How to Prepare Video Anonymization Documentation for a GDPR Auditor: Report and Register Templates

Łukasz Bonczol
Published: 7/8/2026

TL;DR: For a GDPR auditor, an anonymized file alone is not enough. What matters is documentation showing who made the decision, what the publication purpose was, what was blurred, what was not, and on what basis. You need two documents: an anonymization report for each individual item and a consolidated anonymization register, both maintained by the controller. A tool such as Gallio PRO performs anonymization - automatically for faces and license plates, with other elements handled manually in the editor - but it does not replace a compliance register. Below you will find ready-to-copy templates.

Visual data anonymization means permanently reducing the identifiability of people and vehicles in photos and videos before publication - in practice, most often through face blurring and license plate blurring. For an auditor, simply using a tool is not enough. Documentation is usually the weakest link: an organization may have correctly prepared materials, but without an anonymization register and report, it will struggle to demonstrate accountability under Article 5(2) GDPR [1]. This article focuses exclusively on the evidence set a GDPR auditor expects and provides a practical anonymization register template.

What does a GDPR auditor check when photos and videos are published?

A GDPR auditor usually does not start by asking about software features. Instead, they ask whether the controller can demonstrate that the publication decision complies with the principles of lawfulness, data minimization and accountability [1]. For visual materials, this means three levels of review.

Level one - the basis for publication. If the material includes an identifiable person, organizations usually rely on consent, legitimate interest or exceptions related to the dissemination of a person’s image. The obligation to blur faces does not automatically arise from a single provision; it follows from an assessment of the processing basis and the risk of infringing the person’s rights, taking into account the GDPR, the Civil Code and copyright law. Copyright law provides exceptions to the requirement to obtain permission to disseminate an image, in particular where: (1) the person is widely known and the image was captured in connection with the performance of their public functions; (2) the person is merely a detail of a larger whole, such as an assembly, landscape or public event; (3) the person received agreed payment for posing and did not reserve otherwise. Each exception should be described in the documentation, not assumed automatically.

Level two - the scope of anonymization. The auditor checks whether the organization has defined which categories of visual elements must be hidden. In the case of Gallio PRO, automatic detection covers only faces and license plates. The tool does not blur entire silhouettes, does not perform real-time anonymization or video stream anonymization, and does not automatically detect company logos, tattoos, name badges, documents or content displayed on monitor screens. Such elements can be blurred manually in the editor - and this should be reflected in the processing report.

Level three - evidence of completion. The auditor expects a decision trail: you must be able to show that the material was reviewed, not merely run through a tool. This is especially important for event photos, promotional materials, videos recorded in public spaces and footage involving vehicles.

Person writing on a digital tablet with a stylus, checking off items on a list at a desk setup with a keyboard and plant in the background.

Why is the anonymized file alone not sufficient evidence?

In a GDPR audit, the final output is not the only thing that matters. The organization must also be able to reconstruct the decision-making process. A blurred file shows the result, but it does not answer key questions: who approved the publication, what the legal basis was, whether image-related exceptions were checked, whether a manual review was performed, and whether the risk of re-identification was considered.

That is why good practice involves two documents: an anonymization report for a specific item and an anonymization register that organizes all operations over time. The register should be maintained by the controller. This is important from an evidentiary perspective: Gallio PRO does not replace a compliance register and does not independently document the basis for publication, image-related exceptions or the controller’s decisions. The register is created and maintained on the controller’s side.

What should video anonymization documentation for a GDPR auditor look like?

The simplest model usually works best: one report for the material and one consolidated register. The report is used to assess a single photo, a set of photos or a video file. The register allows the auditor to quickly review all publications from a given period.

