Why a license plate is personal data
GDPR defines personal data as any information relating to an identified or identifiable person. A license plate, especially when linked to an apartment, an account or a subscription, identifies the owner or user of the car. Camera images may also capture the driver.
That does not mean ANPR is forbidden. It means the car park operator (association, company, hotel) must follow GDPR. This guide is not legal advice; for specific situations, talk to a data protection specialist.
Legal basis and purpose
For access control, the basis usually relied on is the operator's legitimate interest (security and management of the car park) or performance of a contract (for example a subscription or a rented space). The purpose must be clearly defined, for example access control and billing, and data should not be reused for other purposes without a separate basis.
If monitoring is systematic and large-scale, a data protection impact assessment (DPIA) may be required under Article 35 GDPR.
Informing people
Drivers must know the car park uses ANPR cameras. The EDPB guidelines on video devices recommend layered information: a visible sign at the entrance with the operator's identity, the purpose and where to find details, plus a full notice available online or at the management office.
How long to keep data
GDPR sets no fixed period, but data must be kept only as long as needed for the purpose. In practice:
- Set separate retention periods for the pass log and for images.
- Delete data automatically when the period ends, not by hand.
- Keep data longer only when it relates to a specific, documented incident.
- For payments, also respect tax and accounting retention rules.
Security and access
Limit access by role: the gate operator sees what they need, the manager sees reports and residents see only their own cars. Use two-factor authentication for accounts with broad rights and keep an audit log of who viewed or changed data.
What to ask your software vendor
When choosing an ANPR system, check:
- Whether you can configure retention periods and automatic deletion.
- Where data is hosted and whether on-premise installation is available.
- Whether the vendor signs a data processing agreement (DPA).
- Whether there are roles, two-factor authentication and an audit log.
Frequently asked questions
- Do I need drivers' consent for ANPR?
- Usually not: access control typically relies on legitimate interest or performance of a contract. Informing people is still mandatory.
- How long can I keep images?
- Only as long as needed for the purpose. GDPR sets no fixed period, so define clear, documented periods with automatic deletion.
- Do I need information signs?
- Yes, a visible sign at the entrance stating the operator, the purpose and where to find full information is recommended.