The open question
Does re-publishing a live camera feed, one an operator already made public for their own purpose, on a third-party aggregation/OSINT-branded platform, at national scale, cross into processing that needs its own separate UK GDPR lawful basis?
None of the standard video-surveillance GDPR literature (EDPB, ICO, the usual law-firm explainers) addresses this fact pattern directly. It's all written for the organisation that installs and runs the camera, not a downstream aggregator.
UK and EU data protection law treats re-purposing public data as a live legal question, not a settled non-issue, precisely because the original publication had a specific intended use. IAPP's analysis of publicly available data under GDPR is explicit: "the GDPR applies in full irrespective of if the data are or were publicly available or not" and its legitimate-interest balancing test names purpose alignment as a distinct factor: reuse that stays close to why the data was originally published is more defensible; reuse for a materially different purpose weighs against it.
If a council publishes a traffic camera for road-condition/safety awareness. Redisplaying it for that same kind of purpose is a reasonably aligned reuse. Redisplaying it as part of a platform whose own SECURITY.md describes it as an "OSINT and cybersecurity monitoring tool" is arguably a different purpose than the operator intended and that mismatch is itself a factor against us in the balancing test, independent of anything technical we did right.
The same source also flags audience size as a factor. Limited-recipient use is more defensible than public dissemination, and a public map viewer sits on the less-favourable side of that compared to an internal tool.
For discussion
- Does the project's own framing/branding (OSINT/monitoring) create purpose-limitation exposure that a narrower "public traffic camera viewer" framing wouldn't?
- Is a public privacy/attribution notice (with a takedown-request path) worth building now, given it's the concrete thing Article 14(5)(b) actually asks for?
- At what point (scale, commercial use, real user base) does "we followed a careful, documented process" stop being sufficient and an actual solicitor review become necessary before merging further additions?
The open question
Does re-publishing a live camera feed, one an operator already made public for their own purpose, on a third-party aggregation/OSINT-branded platform, at national scale, cross into processing that needs its own separate UK GDPR lawful basis?
None of the standard video-surveillance GDPR literature (EDPB, ICO, the usual law-firm explainers) addresses this fact pattern directly. It's all written for the organisation that installs and runs the camera, not a downstream aggregator.
UK and EU data protection law treats re-purposing public data as a live legal question, not a settled non-issue, precisely because the original publication had a specific intended use. IAPP's analysis of publicly available data under GDPR is explicit: "the GDPR applies in full irrespective of if the data are or were publicly available or not" and its legitimate-interest balancing test names purpose alignment as a distinct factor: reuse that stays close to why the data was originally published is more defensible; reuse for a materially different purpose weighs against it.
If a council publishes a traffic camera for road-condition/safety awareness. Redisplaying it for that same kind of purpose is a reasonably aligned reuse. Redisplaying it as part of a platform whose own SECURITY.md describes it as an "OSINT and cybersecurity monitoring tool" is arguably a different purpose than the operator intended and that mismatch is itself a factor against us in the balancing test, independent of anything technical we did right.
The same source also flags audience size as a factor. Limited-recipient use is more defensible than public dissemination, and a public map viewer sits on the less-favourable side of that compared to an internal tool.
For discussion