Part 4: Buying and governance · Chapter 13
Privacy, law, ethics and worker trust
How GDPR, UK ICO monitoring guidance, DPIAs, the EU AI Act after the 2026 Digital Omnibus, BIPA, CCPA and works councils apply to AI safety cameras and wearables.
By LIPAI WANG · Updated · 21 min read · 29 sources
AI safety cameras, wearables and proximity systems collect data about people at work, so they sit inside data protection, employment and, increasingly, AI law. In Europe and the UK the core requirements are a lawful basis, a specific purpose, transparency to workers and a data protection impact assessment, with the EU AI Act adding a ban on workplace emotion recognition and, from December 2027, obligations for high-risk employment AI. In the US the main exposure comes from state biometric laws such as Illinois BIPA, California's privacy rules for employee data, and electronic-monitoring notice laws, while worker trust depends on consultation and firm limits on how the data is used.
This chapter is general information for safety, operations and procurement teams. It is not legal advice. Laws, guidance and court decisions change, and the right answer depends on your jurisdiction, your configuration and your workforce. Involve your data protection officer, employment counsel and, where they exist, worker representatives before you deploy.
Why safety technology is a privacy question at all
A camera pointed at a loading dock to spot forklifts near pedestrians is a safety control. It is also a device that records identifiable people for hours a day, and an AI layer that classifies what those people are doing. The European Data Protection Board (EDPB) guidelines on video devices treat any system that captures identifiable individuals as processing personal data, regardless of the operator's motive [2]. A wearable that logs location, heart rate or proximity events is the same.
Three features of modern safety technology raise the stakes compared with ordinary CCTV:
- Continuous analysis. Traditional CCTV footage is mostly never watched. AI analytics reviews every frame, so the practical intensity of monitoring rises sharply even if the cameras do not change.
- Event records about individuals. A system that logs "worker without hi-vis in zone B at 14:02" creates a record that can be linked to a shift roster. That record can be used for coaching, for trend reports or for discipline, and the law cares which.
- Inference. Pose estimation, fatigue detection and behavior classification produce new information about a person that they did not provide.
Safety analytics can still be lawful, provided the employer can explain, in writing, why the processing is needed, why a less intrusive option would not work, and what protects workers from misuse.
How does GDPR apply to AI safety monitoring?
The General Data Protection Regulation (GDPR) applies to employers in the EU and to processing about people in the EU [1]. The UK has its own retained version, the UK GDPR, alongside the Data Protection Act 2018. The structure is the same in both, so the principles below apply to both unless noted.
Lawful basis
Every processing operation needs one of the six lawful bases in Article 6 [1]. For safety monitoring the realistic candidates are:
| Lawful basis | When it fits safety technology | Common pitfalls |
|---|---|---|
| Legitimate interests (Art. 6(1)(f)) | Most private-sector deployments: preventing injuries is a clear, weighty interest | Requires a documented balancing test; fails if the system is more intrusive than needed |
| Legal obligation (Art. 6(1)(c)) | Where a specific health and safety law requires the monitoring itself | General duties of care rarely require a particular camera system, so this is often overstated |
| Consent (Art. 6(1)(a)) | Rarely appropriate | European regulators say employee consent is seldom freely given because of the power imbalance [3] |
The Article 29 Working Party, the predecessor of the EDPB, set out the consent problem in its 2017 opinion on data processing at work: employees are seldom in a position to refuse freely, so employers should look to other bases [3]. The UK ICO takes the same view in its monitoring guidance [5].
Purpose limitation and data minimization
Article 5 requires that data be collected for "specified, explicit and legitimate purposes" and be "adequate, relevant and limited to what is necessary" [1]. In practice this means writing down exactly what the system is for (for example, "detect vehicle and pedestrian conflicts in the yard to redesign traffic routes") and configuring it to match. Useful minimization measures that many vendors support include:
- Face blurring or body anonymization at the edge before footage leaves site.
- Storing event clips and metadata rather than continuous recordings.
- Aggregate dashboards by zone and shift rather than by named worker.
- Short default retention for clips, with longer retention only for incidents under investigation.