Anonymization report template - ready-to-copy fields

The report should be as simple as possible. In practice, the following fields are worth using:

  • Report ID - a unique number linked to the register.
  • Date of material review - the day of the pre-publication review.
  • Person responsible for the review - name, surname or business role.
  • Description of the visual material - e.g. “promotional video from a city event, 2 min 15 sec” or “gallery of 12 conference photos”.
  • Purpose of publication - e.g. marketing, PR, public information, event coverage.
  • Planned place of publication - website, social media, video channel, intranet.
  • Basis for publication or exception - consent, legitimate interest, widely known person, detail of a larger whole, agreed payment for posing.
  • Result of the automatic review - confirmation that automatic detection covered faces and license plates.
  • Result of the manual review - whether other elements were blurred manually, e.g. a document on a desk or content on a monitor.
  • Scope of anonymization applied - number of faces, number of license plates, scope of manual corrections.
  • Re-identification risk assessment - a short note on whether the material may still allow identification after anonymization.
  • Publication decision - publish, publish after corrections, withhold publication.
  • Approval date - the date of final acceptance.
  • Audit notes - a field for comments from the DPO or compliance team.

Each field has evidentiary value. The identifier and date create an audit trail; the description of the material and the publication purpose provide context; the basis/exception field shows that the decision was not accidental. The manual review section is particularly important because automatic detection does not cover every category of information visible in the frame.

Person holding two large binders over a desk with a laptop, papers, and a calculator.

Anonymization register template - the structure auditors actually look for

The register should be consolidated, up to date and easy to filter. A spreadsheet or register system with the following columns usually works best:

Column

What to enter

Why the auditor checks it

 

Entry No.

Sequential operation number

Helps establish register continuity

Report ID

Link to the individual report

Connects the register with detailed evidence

Anonymization date

Date of the review and changes

Allows verification of timelines

Type of material

Photo, gallery, video recording

Organizes the scope of the operation

Purpose of publication

Marketing, PR, public information

Links anonymization to the processing purpose

Elements blurred automatically

Faces, license plates

Shows what was covered by the standard process

Elements blurred manually

E.g. document, monitor screen, ID badge

Confirms manual review

Basis or exception

Description of the adopted basis or exception

Verifies the lawfulness of publication

Final decision

Published, corrected, rejected

Shows the outcome of the process

Approving person

Name and surname or role

Assigns responsibility

This kind of register should not be built solely on the tool’s technical logs, but on the controller’s decisions. If the organization uses locally installed on-premise software, it is easier to describe control over the environment and access to the material. In more complex cases - especially enterprise environments, on-premise configurations and custom compliance requirements - it is worth reaching out to the team to agree on a workflow suitable for the specific compliance scenario.

Recommended workflow: from material to register entry, step by step

  1. Identify the material and the purpose of publication, and assign a person responsible for the review.
  2. Import the material into Gallio PRO and run automatic detection - Gallio PRO blurs faces and license plates, which are the only two elements detected automatically. Gallio PRO works on files, not live streams.
  3. Perform a manual review and mask, in the built-in editor, any elements that are not detected automatically, such as documents, screens, nameplates, tattoos or logos, if they are visible.
  4. Complete the anonymization report - basis/exception, automatic and manual review results, scope, and re-identification risk assessment.
  5. Add an entry to the register on the controller’s side and link it to the report ID.
  6. Approve the publication decision and publish only the approved output file. Gallio PRO does not replace a compliance register and does not store logs containing personal data.

If you want to test this process on your own materials, you can download the free demo and start building your audit documentation from the first file.

See how Gallio PRO anonymizes video recordings.

Person sitting on a chair examining a box of files in a large archive room with shelves full of labeled boxes.

How should faces and license plates be described in the documentation?

It is better to avoid vague statements such as “personal data was anonymized”. A GDPR auditor expects specifics. A stronger formulation is: “face blurring was applied to identifiable persons and license plate blurring was applied to license plates visible in the material”.

For license plates, it is worth describing the adopted compliance logic. In European practice, blurring them before publication is often treated as a precautionary measure, but the assessment depends on the context and national law. In Poland, the situation remains ambiguous: some case law and practice indicate that a license plate number may constitute personal data if it allows a person to be identified by reasonably likely means, while in other cases it has been stated that a license plate alone does not always identify a natural person. In the documentation, it is worth noting that the organization applies a precautionary publication model and therefore uses license plate blurring as a compliance practice. This is not legal advice, but a typical risk-reduction approach.

