Systematic Monitoring
Systematic monitoring refers to processing personal data in a planned, ongoing way to observe, track, or control individuals. A common example under EU and UK data protection guidance is the large-scale monitoring of a publicly accessible area, such as CCTV in a public space. Where such monitoring is likely to result in high risk to individuals, it is one of the factors that may indicate an organisation should carry out a Data Protection Impact Assessment.
Under the EU GDPR (Article 35) and UK GDPR guidance from the ICO and the Irish Data Protection Commission, systematic monitoring describes processing intended to observe, monitor, or control data subjects, including the systematic monitoring of a publicly accessible area on a large scale. It functions as a screening criterion within the DPIA framework: the presence of systematic monitoring, particularly alongside other factors such as processing of special category or highly personal data, large-scale processing, or the matching or combining of datasets, is treated as an indicator of processing that may result in high risk to the rights and freedoms of individuals. The term does not, by itself, establish a lawful basis for the processing, nor does it automatically make a DPIA mandatory in every instance; the DPIA obligation turns on whether the processing is likely to result in high risk, assessed in context. This entry does not cover the substantive content or methodology of a DPIA, the applicable lawful bases, cross-border transfer mechanics, retention rules, or enforcement outcomes. Note that treatment of monitoring activities may differ under other regimes (for example the CCPA/CPRA or HIPAA), which use distinct terminology and thresholds.
Why it matters
Systematic monitoring sits at the heart of the DPIA screening exercise under the EU GDPR (Article 35) and the UK GDPR. When an organisation plans to observe, track, or control individuals in a planned, ongoing way, for example through CCTV covering a publicly accessible area on a large scale, regulators such as the ICO and the Irish Data Protection Commission treat this as a signal that the processing may carry a high risk to people's rights and freedoms. Recognising the criterion early allows an organisation to identify, document, and mitigate risk before processing begins, rather than after individuals have already been affected.
The practical importance lies in how the criterion combines with others. Systematic monitoring is rarely assessed in isolation: its presence alongside factors such as processing of special category or highly personal data, large-scale processing, or the matching or combining of datasets strengthens the indication that a DPIA is warranted. Expert practitioners should be careful not to overstate the effect of the criterion. Systematic monitoring does not by itself make a DPIA mandatory in every case, nor does it establish a lawful basis for the processing. Whether a DPIA is required turns on whether the processing is, in context, likely to result in high risk.
Because accountability under the GDPR framework requires demonstrable evidence rather than stated intent, an organisation that identifies systematic monitoring in its activities should be able to show how it reached its risk conclusion, including where it decided a DPIA was not necessary. Treatment of monitoring activities may differ under other regimes such as the CCPA/CPRA or HIPAA, which use distinct terminology and thresholds, so a monitoring assessment framed for the GDPR should not be assumed to satisfy obligations elsewhere.
Who it's relevant to
Inside Systematic Monitoring
Common questions
Answers to the questions practitioners most commonly ask about Systematic Monitoring.