- Disabling features you do not need, such as identity matching or audio.
Purpose creep is the main legal and trust risk. A system justified for collision prevention that is later used to measure break lengths or productivity has changed purpose, and that change needs its own assessment and its own notice.
Special category data and biometrics
Biometric data processed "for the purpose of uniquely identifying a natural person" is special category data under Article 9, which needs an additional condition beyond Article 6 [1]. Face recognition, gait recognition and fingerprint scanning used to identify workers fall here. The ICO's guidance says biometric data is special category data when used to identify workers, and that a DPIA is required when biometric data is used to monitor workers [6].
Most safety use cases do not need to know who someone is. Detecting that a person is in an exclusion zone, or that a hard hat is missing, does not require identity. Designing the system so it never identifies individuals is the most effective single step to reduce legal risk.
Health data is also special category data. Wearables that measure heart rate, body temperature or fatigue indicators may be processing health data, which raises the bar again.
Transparency to workers
Articles 13 and 14 require that people be told, at the time data is collected, who is processing their data, why, on what basis, for how long and what rights they have [1]. For safety technology that means at least:
- Signage at camera locations that mentions AI analysis, not only "CCTV in operation."
- A worker-facing privacy notice explaining what the system detects, what it does not do, who sees alerts, how long clips are kept and whether data can be used in disciplinary processes.
- Briefings during onboarding and before go-live, in the languages your workforce uses.
Covert monitoring is only defensible in exceptional cases, such as a specific suspected crime, and never as a default for a safety program. The ICO guidance says employers should tell workers about monitoring and that covert monitoring should be rare and tightly justified [5].
Automated decisions
Article 22 restricts decisions "based solely on automated processing" that produce legal or similarly significant effects [1]. A safety system that automatically issues a warning letter or deducts pay from a detected violation risks falling within it. A system that raises an alert which a supervisor reviews before any action is taken generally does not, as long as the human review is real. In the UK, the Data (Use and Access) Act 2025 recast the automated decision-making rules as new Articles 22A to 22D of the UK GDPR; the main data protection changes came into force on February 5, 2026 [8]. The ICO has flagged that its monitoring guidance is under review because of the Act [5], so UK teams should check for updated guidance before relying on older text.
Vendors as processors
Most safety analytics vendors act as processors on the employer's behalf. Article 28 requires a written contract that limits processing to the employer's instructions, imposes confidentiality and security duties, controls sub-processors and requires deletion or return of data at the end of the contract [1]. If the vendor wants to use your footage to train its models for other customers, it may become a controller for that purpose, which needs its own lawful basis and must be disclosed to workers. Chapter 14 covers contract terms in more detail.
What does the UK ICO expect from employers that monitor workers?
The ICO published "Employment practices and data protection: monitoring workers" on October 3, 2023 [5]. It does not ban monitoring. It sets out how to do it lawfully, and it explicitly covers technologies such as video, access control and productivity tools. Points that matter most for safety technology:
- Define the purpose and choose the least intrusive means. If a lower-tech control (physical segregation, a speed limiter, an interlock) would achieve the same safety outcome, it weakens the case for video analytics.
- Carry out a DPIA for high-risk monitoring. The guidance names biometric data and monitoring that may lead to financial loss, such as performance management, as examples of high-risk processing [5].
- Tell workers, explaining the nature, extent and reasons for monitoring.
- Consider workers' expectations. Monitoring in break rooms, toilets or changing areas is very unlikely to be justified.
- Handle solely automated decisions lawfully, with human review where decisions have significant effects.
The Serco Leisure enforcement notices
The clearest UK enforcement example comes from attendance tracking rather than safety, though the reasoning carries over. On February 23, 2024, the ICO ordered Serco Leisure and associated leisure trusts to stop using facial recognition and fingerprint scanning to record attendance for more than 2,000 employees at 38 sites [7]. The ICO found the companies had not shown why biometrics were necessary when ID cards or fobs would do, had not offered workers a real alternative, and had presented the system as a condition of being paid [7]. Information Commissioner John Edwards said that because biometric data is unique to a person, the risks of harm from errors or breaches "are much greater" [7].
