Skip to content
CampaignVision

Blog · August 7, 2026 · 4 min read

The event producer's guide to privacy-safe crowd measurement

By the Campaign Vision team

Crowd measurement and visitor privacy are usually framed as a trade-off. They aren’t — but the market contains everything from genuinely anonymous systems to tools that quietly log device identifiers, all marketed with the same word: “anonymous.” This guide is for producers and brand teams who need to tell the difference, ask vendors the right questions, and get an event’s privacy posture right.

One honest disclaimer up front: we build a camera-based measurement platform, so we have a position here. We’ve tried to write the guide we’d want to be held to — and none of this is legal advice; your obligations depend on your jurisdiction and deployment.

”Anonymous” is a claim, not a feature name

Under GDPR, data is only anonymous if individuals can’t be identified from it — by anyone, using reasonably available means. That standard is where several common practices get uncomfortable:

  • WiFi/Bluetooth tracking works by logging the MAC addresses of visitors’ phones. A device identifier tied to a location and time is personal data under GDPR — pseudonymous at best, not anonymous. (Separately, modern iPhones and Android phones randomize these identifiers by default, which is quietly eroding these systems’ accuracy anyway.)
  • Camera systems that store footage hold identifiable images of every visitor, whatever their analytics layer does. If video is retained, your privacy story depends on how that archive is secured, for how long, and who can access it.
  • Camera systems that store nothing process each frame in memory, keep only derived numbers — counts, dwell, zone totals — and discard the image. Done properly, there is no stored data from which anyone could be identified. This is the architecture we chose, and we’ve documented exactly how it’s enforced.

The lesson: don’t accept the word “anonymous.” Ask what’s stored.

Seven questions to ask any measurement vendor

Put these in writing and keep the answers with your event file:

  1. Is raw video or imagery ever stored? If yes: where, for how long, and who can access it?
  2. Is any facial recognition or unique identification performed? “Detection” (there is a person) and “recognition” (this is a specific person) are different technologies — vendors should state clearly which they do.
  3. Are any device identifiers (MAC addresses, advertising IDs) collected? If yes, “anonymous” needs an asterisk.
  4. What exactly is retained, and what’s the deletion schedule? Look for a concrete retention window and automatic deletion, not a policy PDF.
  5. How are small crowds handled? Aggregates can expose individuals when counts get tiny; good systems suppress small-sample outputs automatically.
  6. If demographics are offered, how? Aggregate estimates with no per-person storage is one thing; anything creating face templates is another. In some US states (Illinois’s BIPA most famously), face-derived data carries specific statutory risk that deserves its own legal review.
  7. Can you give us this in writing for our client’s legal team? A vendor who hesitates has answered the question.

Signage and notice: the unglamorous part that matters

Even fully anonymous measurement benefits from transparency, and some jurisdictions and venues require notice wherever cameras operate. The practical baseline we recommend to every team:

  • Post clear signage at entrances: measurement is in use, it’s anonymous, no video is stored, with a contact for questions.
  • Brief your floor staff with a two-sentence answer for curious visitors — “it counts the crowd anonymously, it doesn’t record anyone” travels much better than “I don’t know.”
  • Keep the vendor’s written answers (from the seven questions above) with the event file, so a client’s procurement or legal team gets same-day answers.
  • If your event runs in multiple jurisdictions, check the strictest one and apply it everywhere — one standard is easier to operate than five.

Privacy as a selling point, not a checkbox

The teams that handle this best have stopped treating privacy as compliance overhead. In pitches, “we measure everything, and we can show your legal team exactly why it’s safe” is a differentiator — brands have been burned by surveillance headlines and increasingly ask hard questions unprompted. Showing up with the answers already written is how measurement becomes an asset instead of a liability in the room.

How our own system handles all of the above — enforced in software, not promised in a PDF — is documented on our privacy & data page. Disagree with something in this guide, or have a scenario we didn’t cover? We’d genuinely like to hear it.

Get the next guide by email

Occasional, practical notes on measuring live events. No spam.

See these metrics on your own event.

Book a demo and we'll walk through the live dashboard and a sample report for a setup like yours.