Module 5/5 · Weeks 13–15 · 27 h

Ethics and the PDPA

UAT 401 UAS Regulations, Safety and Risk Management

About 80 minDraft, awaiting reviewLast updated 28 September 2026

Lesson

By the end of this module you will be able to

  1. Choose a flight height that captures enough detail for the job but no more than needed to identify people
  2. Explain DORI image resolution levels and their limits when applied to drones
  3. Design a retention policy and a review system for deletion
  4. Lay out a traceable data lifecycle for drone imagery from purpose to destruction

Prerequisites: UAT 401 Modules 1–4 · UAT 313 Module 5 (ethics, privacy and the PDPA)

Why this matters

UAT 313 covered the legal bases under the PDPA, sensitive data and breach notification within 72 hours. The drone knowledge base’s unit on ethics, privacy and the PDPA in drone work covers capturing images of people and the ethics of automated systems, and its unit on planning the data lifecycle before capturing drone images advises setting the purpose, the data needed, who has access, onward transfer and retention review points so they can be audited. Overseas guidance, such as from the UK Information Commissioner’s Office and the EU Article 29 Working Party, stresses assessing impact before collection. At the time of checking, no provision was found in the Thai PDPA that requires a data protection impact assessment (DPIA) by that name, but the principle of collecting only what is necessary still fully applies. This module turns that principle into numbers that can be designed.

Collecting only what is needed through flight height

Image detail on the ground depends on flight height, sensor size, focal length and pixel count. CCTV work uses the DORI criteria of IEC 62676-4:2014, which divide resolution into four levels: detection 25 px/m, observation 62.5 px/m, recognition 125 px/m and identification 250 px/m. That standard has been replaced by the 2025 edition, which changes to seven operational requirements, but the old figures remain an easy-to-understand reference. Note that the criteria were designed for cameras seeing faces from the side. A nadir drone image shows heads and shoulders, so identifying people is harder than the numbers suggest, but vehicles, licence plates and activities in homes may still be visible.

Example 1 Choosing a height for a village road map

A hypothetical camera has a 17.3 mm wide sensor, a 12.3 mm focal length and 5,280-pixel-wide images. Mapping the road surface needs a GSD of no more than 2.5 cm per pixel.

sensor_w_mm = 17.3        # sensor width (hypothetical camera)
focal_mm = 12.3           # focal length
image_w_px = 5280         # image width in pixels
DORI = [("identification", 250), ("recognition", 125),
        ("observation", 62.5), ("detection", 25)]   # px/m per IEC 62676-4:2014

def px_per_m(height_m):
    gsd = sensor_w_mm * height_m / (focal_mm * image_w_px)   # m per pixel (nadir view)
    return 1 / gsd

for h in [25, 45, 70, 90]:
    d = px_per_m(h)
    level = next((n for n, t in DORI if d >= t), "below detection")
    print(f"height {h:>2} m: GSD {100/d:.2f} cm/px = {d:6.1f} px/m -> {level}")

for n, t in DORI[1:3]:
    print(f"{n} reached at or below {focal_mm * image_w_px / (sensor_w_mm * t):.1f} m")
height 25 m: GSD 0.67 cm/px =  150.2 px/m -> recognition
height 45 m: GSD 1.20 cm/px =   83.4 px/m -> observation
height 70 m: GSD 1.86 cm/px =   53.6 px/m -> detection
height 90 m: GSD 2.40 cm/px =   41.7 px/m -> detection
recognition reached at or below 30.0 m
observation reached at or below 60.1 m

At 70–90 m, images are still detailed enough for a road map (1.9–2.4 cm per pixel) and below the DORI observation level. Flying lower “for sharper images” therefore adds privacy risk with no benefit to the job. Choosing a height is as much a personal-data decision as a technical one, and it must still stay within the 90 m ceiling of the general conditions.

Pixel density in pixels per metre against flight height from 10 to 100 metres: a blue curve falls with height, with four horizontal dashed lines for identification 250, recognition 125, observation 62.5 and detection 25; points at 25, 45, 70 and 90 metres fall in the recognition, observation and detection levels respectively
Figure 1 Pixel density by height against DORI levels

Retention and deletion

Section 37(3) of the PDPA requires controllers to put in place a review system for erasing or destroying personal data when the retention period ends, or when the data is irrelevant or beyond what the purpose requires. Raw drone imagery usually contains the most personal data, while deliverables such as blurred orthomosaics contain less. A good policy therefore sets different retention periods by data type and reviews on a schedule.

