Privacy and standards
KVKK/GDPR and DOOH: Data Privacy on Digital Screens
DOOH data privacy under GDPR and KVKK: the legal line between anonymous, aggregate measurement and processing personal data on digital screens.
14 min readUpdated
KVKK/GDPR and DOOH: Data Privacy on Digital Screens
As digital out-of-home (DOOH) screens measure audiences on the street, in the metro, and in shopping centres, DOOH data privacy has become an unavoidable topic for planners and brands. This article explains how privacy rules apply to measurement on digital screens under GDPR and KVKK, the key legal line between anonymous measurement and processing personal data, and the practical nuance that can shift one into the other.
Note: This is general information, not legal advice. For a specific campaign or deployment, consult a qualified legal professional.
Why does privacy law matter for digital screen measurement?
In the European Union, personal data is governed by the GDPR (General Data Protection Regulation). In Türkiye, the equivalent framework is the KVKK (Law No. 6698 on the Protection of Personal Data) — effectively Türkiye’s GDPR-equivalent — enforced by an independent authority (kvkk.gov.tr). Both share the same core logic: the law governs any information that makes a person identified or identifiable.
DOOH measurement typically aims to count people who pass or look at a screen, estimate how long they look (dwell), and infer a coarse demographic split. The decisive question is simple: can the data collected be linked to a specific person, or not? The answer determines whether the measurement falls within the scope of GDPR and KVKK at all.
The legal line between anonymous measurement and personal data
At the heart of both GDPR and KVKK sits one distinction: the line between anonymous, aggregate measurement and processing personal data. These two approaches belong to very different worlds in terms of legal obligation.
If a measurement system produces only anonymous, aggregate outputs — “how many people are present now”, “average dwell time”, “coarse age band and gender distribution” — and never identifies or re-identifies a specific individual, the resulting data is generally not personal data. This kind of measurement is considered low-risk under both regimes, because what the law protects is information about an identified or identifiable person, not an abstract headcount.
By contrast, if a system produces data that identifies, profiles, or re-recognises a passer-by as the same person across time — for example by creating and storing a face template (a biometric descriptor) — that constitutes processing personal, and even biometric (special-category), data. In that case both GDPR and KVKK require a transparency notice, a lawful basis for processing (often consent), and stricter conditions for special-category data.
| Dimension | Anonymous / aggregate measurement | Personal-data processing |
|---|---|---|
| Output | Counts, dwell, coarse distribution | Identity, profile, re-recognition |
| Linkable to a specific person? | No | Yes |
| Biometric template | Not created | May be created |
| GDPR/KVKK status | Generally out of scope / low risk | In scope; notice + lawful basis |
| Typical requirement | Good practice, transparency | Consent / notice, strict security |
Read this table as a practical compass: which side of the line you stand on is decided by your design choices. Staying on the anonymous side is not an accident but an architectural decision. The article on privacy-by-design measurement explains how that architecture is built through six principles.
Face detection, not face recognition
The most commonly confused concept in privacy is the difference between face detection and face recognition. Detection determines whether a face is present in the frame and roughly which way it is oriented; it does not know an identity or assign a name. Recognition matches a face to a specific person.
Privacy-first DOOH measurement relies on detection: “a person is present, oriented toward the screen, looked for this long.” This approach focuses on presence and attention (head-pose and dwell), not identity; because it creates no biometric template, it cannot re-recognise the same person who returns later. The details of this technical distinction appear in computer vision for DOOH measurement. An honest caveat: at distances of 2–10 metres, true eye-gaze cannot be measured reliably, so reputable systems say “face-toward-screen plus dwell” rather than claiming precise gaze.
Cross-screen frequency capping: the nuance that shifts the line
Anonymous measurement does not always stay anonymous. The most critical nuance is the desire for cross-screen frequency capping — limiting how many times the same person sees the same ad across different screens.
To match a person as “the same person” across different screens and times, the system must keep a persistent, re-recognisable signature of that individual. This moves the measurement out of anonymous counting and into the pseudonymous or biometric domain. Although technically possible, this feature changes the legal posture: under GDPR and KVKK, a transparency notice and most likely consent come into play, and special-category data rules may apply. In other words, the wish for frequency capping can push you across the boundary from “low-risk anonymous measurement” to “high-obligation personal data.”
In practice this is a design trade-off: cross-screen frequency control offers advertising value but raises the privacy and compliance cost. Many privacy-first approaches therefore deliberately avoid cross-screen identity matching and keep measurement anonymous at the level of a single screen or session.
Practical implications
For brands and agencies, the practical conclusion is clear. When evaluating a measurement provider, ask: is the output genuinely anonymous and aggregate; is the image frame stored or destroyed immediately; is any biometric template created; is there cross-screen identity matching? These questions directly determine your campaign’s obligation level under GDPR and KVKK. For a general picture of the ecosystem and players in this market, see the DOOH market in Türkiye.
Privacy-first, computer-vision-based measurement providers (such as Mecrai) aim to keep outputs anonymous and aggregate so they stay on the low-risk side of the line; even so, because every deployment has its own circumstances, a specific rollout still warrants legal review.
Summary
At the heart of DOOH data privacy under GDPR and KVKK is a single line: as long as measurement stays anonymous and aggregate it is low-risk, but the moment it moves to data that identifies or re-recognises a person, personal-data obligations arise. Cross-screen frequency capping is the most important nuance that can shift this line. The right design choices make privacy not a constraint but a trust signal.
Frequently asked questions
- Is DOOH audience measurement subject to GDPR or KVKK?
- It depends. If measurement produces only anonymous, aggregate counts and distributions and identifies no individual, it is generally low-risk. But if data that identifies, profiles, or re-recognises a person is processed, it falls within scope of GDPR and KVKK and requires a transparency notice and a lawful basis.
- Is face detection the same as face recognition?
- No. Face detection only determines that a face is present in the frame and its rough orientation; it knows no identity. Face recognition matches a face to a specific person. Privacy-first measurement relies on detection and creates no biometric template.
- Why does frequency capping matter for privacy?
- Cross-screen frequency capping requires recognising the same person across different screens. That means keeping a persistent, re-recognisable signature, which moves measurement from anonymous into the pseudonymous or biometric domain — triggering GDPR and KVKK obligations and the likelihood of consent.
- Is consent required for anonymous measurement?
- As a general rule, if the output is genuinely anonymous and aggregate and cannot be linked to a specific person, no personal-data processing occurs, so consent is typically not required. Transparency is still good practice, and each deployment should be assessed on its own legal footing.
Related articles
Privacy and standards
Privacy-by-Design Measurement: Anonymous and On-Device
Privacy-by-design measurement explained: the 6 principles of anonymous, on-device DOOH measurement that stores no image and creates no identity.
16 min read
Privacy and standards
DOOH Measurement Standards: IAB, MRC, and Geopath
DOOH measurement standards: IAB guidance and OpenRTB, MRC independent accreditation, and Geopath/Nielsen/Route currency — why they matter for trust and budget.
18 min read
DOOH fundamentals
cornerstoneWhat Is DOOH? A Guide to Digital Out-of-Home Advertising
What is DOOH? A clear guide to digital out-of-home advertising — its definition, how it differs from print OOH, where screens live, and why it's measurable.
15 min read