People counting privacy: 3D counters and Indivd compared

People counting privacy: 3D counters and Indivd compared

People counting privacy: 3D counters and Indivd compared

Indivd

7 min read

Intro

People counters are often described as sensors rather than cameras. But privacy depends less on the label than on what the system captures, processes, retains and allows people to see.

Two people-counting systems can produce the same entrance total while processing very different information along the way. One may calculate depth from two optical views and discard the visual input locally. Another may process conventional camera images through a documented anonymisation method.

This guide compares those data journeys from capture to deletion. It examines what can be seen during setup, what is retained during normal operation and which safeguards depend on configuration.

In brief

  • Some stereo 3D counters use two optical image sensors. Their routine output may be only counts or coordinates, but certain models can show live or still images and create validation recordings.

  • Edge processing can keep data local and reduce transfers. It does not by itself determine whether GDPR applies or whether the resulting data is anonymous.

  • Deletion and anonymisation answer different questions. Deletion limits retention. Anonymisation addresses whether a person can still be identified, singled out or linked across observations.

  • Indivd processes conventional camera images in volatile memory and deletes them within 1–3 milliseconds, before they can be written to disk. Anonymised intermediate data is retained for up to three hours for statistical aggregation.

  • The right comparison covers the complete installed data lifecycle: capture, transformation, access, output, retention, validation and configuration.

The short answer: A sensor or camera label does not establish the privacy outcome. Buyers should compare what each system processes, what people can see, what remains afterwards and which safeguards are documented.

About this comparison: Indivd publishes this guide and is one of the technologies discussed. We have based the comparison on public product documentation and linked to the relevant sources so readers can verify the claims directly.

How the two approaches compare

Privacy question

Stereo 3D people counters

Indivd

What enters the system?

Two optical views or a derived depth representation, depending on the device

Images from conventional 2D cameras

What is the privacy approach?

Local processing, minimisation and deletion of visual information

Anonymisation during processing, supported by rapid deletion and organisational controls

What normally leaves the system?

Counts, events or coordinates

Anonymised observations and aggregated statistics

Can visual information be viewed?

Often during installation; some models also support live views or validation recordings

Source images are processed transiently and cannot be saved to disk

What depends on configuration?

Privacy level, administrator access and validation functions

Enabled use cases, deployment purpose, access controls and customer configuration

How long is intermediate data retained?

Depends on the product and validation configuration

Up to three hours for statistical aggregation

This table describes common patterns, not every product. Verify the documentation for the exact technology, model, software version and configuration being considered.

The label does not decide the privacy assessment

A stereo 3D counter normally uses two optical sensors to calculate depth and detect a person crossing a counting line. Its routine output may contain only an entry or exit event, but some devices can still display live images, show individual tracks or create recordings during setup and validation. Calling the product a sensor describes its purpose, not every stage of its data processing.

European data-protection rules focus on whether information relating to an identifiable person is processed. Processing includes collection and use. It is not limited to storage. The Swedish Authority for Privacy Protection states that camera-monitoring rules can apply even when images are viewed live and never recorded.

That does not make every visual sensor equally intrusive. On-device processing, short retention and restricted access can materially reduce privacy risk. The European Data Protection Board describes simple counting algorithms as less intrusive than more complex video analysis. The relevant question is how those safeguards operate in the installed system.

Not every 3D counter captures the same data

The term 3D people counter covers several technologies. They should not be treated as interchangeable.

Stereo vision uses two optical views to calculate depth. This is the closest comparison with a camera-based system such as Indivd and is the main focus of this guide.

Time of flight sends infrared light into a scene and measures how long the reflected light takes to return. The system commonly produces a depth map rather than an ordinary colour image. Some products may nevertheless provide visualisation or validation functions, so the exact model still needs to be reviewed.

Radar uses radio waves instead of visible or infrared images. Its privacy characteristics are materially different from an optical counter and should be evaluated separately.

Claims about live video, camera chips or validation clips should therefore name the relevant manufacturer and model. They should not be generalised to every 3D counter.

How stereo 3D counters handle data

Many stereo counters keep most processing inside the device. The sensor converts incoming visual information into detections, tracks and counts, then exports numeric results instead of a continuous video stream. Xovis, for example, says its sensors export anonymous coordinates or defined triggers rather than video streams. This architecture can reduce the number of copies, systems and organisations that handle the source data.

The same documentation shows why configuration matters. Xovis describes its stereo hardware as using “two optical CMOS image sensors”. Its PC Series manual states that its lowest privacy level shows unrestricted live video and tracking. The next level shows a still image, while higher levels remove image information from the interface. Xovis also describes recording snippets for remote data validation when the relevant setting is enabled.

