EvidenceChain answer
What privacy safeguards exist for driver-facing camera data under the new EU mandate, and how does GDPR apply to in-car
The EU mandate that takes effect in 2026 requires all new vehicles to have interior-facing cameras that continuously monitor the driver’s eyes, face, head pose, and gaze direction [1]. Because this collects biometric data, the General Data Protection Regulation (GDPR) applies alongside the mandate’s own built‑in protections.
Privacy safeguards written into the mandate itself
The regulation doesn’t stop at simply ordering cameras. It includes a few direct privacy guards:
- GDPR compliance is a hard requirement – any handling of in‑cabin data must follow EU data protection rules (meaning GDPR) [2].
- Cybersecurity measures must be in place to block unauthorised access to the camera feed [2].
- Closed‑loop operation – the system must work on a closed‑loop basis, so the data stays local and isn’t sent to outside servers, which greatly cuts the risk of leaks [3].
On top of those, the mandate references GDPR directly, which means all of the GDPR safeguards described below automatically kick in.
How GDPR applies to in‑car biometric monitoring
Because driver‑facing cameras capture identifiable faces and can read biometric signals (like eye movements and head pose), GDPR treats the footage as personal data [4][9]. When the system also analyses facial geometry, eye‑closure rates or drowsiness scores, it falls under the stricter rules for biometric data [8][19]. Here is how GDPR’s privacy toolkit protects drivers:
Lawful basis and assessment
A fleet operator, manufacturer or any data controller must pick a valid legal ground for processing. “Legitimate interests” (such as ensuring safety) is a common choice, but the controller has to document a Legitimate Interests Assessment (LIA) to justify it [5][16].
Transparency and people’s rights
- Drivers must receive a privacy notice explaining what data is collected, how long it is kept, who can see it, and what rights they have [6].
- Clear, visible signage inside the vehicle must warn occupants that cameras are operating [11].
- All the usual data protection principles and individuals’ rights must be considered whenever in‑vehicle cameras are used [17].
- Drivers can request access to their own footage and ask for it to be deleted [6][15].
Data Protection Impact Assessment (DPIA)
Before a vehicle camera system is deployed, a DPIA must be carried out. It has to address the privacy risks for both drivers and passengers [10].
Data minimisation and storage limits
- Keeping personal data forever without a solid reason is not allowed under GDPR [7].
- Routine video should be deleted after a clearly defined, short period – typical good practice for commercial fleets is less than 72 hours [18].
- Continuous recording while the vehicle is used privately (outside working hours) is likely to be regarded as excessive [13].
- Drivers should have a simple way to turn off the recording during private use [14].
Extra‑strong rules for biometric data
- Cameras that analyse biometric signals (facial geometry, drowsiness, etc.) are subject to much tougher regulatory scrutiny than simple video recorders [8].
- AI‑powered cabin monitoring that accidentally picks up sensitive conversations could breach Article 9, which specifically protects biometric data [19].
- Any stored biometric template must be encrypted with state‑of‑the‑art algorithms, and the raw biometric readings should be processed in real time without ever being saved locally [29].
- Drivers must always be offered non‑biometric alternatives (e.g., a physical key or passcode) without extra constraints – biometrics cannot be forced [28].
Privacy by design and technical safeguards
GDPR requires that privacy is baked into the system from the start. In practice this means:
- Anonymising facial data where possible, capping retention periods, and keeping all data storage within the EU [18].
- Equipping cameras with physical shutters and LED activity lights so occupants can see when recording is happening [20].
- Using strong encryption (AES‑256) and tamper‑proof access logs to prevent data leaks [21].
- Giving drivers a real‑time disable button for rest breaks, and tiered access so only authorised staff can view recordings [22].
- Keeping audio recording switched off by default and turning it on only in truly exceptional circumstances [12].
- Processing most video analytics locally (edge computing) so that as little raw footage as possible leaves the vehicle [23].
Official oversight
The European Data Protection Board (EDPB) has specifically addressed in‑car cameras, reminding organisations that they must carefully assess their role under GDPR and comply fully [27][30].
What is coming next
Proposed EU legislation (such as the draft Connected Vehicles Data Act) is expected to add even more privacy protections:
- Dynamic consent management – drivers might give permission through an in‑cab touchscreen before recording starts [24].
- Federated learning – systems could improve their AI models without ever exporting raw video [25].
- Self‑destructing metadata – for example, automatic deletion of licence‑plate data after a parking event so it doesn’t linger [26].
In short, the new EU mandate does not leave driver‑facing camera data unguarded. It directly requires GDPR compliance, cybersecurity and closed‑loop operation. GDPR then layers on a comprehensive set of obligations – transparency, impact assessments, strict storage limits, special biometric rules, and a requirement to weave privacy into every piece of the system.
Discussion
Comments
Sign in to join the discussion
Comments are open to registered users so replies and notifications stay tied to a real account.
No comments yet. Be the first to add a useful angle.