Playbook

Privacy-safe video analytics in practice

What you can measure without storing identities, and how to document it for a compliance review.

Home › Resources

A surprising share of video analytics value needs no identity at all. Counting, queueing, dwell, occupancy, safety compliance and intrusion are all answerable from anonymous detections — which means fewer obligations and a much shorter compliance conversation.

Start by asking what the decision actually needs

If the action is "open another till", you need a count, not a person. If the action is "deny access to this door", you need identity. Sorting your use cases into those two buckets removes most of the risk before any design work starts.

What anonymous analytics can answer

  • How many people entered, per hour, per entrance
  • How long the queue was, and when it exceeded the threshold
  • Which zones were occupied and for how long
  • Whether PPE was worn in a restricted area
  • Whether someone crossed a perimeter after hours

When identity is genuinely required

Access control and watchlists need it. In that case the obligations under India's DPDP Act apply: a lawful purpose, notice, consent where required, defined retention and the ability to honour a deletion request. Build those in at design time — retrofitting them is far harder.

Retention is a design decision, not a setting

Decide per zone and per data type: how long raw footage lives, how long an event clip lives, how long a biometric template lives. Then enforce it automatically. A policy document that depends on someone remembering to delete is not a control.

The strongest position in a compliance review is being able to say, with evidence, that the system cannot retain what it does not need — because deletion is automatic, not manual.

Log the lookups, not just the matches

Who searched, what they searched for, and why. Most misuse of a video system is not an outside attack — it is an authorised user looking at something they had no business reason to see. An audit log is what makes that visible.

Write it down before you deploy

  • The purpose of each camera and each analytic
  • What is stored, where, and for how long
  • Who can access it and under what conditions
  • How a deletion or access request is handled
  • Which areas are deliberately excluded from coverage

This is not legal advice — have your counsel review the specific deployment. But a system designed this way makes their job considerably shorter.

Want this applied to your site?

We are happy to walk through any of this against your actual cameras, data and constraints.