For safety buyers: if a vendor's product uses face recognition to attribute violations, ask why identity is needed at all, and what the alternative is for workers who object.
How strict are EU regulators on workplace monitoring?
The French data protection authority, the CNIL, fined Amazon France Logistique 32 million euros in December 2023 over warehouse monitoring [9]. Scanners carried by workers generated indicators of productivity and inactivity, including measures of how long a scanner sat idle, and the CNIL found parts of the system excessively intrusive; it also found failures in information about video surveillance and in its security [9]. On December 23, 2025, France's Conseil d'État reduced the fine to 15 million euros. It overturned the CNIL's findings on three scanner indicators, including the idle-time measure, but upheld the finding that keeping all the indicators for 31 days was excessive [10].
Regulators will look closely at granular, continuous metrics about individual workers, and how long they are kept. The line between lawful operational monitoring and unlawful surveillance is still being drawn in the courts, so a system that looks defensible today may be tested later. Keeping safety analytics aggregate and hazard focused keeps you well away from that line.
When is a DPIA required, and what should it cover?
Article 35 requires a DPIA before processing that is "likely to result in a high risk" to people's rights and freedoms, and specifically for "systematic monitoring of a publicly accessible area on a large scale" and large-scale processing of special category data [1]. The Article 29 Working Party's DPIA guidelines list criteria that indicate high risk, including systematic monitoring, sensitive data, data about vulnerable data subjects (which explicitly includes employees, because of the power imbalance) and innovative use of new technology [4]. As a rule of thumb the guidelines say processing that meets two criteria will usually need a DPIA [4]. AI video analytics of a workforce meets at least three.
Treat a DPIA as required for any AI safety deployment in the EU or UK. A useful DPIA for safety technology covers:
| DPIA section | What to write for a safety analytics deployment |
|---|---|
| Description of processing | Cameras or devices, locations, data captured, what the model detects, where inference runs (edge or cloud), who sees alerts, retention periods, data flows to the vendor and sub-processors |
| Purpose and lawful basis | The specific hazards targeted, the injury data that motivates them, the lawful basis and a legitimate interests balancing test |
| Necessity and proportionality | Why existing controls are not enough; less intrusive options considered and rejected, with reasons |
| Risks to workers | Misidentification, use in discipline, chilling effect on reporting, function creep, data breach, bias in detection across body types, clothing or skin tones |
| Mitigations | Anonymization, no face recognition, retention limits, access controls, a use policy that limits discipline, human review of alerts, worker consultation |
| Consultation | Views of workers or their representatives (Article 35(9) asks controllers to seek them where appropriate [1]) and the DPO's advice |
| Residual risk and sign-off | Whether high risk remains; if it does, Article 36 requires prior consultation with the regulator [1] |
Revisit the DPIA when you add cameras, enable a new detection type, change retention or change how events are used.
What does the EU AI Act require, and when?
The Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024 [11]. It sorts AI systems by risk and applies in stages. The schedule changed in 2026: the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026 [16]. It postponed the main high-risk obligations [17].
| Obligation | Applies from | Relevance to safety technology |
|---|---|---|
| Prohibited practices (Article 5), including emotion recognition at work | February 2, 2025 | Rules out "emotion" or "mood" features aimed at workers |
| AI literacy (Article 4) | February 2, 2025; softened by the Omnibus to a duty to support staff literacy [17] | Train the people who configure and act on alerts |
| Transparency duties (Article 50) | August 2, 2026 (watermarking grace period for existing systems to December 2, 2026) [17] | Mostly relevant to chatbots and generated content, such as EHS copilots |
| High-risk systems listed in Annex III, including employment | December 2, 2027 (moved from August 2, 2026) [17] | Applies if the system monitors or evaluates worker performance or behavior |
| High-risk systems that are safety components of products under Annex I legislation | August 2, 2028 (moved from August 2, 2027) [17] | Relevant to AI embedded in machinery and similar regulated products |
The workplace emotion recognition ban
Article 5(1)(f) prohibits AI systems that infer the emotions of a person in the workplace, "except where the use is intended for medical or safety reasons" [11]. The European Commission's February 2025 guidelines on prohibited practices interpret this ban, and commentators note that the safety exception is narrow [15]. Recital 18 adds that "emotion" does not include physical states such as pain or fatigue, giving the example of systems that detect fatigue in professional pilots or drivers to prevent accidents [14]. Fatigue detection is therefore treated differently from mood or stress inference. Be wary of any product that claims to detect worker frustration, anger, stress or engagement from faces or voices; in the EU that is now a prohibited practice unless it fits the narrow exception, and penalties for prohibited practices reach 35 million euros or 7% of worldwide turnover [11].
