Artificial Intelligence in CCTV Systems Connected to the Police: When Do You Need a DPIA, and When Is AI Prohibited?

18.8.2026 | Autor: Top privacy
8

A camera connected to the police + AI = GDPR, the AI Act, and joint liability all at once. When is a DPIA required, and when is an AI system outright prohibited?

Artificial Intelligence in CCTV Systems Connected to the Police: When Do You Need a DPIA, and When Is AI Prohibited?

A camera system connected to the city police or a government ministry is no longer just about GDPR. If artificial intelligence is added to the mix—facial recognition, automatic detection of suspicious behavior, tracking license plate numbers—the company or city finds itself at the intersection of three separate legal regimes at once, each with its own strict conditions. The combination of “AI + camera + connection to the government” therefore requires a significantly more thorough assessment than a standard parking lot camera system.

First Layer: GDPR and the PIA/DPIA Requirement

A camera recording constitutes personal data whenever a person in it is identifiable. In the case of large-scale, systematic monitoring of publicly accessible areas, conducting a Data Protection Impact Assessment (DPIA, also commonly referred to as PIA—Privacy Impact Assessment) in accordance with Article 35 of the GDPR is mandatory—this is one of the explicitly listed examples in both the Regulation and the list maintained by the Slovak Office for Personal Data Protection. Furthermore, if biometric data (e.g., a biometric facial scan for recognition purposes) is processed, this constitutes a special category of data processed on a large scale—which makes the DPIA requirement even more indisputable.

For public authorities, the legal basis for such processing is typically the public interest (Article 6(1)(e) of the GDPR), whereas a private camera operator cannot rely on this—it must base its processing on a legitimate interest and demonstrate it through a proportionality test. This is where the first practical problem arises: if a private company operates cameras and subsequently makes the recordings available to the police, it must have a separate, clearly defined legal basis for each of these two steps—one for the recording itself, and another for the transfer of the recording to a third party.

The Second Layer: The AI Act and the Question of Whether the Technology Is Permitted at All

It is here that a key distinction arises, one that is most often underestimated in practice. The AI Act (EU Regulation 2024/1689) distinguishes between:

  • real-time remote biometric identification in publicly accessible spaces for law enforcement purposes—which, according to Article 5 of the AI Act, is in principle prohibited, with narrowly defined exceptions (e.g., searching for kidnapping victims, threat of a terrorist attack), and only on the basis of a court order and under independent supervision;
  • subsequent (post) biometric identification, i.e., the evaluation of a pre-recorded image at a later time—this is not prohibited, but falls under the category of high-risk AI systems as defined in Annex III of the AI Act when used for law enforcement purposes, with a whole range of obligations (registration, human oversight, technical documentation, conformity assessment).

The difference between these two categories is not merely cosmetic—a violation of the prohibition under Article 5 is among the most severely penalized offenses in the entire regulation, with fines of up to 35 million euros or 7% of global turnover. Therefore, if a camera system linked to the police operates in real time and is capable of automatically recognizing specific individuals, it is essential to first resolve the issue of AI Act classification—only then does it make sense to address the DPIA, because in the case of a prohibited practice, no impact assessment can save the legality of the action.

It is particularly important to note that the non-targeted collection of faces from surveillance footage to create a facial recognition database is completely prohibited under Article 5 of the AI Act, with no exception for law enforcement agencies.

Third Layer: Who Is Actually the Data Controller When Data Flows to Multiple Entities

When a surveillance system is connected simultaneously to the municipality, the police, and the ministry, the question of joint liability (Article 26 of the GDPR) arises. If these entities jointly determine the purposes and means of processing (for example, they agree on when and under what conditions the police will be granted access to live footage), they are considered joint controllers, who must have a transparent agreement governing who fulfills which obligations toward data subjects. If the police only occasionally request a specific recording during the investigation of a specific incident, this constitutes a one-time disclosure of data to a third party rather than joint processing—the distinction is crucial because it determines who is responsible for informing the data subjects and who maintains records of the disclosed data.

What a PIA/DPIA Must Actually Include in Such a Case

When combining AI, cameras, and integration with government systems, a formal DPIA is not sufficient—it must include:

  • a systematic description of processing operations, including the precise data flow (who sees the data, where it is stored, who has access to it),
  • an assessment of necessity and appropriateness in relation to the intended purpose (proportionality test),
  • a separate assessment of the AI Act classification of the system and associated risks,
  • an evaluation of the risk to the rights and freedoms of data subjects and measures to mitigate them.

If, despite the measures taken, the DPIA indicates a high residual risk, the GDPR (Art. 36) requires prior consultation with the Slovak Data Protection Authority before processing begins—that is, before the cameras are actually turned on.

Key Takeaways

For AI cameras connected to the police or a government ministry, the sequence of steps is exactly the opposite of what most operators assume: first, it must be determined whether the technology is even permitted to operate as designed (AI Act classification), then determine who is responsible for what in the flow of data between entities (joint responsibility), and only then conduct the DPIA/PIA itself. The reverse order—deploying the technology first and addressing compliance afterward—is precisely the scenario that, for systems of this sensitivity, results in the highest fines under the entire EU regulatory framework.

We’d be happy to assist you with classifying your AI system, establishing joint liability, and preparing the DPIA itself—check out our service Compliance with Regulatory Requirements (DORA, NIS2, AI Act).


Top privacy

Top privacy

“High-quality content isn't created by copywriters, but by experts.”