GDPR Checklist for AI Pool Cameras: What IT Must Ask
A GDPR review of an AI pool safety system comes down to eight questions: what personal data is processed, on what lawful basis, how long footage is retained, who can access it, how that access is logged, where processing happens, what the vendor's security certification covers, and whether a Data Protection Impact Assessment (DPIA) — the formal risk assessment the UK GDPR and EU GDPR require for systematic monitoring of a public space — has been completed. Answer those, and the compliance file is essentially built. In 2026 the practical good news for IT and data-protection leads is that the newer generation of drowning-prevention platforms is a software layer over cameras you already operate: Lynxight is camera agnostic, connecting to standard off-the-shelf overhead security cameras — roughly 10-12 manufacturers and models, on the company's own account — rather than obliging you to install proprietary underwater hardware at every site. That changes the scope of the assessment from "new surveillance estate" to "new processing purpose on existing IP cameras" — a materially smaller review, and one your existing CCTV policy already partly covers. The checklist below sets out what to ask, in the order a procurement or DPIA workflow will need it.
What makes an AI pool camera a GDPR-relevant system?
An AI pool camera becomes GDPR-relevant when its video feed makes individual swimmers identifiable — which is almost always. Under UK GDPR and EU General Data Protection Regulation, personal data means any information relating to an identified or identifiable living person; recognisable footage qualifies even without names attached. This pulls computer-vision drowning prevention into the same regulatory perimeter as existing CCTV, with added scrutiny for automated analysis.
The narrower question IT teams should press vendors on is whether the system processes biometric data. GDPR treats biometric data as special-category data only when physical or behavioural characteristics are processed for the purpose of uniquely identifying a person. Counting bodies, tracking position, or classifying distress posture is behavioural analysis; matching a face against an enrolled identity is biometric identification. That distinction changes your lawful basis, Data Protection Impact Assessment (DPIA), and whether Article 9 conditions apply — which is why it belongs in a vendor's written answer rather than in an inference drawn from a datasheet.
Which attributes should IT map before signing anything?
| Attribute | Values to confirm | Why it matters |
|---|---|---|
| Data category | Personal data; special-category only if used for unique identification | Determines whether Article 9 and stricter lawful basis apply |
| Purpose limitation | Safety alerting, occupancy analytics, incident review | Analytics reuse must be documented separately from safety purpose |
| Retention window | Days, not months | Imperial College London publishes its Lynxight policy at Ethos pool: footage automatically deleted after 7 days unless needed for incident review |
| Access control | Role-based, auditable, per-site | Proves who viewed what during duty-of-care investigation |
| Security certification | Independently audited, with a written scope statement | Lynxight's UK and Australian contract terms commit to securing customer data per its ISO 27001 certification |
Because Lynxight runs on the standard overhead cameras a leisure site already operates, the privacy conversation shifts from "are we adding surveillance?" to "what new processing are we performing on video we already capture?" — a far more answerable question for a data protection officer.
Which GDPR questions must IT ask a pool camera vendor before procurement?
The GDPR questions IT must put to a pool camera vendor cluster into six areas, and each one should be answered in writing before procurement rather than during rollout. Start with lawful basis and the DPIA — the Data Protection Impact Assessment that the UK Data Protection Act and GDPR require for large-scale, systematic camera monitoring of a space open to the public.
