Compliance

Video Surveillance & AI Camera Laws by Country: A Compliance Guide

GDPR, UK GDPR, PDPA, KVKK, PDPL and more — what each region actually requires for AI-processed video and biometric data, and how on-premises architecture changes the compliance picture.

Every region a facility operates in has its own rules for what can be done with video containing people, and biometric data specifically draws a heavier regulatory hand almost everywhere. This guide walks through the frameworks Vengeea's own regional deployments are built against — the same regulation names cited on our EU, UK, UAE, Singapore, Turkey and Vietnam pages — and then explains the pattern that runs underneath nearly all of them: why on-premises processing is a genuine architectural simplification for compliance, not just a privacy talking point.

European Union & EEA — GDPR and the AI Act

Across the EU/EEA, video and biometric processing sit under the General Data Protection Regulation, with member states layering their own implementing legislation on top. GDPR Article 9 classifies biometric data used for identification purposes as special-category data, requiring a stronger legal basis and typically a data protection impact assessment before deployment. Cross-border transfers of that data outside the EEA require additional safeguards — standard contractual clauses and a transfer impact assessment — unless the processing simply never crosses a border in the first place. The EU AI Act adds a further layer specifically for real-time biometric identification systems, classifying certain use cases as higher-risk and imposing additional documentation and governance requirements.

Non-biometric modules — intrusion, weapon, fire/smoke and LPR — generally sit outside the biometric-identification scope of the AI Act and carry a comparatively lighter compliance burden, though standard GDPR obligations (lawful basis, retention limits, data-subject rights) still apply to any video containing identifiable people.

United Kingdom — UK GDPR & Data Protection Act 2018

Post-Brexit, the UK operates its own UK GDPR alongside the Data Protection Act 2018, which mirrors the EU's structure closely: biometric identifiers are treated as special-category data, and the Information Commissioner's Office expects a DPIA for biometric video-analytics deployments. International-transfer safeguards apply to data leaving the UK in the same way SCCs apply under EU GDPR — a transfer mechanism has to be justified whenever personal data crosses the border, and that requirement doesn't arise when the data doesn't move.

Nordics & the Netherlands — national GDPR implementation

Denmark, Norway and the Netherlands each apply GDPR as EU/EEA member states, with their own national data-protection authorities enforcing it and, in some cases, additional national guidance on video surveillance and workplace monitoring specifically. The underlying framework — special-category treatment for biometric data, DPIA expectations for higher-risk processing, transfer safeguards for data leaving the EEA — is the same GDPR structure described above; the national layer mainly affects which authority you'd engage with and any country-specific procedural requirements (for example, some Nordic countries have historically had additional expectations around employee notification for workplace video monitoring).

Singapore — PDPA & IMDA guidance

Singapore's Personal Data Protection Act (PDPA) governs the collection, use and disclosure of personal data, including video containing identifiable individuals, with the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC) providing sector guidance relevant to biometric and video-analytics deployments. The PDPA imposes a transfer-limitation obligation on personal data leaving Singapore — broadly, data can only be transferred overseas if the recipient jurisdiction provides a comparable standard of protection, which in practice means cross-border transfer of video or biometric data requires active justification. Processing that stays inside Singapore doesn't trigger that obligation because no transfer occurs.

Turkey — KVKK

Turkey's Kişisel Verilerin Korunması Kanunu (KVKK — Law on the Protection of Personal Data) governs personal data processing broadly, with Article 6 specifically addressing special-category data, including biometric identifiers, and requiring express consent or another specific legal basis for its processing. KVKK has well-documented data-localisation leanings, and cross-border transfer of personal data — biometric data especially — draws additional scrutiny from the Turkish Data Protection Authority (KVKK Kurumu). Processing and storing data inside Turkey, on infrastructure the customer controls, keeps a deployment out of that cross-border-transfer conversation entirely.

UAE — Federal Data Protection Law

The UAE's Federal Decree-Law No. 45 of 2021 (the Federal Data Protection Law) establishes the country's general data-protection framework, and data residency is frequently treated as a hard requirement — not merely a preference — in government and critical-infrastructure procurement specifically. Free-zone entities such as DIFC and ADGM operate under their own separate data-protection regimes layered on top of, or alongside, federal law, meaning a deployment spanning onshore and free-zone sites may need to satisfy more than one framework simultaneously. On-premises, per-site processing sidesteps the question of which cloud region a vendor's default deployment lands data in, because each site's data stays inside that site's own jurisdiction.

Vietnam — PDPL (Decree 13/2023/NĐ-CP) & Cybersecurity Law

Vietnam's Personal Data Protection Decree, Decree 13/2023/NĐ-CP, sets out data-localisation and cross-border-transfer restrictions on personal data, working alongside the 2018 Cybersecurity Law's own data-localisation provisions for certain categories of data and service providers. Together, these create a regulatory environment where processing and storing data inside Vietnam is the more straightforward compliance path, and cross-border transfer of personal data — again, particularly biometric data — requires meeting specific conditions under the decree rather than being a default option.