How can you demonstrate review completeness without excessive bureaucracy?

The best documentation is concise but verifiable. For the auditor, what matters is the ability to trace the material from decision to publication. In each report, three steps are usually enough: (1) identification of the material and publication purpose; (2) indication of which elements were covered by automatic recognition and which required manual correction; (3) final approval with justification.

At the testing stage, it is worth building your own register on the controller’s side from the beginning, because the tool itself does not function as a compliance register.

Rows of neatly organized ring binders on shelves, some leaning, in a monochrome setting.

Most common gaps found during audits

The most common problem is not the lack of anonymization, but the lack of a description of image-related exceptions. Organizations publish event photos assuming that a wide scene always removes the need for further assessment - but that assumption can go too far. If the frame highlights a specific person, the mere presence of a crowd does not solve the issue. The second common gap is skipping the manual review: because automatic detection covers only faces and license plates, other identifying elements may remain in the material. The third is the lack of assigned responsibility: the auditor should be able to see who reviewed the material and who approved it for publication.

How should the tool be described in audit documentation?

The tool description should be precise and restrained. It is worth stating that the organization uses on-premise software for visual data anonymization of photos and video recordings, which automatically blurs only faces and license plates, while other elements can be hidden manually in the editor. Do not claim features the software does not have. For Gallio PRO, it is especially important to state that it does not blur entire silhouettes, does not operate in real time and does not replace the compliance register maintained by the controller. Such a description is more credible than marketing shorthand. Auditors value clear boundaries of responsibility: the tool supports material anonymization, but the controller remains responsible for the publication decision and for maintaining the register.

A pencil and eraser next to a drawing of a lightbulb with a question mark inside, symbolizing creativity or a brainstorming idea.

FAQ - video anonymization documentation for a GDPR auditor

Does a GDPR auditor require a separate anonymization register for photos and videos?

Not always as an explicit legal requirement, but it is a common and reasonable compliance practice. A register makes it easier to demonstrate accountability, publication purpose, scope of blurring and the approving person.

Does an anonymization report need to be prepared for every single photo?

It depends on scale and risk. In practice, materials can be grouped into logical sets, such as a gallery from one event, provided the description remains clear and verifiable.

Is it enough to state that the material was processed through blurring software?

No. An auditor usually expects evidence of review, the scope of anonymization, the basis for publication and the final decision. The mere fact that a tool was used does not complete the controller’s obligations.

Do license plates always have to be blurred before publication?

It cannot always be described as an absolute obligation. In practice, many organizations take a precautionary approach and blur license plates to reduce risk, especially in publicly accessible publications.

Does Gallio PRO maintain an anonymization register for audit purposes?

No. The register should be maintained by the controller. This is consistent with the assumption that the tool does not replace compliance documentation or publication decisions made on the controller’s side.

Does the tool automatically detect all sensitive elements in the frame?

No. Automatic detection covers only faces and license plates. Logos, tattoos, name badges, documents and content displayed on monitors require assessment and, where necessary, manual blurring.

Is anonymization documentation also needed for marketing publications?

Yes, if the publication includes identifiable people or vehicles with visible license plates. Marketing and PR are precisely the areas where organizations most often need to show that the publication decision was deliberate and documented.

This text was prepared by the Gallio PRO team - specialists in data protection and video engineering who develop anonymization software used in security, the public sector and media. This material is for informational purposes only and does not constitute legal advice.

Build audit documentation from the very first material - download the free Gallio PRO demo →

References list

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) - Article 5(2) accountability.
  2. European Data Protection Board, Guidelines 05/2020 on consent under Regulation 2016/679.
  3. Information Commissioner’s Office, UK GDPR guidance on lawful basis.
  4. Information Commissioner’s Office, guidance on video surveillance and personal data.
  5. Act of 23 April 1964 - Polish Civil Code.
  6. Act of 4 February 1994 on Copyright and Related Rights.