# Privacy and governance pack for camera analytics

Ayonix Video Analytics · Version 1.0 · Reviewed 11 September 2026
Author: Gabriel Bamola, Chief Marketing Officer · Technical review: Dr Sadi Vural, Founder and CEO

---

**This pack is a structured set of questions, not legal advice.** Obligations
differ substantially by jurisdiction. Use it to reach a documented position
before deployment, with your own privacy or legal function.

## 1. What camera analytics actually processes

The distinction that governs most of the analysis:

| Processing                    | What it produces                                                   | Typical sensitivity                              |
| ----------------------------- | ------------------------------------------------------------------ | ------------------------------------------------ |
| Object detection and tracking | A bounding box and a track identifier scoped to one camera session | Low — no identity                                |
| Counting, occupancy, density  | Aggregate numbers                                                  | Low — can be retained without imagery            |
| Dwell and heatmap             | Aggregate durations and spatial grids                              | Low — no individual path                         |
| Event evidence                | A frame and clip of a specific incident                            | Moderate — identifiable imagery                  |
| Age/gender estimation         | Aggregate composition estimates                                    | High — needs its own basis                       |
| Licence plate recognition     | Plate text relating to a registered keeper                         | High — personal data                             |
| Face recognition              | A biometric template                                               | Highest — special category in many jurisdictions |

The analytics published on the Ayonix video analytics site sit in the first four
rows. Estimation and plate recognition are separate decisions. Face recognition
is a different product line entirely.

## 2. Questions to settle before deployment

### Purpose

- [ ] What specific purpose does each analytic serve? Stated per analytic, not site-wide.
- [ ] Would a less intrusive method answer the same question?
- [ ] Is the purpose documented somewhere a regulator could read it?

### Lawful basis

- [ ] What is the lawful basis for each processing operation?
- [ ] For legitimate interests: has a balancing test been completed and recorded?
- [ ] Is a data protection impact assessment required? For estimation and plate
      recognition, assume yes until advised otherwise.

### Proportionality

- [ ] Is the coverage limited to areas the purpose requires?
- [ ] Are areas with a higher expectation of privacy excluded — welfare facilities,
      changing areas, treatment spaces, guest rooms, teaching spaces?
- [ ] Are the exclusions documented and verifiable in the configuration?

### Transparency

- [ ] Does signage cover the analytics purpose, not only that recording occurs?
- [ ] Does the privacy notice describe what is produced and how long it is kept?
- [ ] Where staff are covered, have they been consulted?

### Retention

- [ ] What retention applies to event evidence? To aggregate series?
- [ ] Is deletion automatic, and is its operation evidenced?
- [ ] Can aggregate series be kept without retaining imagery? Usually yes — prefer it.

### Access and audit

- [ ] Who can view event evidence, and how is that enforced?
- [ ] Is every access logged?
- [ ] Who reviews the access log, and how often?

## 3. Employee monitoring

Where analytics covers areas staff work in, additional obligations commonly apply
and are frequently underestimated.

- [ ] Have employees or their representatives been consulted?
- [ ] Is the purpose welfare, safety or operations — and is it documented as such?
- [ ] Is individual-level reporting disabled, with aggregate reporting only?
- [ ] Is use for individual performance management explicitly prohibited in policy?
- [ ] Would the deployment survive being described plainly to the people it covers?

That last question is the most useful one in the list.

## 4. Demographic estimation: specific constraints

If aggregate age and gender estimation is being considered:

- [ ] Would an anonymous count answer the same commercial question? **If yes, use it.**
- [ ] Is the output aggregate only, with no individual record retained?
- [ ] Is there an explicit "uncertain" category, rather than forcing every observation into a class?
- [ ] Is minimum-count suppression configured so thin samples are not published?
- [ ] Is it documented that estimates are from appearance, not identity or self-identified gender?
- [ ] Is it prohibited to make any decision about an individual from these estimates?
- [ ] Is it confirmed that race, ethnicity, religion, health and other special-category
      characteristics are never inferred?

## 5. Licence plate recognition: specific constraints

- [ ] Is plate text treated as personal data?
- [ ] Is there a documented lawful basis for this specific purpose?
- [ ] Has a DPIA been completed?
- [ ] Is the retention period the shortest that supports the purpose?
- [ ] Is automatic deletion configured and evidenced?
- [ ] Are plate images retained at all, or only text? Prefer text alone where sufficient.
- [ ] Does signage specifically inform drivers that plate recognition operates?
- [ ] Is use limited to the disclosed purpose, with drift prevented by policy?

## 6. Sample footage shared with a vendor

- [ ] Are you authorised to share it?
- [ ] What is your lawful basis for that disclosure?
- [ ] What are the vendor's handling terms — storage, access, retention, deletion?
- [ ] Is training use excluded in writing?
- [ ] Is deletion automatic and confirmable?
- [ ] Could a shorter or less identifiable clip answer the same question?

## 7. Pre-deployment governance checklist

- [ ] Purpose documented per analytic
- [ ] Lawful basis identified and recorded
- [ ] DPIA completed where required
- [ ] Excluded areas listed and verified in configuration
- [ ] Signage and privacy notice updated to cover analytics
- [ ] Employee consultation completed where applicable
- [ ] Retention periods set and automatic deletion verified
- [ ] Role-based access configured and access logging confirmed working
- [ ] Individual-level reporting disabled where the purpose is aggregate
- [ ] Review date set, with criteria for discontinuing the processing

## 8. The question behind all the others

If the deployment were described plainly — in one paragraph, without euphemism —
to the people it covers, would it be defensible?

If the honest answer is no, the governance work is not finished, whatever the
checklist says.

---

Questions: infojp@ayonix.com · https://videoanalytics.ayonix.com
