Synaedge Logo (500 × 120 px) (10)

Data Protection in AI-Powered Video Surveillance

Video surveillance is today an indispensable part of modern security systems. In particular, 24/7 real-time monitoring gives companies and institutions the opportunity to maintain security measures around the clock. At the same time, significant data protection challenges arise that affect both the privacy of the people being monitored and the legal requirements. Artificial intelligence (AI) offers key advantages for both efficiency and privacy protection. This article examines the data protection-related challenges and potential of AI-supported monitoring, as well as the legal foundations in more detail.

Data Protection in AI-Powered Video Surveillance

Important data protection principles for video surveillance

 

1. Purpose limitation and data minimization

One of the central principles of data protection in video surveillance is purpose limitation. This means that the collection and processing of video data is only permitted if it serves a clear and legitimate purpose. In practice, this is usually the protection of people and property, the prevention of criminal offenses, or ensuring the smooth operation of a business. The principle of data minimization states that the collected data must be limited to the absolute minimum. This means that no more data may be collected than is necessary to achieve the monitoring purpose.

 

2. Transparency and information

Another important data protection principle for video surveillance is transparency. Affected persons—that is, those who are captured by the video surveillance—must be clearly and unambiguously informed that they are being monitored. This is usually done through visible and well-placed information signs that indicate that the area is under video surveillance.

These signs must not only indicate the presence of the cameras, but also include additional information, such as:

  • The party responsible for the monitoring (e.g., the company or organization operating the cameras).
  • The purpose of the monitoring (e.g., “For security and protection of people and property”).
  • Information about how the affected persons can exercise their data protection rights (e.g., how they can contact someone to obtain information about their data).

 

3. Consent

In non-public or particularly sensitive areas—such as at the workplace or in private premises—the explicit consent of the affected persons is often required before the surveillance may be carried out. In this case, consent must be voluntary, specific, and based on informed circumstances. This means that the affected persons must know exactly what they are agreeing to and what consequences the monitoring has for them.

 

4. Retention periods

The collected video data may only be stored for as long as it is necessary for the original purpose of the monitoring. Typically, the retention period for video surveillance is between 48 and 72 hours, unless there is a legitimate reason for longer storage, for example to investigate an incident. In cases where the data are needed for an investigation or for evidence in a criminal proceeding, a longer retention period may be permissible. However, this should always be done in compliance with legal requirements and must be well documented.

 

5. Rights of the data subjects

Under data protection laws, affected persons have various rights that enable them to retain control over their personal data. These rights include:

  • Right of access: Affected persons have the right to request information about whether and which personal data concerning them are processed. This also includes video recordings in which they are visible.
  • Right to erasure: Under certain conditions, affected persons have the right to request the deletion of their data. This may be the case, for example, if the data were collected unlawfully or if the purpose of the monitoring has been fulfilled and the data are no longer needed.
  • Right to object: Affected persons can object to the processing of their data, in particular if the monitoring is carried out on the basis of a legitimate interest of the party responsible. The objection may result in the video surveillance being discontinued or the data needing to be deleted, provided there are no overriding reasons that justify the processing.

These rights must be made easily accessible to affected persons, and companies are required to handle corresponding requests promptly and transparently.

Challenges of traditional video surveillance: More than just security data

Traditional video surveillance systems, which are based on passive or active monitoring, often face significant data protection challenges. These systems typically record data continuously and collect far more information than is necessary for the actual monitoring purpose, which is particularly problematic with regard to protecting privacy.

 

1. Passive monitoring: Surveillance without filtering

With passive monitoring, the surveillance cameras continuously record video data that can later be reviewed manually if an incident occurs. This approach means that all movements and actions in a monitored area are captured without gaps, regardless of whether they are security-relevant or not. Dese comprehensive data collection contradicts the principle of purpose limitation and data minimization, because not only security-relevant information is collected. In addition, the data are often stored for longer periods even when no security-relevant incident has occurred, which increases the risk of data protection breaches.

