
Clearview AI was fined €30.5 million by the Dutch DPA in 2024, and that was not its first fine. EU regulators have hit it seven times since 2020, totalling over €100 million. The product worked. Accuracy was not the problem. The problem was what the system was doing with data that regulators classify as among the most sensitive on earth.
That distinction between a system that performs well and a system that is lawful to operate is the trap most enterprise buyers walk straight into when they procure face recognition for their sites.
Listen to this podcast!
Why Accuracy Is the Wrong First Question

Procurement conversations for AI video surveillance almost always start with accuracy. Understandably so. But accuracy distracts from the harder question: what does this system generate, where does it store it, and which regulations govern that data in every country where you deploy?
Face recognition generates biometric data. Under GDPR Regulation (EU) 2016/679, biometric data is classified as special-category data, the highest-sensitivity tier, alongside health records and racial or ethnic origin. The same processing that makes face recognition operationally useful is the processing that triggers the most stringent regulatory obligations. That is not a trade-off you can engineer away; it is baked into the category.
GDPR is not the only framework in play. HIPAA, CCPA, and Illinois BIPA govern not just how data is stored but how it is captured and processed, and BIPA, in particular, requires written consent before a private entity collects biometric identifiers. Multi-site enterprises operating across jurisdictions may face all four simultaneously, with differing obligations that cannot be resolved by a single policy.
Facial recognition AI processes face geometry, which GDPR classifies as special-category data requiring explicit consent and heightened security. Most buyers learn this after deployment, not before.
The Logging Problem Nobody Mentions in the Demo
Here is where it gets operationally concrete. When VideoraIQ‘s Face Recognition module matches a face against a watchlist, the system generates an automatic access log. That log is the point. It replaces manual entry, paper lists, and the chronic failure mode of former contractors whose credentials nobody ever revoked.
But that log, along with the attached video clip, location tag, and timestamp delivered with every alert, is itself subject to biometric data retention rules. The alert payload is not just an operational artefact. It is regulated data with a clock on it.
This matters because of a figure that should stop every security director cold: 85% of CCTV footage is never reviewed, meaning biometric data is captured, stored, and never acted on. Under GDPR’s data minimisation principle, that unused footage is not neutral. It is a liability. Every day it sits in storage without a documented lawful basis for retention is a day of exposure.
Number plate recognition compounds this. Vehicle plate recognition generates movement history cross-site records of when a given vehicle entered or left each facility. VideoraIQ’s ANPR module logs every vehicle entry and exit and runs blacklist matching across all sites simultaneously. That cross-site movement record carries its own regulatory exposure depending on jurisdiction. Buyers who treat ANPR as a simpler, lower-risk alternative to face recognition are frequently wrong.
The Stale Watchlist Is a Compliance Risk, Not Just an Operational One
Procurement teams spend time evaluating accuracy benchmarks. They spend almost no time evaluating watchlist latency how long it takes for a new entry to propagate to live cameras after it is added.
This matters for two reasons. First, operationally: a new entry added mid-shift may not propagate to live cameras instantly, which means a person added to a restricted watchlist mid-day may move through the facility before any camera matches against the updated list.
Second, the compliance angle is distinct. A system that is supposed to prevent unauthorised access but fails to propagate updates reliably has a documented control gap. Its stated capabilities do not match its actual behaviour, nd that is exactly what regulators examine when something goes wrong.
The recommended pilot test is simple: add a new watchlist entry mid-shift and measure how long before live cameras match against it. Most vendors will not volunteer this test. Run it anyway.
What Lawful Deployment Actually Requires
Compliance cannot be delegated entirely to the vendor. Buyers must map their specific data flows against the regulations active in each deployment country. A platform being GDPR and HIPAA compliant, as VideoraIQ is, establishes the technical and organisational baseline. It does not eliminate the buyer’s obligation to determine the lawful basis for processing in each jurisdiction, implement retention schedules, and document data-subject rights procedures.
These steps belong in your procurement process, not your post-deployment remediation list:
- Map data categories before you map camera feeds: Identify which features generate biometric data (face recognition), movement history (ANPR), or access logs that qualify as personal data. Each category may require a separate lawful basis.
- Set retention schedules at configuration, not at audit: If alert clips are retained indefinitely by default, the system is non-compliant by default. Define retention periods for each data type before go-live.
- Pilot on roughly 20 cameras before scaling: Track false positive rate and mean time from event to operator receipt. At a 200-camera corporate campus, face recognition engines operating at 95–97% accuracy produce hundreds of false-positive alerts per shift, generating regulated data for non-events at scale. Know that number before you have 480 cameras running.
- Test watchlist propagation latency during the pilot: Not as a box to tick, as a documented control you can produce if questioned.
- Verify compliance posture explicitly: A platform that cannot demonstrate alignment with GDPR, CCPA, BIPA, or HIPAA is a procurement risk regardless of its accuracy score.
Read More!
Face Recognition Compliance: Deploy Without Legal Risk
The Market Is Growing Fast, and So Is Regulatory Scrutiny
The global AI-powered video analytics market was valued at $5.63 billion in 2025 and is projected to reach $23.03 billion by 2034, driven by the convergence of AI, deep learning, and edge computing. Regulatory capacity is scaling alongside it. The Clearview AI enforcement pattern repeated, cross-border, and cumulative is not an outlier. It is the template regulators are using.
Detailed, automated logs identify unusual activity and support investigations when issues arise. Continuous monitoring ensures suspicious behavior is flagged early. But those same logs become evidence in a regulatory inquiry if they were generated without a documented lawful basis. The operational value and the compliance exposure are the same artefact.
A platform operating at 99.4% detection accuracy across more than 10,000 cameras in 7 or more countries, with sub-3-second alert latency, is technically capable of generating an enormous volume of biometric data very quickly. The question is not whether your platform can do that. The question is whether your organization has the governance structure to make doing it lawful.
Get the compliance foundation right during procurement. The accuracy scores are the easy part.
Start your free VideoraIQ trial and see how a GDPR and HIPAA-compliant video intelligence platform handles face recognition, ANPR, and alert logging with the audit trail your compliance team will eventually ask for.