Need this mapped to your specific region and facility? This isn't legal advice — but our team can walk your compliance or legal team through how the on-prem architecture applies.

Talk to the team →

The pattern underneath all of it

Read across these frameworks and a consistent shape emerges, even though the statutory language and enforcement mechanisms differ country to country:

  • Biometric data gets a heavier compliance burden almost everywhere. Face-match and other biometric identifiers are treated as a special or sensitive category of personal data under GDPR, KVKK, and most comparable frameworks, requiring a stronger legal basis, more documentation, and typically a formal impact assessment before deployment — regardless of jurisdiction. Non-biometric modules generally don't trigger that heavier category.
  • Cross-border transfer is where the compliance cost concentrates. Every framework above has some version of the same rule: moving personal data — especially biometric data — outside the country or region requires justification, whether that's SCCs and a transfer impact assessment under GDPR, a comparable-protection test under Singapore's PDPA, or a localisation requirement under Vietnam's Decree 13. That justification is what a cloud vendor has to solve for on every deployment: which region does the data land in, which SCCs apply, which sub-processors touch it.
  • Processing that never crosses a border sidesteps that requirement rather than satisfying it after the fact. This is the core reason on-premises, in-country architecture is a genuine compliance simplification and not just a privacy nice-to-have: if video and biometric templates are processed and stored on a server inside the customer's own facility, inside the country where that facility sits, there is no international data flow to justify in the first place. The transfer mechanism a cloud vendor has to build and maintain simply doesn't need to exist.
  • On-prem doesn't eliminate the underlying obligations. Lawful basis for processing, retention limits, access controls, audit logging, and (for biometric modules) an impact assessment are still required regardless of where the server sits. What changes is which parts of the compliance checklist are architecturally solved versus which still require active governance from the customer's own data protection function.

EU / EEA

GDPR Art. 9 (special category) + AI Act (biometric ID) + national implementing law

UK

UK GDPR + Data Protection Act 2018, ICO DPIA expectations

Singapore

PDPA transfer-limitation obligation + IMDA / PDPC guidance

Turkey

KVKK Art. 6 (special category) + data-localisation leanings

UAE

Federal Decree-Law No. 45 of 2021 + free-zone regimes (DIFC, ADGM)

Vietnam

Decree 13/2023/NĐ-CP (PDPL) + 2018 Cybersecurity Law

Not legal advice. This article is general educational information about the regulatory frameworks that apply to video and biometric processing in the regions Vengeea serves, based on publicly available statutory names and provisions. It is not a substitute for legal advice. Specific deployments — including which legal basis applies, what a DPIA needs to cover, and how free-zone or sectoral rules interact with national law — should be confirmed with qualified privacy counsel familiar with the applicable jurisdiction.

FAQ

Frequently asked questions

Is facial recognition treated differently from other video analytics under most privacy laws?

Yes, almost universally. Facial recognition involves biometric identifiers, which most modern data-protection frameworks — GDPR's Article 9, KVKK's Article 6, and equivalents elsewhere — classify as a special or sensitive category of data requiring a stronger legal basis, more documentation, and often a formal impact assessment before deployment. Non-biometric modules like intrusion detection, weapon detection, fire/smoke detection and LPR generally sit outside that special-category classification and carry a lighter compliance burden.

Does on-premises processing actually satisfy cross-border data transfer requirements?

On-premises processing doesn't satisfy a cross-border transfer requirement so much as remove the question entirely — if video and biometric data are processed and stored on a server inside the facility, inside the country, there is no transfer of that data to a foreign jurisdiction to begin with, so the mechanisms designed to justify a transfer (standard contractual clauses, adequacy decisions, local data-center commitments) simply don't come into play.

Do I still need a DPIA or privacy counsel if I deploy on-premises?

Yes. On-premises architecture simplifies the cross-border transfer question, but it does not eliminate the underlying data-protection obligations — lawful basis for processing, retention limits, access controls, data-subject rights, and (for biometric processing) a data protection impact assessment are still required in most jurisdictions regardless of where the server sits. Confirm specific obligations with qualified legal counsel for your deployment.

Which countries have the strictest rules on AI video surveillance?

It varies by what's being measured. The EU (via GDPR and the AI Act) has some of the most detailed rules specifically for biometric identification and high-risk AI systems. Several jurisdictions — including Turkey, Vietnam and China — lean toward data-localisation requirements that make in-country, on-premises processing the practically simpler compliance path regardless of the exact statutory language. There is no single global ranking; each region's framework has its own emphasis.

// Get started

Talk through your region's requirements

On-prem by default. No cross-border transfer to justify. Deployed across the EU, UK, GCC, Turkey, Vietnam and Singapore.