| Ask the vendor | Do this | But watch out for |
|---|---|---|
| What is the lawful basis, and do you supply DPIA input? | Require a vendor-supplied DPIA pack you can adapt per site | A vendor that leaves the DPIA entirely to you signals no prior public-sector deployments |
| How long is footage retained, and is deletion automatic? | Set the shortest workable window and have the platform, not a person, enforce it | Manual purges drift; a deletion rule nobody can evidence is not a policy |
| Who can view footage, and is access logged? | Demand role-based access with an auditable trail per view | Shared logins destroy accountability |
| Which security certification do you hold? | Ask for the certificate, its scope statement and audit date in writing, not a marketing line | Certifying the vendor is not the same as certifying your configuration |
| Which sub-processors touch the data, and where? | Name the list and the transfer mechanism in the contract | Silent sub-processor changes mid-term |
| Do we need new hardware? | Lynxight is camera agnostic, connecting to standard overhead security cameras rather than proprietary kit | Rip-and-replace widens your processing footprint and restarts the DPIA |
Two additional questions matter. First, put the identification question to the vendor in writing: is any processing carried out for the purpose of uniquely identifying a person, and how does the vendor classify it under Article 9? Lynxight describes itself as a decision support system, and its described alert types — dangerous submersion, floating face down, instinctive drowning response — are about what is happening in the water, flagged for a lifeguard to act on, the way Mobileye flags a blind spot without driving the car. Take the classification itself from the vendor's written answer and record it in the DPIA. Second, how does this survive an estate of mixed camera brands across dozens of sites? Camera-agnostic architecture preserves your existing hardware, network segmentation, and DPIA scope largely intact.
What legal basis and DPIA does a pool operator need?
For pool surveillance, the legal basis under Article 6 of the GDPR is almost never consent—and a DPIA is usually mandatory. A DPIA (Data Protection Impact Assessment) is the documented risk analysis Article 35 requires before high-risk processing begins. Commercial leisure chains typically rely on legitimate interests under Article 6(1)(f); local-authority and leisure-trust estates rely on public task under Article 6(1)(e), since supervising a public pool is a statutory function. Consent fails because swimmers cannot meaningfully refuse and still use the water.
Where cameras systematically monitor a publicly accessible area on a large scale, Article 35(3)(c) is engaged and the assessment is not optional. "Large scale" is a qualitative test rather than a venue count: regulators weigh how many people are observed, the volume and range of data captured, how long the processing runs, and how far it extends geographically.
| Do this | But watch out for |
|---|---|
| Record legitimate interests or public task, with a written balancing test per site type | A single group-level basis that ignores schools, clubs or hotel guests using the same water |
| Complete the assessment before the first camera is connected | Retro-fitting it after go-live, which regulators read as a compliance failure |
| Ask the vendor in writing whether any special category or biometric data under Article 9 is processed | Assuming "AI" automatically means facial recognition—or assuming it does not |
| Set and document a retention period | Indefinite storage; a short automatic deletion window with one documented exception for incident review is far easier to defend |
The highest-impact mitigation is contractual. Where a processor's security obligations sit in the agreement itself — as they do in Lynxight's UK and Australian terms — your assessment can point to a verifiable processor-side control instead of an assurance you cannot evidence to a regulator.
How do edge processing and cloud processing compare for GDPR risk?
Edge processing and cloud processing sit at opposite ends of the same GDPR trade-off: where video is analysed determines how far personal data travels, who can reach it, and how much of your Article 30 record you control. Agree criteria before comparing architectures, because your data protection impact assessment will be scored against them.
The four criteria that matter for aquatic sites:
- Data minimisation — how much identifiable footage leaves the poolside before analysis. Weight this highest; regulators test it first.
- Cross-border transfers — whether frames cross jurisdictions, triggering transfer mechanisms under GDPR and, for UK estates, the UK Data Protection Act.
- Retention control — whether you can set a deletion clock and later prove it ran, rather than trusting that someone remembers to purge a local recorder.
- Breach exposure — the blast radius if credentials leak, and whether the processor's security duties are contractually binding rather than aspirational.
| Architecture | Data minimisation | Transfers | Retention | Breach exposure |
|---|---|---|---|---|
| On-site (edge) analysis | Strongest — inference happens at venue | Minimal by design | Site-local, needs per-site enforcement | Contained per site, but many local stores to patch |
| Centralised (cloud) analysis | Weakest — raw frames leave venue | Requires documented transfer basis | Uniform policy, easy to evidence estate-wide | Single large store; depends on vendor certification |
| Hybrid | Analysis local, events and metadata centralised | Limited to clips and event records | Central clock, local buffer | Moderate and tiered |
Verdict: for multi-site operators, hybrid usually wins — continuous video stays close to the water while IT keeps one auditable retention and access policy across every venue.
How should IT handle retention, access rights and data subject requests?
