EU Mandates Driver-Monitoring Cameras in All New Cars: Where's the Line Between Safety and Privacy?
EU Mandates Driver-Monitoring Cameras …
EU GSR mandates driver-facing cameras in all new cars, sparking a safety vs. privacy debate.
The EU's General Safety Regulation (GSR) now requires all new vehicles to include driver drowsiness and attention monitoring systems, often featuring a camera aimed at the driver's face. While the goal is reducing fatigue-related crashes, critics raise serious concerns about biometric data handling, lack of enforceable storage restrictions, and a legal gray zone between GSR and GDPR that leaves consumers with little control over their facial data.
A Regulation That Quietly Took Effect
The EU's General Safety Regulation (GSR) — formally designated EU 2019/2144 — has come into full force. Passed in 2019, it began mandatory phased implementation for new vehicle models in July 2022 and expanded to all newly registered vehicles in July 2024. It sits at the heart of the EU's Road Safety Strategic Action Plan, driving toward the "Vision Zero" goal of eliminating road traffic fatalities in Europe by 2050.
It's worth noting that "Vision Zero" didn't originate with the EU — it was born in Sweden in 1997, passed by the Swedish parliament with the core philosophy that traffic deaths and serious injuries are "unacceptable" rather than "inevitable" systemic outcomes. The underlying idea: humans make mistakes, so transportation systems must be designed to accommodate human error without resulting in death. The EU's 2021 Road Safety Strategic Action Plan 2021–2030 broke Vision Zero into phased targets — a 50% reduction in road deaths and serious injuries by 2030, and zero fatalities by 2050. The GSR is the primary technical instrument for executing this strategy at the vehicle level, standing alongside improved road infrastructure and stronger enforcement as one of three core pillars.
Under this regulation, all new cars sold in the EU must be equipped with a suite of Advanced Driver Assistance Systems (ADAS), with one of the most scrutinized requirements being the Driver Drowsiness and Attention Warning (DDAW) system.
ADAS is not a single technology but a multi-layered system encompassing perception, decision-making, and actuation. Under the Society of Automotive Engineers (SAE) automation level framework, ADAS primarily corresponds to L1 (driver assistance) and L2 (partial automation). The functions mandated by GSR each occupy a distinct role in this taxonomy: Intelligent Speed Assistance (ISA) covers speed control, Autonomous Emergency Braking (AEB) addresses collision avoidance, Lane Keeping Assistance (LKA) handles lateral control, and the Driver Monitoring System (DMS) falls into a special category called "driver state awareness" — it doesn't directly intervene in vehicle control, but monitors the most unpredictable link in the driving chain: the human.
This means every new car on the EU market must continuously monitor driver status through sensors. For the more advanced Advanced Driver Distraction Warning (ADDW) system, automakers typically install a camera aimed directly at the driver's face on the steering column or dashboard, continuously assessing whether the driver is watching the road and detecting signs of drowsiness or distraction.
The topic sparked extensive debate on Hacker News — and the core controversy wasn't about road safety itself, but rather: when a camera is pointed at your face continuously, where exactly does the privacy boundary lie?
The Regulation's Intent: Using Technology to Reduce Casualties
The EU's motivation for this legislation is clear — reduce traffic accidents caused by drowsy and distracted driving. Europe still sees approximately 20,000 traffic deaths per year, with fatigue and distraction cited as major contributing factors in an estimated 20–30% of serious crashes. The European Commission estimates this combination of safety systems could save more than 25,000 lives over the next decade and prevent around 140,000 serious injuries.
Beyond driver monitoring, GSR also mandates that new vehicles come standard with Intelligent Speed Assistance (ISA), emergency braking systems, lane-keeping assistance, reversing cameras, and "black box" Event Data Recorders (EDR). From a product evolution perspective, this marks a pivotal moment in the automobile's transition from a "mechanical tool" to a "mobile intelligent terminal."
The technical principles behind driver monitoring aren't complicated, but the system involves several sophisticated computer vision techniques. These systems typically use near-infrared (NIR) cameras rather than standard RGB cameras, for several key reasons: the NIR band (700–1000 nm) is insensitive to visible light changes, enabling stable imaging in tunnels, at night, or under strong backlighting; NIR light sources are nearly invisible to the human eye and don't interfere with driving; NIR also penetrates skin more effectively, making it easier to capture eye detail. By tracking 68 to 486 facial landmarks, the system focuses on eye openness, head pitch and yaw angles, gaze direction vectors, and microsleep signatures. One key metric is PERCLOS (percentage of eye closure) — developed by the U.S. Federal Highway Administration (FHWA) in the 1990s and validated by numerous driving simulation studies as a reliable predictor of drowsy driving — when it exceeds 80% for several seconds, the system flags the driver as highly fatigued and triggers auditory or visual warnings.
The Privacy Debate: Where Does the Data Actually Go?
What genuinely raises alarm is the question of where the data behind these cameras flows. Discussion has centered on several critical concerns.
Is Data Processed Locally Only?
Many proponents point out that, under the constraints of the EU's GDPR (General Data Protection Regulation), most mainstream driver monitoring systems process image data locally within the vehicle in real time — raw video is not uploaded to the cloud or stored long-term. The system outputs only interpreted results like "attention state."