 

2. Active monitoring: An intrusion into privacy

With active monitoring, the video material is monitored in real time by security personnel. This means that one or more people constantly observe all activities in a monitored area, which can lead to a feeling of constant surveillance. Here, particular problems arise:

  • Lack of focus on relevant events: Although security personnel should be keeping an eye on security-relevant incidents, they also see many private or personal interactions that have nothing to do with security.
  • Loss of attention: Another problem of active monitoring is the limited attention span of the monitoring staff. With hours of observation, concentration decreases, which can lead to security-relevant incidents being overlooked.

 

3. Comprehensive data collection without differentiation

A major problem with both passive and active monitoring is undifferentiated data collection. Traditional surveillance systems generally record everything that happens within their field of view. This means that not only security-relevant events such as break-ins or vandalism are captured, but also completely mundane and private activities. An example from the workplace is the recording of break times. Cameras aimed at the break room or entrance area record every time an employee enters or leaves the room. This results in detailed records about when and how often breaks are taken, which significantly affects employees’ privacy. This is particularly problematic if employers could use this data for disciplinary measures, which can lead to unlawful monitoring in the workplace.

 

4. Lack of flexibility in data collection

Another problem is that traditional video surveillance systems do not offer flexibility in data collection. They either record everything or nothing. There is no intelligent filtering of information, so irrelevant and non-security-related data are collected as well. This comprehensive recording clearly contradicts the principle of data minimization, which requires that only data may be collected that are necessary for the intended purpose.

 

5. Risk of misuse and data protection breaches

Comprehensive data collection inevitably leads to an increased risk of misuse or data protection breaches. The more data that is collected, the greater the risk that this data will be accessed or manipulated by unauthorized persons. In many cases, sufficient access controls are lacking, and the video data may be stored for longer than is necessary or legally permitted.

In addition, there is a risk that these data could be used not only for the original security purpose, but also for other, impermissible purposes. For example, employers could access surveillance data to analyze their employees’ behavior or to monitor how efficiently they use their working time.

The solution is AI video analytics, but careful selection of the provider is important

In light of the significant limitations and data protection risks of traditional video surveillance systems—both for passive and active monitoring—AI-based video analytics is becoming increasingly important. These modern systems offer a wide range of benefits that improve both the efficiency of monitoring and the protection of privacy. AI video analytics uses advanced algorithms and machine learning to process and analyze video data in real time. This allows them to overcome many of the weaknesses of conventional surveillance methods.

However, AI-based video surveillance systems also present challenges, especially with regard to data protection and security. In recent years, there have been significant data protection concerns and violations related to video surveillance technologies, particularly with some Chinese providers such as Hikvision and Dahua.

 

Hikvision

The company has been criticized multiple times for data protection and security breaches. The US government placed Hikvision on the Entity List, which means that US companies need special licenses to do business with Hikvision. This happened due to the company’s role in human rights abuses against Muslim minority groups in China, particularly the Uyghurs. In addition, critical security vulnerabilities were discovered in Hikvision cameras that enabled attackers to gain access to the devices.

 

Dahua

Dahua was also similarly sanctioned. The US government banned the use of Dahua equipment in public facilities due to national security concerns. These concerns relate to potential backdoors in the devices that could be exploited by the Chinese government.

These examples show that despite technological advancements and the benefits of AI-based video analytics, data protection and security must not be neglected. It is essential to select providers carefully and to pay attention to their data protection and security practices in order to ensure the integrity of the surveillance systems and protect the privacy of the people being monitored.

Important considerations to ensure data protection in AI-powered video surveillance

When choosing the right AI video analytics provider, several important aspects should be taken into account. First and foremost, data protection compliance is crucial. The provider must ensure that it complies with all relevant data protection laws and regulations, such as the General Data Protection Regulation (GDPR) in Europe. This includes transparency in data collection and processing as well as measures to secure the data. High security standards are equally important.

Transparency and traceability also play a central role. A trustworthy provider should provide detailed audit logs and access controls to ensure that only authorized personnel have access to the data. Providers that use technologies to anonymize people and license plates in the video data significantly reduce the risk of data protection violations.

Finally, the ability to store data locally is another important factor. Providers that enable local data storage minimize the risk of data loss and misuse. All these considerations help in finding the right AI video analytics provider that meets both security and data protection requirements.

How AI-powered video surveillance with Vaido addresses the problems of traditional video surveillance

A standout example of such a solution is the AI video analytics with Vaidio, which enables efficient and secure video analysis. The AI video surveillance we offer with Vaidio addresses these shortcomings and provides a more privacy-friendly alternative.

