Images, timestamps, location and linked identifiers.
When systems see.
Infer. Act.
Privacy in the age of AI and surveillance. A practical guide to the boundaries that matter, the evidence to request and the decisions people remain accountable for.
Follow the chain.
Select a scenario. These are review patterns, not findings about a particular deployment.
Connected cameras
A camera system starts recording. Search, sharing and inference expand what the footage can do.
Movement patterns, associations or presence. Establish which capabilities are actually enabled.
A search, alert or disclosure may affect someone who never interacted with the operator.
Questions that move the review forward.
- What specific purpose justifies the locations and fields collected?
- Which search and sharing capabilities are enabled for this deployment?
- What retention and access rules are enforced, and where is the evidence?
Evidence to request.
- Deployment purpose and camera locations
- Local configuration and access logs
- Retention, sharing and oversight records
EU / EEA · final guidelines, January 2020
The boundary is bigger than the prompt.
Privacy review often starts with information entering a system. That remains important, but it is only the first boundary. An AI-enabled system may turn information into an inference, an inference into a recommendation, and a recommendation into an action. Review each transition separately.
A camera recording an entrance, software labelling a person and an agent sending a message have different consequences. Start by naming the actual activity. Avoid treating “AI” or “security” as a complete description of purpose.
Describe collection, inference and action in separate sentences.
Make the purpose specific enough to challenge.
Ask what outcome is needed, who benefits and what evidence supports the need. Then examine a less intrusive way to obtain that outcome. A legitimate organisational problem does not automatically justify every available feature.
Separate the original purpose from later uses. Information gathered for building security might later be proposed for attendance scoring. Treat that change as a new review question rather than assuming the first decision covers it.
Record the proposed use, alternatives and what would count as an unacceptable expansion.
A claim, a document and a test are different things.
A supplier’s privacy statement is a claim about practice. A contract can establish a commitment. A configuration record can show a setting. A relevant test or audit can provide evidence about implementation. None substitutes for every other layer.
NIST’s face recognition work distinguishes false positives from false negatives and shows why demographic effects and image conditions matter. Our practical interpretation: ask which result applies to the exact algorithm, version, task and setting. A general accuracy percentage cannot answer every deployment question.
Label evidence by type and document what it does not establish.
Human review needs authority, time and context.
Putting a person at the end of a workflow is not enough to show that the decision is meaningfully reviewed. Ask whether the reviewer understands the inputs, sees uncertainty, can request more evidence and can reject the recommendation.
The ICO’s worker-monitoring guidance discusses meaningful human involvement, but flags that its guidance is under review after UK legislative changes. Use the current official text for legal analysis. Our operational question is broader: could the person reviewing the outcome realistically change it?
Define what the reviewer can see, change and escalate before deployment.
Global systems still need local analysis.
A single vendor may serve people in many jurisdictions. Do not assume one contract or framework resolves all those contexts. Identify where people are affected, who determines the processing, which recipients receive information and which rules require examination.
Singapore’s PDPC publishes advisory guidance for personal data in AI recommendation and decision systems. Brazil’s ANPD explains international-transfer mechanisms under the LGPD. These are useful starting points for their respective contexts, not interchangeable permissions or a worldwide rulebook.
Create a jurisdiction-and-flow map, then verify the source status and applicable requirements.
Finish with ownership, not a score.
A useful review ends with evidence, unresolved issues, named owners and a decision rationale. A green badge or completed checklist can hide unanswered questions. Identify what must happen before someone authorises the next step.
Decide what change reopens the review: a new model, a new recipient, broader access, a new purpose or an unexpected effect on people. Keep the review connected to the system’s life rather than treating it as a document produced once.
Assign the next action, target date and accountable reviewer; record review triggers.
Read beyond our interpretation.
PrivacyAF authored the review patterns and practical questions. Official sources support the attributed statements; they do not endorse this guide. This is educational analysis, not a legal opinion or a complete regulatory assessment.
Better questions.
A stronger community.
Prepare a brief for your team or contribute a perspective from your region.