Skip to main content
Category: Breach and Risk Assessment

Systematic Monitoring

Simply put

Systematic monitoring refers to processing personal data in a planned, ongoing way to observe, track, or control individuals. A common example under EU and UK data protection guidance is the large-scale monitoring of a publicly accessible area, such as CCTV in a public space. Where such monitoring is likely to result in high risk to individuals, it is one of the factors that may indicate an organisation should carry out a Data Protection Impact Assessment.

Formal definition

Under the EU GDPR (Article 35) and UK GDPR guidance from the ICO and the Irish Data Protection Commission, systematic monitoring describes processing intended to observe, monitor, or control data subjects, including the systematic monitoring of a publicly accessible area on a large scale. It functions as a screening criterion within the DPIA framework: the presence of systematic monitoring, particularly alongside other factors such as processing of special category or highly personal data, large-scale processing, or the matching or combining of datasets, is treated as an indicator of processing that may result in high risk to the rights and freedoms of individuals. The term does not, by itself, establish a lawful basis for the processing, nor does it automatically make a DPIA mandatory in every instance; the DPIA obligation turns on whether the processing is likely to result in high risk, assessed in context. This entry does not cover the substantive content or methodology of a DPIA, the applicable lawful bases, cross-border transfer mechanics, retention rules, or enforcement outcomes. Note that treatment of monitoring activities may differ under other regimes (for example the CCPA/CPRA or HIPAA), which use distinct terminology and thresholds.

Why it matters

Systematic monitoring sits at the heart of the DPIA screening exercise under the EU GDPR (Article 35) and the UK GDPR. When an organisation plans to observe, track, or control individuals in a planned, ongoing way, for example through CCTV covering a publicly accessible area on a large scale, regulators such as the ICO and the Irish Data Protection Commission treat this as a signal that the processing may carry a high risk to people's rights and freedoms. Recognising the criterion early allows an organisation to identify, document, and mitigate risk before processing begins, rather than after individuals have already been affected.

The practical importance lies in how the criterion combines with others. Systematic monitoring is rarely assessed in isolation: its presence alongside factors such as processing of special category or highly personal data, large-scale processing, or the matching or combining of datasets strengthens the indication that a DPIA is warranted. Expert practitioners should be careful not to overstate the effect of the criterion. Systematic monitoring does not by itself make a DPIA mandatory in every case, nor does it establish a lawful basis for the processing. Whether a DPIA is required turns on whether the processing is, in context, likely to result in high risk.

Because accountability under the GDPR framework requires demonstrable evidence rather than stated intent, an organisation that identifies systematic monitoring in its activities should be able to show how it reached its risk conclusion, including where it decided a DPIA was not necessary. Treatment of monitoring activities may differ under other regimes such as the CCPA/CPRA or HIPAA, which use distinct terminology and thresholds, so a monitoring assessment framed for the GDPR should not be assumed to satisfy obligations elsewhere.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads use the systematic monitoring criterion when advising on whether a planned processing activity should trigger a DPIA. They are typically responsible for maintaining and applying the screening logic and for ensuring that any decision, whether to proceed with a DPIA or not, is documented as demonstrable evidence of the accountability required under the GDPR framework.
Compliance and Information Governance Teams
These teams need to recognise systematic monitoring within business processes, particularly where monitoring of publicly accessible areas or ongoing observation of individuals is proposed. Their role in governance, covering ownership, policy, and documentation, complements, but does not replace, the security controls applied to the monitoring data itself.
Legal and Risk Advisors
Legal advisors assess, in context, whether processing that involves systematic monitoring is likely to result in high risk and therefore points toward a DPIA obligation under the EU or UK GDPR. They should also flag that the criterion neither establishes a lawful basis nor guarantees compliance, and that treatment differs under regimes such as the CCPA/CPRA or HIPAA.
Security and Engineering Teams Deploying Monitoring Systems
Teams implementing CCTV, workplace monitoring, or automated tracking systems are often the first to encounter the systematic monitoring criterion in practice. Engaging privacy stakeholders during design, rather than after deployment, helps ensure that the screening assessment is completed and, where indicated, a DPIA is undertaken before processing begins.

Inside Systematic Monitoring

Regular and systematic monitoring
A concept referenced in the EU GDPR (and mirrored in the UK GDPR) describing the ongoing, planned, or organized observation or tracking of individuals. It is one of the triggers that may indicate large-scale or higher-risk processing, though the regulation does not fix a precise numeric threshold for what constitutes systematic or large scale.
Behavioral tracking element
Monitoring frequently includes the tracking of individuals' behavior, activity, or location, whether online (for example, profiling, analytics, or ad tracking) or in physical spaces (for example, CCTV). The characterization depends on the purpose and organized nature of the activity rather than on the technology alone.
Relationship to DPIA triggers
Under the EU GDPR framework, regular and systematic monitoring of data subjects on a large scale is one of the criteria that can make a Data Protection Impact Assessment likely required. It is a factor to weigh, not an automatic guarantee that a DPIA is or is not mandatory in a given case.
Relationship to DPO designation
Where an organization's core activities consist of processing that requires regular and systematic monitoring of data subjects on a large scale, the EU GDPR may require designation of a Data Protection Officer. Whether the condition is met depends on the facts of the specific processing.
Controller accountability dimension
The controller determining the purposes and means of the monitoring generally bears the accountability for assessing risk, documenting the assessment, and demonstrating that determination with evidence. A processor carrying out monitoring on the controller's instructions holds distinct, narrower obligations.

