GDPR-Compliant Camera and Video Analytics
GDPR-compliant video analytics starts with a simple observation: in camera analytics, most privacy risk comes not from the analysis itself but from where the video goes and what the system produces. ALGI is built to answer 'how many' and 'was the rule followed', never 'who'. The system does not recognize people, does not identify them and does not match visits to one another. Face recognition and biometric identification are not features of the platform; they are not a setting that can be switched off, but capabilities that were never built.
What is GDPR-compliant video analytics?
GDPR-compliant video analytics, or KVKK-compliant in Turkey, means video analysis designed to work without identifying anyone. The line is drawn here: a system that answers 'how many people passed' is performing anonymous counting; a system that answers 'who was this, and have they been here before' is processing personal data about identifiable individuals. That difference is not a technical detail; it is a legal threshold.
ALGI stays on the first side of that line. Counting, rule checks and object verification run anonymously, and the output consists of zone, time and event information. No identifier belonging to a person is created or stored.
This position is secured by architecture, not only by contract. Video is processed either on an Algi Edge device installed on site or on ALGI AI servers. With an on-site Algi Edge device, live video stays on your premises and only event records and event snapshots leave the site, so there is no central pool of footage that could leak. With server processing, video is processed on ALGI AI servers, and that processing belongs in your own data protection assessment.
How is privacy by design achieved?
Privacy is built in three layers.
Choose where video is processed. Camera streams are analysed either on an Algi Edge device in your facility or on ALGI AI servers. With the on-site device, what leaves the site is not video but numerical summaries and event records: zone, time window, count and event type, plus event snapshots. This keeps questions about transferring footage off site, including across borders, largely out of scope.
No personal identifiers are created. The system does not create face vectors, biometric templates or persistent person IDs. It cannot tell that the same person returned the next day; no such matching capability exists on the platform.
Access and retention are restricted. Who can see which record is defined by role. The retention period for event records is set in the dashboard, and records are deleted when it expires. For data that could be linked to a person, such as licence plates, the retention period is shortened further.
Obligations such as privacy notices, records of processing and, in Turkey, VERBİS registration arise from your use of cameras in the first place and do not disappear with this architecture. Because the data set being processed is narrower, managing them becomes noticeably easier.
Which industries use it?
Frequently asked questions
- Is camera analytics legal under GDPR and KVKK?
- Camera recording is already processing that falls under data protection law; an analytics layer does not create it, but it can widen or narrow its scope. A system limited to anonymous counting and rule checks does not introduce a new category of personal data. The deciding factor is what the system produces: a number or an identity.
- Does the system recognize or identify people?
- No. The platform has no face recognition and no biometric identification; this is not a disabled feature but a capability that was never developed. The system counts people in the frame and performs rule checks. A second visit by the same person cannot be matched, and no persistent identifier belonging to a person is created.
- Where is the video processed, and does it go to the cloud?
- Video is processed either on an Algi Edge device installed on site or on ALGI AI servers. With an on-site Algi Edge device, live video stays on your premises and only numerical summaries, event records and event snapshots leave the site. Retention periods and access rights for event snapshots are restricted in the dashboard, and records are deleted when retention expires.
- What is the difference between anonymous counting and face recognition?
- Anonymous counting answers 'how many people passed' and stores no identifier belonging to anyone. Face recognition creates a biometric template from a face and matches it to an identity; biometric data used this way is a special category of personal data under both KVKK and GDPR, subject to a separate regime. ALGI works only in the first group.
- Do we still need privacy notices and consent?
- The notice obligation arises from camera recording itself and does not disappear with this system; it applies to every workplace that uses cameras. Anonymous counting does not process special-category data, so it does not fall under the explicit-consent regime that applies to biometric identification. The final assessment is specific to your installation and should be made with your legal counsel.
Related rules from the library
ALL →LINE_CROSSING
Total Entry Count (Per Door)
Visitors through main entrances counted and reported per door.
THRESHOLD
Capacity Control
Automatic alert and reporting when maximum person count is exceeded.
PPE_DETECTION
Hard-Hat Detection
Workers without hard hats are detected instantly; site safety gets an alert.
DON'T SEE YOUR NEED?
Dijital Atölye listens to the problem in the field, prototypes, validates and productizes. Some of the products running in the field today were born on this line.
Bring the problem, let's talk prototype →