feeds pre-litigation or litigation, the data may become offence-related data under Article 10 GDPR, triggering additional conditions and tighter restriction to preparing and pursuing legal claims. Document the necessity analysis, keep alert handling in a named-person workflow, and give people a realistic way to avoid the analytics lane — for example a checkout or payment path without the augmented camera — so the interference is not disproportionate.

  • Purpose stated precisely and tied to one observable claim event.
  • Less intrusive alternatives tested and rejected with recorded reasons.
  • Real-world pilot measures accuracy, false positives and actual loss reduction.
  • Effective opt-out or non-analytics path available without disadvantage.
  • Offence-related data handled under Article 10 rules and restricted to legal-claim purposes.

Minimisation, retention and transparency by design

Minimisation is decided at design time, not after a privacy complaint. Restrict the camera to the area needed for the check — the scan zone, the aisle where the fall happened — and angle lenses to avoid faces where possible. Mask or blur areas of no interest, reduce resolution and capture rate to what detection needs, process locally on the device rather than in the cloud, disable audio, and strip functions that serve no purpose such as reading hesitation, emotion or physical characteristics.

Retention should be tied to purpose: data deleted as soon as detection is done, with the controller only keeping frames where a further lawful purpose (improving the algorithm or pursuing a claim) genuinely exists and for no longer than needed. When footage becomes evidence in a contested claim, treat that as a separate documented legal-hold decision. Transparency requires layered notice — clear signage at the location plus an on-device or on-screen message describing the algorithmic nature of the analysis — and a second layer online or via QR code with details of the processing and rights.

If you reuse images to train the model, remember they may still identify people through timestamps, distinctive hands, jewellery or purchase sequences; apply pseudonymisation such as pixelation and masking, allow objection through a checkbox, and keep a short training-data retention period.

  • Camera covers only the zone needed; non-interest areas masked or never recorded.
  • Audio disabled; emotion, age, gender and physical profiling excluded from scope.
  • Local processing preferred; resolution and frame rate reduced to the minimum.
  • Retention written into policy with automatic deletion and a separate legal-hold path.
  • Layered notice: site signage, on-screen message, online policy and opt-out for training data.

The red line: biometrics and high-risk analytics

There is a clean distinction between event analytics and identification. Detecting that an item was not scanned or that a person fell is generally low-risk event processing. The moment the system identifies who someone is, categorises people, or infers emotions, it crosses into special territory. The EU AI Act treats remote biometric identification, emotion recognition and biometric categorisation as areas of concern, and bans several uses outright.

Specifically, the AI Act prohibits untargeted scraping of internet or CCTV footage to create or expand facial-recognition databases, and bans emotion recognition in workplaces and education, along with biometric categorisation used to deduce protected characteristics. These prohibitions entered into force in stages from February 2025. High-risk rules for sensitive areas including certain biometrics are scheduled to apply from December 2027, though the implementation timeline has been adjusted by the 'AI Omnibus' simplification and can change — always confirm current dates on the official AI Act pages before planning. Insurers that stay on the event side of this line face far lighter obligations; crossing it triggers impact assessments, documentation and, in many cases, a rethink of the whole design.

  • Event detection (was it scanned, did they fall, where) is the low-risk lane.
  • Identification, categorisation or emotion inference is the high-risk lane.
  • Untargeted CCTV scraping to build face databases is prohibited.
  • Emotion recognition in workplaces is prohibited under the AI Act.
  • Confirm the evolving high-risk timeline on official EU sources before planning.

Keep the evidence usable and the decision human

Privacy compliance and evidential integrity converge. Footage obtained through covert or disproportionate surveillance can be challenged in civil proceedings, and courts in several EU states have declined to admit recordings collected in breach of data-protection rules, even where they appeared to support a party's case. An insurer that quietly hires a private investigator to film a claimant for weeks risks both an exclusion order and its own legal exposure. The robust alternative is open, documented and proportionate capture with a recorded basis.

Documentation is the evidence. Record when and why cameras were installed, the legal basis, capture parameters, who accessed footage and for what purpose, and keep an unbroken chain of custody through secure storage and access logs. Finally, keep the decision with a person: analytics generates alerts and structured facts, a named adjuster or investigator reviews them, and no outcome flows automatically. This human-in-the-loop design protects claimants' rights and shields the insurer from both privacy complaints and disputes over the reliability of the analytics.

  • Capture is open, documented and proportionate; covert surveillance is a high-risk strategy.
  • Purpose, legal basis, time, place and camera settings are recorded.
  • Access to footage is logged; chain of custody is unbroken and secure.
  • Every alert is triaged by a named human; no automatic denial or accusation.
  • Outcomes are logged and reviewable so the claimant can challenge an error.

Privacy-by-design intake matrix for video analytics in a claim

Before any claims or fraud team runs analytics over footage, complete this matrix line by line. Each answer becomes part of your data-protection impact assessment, policy and audit trail, and proves proportionality if the processing is ever questioned.

