The question is simple enough to fit on one line. Of the faces your cameras see, what proportion do you actually obscure?
It is the first question a data protection authority asks. It is the first question a works council asks. It is the question a procurement lead is supposed to ask and usually does not, because nobody has told them it has no answer.
What we did
We read the public documentation of every major vehicle-camera platform and every street-level imagery service we could find. Not the marketing pages. The privacy notices, the help centres, the engineering blogs, the terms of service, and the letters companies have written to legislators.
The tally, and every claim in it comes from a document the company published itself:
- Redaction before upload — one. Redaction performed on the camera, so identifying material never reaches a server. We could find no other operator claiming it, in either category.
- Redaction in the cloud — three. Applied when video is served or downloaded. The unredacted original therefore exists on their systems by design. One states plainly that its blurring is not retroactive, which is an elegant confirmation that the stored master is untouched.
- Redaction, stage unstated — one. The feature is announced. Where it runs is disclosed nowhere.
- No redaction claim of any kind — two, and they operate two of the largest camera fleets on earth. Their published privacy mechanism is de-linking footage from your account, or encrypting it. Neither obscures anyone in frame.
- A published recall figure — none.
Among street-imagery services the picture is the same. Every operator that says anything places blurring after ingest and before publication. One publishes a retention period for its unredacted originals, which is more than anyone else does. One names its national regulator as the reason its blurring must be automatic, and concedes in the same sentence that the automated pass sometimes misses a face. Nobody publishes a number.
The word doing the work is “anonymous”
One of the largest fleets uses that word repeatedly, and it means something specific and much narrower than a reader assumes. It means not linked to your account. A thirty-second clip in which every face and every plate is perfectly legible satisfies that sentence completely.
De-linking and de-identification are different operations solving different problems, and the category has one word for both. That is not deception. It is worse in a way, because it is a genuine ambiguity that nobody has an incentive to resolve.
The refusal is now on the record
In November 2025 a United States Senator asked one of these companies for the performance metrics behind its face recognition. The written answer, from the vice president of public policy:
We do not publicly disclose detailed test results or specific performance metrics from these assessments.
That is not an absence we inferred from silence. It is a formal refusal, in a letter to Congress, from a company that had shipped a facial recognition product across two countries six months earlier — and whose privacy notice, updated after that launch, does not mention faces, biometrics or facial recognition at all.
There is nothing to comply with
Before publishing a figure of our own, we went looking for the bar we would be measured against. We checked the international standards catalogues for both committees that would own it, and read the relevant national publications end to end.
The de-identification standard excludes images explicitly — its own introduction says the techniques do not apply to images, audio or video. The privacy framework standard defines anonymisation as an absolute rather than a percentage. The biometrics standards cover recognising people in video, which is the opposite problem. The video-surveillance guidance sets a reversibility test and no threshold. The privacy framework from the American standards body contains no numeric target of any kind, by design.
And the most directly relevant publication, from 2015, says this about photographs and video:
We have found no significant efforts to quantify the effectiveness of multimedia de-identification.
That was eleven years ago. There is no work item on imagery de-identification at any stage in the relevant committee today. Nothing has filled the gap.
One number exists, and it runs the other way
In 2012 the Swiss Federal Supreme Court tolerated a failure rate of about one per cent for automated blurring of street-level imagery. As far as we can establish it is the only figure any tribunal anywhere has attached to this problem.
It is worth reading which direction it points. The regulator had demanded complete anonymisation and won at first instance. The Supreme Court overturned that on proportionality — so the one per cent is a ceiling on tolerated failure granted to an operator, not a bar imposed on an industry. The court found the operator’s actual error rate at the time ran between 0.9 and 2.5 per cent, and observed that even at 99.5 per cent, a hundred thousand images would remain inadequately treated.
The two conditions attached to that tolerance are the instructive part, and we have adopted both. The automated system must be continuously brought up to the state of the art — a figure published once and left to age would not have satisfied the court. And around hospitals, schools, prisons and women’s shelters, anonymisation must be complete and manual, because obscuring a face is insufficient where clothing, skin tone and mobility aids identify a person just as well.
Why the absence persists
Not conspiracy. Three ordinary reasons.
The denominator is genuinely hard. What counts as a face? A face at eight pixels? In a wing mirror? On a billboard? On a passenger’s T-shirt? A German anonymisation vendor says publicly that clients ask for a stated error rate and that defining one is difficult, then resolves it by agreeing a criteria catalogue bilaterally with each customer. That is an honest answer and it is also why no public number exists.
Nobody is obliged to. No regulator asks. No standard specifies. The only percentages in this market appear in procurement documents and marketing copy, and both sides know the denominator is undefined.
The first number published becomes the number everyone is held to. There is no upside to going first, unless going first is the point.
Which is why we are going first
We will publish a recall figure with its protocol, its held-out set, its counting rule and its confidence interval, stratified rather than blended, and re-measured rather than framed. Not because a rule requires it. Because a company that sells measurement and declines to be measured has answered the question about itself.
We would rather the figure was uncomfortable and real than absent and implied.
What would change our mind
If a regulator or a standards body publishes a threshold, we will measure against it rather than against our own protocol, and we will say so if we fall short of it. And if publishing turns out to mislead more than it informs — if the number gets quoted without its stratification, which is the obvious risk — we will change how we publish rather than stop.
What we are least sure about
Whether anyone follows. The most likely outcome is that we publish, nobody matches it, and buyers conclude the figure is a weakness rather than a disclosure — because a company that admits a miss rate looks worse beside a company that admits nothing. That is a real risk and it is the argument our own commercial people make. We think it is worth taking anyway, and we would rather have made the argument in public than lost it in a meeting.