GDPR-compliant is a claim. Approved by an authority is a finding.
Every people-counting supplier in Europe describes itself as GDPR-compliant. The phrase sounds like a verdict, but in almost every case it is the supplier grading its own homework. Here is the difference between saying it and having a regulator conclude it, and how to tell which one you are buying.
Read any people-counting website in any European language and the same phrase appears: GDPR-compliant, DSGVO-konform, conforme au RGPD, RODO-compliant. The phrase costs nothing to write, which is exactly the problem: it tells a buyer nothing about who reached that conclusion. In almost every case, the answer is the supplier itself.
Self-assessment is the norm, not the exception
To be fair to the industry, self-assessment is how GDPR generally works. The regulation makes organisations responsible for their own compliance and does not hand out product badges. A supplier that says “GDPR-compliant” is usually describing its honest reading of its own architecture, with a privacy policy and a DPA template to back it up.
But that is precisely why the phrase cannot carry the weight buyers put on it. When every supplier makes the same claim in the same words, the claim stops distinguishing careful engineering from wishful thinking. Your compliance review still starts from zero: someone on your side has to examine what the system actually collects, keeps and could expose. The supplier’s self-description is an input to that review, not a substitute for it.
What a regulator’s review adds
A data protection authority is the body GDPR itself appoints to judge these questions. When an authority examines a measurement method, it does what your DPO would do with more mandate and more depth: it looks at what is collected, what happens to it, what remains, and whether any individual could be identified at any stage.
Bumbee Labs went through that examination. The result is the only footfall method in Europe approved by a data protection authority: the approval was issued by IMY, the Swedish Authority for Privacy Protection, for our Wi-Fi footfall method, after reviewing how signals are collected, irrevocably deleted and reduced to anonymous, aggregated statistics. The same privacy-by-design engineering builds everything we deliver alongside it, from 3D sensors to LiDAR and cellular analytics.
Because GDPR is one regulation across the EU and EEA, the question IMY answered is the same question a reviewer in Paris, Munich or Milan starts from: does this produce personal data? An approval does not end your review, but it changes what the review is: verifying documented findings instead of investigating bare claims.
Three questions that separate the two
Put these to any supplier, including us, and ask for the answers in writing: what independent review the method has passed, and by whom; what exactly the review covered, which method and which data journey; and what documentation the supplier can hand your DPO. A self-declared supplier answers the first question with its own policies. That is not a scandal, but it is a different product than it sounded like in the sales deck, and your legal team should know which of the two it is signing off.
The GDPR footfall analytics page walks through our answers in full, and the DPIA guide collects the questions a DPO typically asks with pointers to where each answer lives. If a tender is being written, procurement for people counting turns the same distinction into specification language.
We have extensively evaluated Bumbee Labs' solution and the quality insights they produce, in combination with the efficiency of the remote installation process, make this a valuable collaboration. This alliance presents a great opportunity for our distribution ecosystem to provide a variety of service offerings to their customers, opening up new revenue streams.
Frequently asked questions
Is "GDPR-compliant" a certification?
No. GDPR does not certify products by default; unless a regulator or an accredited body has actually examined a system, 'GDPR-compliant' is the supplier's own conclusion about its own product. It may well be correct, but nothing in the phrase tells you that anyone independent has checked.
What exactly was approved in Bumbee Labs' case?
IMY, the Swedish Authority for Privacy Protection, reviewed Bumbee Labs' Wi-Fi footfall method: what is collected, what is deleted and what remains. No other footfall method in Europe has that standing. The same privacy-by-design engineering carries every method we deliver alongside it.
Does an approval from one EU authority matter in other countries?
GDPR is one regulation across the EU and EEA, so the question a reviewer in any member state asks is the same: does this produce personal data? A method that has answered that question in front of a data protection authority gives your DPO documented evidence to start from, wherever you operate.
How should procurement test a compliance claim?
Ask every supplier the same three things in writing: what independent review has your method passed, what exactly did it cover, and what evidence can you attach? Self-declared compliance answers with policy documents. Reviewed compliance answers with a regulator's conclusion. The difference shows up quickly.