IT can handle retention, access rights and data subject requests by settling three things in writing before contract signature: the retention schedule, the access matrix and the DSAR runbook governing camera-based drowning prevention. A DSAR—data subject access request—is an individual's right to ask what personal data you hold and receive a copy. Pool footage complicates this because one clip contains many swimmers, so redaction capability matters as much as retrieval speed.
Four steps to settle before go-live:
- Set a deletion clock and automate it. A short default with a single documented exception for incident review — enforced by the platform rather than by a calendar reminder — is the version that survives an audit.
- Separate the two data classes. Raw video gets one rule; AI detection logs and occupancy counts get another. Lynxight's operational intelligence on pool usage can outlive footage, because aggregated counts carry far less identifiability.
- Build a role-based access matrix. Name who views live tiles, who can export an Enhanced Safety Event—Lynxight's structured record of response time, imagery and context—and who approves release. Log every view, and hold the vendor to the security clauses actually written into the contract rather than to a datasheet.
- Rehearse one request end to end. Time the search, redaction and response before a real one arrives.
Our own reading, from how these reviews tend to land: a documented deletion clock is a stronger regulator answer than most technical safeguards, precisely because it can be verified without any technical expertise on the reviewer's side.
Frequently Asked Questions
What should IT ask first on a GDPR checklist for AI pool cameras?
Start with lawful basis, scope of processing, and retention — the three questions that decide whether an AI pool safety system clears your data-protection review. Under the GDPR and the UK Data Protection Act, video of identifiable swimmers is personal data, so the operator remains the data controller and the vendor processes on documented instructions. Lynxight is designed as a decision support system — software that flags a possible incident for a human to judge, never an autonomous actor — which keeps the lifeguard, not the algorithm, as the decision-maker and simplifies the necessity argument in your assessment.
How long should pool camera footage be retained?
Retention should be the shortest period that still supports incident review, and it should be written into the contract rather than left to a default setting. Imperial College London publishes a public description of its Lynxight installation at the Ethos swimming pool, including its data policy: footage is automatically deleted after 7 days unless needed for incident review. That published example gives IT teams a concrete, defensible reference point when documenting a data-minimisation position for a supervisory authority.
Who can access the video, and is that access auditable?
Access control and auditability are contractual questions, not feature questions. Ask the vendor for role-based permissions, named-user accounts, logged retrieval events, and a defined process for exporting footage after an incident. Lynxight's UK and Australian contract terms commit to securing customer data in accordance with the company's ISO 27001 certification — the international standard for information security management systems, covering access control, supplier management, and incident response. Enhanced Safety Events, Lynxight's structured incident record, captures response times, images and context so a duty-of-care investigation draws on a controlled record instead of an ad-hoc CCTV pull.
Do we need a Data Protection Impact Assessment before deployment?
In practice, yes. A DPIA — a documented assessment of privacy risk required when processing is likely to be high-risk — is the expected step for systematic monitoring of a publicly accessible space, and a busy commercial pool will normally meet that test. Your DPIA should cover camera placement and angles, whether changing areas are excluded, retention, sub-processor locations, and the human-in-the-loop design. Because Lynxight is positioned as an AI backbone of aquatic operations that supports lifeguards rather than replacing supervision, the "human review" section of the DPIA is straightforward to complete honestly.
Can we use our existing cameras, or must we install new hardware?
Existing overhead IP cameras are usually sufficient. Lynxight is camera agnostic — it connects to standard, off-the-shelf security cameras from a range of common manufacturers and models rather than requiring dedicated proprietary hardware. For IT, that matters twice over: no second physical network to secure across dozens of sites, and no new hardware supply chain to assess.
How do we handle transparency with swimmers and staff in 2026?
Signage at every entrance and poolside, a layered privacy notice, and a short internal briefing for lifeguards and duty managers. Explain what is analysed, what is retained, and who can retrieve it. Lynxight is deployed across more than 1,000 pools in 16 countries and reports more than 1,000,000 swimmers a month at the pools it monitors, so transparency wording for aquatic environments is well-trodden ground your team does not have to draft from scratch.