  1. Purpose stated: exactly which observable event does the analytics verify, and for which claim?
  2. Lawful basis chosen and recorded (legitimate interest, contract, legal claim; in the UK the crime compatibility condition if fraud is suspected).
  3. Less intrusive alternatives identified and rejected with reasons on file.
  4. Camera scope mapped: what is captured, what is masked or blurred, what is never recorded.
  5. Biometric check: does the system identify, categorise or infer emotion from individuals? If yes, stop and redesign.
  6. Audio disabled unless separately justified and documented.
  7. Retention period set in writing, tied to the claim lifecycle, with automatic deletion configured.
  8. Legal-hold decision made separately for footage that becomes evidence, with an owner and date.
  9. Layered transparency implemented: site signage, on-screen or on-device notice, online policy with QR code.
  10. A workable non-analytics path (lane, checkout or handling option) exists for people who decline.
  11. Human review confirmed: a named person triages every alert and logs the outcome; no automatic results.
  12. DPIA completed and a real-world pilot run with measured accuracy before full deployment.

Questions people ask

Do I need consent to run analytics over CCTV footage of a claimant?

Not necessarily, but you need a lawful basis. Consent is only one option and is often impractical for third parties who happen to be filmed. Legitimate interest is the common basis for claim verification and fraud prevention, provided processing is necessary and proportionate — you must show a specific purpose, explain why less intrusive checks fail, keep capture to a minimum and set short retention. In the UK, reusing footage to detect or investigate fraud can also rely on the crime compatibility condition alongside recognised legitimate interest, unless you are a public or competent authority. If analytics identifies a person by face rather than just detecting events, the bar rises substantially (biometric data, often a separate condition and a DPIA).

Our adjuster has dashcam or store footage for a slip-and-fall claim — can we run analytics over it?

Yes, within limits. Running event analytics to verify whether the claimant fell, where and when is typically a legitimate-interest processing for claim verification, as long as you respect data minimisation and retention. Store footage comes from the retailer as controller, so you need a proper basis to receive and process it — usually a data-sharing arrangement and their confirmation of lawful capture. Only process the frames relevant to the incident, disable audio unless justified, delete the material once the claim closes, and keep a human adjuster making the decision. Do not use it to identify or profile the person beyond what the claim needs, and keep a clean chain of custody if the footage may go to court.

What is the difference between video analytics and facial recognition for privacy law?

Video analytics detects events — a product not scanned, a person falling, movement through a zone — and usually does not need to know who someone is. Facial recognition identifies or verifies a specific individual against a reference or database and relies on biometric data, which the GDPR treats as special-category data with extra conditions and, in many jurisdictions, stricter rules. The EU AI Act draws the same line differently: it bans some uses outright, such as untargeted scraping of CCTV to build face databases and emotion recognition in workplaces, and treats remote biometric identification and categorisation as high-risk. If your analytics can identify people rather than just detect events, you have crossed into a much heavier compliance regime.

When does the EU AI Act apply to analytics used in insurance claims?

The AI Act entered into force in August 2024 and generally became applicable in August 2026. Event-based analytics for claim verification usually falls below the high-risk threshold. The risk picture changes if the system performs remote biometric identification, emotion recognition or biometric categorisation: the Act prohibits untargeted scraping of CCTV to build facial-recognition databases and bans emotion recognition in workplaces, and treats certain biometric uses as high-risk, with obligations scheduled to apply from December 2027. That timeline was adjusted by the 'AI Omnibus' simplification and can shift, so always confirm the current dates on the official European Commission AI Act pages. As a rule of thumb, stay on the event side and you face transparency and data-protection duties rather than the full high-risk regime.

How long may we keep analysed footage if a claim is contested?

Under the GDPR and UK GDPR you keep personal data only as long as needed for the purpose (storage limitation). For routine footage used to verify a claim, delete it once the analytical purpose is met or the claim is settled. If footage becomes evidence in a contested claim or suspected fraud, treat it under a documented legal hold: freeze the relevant clips for the duration of the dispute and any litigation, with an owner, date and reason recorded. 'Just in case' retention beyond your stated policy is a compliance risk, so set retention in writing, configure automatic deletion, and make the evidence hold a separate, explicit decision rather than the default.

Covert surveillance by a private investigator caught our claimant on camera — is it usable evidence?

Probably not, and pursuing it is risky. Courts in several EU states have declined to admit recordings obtained through covert or disproportionate surveillance that breaches data-protection and privacy rules, even when the footage appeared to support a party's case. GDPR compliance and evidential integrity are linked: unlawfully obtained material can be excluded, and the investigation itself may expose the insurer to complaints. A safer approach is open, documented and proportionate capture with a recorded legal basis, clear purpose, minimal scope and a verifiable chain of custody. If covert methods seem necessary, treat that as a red flag that your evidence strategy needs legal review in the specific jurisdiction before anyone is filmed.

We operate across several EU member states — are the rules uniform?

The GDPR and the AI Act give a common baseline, but national regulators and courts apply them with local variations. Storage periods for video can differ by country, signage and notification practices vary, and some member states have sector codes (for example insurance) that regulators expect you to follow. EDPB Guidelines 3/2019 on video devices offer a cross-border reference for lawful bases, transparency and retention, while national guidance such as CNIL's on augmented cameras shows how a regulator interprets analytics in practice. Before deploying across borders, run a local compliance check in each state, confirm sector codes, and keep your DPIA updated for the strictest of your operating territories.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. Caméras augmentées aux caisses automatiques : comment se conformer au RGPD ?CNIL
  2. Crime compatibility conditionInformation Commissioner's Office (ICO)
  3. Guidelines 3/2019 on processing of personal data through video devicesEuropean Data Protection Board
  4. AI ActEuropean Commission
  5. Видеонаблюдение и персональные данные: требования, согласие и хранение записейCyberOsnova (Кибероснова)