Axis’s discontinued P8815-2 3D People Counter provides another documented example. Its datasheet lists an RGB CMOS sensor, H.264 and Motion JPEG video streams, and video-stream anonymisation. Axis replaced this legacy product with AXIS Object Analytics.

These examples do not describe every 3D counter. They show that routine numeric output, visual access and recording capability are separate properties that must be checked for the exact product.

What edge processing changes

Edge processing can provide meaningful privacy and security advantages:

  • It can keep source data close to where it was captured.

  • It can reduce copies and transfers.

  • It can limit the number of organisations receiving the data.

  • It can support data minimisation and reduce exposure in a breach.

Edge processing cannot answer every privacy question:

  • It does not determine whether GDPR applies.

  • It does not make initial image processing legally irrelevant.

  • It does not guarantee that administrators cannot view images.

  • It does not replace the controller’s assessment of purpose, legal basis and configuration.

The GDPR defines processing by what happens to personal data, not where it happens. Processing location affects the safeguards and obligations required, including processor agreements, transfer rules and security measures.

How Indivd handles data

Indivd uses conventional 2D cameras, so we treat the image-processing stage as part of the privacy assessment rather than describing the camera input itself as anonymous.

Our people-counting data flow is:

  1. A camera image is processed in volatile memory.

  2. The source image is deleted within 1–3 milliseconds, before it can be written to disk.

  3. A counting event is produced when a person enters, exits or passes a customer-defined zone.

  4. Anonymised intermediate data is retained for up to three hours for statistical aggregation.

  5. Aggregated insights are made available to the customer.

The system does not retain facial features or create biometric templates. Our DPIA guide for people counting describes the data flow, purposes, retention periods, hosting and customer responsibilities. Our anonymisation policy requires a documented risk assessment for changes that could affect the anonymisation method.

The Swedish Authority for Privacy Protection considered a defined Indivd people-counting implementation through prior consultation. Under the purposes and safeguards presented, the authority confirmed that legitimate interest could support that implementation.

This was not a general certification of Indivd or approval of every deployment. Each customer remains responsible for the purpose, legal basis, configuration, transparency measures and assessment of its installation.

Anonymisation and deletion are not the same

Deletion answers how long source data remains available. Anonymisation answers whether the information that remains can relate to an identifiable person. A strong privacy design may use both.

Regulators consider whether a person can be singled out, whether records relating to the same person can be linked and whether information can be inferred about that person. A total such as “125 visitors entered” presents a different risk from a stream of individual movement coordinates, even if neither contains a name.

Rapid deletion does not mean that the initial capture never occurred. Swedish guidance states that privacy-friendly technology can reduce intrusion while the initial capture and transformation may still be subject to GDPR and camera-monitoring requirements.

Demographic estimates require a separate assessment

Age or gender estimation should not automatically be equated with biometric identification. The EDPB Guidelines on processing personal data through video devices explain that video footage does not always constitute biometric data. The special-category rules in Article 9 of the GDPR apply when biometric data is processed for the purpose of uniquely identifying a person. Classification that does not seek to identify an individual is a different operation.

That does not make demographic estimation irrelevant to privacy. Its purpose, necessity, accuracy, fairness and transparency should be assessed separately from basic people counting. Indivd’s DPIA guide for demographic classification describes group-level aggregation and states that no biometric templates or facial-recognition mechanisms are used.

An overhead view is not automatically anonymous

The absence of a clear face can reduce identification risk, but it does not prove that identification is impossible. In a controlled study involving 100 participants, researchers matched people across top-view observations using depth-based body measurements and colour information from hair and clothing.

The study did not evaluate any commercial product discussed here. It supports a narrower point: camera position alone is not an anonymisation method. Resolution, available attributes, linkability and surrounding data also matter.

Setup and validation are part of the data lifecycle

The routine output of a counter may be only a number, while its setup interface reveals considerably more. A configuration view can show an entrance, visitors, counting zones and individual tracks. Accuracy validation may introduce recordings, remote access and longer retention.

FootfallCam documents audits based on short prerecorded clips, retained for up to seven days before verification and up to 30 days afterwards. Milesight’s VS133-P documentation describes video preview and a validation function that allows video to be downloaded. These are product-specific examples, not characteristics of every counter.

Before approving a deployment, establish:

  • whether a live or still image remains available after installation;

  • who can change the privacy mode;

  • whether validation recordings are enabled;

  • where recordings are stored and when they are deleted;

  • whether the vendor or an installation partner can access them; and

  • how access and configuration changes are logged.

