Guide

Video anonymization and privacy law: GDPR, CCPA and de-identification

What counts as personal data in footage, and why anonymization must be irreversible to fall out of scope.
By the Firsthand capture teamLast updated September 23, 2026

Short answer

Under regimes like GDPR, video showing an identifiable person is personal data. Anonymization aims to make a person no longer identifiable by any reasonably likely means — which requires irreversible redaction of faces, plates, screens, and identifying speech. Reversible masking is pseudonymization, which stays in scope. This is general information, not legal advice.

What in a video counts as personal data?

More than faces. A licence plate can be tied to a keeper; a name on a monitor, a badge, a letter, or a spoken address all identify a person; and in context even a distinctive tattoo or gait can. Under GDPR, any footage from which a living individual can be identified — directly or indirectly — is personal data, which is why a serious anonymization pass covers the whole set, not just the obvious faces.

  • Faces and heads of un-consented people
  • Licence plates linkable to a registered keeper
  • Legible screens, documents, forms, badges, and mail
  • Names, addresses, and numbers spoken in the audio
  • On request, distinctive identifying marks

What is the difference between anonymization and pseudonymization?

The line is reversibility. Pseudonymization replaces or hides an identifier in a way that can still be undone with additional information — a mask layer you can toggle off, or an un-blurred master kept alongside. Pseudonymized data is still personal data and stays in scope. Anonymization means the identifier cannot be recovered by any reasonably likely means; only then does the data fall outside the regime. That is why the redaction has to be baked into the pixels and any un-redacted source destroyed or controlled.

Reversible mask / blur overlay
Pseudonymization — still personal data, still in scope.
Un-blurred master kept alongside
Still identifiable via that copy — not anonymized.
Irreversible blur baked into pixels, source controlled
Anonymization — no reasonably likely means to re-identify.

What does an auditable anonymization record need to show?

If a regulator, a customer, or your own counsel asks whether a batch was anonymized, "we ran a blur tool" is not an answer. An auditable record shows, per file: which identifier classes were in scope, the detector version and settings, the recall measured on a labelled sample, who reviewed it, and what happened to the source footage. That record is what turns a privacy claim into something you can defend.

Firsthand delivers this record with every anonymization job and a data-processing summary suitable for a DPIA. This guide is general information, not legal advice — your counsel makes the determination for your jurisdiction and use.

Check it against the sample pack.

40 episodes across 4 environments, delivered in the exact schema these guides describe.