Importantly, GDPR (which took effect in 2018) explicitly classifies facial images as "biometric data" (Article 9 special category data), in principle requiring explicit user consent before processing. Yet there is an unresolved legal priority conflict between GDPR and GSR: drivers of vehicles mandatorily equipped with DMS have neither actively consented nor the ability to decline — creating a legal paradox of "coerced consent." GDPR contains exceptions for "public security" and "legitimate interests," and GSR, as a mandatory safety regulation, may constitute a legal basis for processing such data — effectively bypassing the user consent mechanism. The European Data Protection Board (EDPB) has yet to issue dedicated guidance for DMS scenarios, and in terms of EU legislative hierarchy, neither regulation explicitly establishes priority, creating a legal gray zone. This conflict between two EU regulations remains without clear judicial interpretation.
Critical voices are equally well-founded: GSR only specifies "must monitor" — it does not mandate that "data must be processed locally and not retained." Whether data is uploaded, stored, or how it's used ultimately depends on each automaker's specific implementation. In an era of increasingly normalized data monetization, this gap leaves enormous room for abuse.
Who Can Access This Data?
Another recurring concern is whether facial data could be retrieved in accident investigations, insurance claims, or law enforcement contexts. The EDR — the automotive "black box" simultaneously mandated by GSR — draws its design inspiration from aviation flight recorders. Standard EDRs record critical parameters from at least 3 seconds before a collision and afterward, including vehicle speed, braking status, and seatbelt use. The U.S. NHTSA has required EDRs in new cars since 2012, and EDR data has been used as evidence in hundreds of criminal and civil cases in the United States, most notably in multiple criminal prosecutions for speeding-related fatalities. European legal circles are also beginning to debate the admissibility of DMS data, with the core question being: can records of a driver's "attention state" at the time of an accident be subpoenaed without legal authorization, and is this data protected by the principle against self-incrimination? This question may have vastly different answers across the legal frameworks of different EU member states. Once camera data is combined with EDR driving data, accident reconstruction expands from "vehicle behavior" to "driver behavior" — making individual conduct inside the vehicle highly traceable, with profound implications for liability determination and criminal investigations.
One commenter cut to the chase: even if data is only processed locally today, the mere existence of the hardware means "the capability is already in place" — a single software update in the future could completely change how that data is handled.
The Auto Industry's Deep Structural Tension: Safety, Convenience, and Privacy
This EU regulation reflects a structural tension that is only intensifying across the modern automotive industry.
In recent years, from Tesla's cabin cameras to the connected services of every major brand, cars have been collecting ever-growing volumes of user data. The Mozilla Foundation's 2023 Privacy Not Included report conducted the most systematic third-party privacy assessment of 25 major automotive brands to date. By analyzing each brand's privacy policies, data sharing terms, and user agreements, the research team reached startling conclusions: not a single brand met basic privacy protection standards; 84% share user data with third parties (including data brokers); 76% claim they can sell data to law enforcement; and brands including Hyundai and Nissan were specifically called out for collecting highly sensitive personal information — including location history, driving behavior, in-cabin conversations, and contacts from connected phones. The Mozilla Foundation called modern cars "the worst product category we have ever reviewed for privacy."
McKinsey projects the automotive data monetization market will reach $650–750 billion by 2030, a figure based on the combined monetization potential of vehicle data across predictive maintenance, actuarial insurance models, in-car commercial services, and urban planning. Against this commercial logic, the technical promise of "local processing, no retention" faces serious pressure from business incentives — a reality consumers cannot afford to ignore.
In this context, the mandate to install facial cameras — however well-intentioned — further expands the sensor coverage inside vehicles. There is a gap that cannot be overlooked between the technical promise of "local processing" and the regulatory reality of "no explicit constraints."
Privacy Blind Spots in a Well-Meaning Regulation: What Should Consumers Watch For?
Objectively speaking, driver monitoring systems do offer genuine value in reducing fatigue-related accidents — this is broadly accepted. The debate has never been about whether to improve safety, but about how to preserve privacy while doing so.
For consumers, several points deserve close attention:
- Does your vehicle's monitoring system explicitly commit to local-only data processing with no retention?
- Do the automaker's privacy policies clearly define access rights and permitted uses of the data?
- Are there options to disable the feature or view data records?
Now that cameras are becoming standard equipment in new cars, privacy protection cannot be left to automakers' goodwill alone. As the EU pushes forward with safety legislation, it must also urgently fill the gaps in data governance — clarifying the legal priority relationship between GSR and GDPR, defining the boundaries for processing biometric data, and empowering the European Data Protection Board (EDPB) to issue binding, scenario-specific guidance on DMS. Without these measures, a camera installed to "protect lives" could quietly become a window for "monitoring daily life."
Key Takeaways
Related articles

Disaster and Glory of the Apollo Program: The History We Must Revisit Before Returning to the Moon
From the fatal Apollo 1 fire to Apollo 8's daring lunar orbit to Apollo 11's successful landing—revisiting the disasters, fears, and compromises of the Apollo program and their lessons for today's return to the Moon.

Netflix Trust Exercise Turns Into Firing Trap: Where Are the Boundaries of Corporate Trust?
A Netflix employee was fired after sharing private info in a trust exercise. We analyze the risks of corporate trust exercises and how employees can protect themselves.

AMD CDNA5 Architecture Deep Dive: Technical Evolution and the AI Computing Competition Landscape
Deep analysis of AMD's CDNA5 architecture covering Chiplet packaging upgrades, HBM memory evolution, and low-precision compute optimization, examining how AMD challenges NVIDIA's AI chip dominance.