These questions determine whether the installed system matches the privacy description used during procurement and in the customer’s DPIA.

Questions to ask every people counting vendor

Capture and identification

  • What information enters the system before a count is produced?

  • Is a conventional image, depth map or another representation created?

  • Could somebody be identified, singled out or linked across observations?

Access and validation

  • Can installers, administrators or the vendor view live or recorded images?

  • Are validation recordings enabled, and how long are they retained?

Output and governance

  • What leaves the device or processing environment?

  • Which safeguards depend on customer settings?

  • What documentation supports the data flow, retention schedule and privacy assessment?

The answers should identify the exact product version and configuration. Marketing descriptions are not a substitute for technical and governance documentation. For a broader procurement assessment, see How to choose a people counting system: 19 questions to ask vendors.

Choosing between the approaches

A stereo 3D counter can offer a narrow, locally processed data flow. For a straightforward entrance count, that may be an attractive privacy architecture when higher privacy settings are enforced and validation recording is tightly controlled.

Indivd takes a different approach. We accept conventional camera input and apply a documented anonymisation process supported by published governance material and DPIA guidance. This can be valuable when an organisation wants to use existing cameras or needs analytics beyond a basic doorway count.

Neither the word sensor nor the word anonymous resolves the assessment. The defensible comparison is the complete installed data lifecycle: capture, transformation, output, access, retention, validation and deletion. The best choice is the one whose capabilities match the purpose and whose safeguards can be verified in documentation and configuration.

SOURCES AND FURTHER READING

European Parliament and Council. (2016). Regulation (EU) 2016/679. See especially Recital 26 and Articles 4, 5, 9, 28, 32, 42 and 44.

European Data Protection Board. (2020). Guidelines 3/2019 on processing of personal data through video devices. Version 2.0.

Article 29 Data Protection Working Party. (2014). Opinion 05/2014 on anonymisation techniques.

Swedish Authority for Privacy Protection. Assessing whether camera monitoring is permitted. Guidance on personal-data processing and live camera monitoring.

Swedish Authority for Privacy Protection. Balancing interests for camera monitoring. Guidance covering privacy-friendly technology and safeguards.

Indivd. DPIA guide for people counting. Help Centre.

Indivd. Anonymisation policy. Help Centre.

Indivd. DPIA guide for demographic classification. Help Centre.

Xovis. 3D sensors and data privacy.

Xovis. PC Series sensor user manual. Privacy levels and visualisation settings.

Axis Communications. AXIS P8815-2 3D People Counter datasheet.

Axis Communications. AXIS P8815-2 support and discontinuation information.

Axis Communications. GDPR and Axis retail applications.

FootfallCam. Device accuracy audit. Documentation covering validation recordings and retention.

Milesight. VS133 AI ToF People Counting Sensor privacy and security guide.

Paolanti, M., Romeo, L., Liciotti, D., Pietrini, R., Cenci, A., Frontoni, E., and Zingaretti, P. (2018). Person re-identification with an RGB-D camera in a top-view configuration through multiple nearest neighbour classifiers and neighbourhood component features selection. Sensors, 18(10), 3471.

Common questions

Is people counting GDPR compliant?

People counting can be operated in accordance with GDPR, but compliance does not come from the product label alone. It depends on the purpose, legal basis, technology, configuration, access controls, retention periods and information provided to visitors. The organisation deploying the system remains responsible for assessing its particular use.

Do people counters record video or faces?

It depends on the product and configuration. Some people counters process visual information without retaining video during normal operation, while others can display live images or create short recordings for setup and accuracy validation. Buyers should check what is available during installation and validation as well as what happens during routine counting. Indivd processes source images in volatile memory and deletes them within 1–3 milliseconds, before they can be written to disk. Our system does not retain facial features or create biometric templates. The data flow is described in our DPIA guide for people counting.

Can people counters track individual visitors?

Some systems generate individual tracks or coordinates temporarily in order to determine whether somebody crossed a counting line. Whether this amounts to tracking depends on whether observations can be linked over time or across locations and whether a person can be singled out. Indivd uses transient, non-deterministic group identifiers for statistical processing. The system is not designed to identify a visitor or follow the same person between locations.

Does edge processing make people counting anonymous?

Not by itself. Edge processing describes where the data is processed, while anonymisation describes whether the resulting information can relate to an identifiable person. Processing inside a device can reduce transfers and copies, but visual information may still be personal data while it is being captured and analysed. A privacy-preserving design may combine local or controlled processing, rapid deletion, anonymisation, restricted access and clear retention rules.

No headings found on page