The moment a people counting project usually stalls is not the pilot. It is week six, when the vendor's security questionnaire lands on the desk of your DPO and the answers to questions 14 through 22 — sub-processors, encryption at rest, deletion procedures — come back vague or contradictory. Procurement has already negotiated the price. Store operations wants the data. And now the whole rollout waits while someone works out whether the sensor on the ceiling is quietly creating a personal-data processing operation nobody signed off.
That scenario is avoidable, but only if security requirements for GDPR visitor analytics are written into the procurement documents before the pilot, not reverse-engineered afterwards. This article sets out what those requirements actually are — at the sensor, in transit, in the platform, and in the contract — for teams who have already read the generic "is people counting GDPR compliant?" explainers and need something they can put into an RFP.
The single most important security question in visitor analytics is whether personal data ever exists at all. GDPR obligations scale with risk, and the risk profile of a system that produces only anonymous aggregate counts is fundamentally different from one that stores video or biometric templates. Push vendors past marketing language ("privacy-first", "anonymised") to technical specifics:
A practitioner's note here: ask to inspect the sensor's diagnostic mode during the proof of concept. Several deployments have been derailed at audit because a technician-facing debug view could display live imagery, even though the production data flow was fully anonymous. If that view exists, it needs access controls, logging, and a mention in your records of processing — or it needs to be disabled at firmware level.
Counting sensors are IoT devices on your store network, and security teams should treat them exactly as they treat any other networked hardware. Minimum requirements worth writing into the contract:
Even fully anonymous count data has security requirements, because the analytics platform still holds commercially sensitive footfall figures, user accounts, and integration credentials. For enterprise buyers, three areas typically decide whether legal signs off:
If the system genuinely never processes personal data, some GDPR artefacts become lighter — but not optional. A short DPIA documenting why the data is anonymous (edge processing, no identifiers, aggregation) is your best defence in a supervisory-authority enquiry or a customer complaint. You will also want the vendor's cooperation clause for audits, a breach-notification commitment with a defined timeline, and clarity on what happens to configuration data and historical counts at contract exit. Compliance officers should insist the anonymisation claim is stated as a contractual warranty, not a marketing description; that shifts risk where it belongs.
One trade-off buyers should understand: the most privacy-protective architectures — full edge anonymisation, no image retention — remove the vendor's ability to "check the tape" when counts look wrong. That makes contractual accuracy commitments more important, not less. Vemco commits to a 96% contractual minimum, with 98–99% typically achieved when lighting, store layout and visitor behaviour allow. A vendor who guarantees a flat 99% while also claiming zero image retention is telling you one of those two claims is soft. Put both figures — the guaranteed floor and the typical range — in the contract, alongside the security schedule, and you have a document that satisfies procurement, IT and compliance in one pass.
The teams that move fastest are the ones who hand the vendor a single combined requirements list — sensor behaviour, network rules, hosting model, DPA terms, accuracy floor — before the pilot begins. Everything above fits on two pages. Write it once, and every future analytics procurement gets easier.
If you are preparing a security review or RFP for GDPR visitor analytics and want direct answers on hosting options, anonymisation architecture, staff exclusion and contractual accuracy terms, talk to the Vemco Group team — bring your security questionnaire, and we will complete it with you.