The widespread deployment of closed-circuit television (CCTV) systems across public, semi-public, and private environments has made video surveillance a central component of modern digital infrastructure. These systems play an increasingly important role in public safety, crime investigation, urban management, and operational monitoring. At the same time, they generate vast volumes of visual data that frequently contain highly sensitive personal information. This has led to growing societal, ethical, and legal concerns regarding privacy, data protection, and public trust in surveillance technologies. Within the European Union, these challenges are framed by the General Data Protection Regulation (GDPR), which establishes data protection as a fundamental right and requires lawful, transparent, and proportionate processing of personal data. Despite the regulatory clarity of the EU General Data Protection Regulation (GDPR), existing CCTV technologies remain largely misaligned with its core principles. Conventional surveillance systems typically store raw or weakly protected video footage, exposing data controllers to significant compliance risks. At the same time, large-scale CCTV infrastructures generate vast volumes of video data, much of which is redundant. Conversely, many privacy protection solutions rely on irreversible anonymisation techniques, such as permanent blurring or masking, which destroy evidential value and severely limit lawful analytics, post-event investigation, and forensic use. This situation creates a persistent gap between regulatory requirements and technological practice in real-world surveillance deployments. The need for data minimisation mechanisms further highlights the lack of GDPR-aligned design in existing surveillance technologies.
The overall objective of the project SISSVid (Secure and Intelligent Visual Data Storage for Analytics) was to design, implement, and validate a GDPR-compliant framework for secure storage, intelligent search, and retrieval of large-scale CCTV video data, without sacrificing analytical utility or operational efficiency. Our work was motivated by the recognition that privacy protection and effective surveillance analytics should be treated as complementary design requirements, rather than competing objectives.
Specifically, the project aimed to:
• Enable privacy-by-design video storage through selective and reversible protection of sensitive visual content;
• Implements the summarisation to identify frames containing meaningful events while filtering redundant content;
• Support intelligent search and retrieval directly over encrypted video data;
• Operationalise GDPR principles such as data minimisation, confidentiality, accountability, and lawful access in a technically feasible and scalable manner;
• Bridge the gap between legal compliance, technical implementation, and real-world surveillance needs.