Everything About People Counting Solutions & Features

visitor analytics GDPR compliance — Complete Guide to Visitor Analytics GDPR Compliance | Vemco Group

Written by Admin | Aug 9, 2026, 7:19:19 PM

Here is the distinction that decides most visitor analytics GDPR compliance reviews: whether your counting system processes personal data at all. If a sensor captures identifiable images or device identifiers — even briefly, even if deleted later — you are inside the GDPR's full scope, with everything that implies for DPIAs, lawful basis, retention schedules and data subject rights. If the system produces only aggregate counts and never creates identifiable data in the first place, most of that burden disappears. Procurement teams routinely miss this fork in the road and spend months building compliance scaffolding around a system that never needed it — or worse, skip the scaffolding around one that did.

Why "anonymised" is the most abused word in vendor decks

Under GDPR, data is anonymous only if re-identification is impossible by any reasonably likely means — not merely difficult, not merely against policy. A camera feed that runs facial detection and then discards the frame still processed biometric-adjacent personal data at the moment of capture. Wi-Fi tracking that hashes MAC addresses produces pseudonymised data, which remains personal data under Recital 26. Several European data protection authorities have taken enforcement action on exactly this point, and the salted-hash defence has repeatedly failed because the hash still singles out an individual device over time.

So when a vendor says "anonymised", your compliance officer should ask three questions in writing: What does the sensor capture at the moment of detection? Where does any identifiable representation exist, for how long, and on which hardware? And can any output, combined with other data you hold, single out one person or device? If the answers are "silhouettes or depth maps, never, and no", you are dealing with data that arguably never becomes personal data. That is a fundamentally different procurement conversation.

Sensor technology determines your legal exposure

Your legal position is largely fixed the day you choose the counting technology. In rough order of GDPR risk:

  • Facial recognition or re-identification cameras — biometric data under Article 9. Explicit consent is effectively unworkable at a store entrance, which is why regulators keep striking these deployments down.

  • Wi-Fi and Bluetooth tracking — pseudonymised device identifiers, personal data by default, plus ePrivacy Directive obligations on top of GDPR in many member states.

  • Video analytics with on-edge anonymisation — defensible if identifiable frames genuinely never leave the device and never persist, but you must be able to prove that architecture, not just assert it.

  • 3D stereo, time-of-flight and thermal sensors — these detect shapes and movement, not faces or devices. Configured correctly, no identifiable data is created at any point in the pipeline. This is privacy by design in the Article 25 sense: compliance built into the hardware, not bolted on through policy.

This is the approach Vemco Group has built its people counting around since 2005: no personal identification at any stage, staff exclusion handled without identifying individual employees, and outputs that exist only as aggregate counts. Across more than 2,000 customers in over 95 countries, that architecture means the compliance conversation starts from "no personal data processed" rather than "here is our mitigation plan".

The staff exclusion trap

Here is something implementers learn the hard way: staff exclusion is where otherwise-clean deployments quietly acquire personal data. If your system excludes employees by recognising their faces or tracking their badges' Bluetooth signals, you are now processing employee personal data — and employee monitoring triggers works-council consultation in Germany, specific labour-law provisions in France and Spain, and heightened DPA scrutiny almost everywhere. Anonymous methods — zone-based exclusion, wearable tags that carry no identity, entrance-lane logic — keep the system clean. Ask the vendor precisely how exclusion works before signing, because retrofitting this is expensive and your works council will notice.

What your DPIA actually needs to say

Even where a system processes no personal data, a short screening assessment documenting why is worth its weight in audit hours. If personal data is processed, Article 35 likely requires a full DPIA given systematic monitoring of publicly accessible areas. Either way, the document should cover:

  • A data-flow diagram from sensor to dashboard, naming every system, network segment and jurisdiction the data touches.

  • Whether identifiable data exists at any point, including transiently in sensor memory during processing.

  • Hosting model and data residency — a private cloud or self-hosted deployment inside your own IT estate, which Vemco supports alongside hosted options, removes entire categories of transfer-impact analysis post-Schrems II.

  • Retention periods for raw sensor output versus aggregated counts, with the technical mechanism that enforces them.

  • Signage assessment: purely anonymous counting generally does not require Article 13 notices, but many retailers post brief signage anyway as a trust measure — decide deliberately and record the reasoning.

Procurement questions that separate real answers from marketing

Beyond the standard security questionnaire, put these to every shortlisted vendor:

  • Can you demonstrate, on hardware in our environment, that no identifiable image or identifier is retrievable from the device?

  • Which certifications do you hold, with current audit reports — not "aligned with" or "designed to meet"? Ask for the documents, and verify them independently.

  • How does the platform integrate with our existing IT systems and identity infrastructure, and what network access do sensors require? Counting sensors that demand broad outbound internet access from the store LAN will fail most enterprise security reviews.

  • What accuracy will you commit to contractually? Treat any flat guarantee of 98% or 99% with suspicion — honest vendors distinguish between contractual minimums and typical performance. Vemco, for instance, commits to a 96% contractual minimum, with 98–99% typical where lighting, store layout and visitor behaviour allow. That distinction matters for GDPR too: a vendor tempted to boost accuracy by capturing richer imagery is trading your compliance posture for a marketing number.

The controller-processor question nobody resolves early enough

If the system does process personal data, you are almost certainly the controller and the analytics vendor a processor — which means an Article 28 data processing agreement, documented sub-processor lists, and your name on any enforcement action. If it genuinely does not, a DPA may be unnecessary, but legal teams often insist on one anyway as belt-and-braces. Agree this classification during procurement, in writing, not after the contract is signed. It shapes liability allocation, breach notification duties and who answers when a data subject access request arrives citing "the cameras at the entrance".

The pattern across successful enterprise deployments is consistent: choose an architecture that avoids creating personal data, document why it qualifies as anonymous, keep staff exclusion identity-free, and hold vendors to written, verifiable answers. Do that, and visitor analytics becomes one of the least contentious items on your compliance register rather than a recurring audit finding.

Planning or reviewing a people counting deployment and need answers your DPO and security team will accept? Vemco Group has delivered GDPR-compliant, anonymous-by-design visitor analytics since 2005, with hosted and private cloud options that fit your existing IT estate. Contact us to walk through your data-flow, hosting and staff-exclusion requirements with a specialist before you commit budget.