Common questions

Answers to the questions practitioners most commonly ask about Systematic Monitoring.

Does any use of monitoring technology automatically count as systematic monitoring that triggers heightened obligations?
No. Not all monitoring qualifies as systematic monitoring in the sense that raises additional obligations under regimes such as the EU GDPR and UK GDPR. The concept generally implies monitoring that is organized, methodical, ongoing, or carried out according to a strategy or plan, rather than occasional or one-off observation. A single, isolated act of monitoring typically does not meet this threshold. Whether a given activity qualifies depends on its scope, regularity, and purpose, and should be assessed case by case rather than assumed from the mere presence of monitoring tools.
If an activity is systematic monitoring, does that mean a data protection impact assessment is always required?
Not automatically. Systematic monitoring is one factor that can indicate a processing activity may result in a high risk to individuals, and in some cases it is associated with a DPIA obligation, particularly where it occurs on a large scale or in publicly accessible areas under the EU GDPR and UK GDPR. However, a DPIA is not universally mandatory for every instance of monitoring. The requirement depends on the specific criteria in the applicable regime and the overall risk profile of the processing. The classification as systematic monitoring should prompt a risk assessment to determine whether a DPIA is needed, not substitute for that assessment. Treatment differs across jurisdictions, and this entry does not cover the detailed DPIA thresholds of regimes outside the EU and UK GDPR.
How should an organization determine whether its monitoring activity meets the systematic threshold?
Assessment generally focuses on factors such as whether the monitoring is ongoing or repeated over time, whether it follows a predetermined plan or strategy, the scale of individuals affected, and whether it takes place in areas where individuals may not expect to be observed. Documenting this analysis is advisable so the reasoning is demonstrable rather than merely asserted. This entry does not provide a fixed numeric threshold, as none is stated in the underlying framework, and the evaluation remains context-dependent.
Who within an organization bears responsibility for identifying and governing systematic monitoring?
The data controller generally bears accountability for determining whether an activity constitutes systematic monitoring and for meeting any resulting obligations, since it defines the purposes and means of the processing. Where a data protection officer has been designated, that individual typically advises on the assessment and monitors compliance, but the DPO does not assume the controller's accountability. Where a processor conducts monitoring on the controller's behalf, obligations are allocated through the arrangement between them, with the controller retaining primary accountability. Accountability here requires demonstrable evidence of the assessment and decisions made, not simply a stated position.
What documentation supports a defensible position on systematic monitoring?
Organizations generally maintain records of the monitoring's purpose, scope, duration, the categories of individuals and data involved, and the analysis of whether the activity meets the systematic threshold. Where relevant, this connects to records of processing activities and any risk assessment or DPIA conducted. Note that records of processing activities are a governance and accountability obligation and are distinct from any particular data inventory tool used to maintain them. This entry does not address specific retention periods for such documentation.
How does governing systematic monitoring differ from securing the monitoring data?
These are related but separate concerns. Governing systematic monitoring addresses questions of lawful basis, purpose, proportionality, transparency to affected individuals, ownership, and demonstrable accountability, which fall within data governance and data protection. Securing the resulting data addresses confidentiality, integrity, and availability through information security controls. The two overlap, since safeguarding monitoring data is often part of a proportionate approach, but implementing security controls does not by itself establish that the monitoring is lawful or appropriately governed. Note that applying controls such as encryption to monitoring data does not render that data non-personal.

Common misconceptions

Any processing described as systematic monitoring automatically requires a DPIA.
Regular and systematic monitoring on a large scale is one indicator that a DPIA is likely needed under the EU GDPR, but a DPIA is not universally mandatory. The requirement depends on an assessment of the specific processing, its scale, and its risk to individuals, and treatment can differ under other regimes such as the CCPA/CPRA or HIPAA.
Systematic monitoring is defined by a fixed number of individuals or records.
The EU GDPR does not set a precise numeric threshold for what is systematic or large scale. Guidance and practice frame these as qualitative and contextual assessments considering factors such as the volume of data, the number of data subjects, duration, and geographic reach, rather than a single substantiated figure.
If monitored data is pseudonymized, tokenized, or encrypted, the monitoring falls outside data protection scope.
Pseudonymization, tokenization, and encryption are security or risk-reduction measures; they generally do not make monitored data non-personal because the process typically remains reversible or linkable. Only genuinely irreversible anonymization would move data out of most regulatory scope, and monitoring of personal data remains in scope until that point.

Best practices

Document, with demonstrable evidence, whether your monitoring activities meet the criteria of regular and systematic monitoring on a large scale, rather than relying on stated intent, since accountability requires an auditable record.
Assess DPIA necessity on a case-by-case basis using the specific purpose, scale, and risk of the monitoring, and record the reasoning even where you conclude a DPIA is not required.
Evaluate whether monitoring forms a core activity that triggers a mandatory Data Protection Officer designation under the EU GDPR, and note that the analysis may differ under the UK GDPR or other regimes.
Clearly assign controller and processor roles for the monitoring so that risk assessment, documentation, and data subject-facing obligations sit with the accountable party.
Do not treat pseudonymization, tokenization, or encryption of monitored data as removing it from personal data scope; continue to apply relevant protections and lawful basis analysis.
Confirm the lawful basis for monitoring on its own merits rather than assuming consent applies, and reassess where jurisdiction or purpose changes.