When is safety analytics high-risk?
Annex III, point 4 lists AI used "to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits" and to monitor and evaluate the performance and behavior of workers [13]. Point 1 covers remote biometric identification and emotion recognition systems, with biometric verification (confirming a person is who they claim to be) excluded [13].
A hazard-focused system that detects forklifts, pedestrians and missing guards without identifying anyone has a reasonable argument that it is outside point 4. A system that scores individual workers' compliance, feeds those scores into appraisals or triggers discipline is much closer to it. The classification depends on intended purpose and actual use, so record the intended purpose in the DPIA and in procurement documents, and enforce it.
Deployer obligations for high-risk systems
If a system is high-risk, the employer is a "deployer" with duties under Article 26 [12], including:
- Use the system according to the provider's instructions and assign human oversight to competent people.
- Keep automatically generated logs for at least six months, where under the deployer's control.
- Before putting a high-risk system into use at the workplace, "inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system" [12].
- Use the provider's transparency information to carry out the GDPR DPIA [12].
- Inform people when Annex III systems make or assist decisions about them [12].
Providers (the vendors) carry heavier duties, such as risk management, data governance, technical documentation, accuracy and robustness testing, and conformity assessment. Ask vendors now how they plan to meet them by December 2027 if their product could be classed as high-risk.
Platform work
Directive (EU) 2024/2831 on platform work, which member states must transpose by December 2, 2026, restricts algorithmic management of people working through digital labor platforms, including a ban on processing data about their emotional or psychological state [18]. It matters for logistics operators that use platform-based drivers or couriers.
How do works councils and unions affect deployment?
In much of Europe, worker representatives have legal rights over monitoring technology, and those rights often set a project's timeline more than the regulator does.
Germany. Section 87(1) no. 6 of the Works Constitution Act (BetrVG) gives the works council a co-determination right over the introduction and use of technical devices designed to monitor employees' behavior or performance [19]. German labor courts have held that it is enough for a device to be objectively capable of monitoring; the employer's intention does not matter [19]. In practice an AI camera system cannot be lawfully introduced at a German site with a works council until a works agreement (Betriebsvereinbarung) is concluded or a conciliation committee decides. These agreements usually specify the purposes, the detection types enabled, access rights, retention, a ban or limits on performance evaluation and discipline, and the council's audit rights.
Elsewhere in the EU. Several other countries give worker representatives information and consultation rights over new monitoring technology. The scope varies by country and by company size, so check local labor law before you schedule a pilot.
The AI Act. Article 26(7) adds a separate duty to inform workers' representatives before using a high-risk AI system at work [12], on top of national rules.
The UK. There is no general works council system, but recognized trade unions often have collective agreements covering new technology, and the ICO guidance encourages consultation with workers and their representatives [5].
The US. In 2022 the then General Counsel of the National Labor Relations Board issued memo GC 23-02 warning that intrusive electronic monitoring could interfere with workers' rights to organize. The Acting General Counsel rescinded that memo in February 2025 as part of GC 25-05 [29]. The National Labor Relations Act itself still protects concerted activity, and unionized sites may have contract terms or bargaining obligations that cover new surveillance technology.
A works agreement or union side letter negotiated before a pilot often becomes the template for a wider rollout.
Which US state laws matter for safety technology?
The US has no federal general privacy law covering private-sector employees. Exposure comes from state laws, several of which are specific to biometrics or workplace monitoring.
