Yes — people counting cameras are legal in Australia and in GDPR jurisdictions, provided they are genuinely anonymous: no facial recognition, no stored footage, and no data that could identify an individual. A privacy-first sensor that processes video on-device and emits only aggregate counts collects no personal information at all, which places it outside the obligations that apply to CCTV and visitor tracking. The legal risk sits with systems that record footage, stream video to the cloud, or track personal devices.
If you're evaluating a people counter for your store, this guide explains where the legal lines are, what the Australian Privacy Act and GDPR actually require, and the questions that separate privacy-safe sensors from surveillance dressed up as analytics.
Counting people is not the same as watching people
The legal analysis turns on one question: is personal information being collected?
- A CCTV system records identifiable faces. That is personal information — it triggers obligations around notice, security, retention and access, and creates an asset that can be hacked, leaked or subpoenaed.
- A Wi-Fi tracking system logs identifiers from shoppers' phones. Regulators in several jurisdictions have treated device identifiers as personal data, because they single out an individual even without a name.
- An anonymous counting sensor converts what it sees into numbers — entries, exits, U-turns — and keeps nothing else. If no individual is identified or identifiable at any point, no personal information is collected, and most privacy obligations simply never arise.
The architecture that makes the third category possible is on-device (edge) processing:
The frames exist for milliseconds, are never written to storage, and never leave the device. There is no footage to secure, because the footage never exists. As we put it on our homepage: it can't leak what it never keeps.
What the Australian Privacy Act requires
The Privacy Act 1988 and its Australian Privacy Principles (APPs) govern the handling of personal information — information about an identified individual, or one who is reasonably identifiable.
For store owners, the practical implications:
- Anonymous, aggregate counts are not personal information. A sensor that performs no facial recognition, stores no video and emits only numbers has nothing for the Act to regulate on the visitor side.
- Recorded CCTV is different. If your counting solution stores footage, you take on APP obligations: collection notices, secure storage, retention limits, and handling access requests. Many "camera-based analytics" products quietly put you in this category.
- Surveillance device laws still apply to recording. States and territories regulate optical surveillance and recording. A device that doesn't record sidesteps the issue at the architectural level.
- Signage remains best practice. Even where anonymous counting creates no legal notice requirement, clear signage is cheap goodwill. BitOculus provides signage guidance to every store as a courtesy to customers.
What GDPR requires
Under the GDPR, the threshold concept is personal data — and the same architecture-based logic applies:
- Truly anonymous data is outside GDPR entirely. Recital 26 is explicit: the principles of data protection do not apply to anonymous information. Aggregate counts that never pass through an identifiable state in storage meet that bar when processing is instantaneous and on-device.
- Facial recognition is the bright line. Biometric identification triggers Article 9 special-category rules and, in most retail scenarios, is effectively impossible to justify. No legitimate people counter needs it.
- Stored or streamed video is personal data, with the full apparatus that follows: lawful basis, data protection impact assessments, retention policies and data subject rights.
A sensor designed so that identifiable data never exists — rather than one that collects video and promises to handle it carefully — is what "GDPR-ready by design" actually means.
Privacy checklist: 6 questions to ask any people counting vendor
- Where does the video processing happen? "On the device" is the right answer. "In our secure cloud" means your visitors' images are leaving the building.
- Is any footage ever stored — even temporarily, even for support or recalibration? The right answer is no, with no exceptions.
- Is there any facial recognition or biometric matching? Walk away if yes. Counting does not require knowing who anyone is.
- What exactly leaves the sensor? You want events and aggregate numbers, not images, embeddings or device identifiers.
- Can the vendor state its position under the Privacy Act and GDPR in writing? Vague reassurance is a red flag; an architectural explanation is a good sign.
- Do they help with signage and customer communication? A vendor confident in its privacy design will help you explain it to your customers, not hide it from them.
BitOculus answers all six the way you'd hope: all processing on a dedicated edge AI processor inside the sensor, no footage ever stored or transmitted, no facial recognition, only anonymous counts leaving the device, Australian Privacy Act aligned and GDPR-ready, with signage guidance included at install.
Frequently asked questions
Do I need my customers' consent to use a people counter?
Not for a genuinely anonymous sensor — there is no personal information being collected to consent to. Consent (or another lawful basis, plus notices) becomes relevant the moment a system records identifiable footage or tracks personal devices.
Are people counting cameras legal in Australia?
Yes. Anonymous counting sensors that store no footage and identify no one operate outside the personal-information obligations of the Privacy Act. Systems that record footage are also legal but carry real compliance obligations — notices, secure storage and retention discipline.
Is a people counter GDPR compliant?
A counter whose output is truly anonymous falls outside GDPR's scope. The compliance question is architectural: if identifiable video is stored or transmitted, GDPR applies in full; if frames are processed and discarded on-device in milliseconds, there is no personal data to regulate.
What's the difference between a people counter and CCTV?
Purpose and output. CCTV exists to record and review footage of identifiable people, and is regulated accordingly. A people counter exists to produce numbers; the privacy-first ones never store an image at all. The two can coexist in one store — they're answering different questions. For what those numbers can do for your business, see the four metrics a people counter unlocks, and for the underlying technology, how AI people counting cameras work.
This article is general information, not legal advice — for specific obligations, talk to a privacy professional. BitOculus is a privacy-first AI people counting sensor: on-device AI, no footage ever stored, no one ever identified. Join the waitlist or ask us anything.