Writing the Notice
A sign saying the area is under video surveillance does not describe automated analysis. What a useful notice contains and where it goes.
Procedure
The notice is the control that makes everything else meaningful, and it is usually a sign that was ordered before the analytics were installed.
What a standard sign fails to cover
That analysis happens at all, as opposed to recording.
What is detected.
Whether anyone is identified, which is the question people actually have.
How long anything is kept.
Who to contact.
A notice describing recording when the system analyses is inaccurate, and inaccuracy in a notice is a compliance problem rather than a presentational one.
What to include
That automated analysis is in use.
What it detects, in plain terms: "counts people entering", "detects vehicles in the pedestrian aisle".
What it does not do, which is the sentence people remember: "does not identify individuals; no facial recognition; no images of individuals are stored".
The purpose, in a phrase.
Retention, as a number.
Who operates it and how to contact them.
Where to find more, for anyone who wants the full detail.
Where it goes
Before the analysed area, not inside it and not at the exit.
At eye level, readable at the distance people pass.
At every entrance, including staff and service entrances.
In the languages the people entering actually use, which in many workplaces is not one language.
Online too, for anything about customers, findable rather than buried in a policy.
For employees, additionally
In writing, before deployment, not only on a sign.
With the consultation outcome, where consultation occurred.
With the purpose limitation stated: what it will not be used for.
With the exclusions listed: which areas are not analysed.
With a contact for questions who will actually answer.
The honest-answer test
Write the notice, then imagine someone asking: "so are you watching me?"
If the notice does not answer that question, it is not doing its job.
If the honest answer is uncomfortable, the design is the problem rather than the wording, which is the whole argument for aggregating at source and discarding individual data.
A system whose notice reads well is usually a system that was designed well, and the notice is a good place to discover that it was not.
What not to do
Do not describe capabilities you do not use to sound impressive, or capabilities you do use in vague terms to sound harmless.
Do not bury it in a policy document.
Do not rely on a contract clause as notice of a specific processing operation.
Do not leave signage describing analysis that no longer happens, which accumulates as deployments end.
Reviewing it
Whenever the system changes, including a vendor upgrade that enables a new feature.
Annually otherwise.
Against the inventory, so that every deployment has a notice and every notice describes a deployment that exists.
The mismatch between what the signage says and what the system does is a standard audit finding, and it is entirely avoidable with one annual comparison.
The annual notice comparison
A standing audit finding, avoidable with one comparison.
Take the register: what does each deployment actually do?
Take the notices: what does each say?
Compare.
Expect: notices describing recording where analysis happens, notices that predate a feature change, and signage for deployments that ended.
Fix both directions, because a notice describing capability that no longer exists is its own small dishonesty.
Do it annually and after every vendor upgrade.
Languages and placement
A notice nobody can read is not a notice.
In the languages the people entering actually use, which in many workplaces and public spaces is not one.
Before the analysed area, not inside it and not at the exit.
At eye level, legible at the distance people pass.
At every entrance, including staff, service and delivery.
Online too, findable rather than buried, for anything customer-facing.
Check by walking in as a visitor would and seeing whether you encounter it before being analysed.