Illinois Biometric Information Privacy Act (BIPA)
BIPA, enacted in 2008, requires a written policy on retention and destruction, informed written consent before collecting biometric identifiers such as face geometry, fingerprints or retina scans, and limits on disclosure. It gives individuals a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, which has produced large volumes of workplace class actions, many involving fingerprint time clocks.
On August 2, 2024, Illinois amended BIPA (SB 2979) so that repeated collection of the same biometric identifier from the same person by the same method counts as a single violation, and so that an electronic signature satisfies the written release requirement [20]. On April 1, 2026, the US Court of Appeals for the Seventh Circuit held that the damages change applies retroactively to pending cases [21]. Exposure is lower than it was after the Illinois Supreme Court's 2023 Cothron v. White Castle decision, but $1,000 to $5,000 per worker is still significant for a large site.
For safety technology, the practical question is whether the system extracts face geometry or any other biometric identifier. Person detection and PPE detection normally do not. Face recognition for attribution, or "re-identification" of the same person across cameras using biometric features, may. Get the vendor's answer in writing.
Texas and Washington
Texas's Capture or Use of Biometric Identifier Act (CUBI), enacted in 2001, requires notice and consent before capturing biometric identifiers for a commercial purpose. It has no private right of action, but the attorney general enforces it, and in 2024 secured a $1.4 billion settlement with Meta [22]. Washington's biometric law, Chapter 19.375 RCW, requires notice and consent (or a mechanism to prevent later commercial use) before enrolling biometric identifiers in a database for a commercial purpose, and is enforced by the attorney general [23].
California: CCPA and employee data
Since January 1, 2023, when a temporary exemption expired, the California Consumer Privacy Act (CCPA) has applied in full to personal information about employees, applicants and contractors of covered businesses [24]. California workers therefore have rights to notice at collection, to know, to delete and to correct, and to limit use of sensitive personal information, subject to exceptions.
The California Privacy Protection Agency finalized regulations on automated decision-making technology (ADMT), risk assessments and cybersecurity audits in September 2025; they took effect on January 1, 2026 [25]. Risk assessments are required for higher-risk processing, which includes processing sensitive personal information and profiling of people in employment contexts, and businesses must submit attestations to the agency by April 1, 2028 [25][26]. Businesses that use ADMT to make significant decisions, which include decisions about employment, must comply with notice, opt-out and access requirements from January 1, 2027 [25][26]. A safety system whose outputs feed decisions about pay, scheduling or discipline of California workers should be reviewed against these rules.
Electronic monitoring notice laws
New York Civil Rights Law Section 52-c, in force since May 7, 2022, requires private employers that monitor employees' telephone, email or internet usage to give written notice on hiring, obtain acknowledgment and post a notice [27]. Connecticut and Delaware have similar notice laws. These statutes focus on electronic communications rather than cameras, but many employers fold all monitoring into a single notice, which is good practice.
Colorado and the state AI laws
Colorado's original AI Act (SB 24-205) never took effect. In May 2026 it was repealed and replaced by SB 26-189, which regulates automated decision-making technology used in consequential decisions, including employment, and applies from January 1, 2027 [28]. Other states are considering similar bills. If safety analytics feed employment decisions about Colorado workers, include them in your review.
A US quick reference
| Law | What it covers | Who enforces | Relevance to safety tech |
|---|---|---|---|
| Illinois BIPA | Biometric identifiers and information | Private lawsuits | High if face recognition or biometric re-identification is used |
| Texas CUBI | Biometric identifiers for commercial purposes | Attorney general | Same trigger as BIPA, no private action |
| Washington RCW 19.375 | Biometric identifiers enrolled for commercial purposes | Attorney general | Same trigger, narrower |
| California CCPA and regulations | All personal information of California workers | CPPA and attorney general | Notice, rights, risk assessments, ADMT rules |
| New York Civil Rights Law 52-c | Monitoring of phone, email, internet | Attorney general (civil penalties) | Notice good practice for any monitoring |
| Colorado SB 26-189 | ADMT in consequential decisions | Attorney general | Applies if outputs feed employment decisions, from 2027 |
Ethics: what the law does not settle
Several questions sit mostly outside the law, and they shape whether workers accept the system.
