Skip to content

Open question: does aggregating public UK webcam feeds need its own GDPR basis? #298

Description

@beecho01

The open question

Does re-publishing a live camera feed, one an operator already made public for their own purpose, on a third-party aggregation/OSINT-branded platform, at national scale, cross into processing that needs its own separate UK GDPR lawful basis?

None of the standard video-surveillance GDPR literature (EDPB, ICO, the usual law-firm explainers) addresses this fact pattern directly. It's all written for the organisation that installs and runs the camera, not a downstream aggregator.

UK and EU data protection law treats re-purposing public data as a live legal question, not a settled non-issue, precisely because the original publication had a specific intended use. IAPP's analysis of publicly available data under GDPR is explicit: "the GDPR applies in full irrespective of if the data are or were publicly available or not" and its legitimate-interest balancing test names purpose alignment as a distinct factor: reuse that stays close to why the data was originally published is more defensible; reuse for a materially different purpose weighs against it.

If a council publishes a traffic camera for road-condition/safety awareness. Redisplaying it for that same kind of purpose is a reasonably aligned reuse. Redisplaying it as part of a platform whose own SECURITY.md describes it as an "OSINT and cybersecurity monitoring tool" is arguably a different purpose than the operator intended and that mismatch is itself a factor against us in the balancing test, independent of anything technical we did right.

The same source also flags audience size as a factor. Limited-recipient use is more defensible than public dissemination, and a public map viewer sits on the less-favourable side of that compared to an internal tool.

For discussion

  • Does the project's own framing/branding (OSINT/monitoring) create purpose-limitation exposure that a narrower "public traffic camera viewer" framing wouldn't?
  • Is a public privacy/attribution notice (with a takedown-request path) worth building now, given it's the concrete thing Article 14(5)(b) actually asks for?
  • At what point (scale, commercial use, real user base) does "we followed a careful, documented process" stop being sufficient and an actual solicitor review become necessary before merging further additions?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions