ANPR on Your Car Park and the GDPR: A Practical Checklist for Operators

On 9 July, The Hague Court of Appeal heard Privacy First's challenge to ANPR mass surveillance by Dutch police. Since then VvE boards, facilities managers and hotel operators have been asking us the same question: "Do we have a problem with our ANPR cameras too?" No — not the same problem. But you do have your own GDPR obligations, and they are worth checking.

Revtek  ·  21 July 2026


What the Privacy First case does and does not cover

The Privacy First lawsuit targets Article 126jj of the Dutch Code of Criminal Procedure, which requires police to store the licence plates and locations of every car on Dutch roads for four weeks in a central database — regardless of whether the driver is suspected of anything. Privacy First argues this is disproportionate mass surveillance.

This is the state contesting its own surveillance infrastructure in court. Your residential complex, office car park or hotel parking area is a different matter entirely. You hold no police powers, you run no national network, and you are not recording the movements of random passers-by.

Your ANPR camera reads plates of people who are trying to enter your private site, for one purpose: granting access to those who are entitled and refusing those who are not. That sits on a different legal footing — the General Data Protection Regulation (GDPR) — and the requirements are manageable once properly set up.

What legal basis are you relying on?

The GDPR requires a valid legal basis for every processing activity. A licence plate is personal data, because it can be traced to a specific vehicle and, in most cases, to an individual.

For private parking operators, the most widely used basis is legitimate interests (Article 6(1)(f) GDPR). You have a legitimate interest in enforcing your parking policy on your own land. That interest generally outweighs the privacy impact, which is limited: you are controlling access to your site, not tracking travel patterns across a city.

If residents or tenants rent a parking space under a contract, the performance of that contract is a supplementary basis worth including.

Whichever basis you choose, document it in your processing register and privacy statement. "We thought it was useful" will not satisfy the Dutch Data Protection Authority (AP).

How long can you keep the data?

Here is a practical distinction many operators overlook: camera footage and access log data are different things.

For camera footage — recordings in which people may be visible — most security practitioners apply a maximum of 28 days. This is not a hard statutory limit but a practical benchmark the AP treats as the starting point. Longer retention is possible, but you need a documented reason, such as an ongoing incident investigation.

Access log data is something else: plate number, timestamp and access decision, with no image attached. Here the principle of data minimisation applies. Keep what you need for the purpose, no longer. For a residential complex or office building where you are simply tracking who may enter, four to eight weeks is proportionate in most scenarios. For a commercial car park where you need to resolve billing disputes or chargebacks, a longer documented retention period is defensible — write it down explicitly.

Set up automatic deletion where the system allows it. Manual retention management is rarely done consistently.

The sign at the entrance is not optional

Article 13 GDPR requires you to inform data subjects at the point their data is collected — which means before the plate is read. A sign at the car park entrance is the standard solution.

That sign must include at minimum: who the data controller is (name and contact details), the purpose of processing, how long data is retained, and where people can submit an access request or complaint.

Alongside the physical sign, a privacy statement on your website should describe the processing. VvE boards without a website can make a document available to residents through their residents' portal or on request.

This is the most common gap we encounter. The cameras are up, the system is running — but the entrance sign is missing, or it names a supplier that no longer exists. The AP treats missing signage as a straightforward violation: you will receive a remediation order, and a repeat finding can lead to a fine.

Your processing register: one page is enough

Article 30 GDPR requires organisations to maintain a record of processing activities. Organisations with more than 250 employees must always do this. Smaller organisations must too if the processing is not occasional — and scanning plates every day at a car park entrance is definitionally not occasional.

For your ANPR processing, the record should include:

  • Purpose (access control for private site)
  • Legal basis (legitimate interests; contract performance where applicable)
  • Categories of data subjects (residents, staff, visitors)
  • Categories of data (plate number, timestamp, access decision; camera footage if retained)
  • Retention period (differentiated by data type)
  • Security measures (encryption, access restrictions)
  • Processors (your ANPR software provider is a processor — document this and sign a data processing agreement)

That last point catches operators off guard. If you use a platform like Revtek to manage your car park, Revtek processes your plate data on your behalf. You are the controller; Revtek is the processor. A data processing agreement is mandatory and is provided at the point of setup.

Rights of residents and visitors

Data subjects have the right to know what data you hold about them (right of access) and the right to have it erased if there is no compelling reason to keep it (right to erasure).

In practice, these requests are straightforward to handle once the system is properly configured. A resident wants to see when their car entered and exited the site last month? Pull it from the access log. A one-time visitor wants their plate removed? Delete the relevant record if it is still within the retention window. A system that auto-deletes after the configured period handles most requests before they arrive.

Record all requests and your responses in writing. You have 30 days to reply.

What this means in practice

GDPR compliance for private ANPR is not complicated: document your legal basis, configure retention, put up a sign, maintain a processing register, sign a data processing agreement with your supplier. Set it up correctly at the start, rather than trying to reconstruct it after a complaint.

For VvE boards, the risk is institutional memory loss as the committee changes. Do not assume a previous manager sorted this out — check it yourself. An AP fine runs to thousands of euros at minimum; the entrance sign costs a fraction of that.

Revtek supplies a data processing agreement as standard and can assist with the text for your entrance sign and privacy statement. That does not remove your own responsibility as controller — but it removes a significant amount of groundwork.

This article is for informational purposes only and does not constitute legal advice. Consult a privacy specialist or legal adviser for your specific situation.

Want to know more about Revtek?

Book a free demo and find out what Revtek can do for your situation.

Book a demo

Or email info@revtek.nl