Safety or surveillance? The same camera and model can support either, depending on what the organization does with the outputs. Programs that use detections to fix layouts, traffic routes, staffing and equipment are usually accepted. Programs that use them to rank or punish individuals are usually resisted.
Who bears the cost of errors? False positives are an annoyance to a safety manager and a grievance to a worker who is wrongly flagged. Commit to human review before any individual consequence, and give workers a way to challenge a flagged event.
Bias and accuracy across groups. Detection accuracy can vary with lighting, clothing, body size, skin tone, headwear and posture. Ask vendors for accuracy results broken down by condition, and test in your own environment (Chapter 14).
Chilling effects on reporting. If workers believe camera evidence will be used against them, near-miss reporting tends to fall. Treat a drop in reported near misses after go-live as a warning sign (Chapter 15).
Function creep. Data collected for safety is attractive to HR, security, productivity and insurance teams. Decide in advance which requests you will refuse.
Contractors and visitors. They appear on camera too, often without having seen your internal briefings. Include them in signage, notices and site inductions.
How to build worker trust
The organizations with the smoothest deployments tend to follow a similar sequence:
- Start with the hazard. Share the injury and near-miss data that motivates the project.
- Consult before buying. Involve safety representatives, the works council or union, and frontline supervisors in defining the use cases.
- Write a use policy and publish it. State what the system detects, what it does not do, who sees what, retention, whether and when footage can be used in discipline, and how workers can raise concerns or access their data.
- Anonymize by default. Blur faces, report by zone and shift, and keep identity out of the pipeline unless a specific, documented need exists.
- Put a human in the loop, with no automated individual consequences.
- Show results. Share what was fixed because of the data: a re-routed walkway, a new barrier, a changed shift pattern.
- Review together. Hold periodic reviews with worker representatives, including audits of access logs and any disciplinary use.
- Plan an exit. Commit to switching off detections that do not deliver safety value.
| Practice | Builds trust | Erodes trust |
|---|---|---|
| Use of data | Engineering fixes, coaching, aggregate trends | Individual rankings, automated warnings, pay deductions |
| Identity | Anonymized by default | Face recognition to name violators |
| Transparency | Published use policy, clear signage mentioning AI | Generic CCTV signs, hidden features |
| Retention | Days to weeks for routine clips | Indefinite storage "in case" |
| Governance | Joint review with worker representatives | Decisions made by IT and HR alone |
| Errors | Human review and a right to challenge | Alerts treated as proof |
Summary
Safety technology that watches or measures people is subject to privacy, employment and AI law, and the details differ by jurisdiction. In the EU and UK, plan on a legitimate interests basis rather than consent, a specific written purpose, strong minimization, clear notice and a DPIA before go-live; the ICO's 2023 monitoring guidance, now under review after the Data (Use and Access) Act, sets the UK expectations, and the Serco Leisure and Amazon France Logistique cases show regulators will act against intrusive or biometric workplace monitoring. Under the EU AI Act, workplace emotion recognition has been banned since February 2025, and after the 2026 Digital Omnibus the high-risk obligations for employment AI apply from December 2, 2027, with a duty to inform workers' representatives before use. In the US, biometric laws (BIPA, CUBI, Washington), California's CCPA rules and ADMT regulations, state notice laws and Colorado's new ADMT law are the main sources of obligation. In Germany a works council can block deployment until an agreement is reached. Across all of them, the most protective design choices are the same: detect hazards rather than identify people, keep a human between alerts and consequences, limit retention, rule out or tightly limit disciplinary use, and consult workers early. This chapter is not legal advice; confirm your position with qualified counsel.
Frequently asked questions
+Do we need worker consent to run AI safety analytics on our CCTV?
In the EU and UK, usually not, and consent is usually the wrong basis. Regulators say consent between employer and employee is rarely freely given because of the power imbalance. Employers normally rely on legitimate interests or a legal obligation, backed by a DPIA, a balancing test and clear notice to workers.
+Is AI safety video analytics high-risk under the EU AI Act?
