Drone operations in Europe sit under two separate rulebooks that are easy to confuse. EASA regulation governs whether and how you may fly. The GDPR governs what you may do with the data you collect while flying. Passing an operational authorisation says nothing about whether your data handling is lawful.
This is a practical overview, not legal advice — take specifics to your DPO or counsel.
When drone footage becomes personal data
More often than operators expect. Aerial imagery is personal data whenever a person can be identified from it, directly or in combination with other information you hold. A recognisable face is the obvious case, but so are a readable number plate, a person identifiable by context in their own garden, and a flight log that shows a named employee's location over time.
Note that thermal imagery, low resolution and altitude do not automatically make data anonymous. The test is identifiability, not image quality.
What that obliges you to do
Broadly:
- Have a lawful basis for the processing, and be able to state it.
- Be transparent — signage, notices, and a privacy policy that explains what is captured and why.
- Minimise — capture what the job requires and no more; blur or crop where you can.
- Limit retention — define how long each category of media is kept and delete on schedule.
- Run a DPIA where the processing is likely high risk. Systematic monitoring of publicly accessible areas usually qualifies.
- Secure the data — encryption, access control, and an audit trail of who saw what.
- Handle data subject rights — access, erasure, objection — within the legal deadlines.
Why residency is a separate question
GDPR does not literally require data to stay in the EU. It restricts transfers to third countries unless a valid transfer mechanism applies. But in practice, EU residency is the simplest way to keep that question closed: no transfer, no transfer mechanism, no analysis of foreign government access, no renegotiation each time the legal landscape shifts.
That is why public sector tenders, critical infrastructure operators and utilities increasingly write EU hosting into their requirements outright. If you sell drone services to those buyers, where your platform stores the data is a commercial qualification criterion, not a technical detail.
Questions to ask a platform vendor
- In which countries are the data — media, telemetry, backups and logs — stored?
- Who is the controller and who is the processor, and is there a data processing agreement?
- Which sub-processors are used, and where are they?
- Can support staff outside the EU access customer data, and under what controls?
- How long is each data category retained, and can we configure it?
- How are erasure requests executed, including in backups?
- What does the audit log record, and can we export it?
A vendor that cannot answer these quickly and in writing is a risk you are inheriting.
Where Timoneiro stands
Timoneiro is EU-native: mission data, media and telemetry stay in European datacentres, and the product is built around GDPR expectations rather than retrofitted to them. That is a deliberate design constraint, because for most of our users it is the difference between being able to bid for a contract and not.
