Balancing AI security with privacy and GDPR
16:00 · July 22, 2026 · RSS APP - AI Security and Privacy

Digital Content Editor, Eve Goode speaks exclusively with Elizabeth Davies, Chief Privacy Officer of Verkada.
Summary
Elizabeth Davies, Chief Privacy Officer at Verkada, describes how privacy considerations have moved from peripheral checks to central design decisions as organizations adopt AI-driven security platforms. Legal, compliance and data-protection teams now collaborate with security staff from the outset to define policies, set safeguards and establish accountability before deployment. The conversation around capabilities such as facial recognition has shifted from questions of legality to practical questions of correct use, with privacy-by-design embedded in default settings, access controls and data-collection choices.
Cloud architectures support these requirements through built-in audit trails, configurable retention periods and regional storage options that give organizations continuous visibility into data handling. These features help demonstrate accountability under GDPR while reducing the operational burden of compliance. Sensitive functions, including facial or licence-plate recognition, remain disabled by default and require explicit administrator action to activate. Additional tools such as face blurring, privacy masking and identity-based access logging further limit exposure and create verifiable records of every action.
Human oversight remains a core requirement: AI is positioned to surface relevant events in real time rather than to replace human judgment. Systems that discard non-matching facial detections immediately or operate on aggregated, tokenized data illustrate how performance can be maintained while minimizing individual-level tracking. Data-minimization controls, such as adjustable camera angles and selective analytics, allow organizations to collect only what is necessary and to adjust those boundaries without sacrificing functionality.
Davies notes increasing global convergence around data-protection expectations, with greater emphasis on transparency, explainability and ongoing governance. Privacy and compliance teams are now routinely involved in procurement decisions, raising evaluation standards and reducing the risk of later remediation. The result is a more mature approach in which security capability, accountability and demonstrable trust are treated as interdependent requirements rather than competing priorities.
Why it matters
Directly addresses GDPR compliance and privacy risks in AI security deployments, offering actionable guidance highly relevant to Dutch and EU organizations. Provides practical recommendations for security and privacy professionals on balancing capabilities with regulatory obligations.






