Privacy-Preserving Vision in Aged Care
SilverGuard Technologies Limited7 min read
Privacy is the first question, not the last
Put a camera in a bedroom corridor and the first question will not be about accuracy. It will be about who can watch, what is recorded, and who owns the footage. Care providers who treat that as an afterthought end up with a system staff quietly work around and families quietly resent.
Privacy-preserving vision is the design answer to that question. It is not a marketing phrase: it describes a set of concrete technical choices about what the system computes, what it stores and where it runs.
Three levels of camera monitoring
It helps to separate three things that are often sold under one label.
- Full recording: continuous video retained for a period, with people identifiable. The most capable for investigation, and the hardest to justify in a bedroom.
- Event clips: short clips captured when motion or an event triggers, which limits retention but still stores identifiable footage.
- On-device detection: the model runs locally and produces a signal, such as the position of a body over time, rather than a reel of video. The building keeps the answer and discards the raw frames.
What a privacy-preserving system actually stores
In an edge-first design, a small device inside the home runs the model. It converts each frame into a sparse representation of a body, typically a set of joint positions rather than an image, evaluates whether what it sees looks like a fall, and raises an alert if it does. The raw frames never have to leave the device.
Two design choices do most of the work. The first is processing at the edge rather than in a cloud service. The second is detecting on skeletal posture instead of facial identity, so the system does not need to recognise anyone to know that someone has fallen. A short technical summary of that approach sits with the rest of our platform notes on our FAQ.
The regulatory backdrop, in plain terms
In Hong Kong, the Personal Data (Privacy) Ordinance governs how personal data is collected, used and retained, and it applies to camera systems in care settings. In practice this means asking what data is collected, for what purpose, for how long it is kept, who can access it and how a resident or family member can raise a concern.
This is a design and governance question, and it is not something a vendor can settle for you. A privacy-preserving architecture makes the answers shorter, but the home still has to write them down and be able to explain them.
What to tell residents and families
Explain the purpose before the technology. Residents and families generally accept monitoring that is framed as safety and explained honestly; they object to discovering it. A short, plain notice that covers why the system exists, what it stores, how long it is kept and who can see it does more for trust than any brochure.
- Why: to shorten the time to help after a fall.
- What is stored: alerts and derived signals, not continuous video, in an edge design.
- How long: state the retention period explicitly rather than leaving it open.
- Who can access: name the roles, not just 'staff'.
- How to ask a question: give a named contact and a way to escalate.
The questions families ask
Three come up again and again, and they deserve direct answers.
- 'Can you see my mother on camera?' With on-device skeletal detection, the building keeps an alert, not a video of her.
- 'Who else sees this?' Only the roles you list, on the network you control, unless the design sends data off site, which is the first thing to verify.
- 'What if you are hacked?' Edge-first processing removes the cloud copy entirely, which removes a whole category of exposure with it.
How this should shape procurement
Put the privacy answer in the tender, not in the appendix. Ask for the data flow in a diagram, the retention period in a sentence, and the processor's role in writing. That is also the fastest way to compare two systems that look identical on a datasheet.
For the wider choice, our note on choosing a fall detection system covers camera, radar and wearable options, and the practical fall prevention checklist covers everything the technology does not do. Our own product family separates the sensing and risk-prediction platform, Steadicore, from the cognitive and physical training side, Sanospark, so the privacy decision can be made once and applied to both.
What a derived signal actually is
It is worth being precise about the middle ground, because privacy claims tend to collapse into two extremes that are both false. Most edge systems do not store video, and they are not memoryless either. They keep a short numeric record: a confidence value, a zone identifier, a timestamp.
That record is what makes an alert reviewable the next morning, and it is also personal data where it can be linked to an individual. The right response is not to hide the log but to describe it, keep it short and treat it with the same care you would apply to the video it replaced.
Explore more
- Who we are : the team and the design principles behind our platform.
- Easikin : the family-coordination side of care, where data-sharing questions also land.