ฉบับเบต้า · เนื้อหาบางส่วนแปลด้วยเครื่องหรือแสดงเป็นภาษาอังกฤษ
Skip to content
Back to blog
Insight2023-11-148 min

CCTV anonymization: what to check before store analytics

Map the camera, recorder, analysis pipeline and shared results before deployment. Learn what anonymization changes and which operating decisions remain yours.

Author DEEPINGSOURCE

Store analytics can answer questions about visits and movement without making a customer's identity the purpose of the analysis. Before choosing a system, map what happens to the video at input, during processing and after analysis. An anonymized analysis pipeline and an existing camera recorder are separate parts of that review.

What video anonymization means

Video anonymization aims to remove the information that makes a person identifiable while retaining the signals needed for a defined task. A name replaced with a code is not, by itself, proof of anonymity. Other available information and the possibility of linking records matter. The UK's ICO introduction to anonymization explains that distinction in its UK context.

For a store project, start with the question the output must answer. Hourly visits or movement through a shared aisle need a different level of detail from an identifiable customer history. Choose the fields and time resolution needed for the task before deciding what to retain.

Draw the recording and analysis paths separately

The phrase “anonymized CCTV” describes a processing arrangement; it does not tell you how every connected device behaves. Review these points with the provider and your own operations team:

  • Camera input: which feeds and areas enter the analysis, and which areas are excluded.
  • Processing: where anonymization takes place and what happens before the next analysis step.
  • Storage: what is retained by the analysis service, camera memory, recorder, backups and diagnostic tools.
  • Sharing: which results users can view or export, who receives them and when copies are removed.

If an existing recorder stores its own camera feed, adding an anonymized analysis path does not automatically change that recorder's settings. Mark that separate recording path on the diagram. Check its purpose, access and retention with the responsible team rather than assuming the analytics product manages it.

Where SEAL fits

The technology overview describes anonymization at input, before analysis, with original video not retained in the analysis system. SEAL is the SDK used to integrate anonymization into a video pipeline. It is designed to remove identity information while preserving scene signals for analysis.

Use those descriptions as the starting point for a deployment review. Ask where the SDK is integrated, which outputs are enabled, and what the connected systems retain. Evaluate the intended analytics task using representative camera angles, lighting and occlusion. A statement about preserving useful signals is not a guarantee of identical accuracy for every model and scene.

Put privacy decisions into the design

Privacy by design means making these decisions while defining the project, then maintaining them during operation. The ICO guidance on protection by design and default describes building safeguards into processing and limiting default use to what is needed. It is a design reference here, not a finding that a particular store meets local requirements.

For an illustrative checkout project, the initial question might be when the shared waiting area becomes busy. The team can document the relevant zone, the time intervals needed for comparison, the permitted viewers and the retention period. If the project later adds transaction or membership records, review that new combination before enabling it. A decision made for one output does not automatically cover a different use.

Keep the review useful after launch

When cameras, integrations or exports change, update the data-flow record. Give someone responsibility for access changes, retained copies and questions from staff or customers. Confirm applicable requirements with the people responsible for the installation and jurisdiction; a product feature alone does not settle them.

Write the operating question and the minimum output needed to answer it.
Map the recording path separately from the analysis path.
Confirm processing location, retained fields, access and deletion for each system.
Test the intended analytics task in representative conditions.
Review the design again when a data source or purpose changes.

Start a deployment review with the SEAL integration overview. Bring the data-flow record so the discussion can address your actual configuration.

#Company
DEEPINGSOURCE

Considering privacy AI?

Talk to our team about a rollout plan for multiple stores and HQ.