I’m deploying mobile robots around people, and I think deleting every near-miss buffer is the wrong default. A short, event-triggered raw window can show the failure an event summary hides: glare, an occluded person, lidar dropout, bad timing, or a mistaken classification. That matters for root-cause work and possibly improving the fleet.
But this should not become a surveillance archive. Process and mask locally where possible, provide clear notice and consent where feasible, encrypt the buffer, publish a short retention period, and delete automatically unless designated safety or engineering staff formally preserve it. Retrieval should be role-based, logged, and limited to a genuine investigation. The serious counterargument is that “anonymized” summaries can still carry re-identification risk, while raw footage creates a tempting archive.
Would you trust an anonymized incident log, or insist raw sensor data never leave the robot?