Example 2 Reviewing the image archive on 1 December 2026

The company’s policy keeps raw imagery 90 days, blurred images 365 days and orthomosaics 5 years (assumed project values, not periods set by law).

from datetime import date, timedelta

review = date(2026, 12, 1)
policy_days = {"raw": 90, "blurred": 365, "orthomosaic": 1825}   # project retention policy (assumed)
datasets = [                                                       # (name, type, collection date)
    ("F-0712 raw video", "raw", date(2026, 7, 12)),
    ("F-0712 blurred frames", "blurred", date(2026, 7, 13)),
    ("F-0903 raw photos", "raw", date(2026, 9, 3)),
    ("F-0903 orthomosaic", "orthomosaic", date(2026, 9, 5)),
    ("F-1020 raw photos", "raw", date(2026, 10, 20)),
]
for name, kind, got in datasets:
    due = got + timedelta(days=policy_days[kind])
    action = "DELETE now" if due <= review else f"keep until {due.isoformat()}"
    print(f"{name:22s} {kind:11s} collected {got.isoformat()}  -> {action}")
F-0712 raw video       raw         collected 2026-07-12  -> DELETE now
F-0712 blurred frames  blurred     collected 2026-07-13  -> keep until 2027-07-13
F-0903 raw photos      raw         collected 2026-09-03  -> keep until 2026-12-02
F-0903 orthomosaic     orthomosaic collected 2026-09-05  -> keep until 2031-09-04
F-1020 raw photos      raw         collected 2026-10-20  -> keep until 2027-01-18

Raw imagery from the July flight must be deleted in this review. Raw photos from September fall due on 2 December, the very next day. If reviews are monthly, that data would stay nearly a month beyond policy. The system should therefore delete automatically when data falls due, or review often enough, and record each deletion as evidence.

Timeline bars for five datasets from July 2026 to July 2027: July raw imagery is a pink bar ending before the dashed review line of 1 December 2026, while the others are green bars extending past it; September raw photos end right at the review line
Figure 2 Image data retention by policy

Class activity

Activity: the data lifecycle of a community survey

  1. Write the mission’s purpose and state the minimum detail it needs as a GSD
  2. Use Example 1 with the training drone’s camera to find the height range that gives enough detail but no more
  3. Classify the data produced, and set retention, access and onward transfer for each type
  4. Use Example 2 to review a hypothetical archive and write a deletion log
  5. Discuss what the company should do when images happen to capture an unlawful act

Common mistakes

Watch out

  • Flying lower than the job needs just because images look better
  • Treating DORI as proof that no one can be identified
  • Keeping raw imagery forever in case it is useful later
  • Deleting data without a record
  • Citing a superseded standard without telling the reader

Summary

  • Flight height sets image resolution and is a tool for collecting only what is necessary
  • DORI (IEC 62676-4:2014) gives reference levels of 25, 62.5, 125 and 250 px/m, but applies only approximately to nadir images
  • PDPA section 37(3) requires a review system to delete data after its retention period
  • Retention policies should differ by data type and record deletions

Check your understanding

  1. A GSD of 2 cm per pixel equals how many pixels per metre?
  2. Which DORI level is 100 px/m?
  3. If the flight height doubles, how does GSD change?
  4. Which PDPA section requires a review system to delete data after its retention period?
  5. Raw imagery collected on 1 October under a 90-day policy must be deleted on what date?
Answers
  1. px/m
  2. Observation (above 62.5 but below 125)
  3. GSD doubles
  4. Section 37(3)
  5. 30 December

Key formulas

Ground sampling distance, nadir view
Pixel density

Key references

  1. พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562. ราชกิจจานุเบกษา, 136(69 ก), 52–95. link
  2. Axis Communications. Pixel density based on IEC 62676-4:2014 [White paper]. link
  3. International Electrotechnical Commission. (2025). Video surveillance systems for use in security applications – Part 4: Application guidelines (IEC 62676-4:2025, Ed. 2.0). link
  4. Information Commissioner’s Office. Unmanned aerial systems (UAS) / drones. In Guidance on video surveillance (including CCTV). link
  5. Article 29 Data Protection Working Party. (2015). Opinion 01/2015 on privacy and data protection issues relating to the utilisation of drones (WP 231). link

Further reading

Study the assigned knowledge units in advance, review media and take the module quiz

In class / field

Lecture, case discussion and in-class problem solving

Learning evidence: Quiz results and submitted exercises

Module quiz

This is a formative self-check, not a graded exam

Knowledge domain: Law, safety and risk · Management, innovation and professional practice · Artificial intelligence and computer vision