Privacy, in this atlas, is not a feature a city buys. It is a limit that arrives afterwards — from a court, an auditor, a protest or a law — and in most of these entries it had not arrived yet when the system went live. Eighty projects across sixty-one cities carry this tag: camera networks, plate readers, biometric gates, contact tracing, identity registers and the fights over who may look at what they collect.
The pattern is visible in the sourcing before it is visible in the stories. Of the eighty entries, forty-nine rest on the operator's own account of what it does with the data, and only nine on peer-reviewed work. That is not an accusation. It is the measurement problem: a city can publish how many plates its cameras read without ever publishing what happened next, and almost nobody audits the difference.
Who decides what a camera may do?
The useful question is not whether a system collects personal data — nearly all of these do — but who is entitled to say no, and whether that entity ever did. The entries sort onto a ladder.
| Who sets the limit | What that looks like | Example |
| Nobody but the owner | A private operator chooses the streets, the price and the access rules, and holds the footage | Vumacam, Johannesburg |
| The operator, on itself | A published self-restriction: opt-in enrolment, no stored video, no faces | Osaka Metro's gates |
| A standard the city wrote | Data is required, but in a defined, anonymised form — and the rule survived a legal challenge | Mobility Data Specification, Los Angeles |
| A law with a register | Approval, impact report and use policy before acquisition — enforcement imperfect | San Francisco's ordinance |
| A court | The system is suspended, or the challenge is dismissed — both happen | Buenos Aires |
| The public, physically | The hardware becomes the protest target | Hong Kong's lampposts |
A statutory limit is worth what its enforcement is worth
Buenos Aires is the clearest case in the corpus, and it is filed as a failure. The city matched live camera feeds against a national fugitives list that carries names and ID numbers but no photographs — so the reference faces came from the national identity registry instead. The law confined the system to people on that list. The Legislature's oversight commission was never seated and the ombudsman's audit never happened, and the system was ultimately stopped on the city's own security statute rather than on data-protection law.
San Francisco is the counter-example that refuses to be a clean one. Its 2019 ordinance did two separate things: it barred city departments from using facial recognition, and it required published approval before any department acquires surveillance technology. The public register works. In the same years, the police department admitted six breaches of the facial-recognition ban.
Santiago points the opposite way. Chile's Supreme Court dismissed a residents' challenge to municipal drones in December 2017, and no statute has followed. There, the limit was asked for and declined.
The cities that chose not to look
A privacy guide that only lists surveillance misses the more interesting half. Several entries here are tagged because the operator deliberately did not identify anyone, and said so: Rome's crowd analytics gauge density without capturing faces or plates, Osaka converts a face to feature data and stores no video, and Los Angeles required trip data in anonymised form and won in federal court on that basis. Rio is the sharpest version: the city runs thousands of cameras and declines to run biometrics on them — the recognition belongs to the state police, and so does the accountability.
Questions to ask before procurement
- Who can compel disclosure? If the answer is a private contract rather than a public body, no audit is possible later. Vumacam is the case.
- Does a named body have a duty to review it, and has that body been constituted? Buenos Aires had the law and not the commission.
- What is published: detections, or outcomes? Lagos publishes how many plates its cameras read and nothing about what followed.
- Is the reference database yours? Matching against a national identity registry is a different system from matching against a warrant list, whatever the procurement says.
- What happens to the data when the emergency ends? Singapore deactivated TraceTogether in February 2023 and deleted the data in 2024 — after a 2021 controversy over police access.
The takeaway
Sensors are procurable; jurisdiction is not. Across these eighty entries the technical capability is almost never the constraint — the constraint is whether some body outside the operator has both the standing and the appetite to say no, and whether anyone checks afterwards. Where that body existed and acted, the record is legible. Where it did not, what remains is the operator's own account, which is what forty-nine of these entries rest on.
Frequently asked
Which cities have banned facial recognition?
San Francisco barred its own city departments from using facial recognition in 2019 — the first US city to do so — while separately requiring published approval before any department acquires surveillance technology. The ban applies to city departments, not to private users, and the police department later admitted six breaches of it. Buenos Aires reached a similar end by a different route: its live facial-recognition system was stopped through the courts, on the city's own security statute rather than on data-protection law.
Do smart city cameras identify individual people?
It depends entirely on what sits behind the lens, and cities in this atlas differ deliberately. Rome's Jubilee analytics measure crowd density without capturing faces or licence plates. Osaka Metro's ticket gates do recognise faces, but enrolment is opt-in and the operator says no video is stored. Rio runs thousands of municipal cameras and does not run biometrics on them — that is the state police, a separate body. The camera is not the decision; the database it is pointed at is.
Who audits a city's surveillance systems?
Usually nobody. Of the eighty entries tagged here, forty-nine rest on the operator's own account of what it does with the data and only nine on peer-reviewed work. Where an external check did happen it was decisive — a court in Buenos Aires and in Santiago, a published register in San Francisco, a physical audit ordered in Delhi after the city found 263,000 cameras recorded as installed and wanted to know how many existed. A privately owned network like Johannesburg's Vumacam has no such route at all.
What happens to the data after the system is switched off?
Rarely stated in advance, and that is the point of asking. Singapore's TraceTogether and SafeEntry were deactivated in February 2023 and the data deleted in 2024, after a 2021 controversy over police access to it. Hong Kong disabled the Bluetooth and plate-recognition functions of its smart lampposts after a public backlash, and had to replace hardware that protesters had physically removed. Both are unusual for being documented at all.