Video-based care monitoring offers capabilities that conventional sensors cannot always provide: it can detect complex situations, distinguish different movement patterns and, where permitted, support the visual assessment of an alarm.
At the same time, the use of video in resident rooms requires particularly careful handling of privacy, security and personal data.
The key question is therefore not simply:
“Is the device a camera?”
The more relevant question is:
“What data is processed, where is it processed, who can access it, and does it need to be transmitted or stored?”
“Not a Camera” Does Not Automatically Mean More Privacy
Some care-monitoring solutions emphasize that they are “not cameras.” While this may sound reassuring, the product category or marketing description alone does not determine GDPR compliance.
The GDPR is technologically neutral. Its requirements apply according to the personal data being processed, the processing purpose and the associated risks—not according to whether a manufacturer describes a device as a camera, radar sensor or another type of detector.
A non-video sensor may still collect sensitive information about presence, movement, sleep patterns or health-related behaviour. Conversely, an intelligent video sensor can be designed so that image data is processed locally without being stored or transmitted.
Privacy must therefore be evaluated based on the complete data-processing concept.
A Video Sensor That Does Not Need to Transmit Video
The c ONE NurseAssist follows the decentralized MOBOTIX approach: the image analysis takes place directly on the sensor.
For normal NurseAssist operation, the sensor can detect relevant situations and generate alarms without storing or transmitting a single video image. The operator decides which alarms and application data may leave the sensor and be forwarded to a nurse call system or video management system.
This architecture supports several central Privacy-by-Design principles:
- Local processing instead of continuous cloud transmission
- No video recording required for event detection, but available if applicable and value-adding
- Transmission limited to required alarms and anonymized application data
- Controlled access for authorized personnel
- Optional image access based on the defined care workflow
These measures directly support GDPR principles such as data minimization, protection by default and security appropriate to the processing risk.
Privacy Masking Without Losing the Analytics
Where usable video images are not required, the image can be protected by a privacy mask directly on the sensor.
The NurseAssist analytics continue to operate while the resident room remains visually concealed. The sensor can still detect situations, generate alarms and transfer anonymized application information without providing a usable view of the resident.
The privacy mask can therefore support different operational models:
- No visual access at any time
- Visual access only during a defined critical event
- Visual access only for specifically authorized personnel
The concealed personal image information cannot subsequently be reconstructed from the transmitted image.
This provides a decisive advantage: care organizations do not have to choose between advanced analytics and privacy. Both can be implemented within the same system.
The MOBOTIX Video Approach
MOBOTIX does not treat data and privacy protection and cybersecurity as external additions. They are part of the system architecture.
The decentralized design reduces dependency on central processing servers or a cloud and limits unnecessary data transmission. The MOBOTIX Cactus Concept provides additional protection measures such as strong authentication, IP access control, intrusion detection, individual certificates, encrypted connections and network access control. In the corresponding NurseAssist guideline MOBOTIX also describes vulnerability assessments, security testing and ISO 27001-certified AI development processes.
MOBOTIX develops and manufactures its video systems in Germany and combines this approach with decentralized processing, embedded intelligence and a strong focus on cybersecurity throughout the product lifecycle.
Can c ONE NurseAssist Be Used in a GDPR-Compliant Solution?
Yes—video-based care monitoring can form part of a GDPR-compliant solution when it is configured and operated appropriately.
However, GDPR compliance does not result from one product feature or manufacturer statement alone. It depends on the complete deployment, including the intended purpose, legal basis, configuration, access rights, transparency and organizational processes defined by the care provider.
The operator should therefore address topics such as:
- Lawful basis and, where applicable, informed consent
- Transparent resident and patient communication
- Role-based access policies
- Data-processing agreements
- Staff training
- Incident-response procedures
- Regular compliance and security reviews
- A Data Protection Impact Assessment where required
Technical Privacy-by-Design features provide the foundation. The care organization remains responsible for selecting and implementing the appropriate organizational and legal measures for its specific use case.
The Better Question
The future of care monitoring should not be reduced to camera versus non-camera.
The better comparison is between systems that process sensitive information transparently, securely and only when necessary—and systems that do not provide the same level of control.
With decentralized analysis, optional image-free operation, sensor-level privacy measures and a cybersecure Made-in-Germany platform, c ONE NurseAssist combine the analytical advantages of video with a strong Privacy-by-Design architecture.
For detailed technical and organizational guidance, refer to the MOBOTIX NurseAssist privacy guideline.
This article provides general product and data-protection information and does not constitute legal advice. Local requirements should be assessed together with the responsible data protection officer or legal adviser.