 

1. Purpose limitation and data minimization through event-based capture

Unlike conventional surveillance systems that record all data without distinction, Vaidio enables event-based capture. This means that only security-relevant incidents are detected and recorded. Instead of collecting continuous video material, the system activates recording only when a defined event is detected—such as an unauthorized movement in a protected area or entering a prohibited zone.

Through this intelligent filtering of events, the amount of captured data is significantly reduced, in line with the principles of purpose limitation and data minimization. Insignificant activities, such as employees’ break times or personal conversations, are ignored because they are not relevant for the surveillance purpose. This protects the privacy of the monitored individuals and prevents unnecessary data from being collected.

 

2. Anonymization and privacy protection

One of the outstanding features of Vaidio is the anonymization of people and vehicle license plates. The system can automatically anonymize faces and other personal data before they are processed further or stored. This ensures that the privacy of the monitored individuals is maintained—even if recordings need to be stored for later analysis or to clarify an incident.

This anonymization feature is particularly useful in sensitive areas such as the workplace, where recording employees can lead to data protection issues. Vaidio ensures that only security-relevant information is recorded, while personal data is encrypted or redacted to meet the requirements of the General Data Protection Regulation (GDPR).

 

3. Real-time analysis and reduction of human error

One of the biggest advantages of the AI video analytics with Vaidio is the ability to perform real-time analysis. Instead of having to manually review the video footage laboriously after an incident, Vaidio analyzes the data in real time and detects anomalies or suspicious activities immediately. This not only reduces the workload for security personnel, but also minimizes human errors that can arise from fatigue or lack of attention, as is often the case with the active monitoring.

By using pattern recognition algorithms, Vaidio identifies security-relevant incidents faster and more reliably than a human observer. For example, the platform can automatically detect whether someone is trying to enter a building without authorization, whether an object has been located at an unusual place for a longer period of time, or whether an unusual number of people is gathering in a certain area. This enables an immediate response to security-relevant incidents while everyday private activities remain unnoticed.

 

4. Flexible storage options and secure data storage

Vaidio offers flexible data storage, which can take place either locally (edge-based) or in the cloud. This gives companies the ability to store their sensitive data where it meets the highest security standards and complies with data protection requirements. In any case, Vaidio ensures that the recorded data is encrypted to prevent access by unauthorized individuals.

In addition, Vaidio allows the limited retention of data. The system can be configured so that recordings are automatically deleted after a certain period if they are no longer needed. This complies with the statutory requirements for the retention periods and reduces the risk of data protection breaches caused by overly long storage.

 

5. Access control and audit logs

A central element of the GDPR is ensuring that only authorized persons can access personal data. Vaidio enables this through strict access controls and detailed audit logs, ensuring that access to the video data is documented without gaps. Every instance of viewing or changing the data is logged, ensuring complete transparency.

This feature ensures that companies can prove at any time who accessed the data and for what purpose. This not only increases security, but also provides trust for the individuals concerned, as they can be confident that their data is used only for legitimate and documented purposes.

 

6. Avoiding surveillance beyond the legitimate purpose

One of the biggest problems with traditional video surveillance is the collection of data that has nothing to do with the security purpose—for example, observing employees’ break times or personal interactions. Vaidio addresses this problem directly by ensuring that only events are captured that match the predefined surveillance objectives.

By using intelligent analysis models, surveillance cameras can be targeted to specific zones or event types. This means that only security-relevant data is collected, while other activities affecting privacy are hidden or ignored. This leads to a clear reduction in unnecessary data and protects the rights of the monitored individuals.

Conclusion

Conventional video surveillance is associated with significant data protection issues that endanger the privacy of the people affected and raise legal as well as ethical questions. The integration of AI and advanced technologies offers a promising solution to address these problems. Through real-time analysis, anonymization, and strict access controls, modern surveillance systems can increase efficiency while also protecting privacy. In addition, legal and organizational measures should be taken to ensure the transparency and security of surveillance systems. Careful selection of providers that meet these standards is crucial to avoid data protection violations and to ensure security.

Picture of Anne-Katrin Michelmann

Anne-Katrin Michelmann

Date: 23.10.2024