Balancing AI security with privacy and GDPR
10:02 · July 28, 2026 · RSS APP - AI Security and Privacy

SJUK hears exclusively from Elizabeth Davies, Chief Privacy Officer, Verkada about the importance of balancing AI security with privacy and GDPR.
Summary
As organisations adopt cloud-based security platforms, discussions around facial recognition and similar AI capabilities have moved from questions of basic legality toward practical governance. Elizabeth Davies, Chief Privacy Officer at Verkada, notes that privacy and compliance teams now participate from the outset, establishing policies that embed data protection into system architecture rather than treating it as an add-on. Cloud infrastructure supports this shift by offering audit trails, configurable retention rules and regional data storage, which together improve visibility and help demonstrate accountability under GDPR.
Privacy by design appears in concrete controls such as default restrictions on sensitive analytics, identity-based access that logs every action to a specific user, and tools like face blurring or privacy masking. These measures reduce unnecessary data collection while preserving operational value. Human oversight remains central: AI is positioned to surface patterns or prioritise alerts in real time, not to replace human judgment, with systems discarding non-matching facial data in “person of interest” searches to limit exposure.
Common compliance hurdles include shared credentials that obscure accountability and fragmented oversight of sub-processors. Organisations address them through individual access controls, data-minimisation settings that restrict camera angles or analytics, and continuous monitoring of where data resides and how it moves. Looking ahead, Davies highlights converging global expectations around AI transparency and explainability, alongside greater involvement of privacy teams in procurement decisions, which together raise the standard for secure, auditable deployments.
Why it matters
Strong EU/GDPR focus makes content immediately actionable for Dutch security teams implementing AI tools while ensuring regulatory compliance and privacy safeguards.