It depends on the purpose. Systems used to monitor and evaluate the performance and behavior of workers, or to make decisions about their employment, fall under Annex III and become high-risk. A system that only detects hazards and does not identify or evaluate individuals has a stronger argument that it is outside that category. Get a documented legal view for your specific configuration.
+Can we use footage from a safety system to discipline a worker?
Legally it can be possible if workers were told this could happen and the use is proportionate, but many employers choose to rule it out or limit it to serious, deliberate violations. Using safety data for discipline is the single most common reason workers and unions turn against these systems, and it can suppress the near-miss reporting you want.
+Does the Illinois BIPA apply if our safety cameras do not use face recognition?
BIPA covers biometric identifiers such as face geometry, fingerprints and retina scans. A system that detects people, vehicles and PPE without extracting face geometry or identifying individuals is generally outside BIPA's core scope. Confirm in writing with the vendor exactly what the model extracts, stores and transmits.
Related reading
- Buying and piloting40 questions to ask AI safety vendors: an RFP checklist
- Buying and pilotingAI safety pilot acceptance criteria: how to define pass and fail
- Privacy and data protectionDPIA for Workplace Video Analytics: A Step-by-Step Template for UK and EU Sites
- Cameras and infrastructureExisting CCTV Readiness Checklist: Can Your Cameras Run Safety Analytics?
- RegulationThe EU AI Act and Workplace Safety Systems: What Applies and When
- Ports and terminalsVehicle-Pedestrian Separation in Port Yards: Technology Options for Terminals
- BuyingWhat AI Video Safety Vendors Publish for Buyers: A Public Evidence Check
Sources
- [1]Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex
- [2]EDPB Guidelines 3/2019 on processing of personal data through video devices
- [3]Article 29 Working Party, Opinion 2/2017 on data processing at work (WP249)
- [4]Article 29 Working Party, Guidelines on Data Protection Impact Assessment (WP248 rev.01)
- [5]ICO, Employment practices and data protection: monitoring workers
- [6]ICO, Can we use biometric data for time and access control and monitoring?
- [7]ICO orders Serco Leisure to stop using facial recognition technology to monitor attendance of leisure centre employees (February 2024)
- [8]DLA Piper, UK: Commencement of the data protection provisions in the Data (Use and Access) Act (February 2026)
- [9]Fieldfisher, Amazon France Logistique fined EUR 32 million for excessively intrusive employee monitoring
- [10]PPC Land, France slashes Amazon's GDPR fine from EUR 32M to EUR 15M over warehouse monitoring
- [11]Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
- [12]AI Act, Article 26: Obligations of deployers of high-risk AI systems
- [13]AI Act, Annex III: High-risk AI systems
- [14]AI Act, Recital 18
- [15]Future of Privacy Forum, Red lines under the EU AI Act: emotion recognition in the workplace
- [16]European Commission, AI Act: regulatory framework for AI (Digital Omnibus on AI, Regulation (EU) 2026/1744)
- [17]Gibson Dunn, EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changes
- [18]Directive (EU) 2024/2831 on improving working conditions in platform work, EUR-Lex
- [19]German Law International, The co-determination rights of works councils
- [20]Inside Privacy (Covington), Illinois enacts BIPA amendment limiting violation accrual
- [21]Jackson Lewis, 7th Circuit rules change to BIPA damages provision applies retroactively
- [22]Texas Attorney General, $1.4 billion settlement with Meta over biometric data
- [23]Washington State Legislature, Chapter 19.375 RCW: Biometric identifiers
- [24]Holland & Knight, California employee data exemption expires on January 1 (2023)
- [25]California Privacy Protection Agency, California finalizes regulations to strengthen consumers' privacy (September 2025)
- [26]Skadden, California finalizes CCPA regulations for ADMT, risk assessments and cybersecurity audits
- [27]New York Civil Rights Law Section 52-C
- [28]Epstein Becker Green, Inside Colorado's Senate Bill 26-189: impacts and implications for employers
- [29]NLRB, GC 25-05 Rescission of certain General Counsel memoranda
New chapters and updates, once a month
One email when we publish or update guidance. No vendor promotions. Unsubscribe any time.