Balancing AI security with privacy and GDPR

Digital Content Editor, Eve Goode speaks exclusively with Elizabeth Davies, Chief Privacy Officer of Verkada about the importance of balancing AI security with privacy and GDPR.

As more organisations move to cloud-based security systems, how has the approach to privacy and GDPR changed?

Privacy has always been a core consideration in how leading security systems are designed, what’s evolved is the level of sophistication in how organisations approach security, and how central those conversations have become to the decision-making process.

For powerful security capabilities like facial recognition, conversations have shifted from “Is this allowed?” to “How do we use this correctly?”

As these technologies become more widely adopted, organisations are increasingly considering privacy from the outset.

Legal, compliance and data protection leaders are working alongside security teams to establish clear policies, ensure appropriate safeguards are in place and build trust from day one.

Cloud-based systems have made strong GDPR compliance more achievable at scale. Capabilities like audit trails, flexible data retention policies and options for regional data storage provide users with greater visibility and control over how data is managed.

This supports compliance while also helping organisations demonstrate accountability in a clear and practical way.

GDPR has set the standard across Europe, and its influence has become global.

As expectations around data protection continue to rise, the organisations that prioritise privacy today will be best positioned to navigate these evolving requirements and foster long-term trust.

What does “privacy by design” mean in practice for modern security technologies?

Privacy by design shows up in the everyday decisions that shape how a system functions.

It’s in default settings, how access is granted and every choice made about what data is and isn’t, collected.

The architecture itself supports a strong compliance posture from the start.

Practically, that means that sensitive capabilities like facial or licence plate recognition are typically restricted by default and require deliberate action from authorised administrators to enable.

Modern security platforms log all actions within the system, providing a clear record of who did what, when.

Features like face blurring, privacy regions and QR-code public disclosures are designed to make responsible choices the easiest ones for users to make.

And governance is continuing to evolve industry-wide. Privacy isn’t a one-time configuration at deployment – it requires ongoing visibility.

If settings can be changed without proper oversight and a clear record, there’s risk.

Organisations are more frequently looking for systems that provide transparency into these actions, whether through auditability or proactive alerts, so they can maintain confidence in their privacy controls as standards change.

How can organisations balance the benefits of AI-powered security tools with privacy and compliance requirements?

Balancing the benefits of AI-powered security tools with privacy and compliance requirements demands a deliberate approach to how the technology is scoped and governed.

This starts with the principle that AI should support human decision-making, never replace it.

Human oversight is key to ensuring these systems are used responsibly and accountability stays clear.

We’re also seeing a shift in how AI is evaluated.

It’s no longer just about whether it’s being used, but how it works and what it delivers. Buyers, regulators and the public want clarity on what a system is designed to do, and where its boundaries are.

Being able to explain that clearly is increasingly a marker of maturity in how organisations approach advanced systems and privacy.

AI is most impactful when it helps teams prioritise what’s happening in real time, rather than reviewing large volumes of footage or alerts following an event.

That value depends heavily on how data is handled. Systems that are designed with privacy built in from the start minimise unnecessary data transmission and reduce exposure by design.

A great example of this is a “person of interest only face search,” which immediately discards facial detections that don’t match a pre-defined list. 

AI doesn’t always need to operate at the individual level to be effective.

When systems rely on aggregated or tokenised insights rather than individual-level tracking, they can still surface relevant patterns and trends while reducing privacy risk.

This balance is what allows organisations to maintain strong performance while keeping privacy protections firmly in place.

What are the most common GDPR challenges organisations face when deploying security systems, and how can they avoid them?

Involving privacy and legal teams from the start helps organisations make better, more informed privacy decisions and streamlines the implementation process.

Challenges are identified early so that measures can be taken to balance the security and privacy risks.

Good governance is also key.

Having the confidence to know if your policies are well understood and followed by your security teams makes all the difference.

Accountability is the foundation for building community trust. Environments with multi-shift teams using shared access credentials creates blind spots, making it difficult to determine who performed a specific action, when and under what circumstances.

Individual, identity-based access controls address this by tying every action to a specific user.

This makes it easier to understand what happened, improves accountability and provides clearer records for audits or investigations.

Another key consideration is data minimisation.

Cloud-based systems can include configurable controls that allow organisations to limit data collection to only what is necessary, through configurable camera angles, privacy masking to obscure parts of a frame and the ability to enable or disable specific analytics.

These capabilities reduce data exposure and the compliance burden without limiting functionality.

Lastly, these systems are helping organisations improve visibility into sub-processor relationships.

Rather than relying on fragmented documentation or periodic checks, organisations can maintain a more continuous view of where data is hosted, how it moves across providers and what safeguards are in place.

This makes governance more operational, allowing oversight to be maintained as part of day-to-day system use rather than reconstructed retrospectively.

Looking ahead, what privacy and compliance trends should security leaders be preparing for?

The regulatory direction is becoming more consistent globally.

We’re seeing greater convergence across frameworks, clearer expectations around AI and a stronger shared understanding of what good data protection looks like in practice.

These changes are showing up directly in customer conversations.

The focus on AI has moved toward transparency and explainability: how systems are designed, what they’re optimised to do and explicitly what they aren’t intended to do.

This shift is only going to deepen as AI becomes more embedded in everyday security operations.

There’s also a growing emphasis on data control and ownership.

Expectations around how data is governed and how trust is operationalised in practice is rapidly changing.

Another notable trend is who is now involved in these decisions.

Privacy and compliance teams are now embedded in the entire process of security technology purchases.

This early involvement is helping raise the standard of evaluation and pushing organisations toward more deliberate and well-governed decisions.

This transformation is centered on maturity.

As these expectations evolve, they’re helping shape a clearer view of what good security technology should look like: balancing capability, accountability and trust.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *