- Regulation (EU) 2016/679 — GDPR, Articles 27 and 35
- Directive 2002/58/EC for device identifiers
- Regulation (EU) 2024/1689 — AI Act for biometric categorisation
Who has to appoint one
Vendors outside the Union supplying in-store analytics to EU retailers. MAC address collection, camera-based counting and beacon tracking all process personal data before any aggregation, and the vendor is usually a controller for its own product improvement purposes.
Thresholds and exemptions
None. Data protection authorities have consistently held that device identifiers and camera images are personal data even where the retailer only wants counts.
What must appear on the label
Not physical, but signage informing customers is required in practice, and several authorities require it at every entrance with meaningful detail rather than a pictogram.
Marketplace fields
Retail buyers require a data protection impact assessment they can rely on, and several deployments have been stopped by authorities after complaints about undisclosed tracking.
Documentation you must hold
Article 30 records, Article 28 terms with retailers, the Article 27 designation, a data protection impact assessment, documentation of the anonymisation or pseudonymisation method with its limitations, and retention and deletion procedures.
Standards and testing
Verification that the claimed anonymisation actually prevents re-identification, which authorities test rather than assume, and for AI-based demographic estimation, accuracy and bias evaluation.
Language requirements
Customer-facing signage in the language of the store's location.
When it applies
Before deployment. The impact assessment must precede processing, not follow a complaint.
How long records are kept
Raw identifiers and images for the shortest possible period, ideally seconds, with only aggregates retained. Retaining raw data for later analysis defeats the anonymisation argument.
What happens if you do not comply
Up to €20 million or 4% of turnover, and orders to stop processing, which have been issued against footfall systems in several member states.
Who enforces it
Data protection authorities.
Where the boundary lies
Estimating age or gender from camera images is biometric categorisation, which under the AI Act is prohibited where it infers sensitive attributes and otherwise heavily regulated. Counting people without identifying them is possible, but only with genuine on-device processing that never stores images.
Questions we are asked
- Is MAC address tracking anonymous?
- No. Randomisation has weakened it commercially, but where identifiers can single out a device the data is personal, and authorities have fined operators of such systems.
- Can we estimate customer age from cameras?
- Biometric categorisation to infer sensitive characteristics is prohibited under the AI Act, and demographic estimation generally requires a strong basis and is often disproportionate for marketing.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom