Guide · 2026

EU drone rules for security and drone-in-a-box operations (2026 guide)

Automated security patrols from a docking station almost always fall into the EU “specific” category under Regulation (EU) 2019/947, because the open category requires the pilot to keep the drone in visual line of sight. Beyond-visual-line-of-sight (BVLOS) dock flights therefore need an operational authorisation from the national aviation authority (based on SORA or a PDRA), a declared standard scenario, or a Light UAS Operator Certificate.

Short answer: a drone that launches from a box on its own, patrols a warehouse yard, solar park or substation and lands again is a “specific” category operation in the EU. The open category only covers flights kept in the remote pilot’s visual line of sight (VLOS), below 120 m and under 25 kg. Beyond VLOS the operator needs approval from the national aviation authority, and video of people on site brings in data protection law.

  • Aviation rules: Regulation (EU) 2019/947 (how drones are operated) and Delegated Regulation (EU) 2019/945 (the drones themselves, including class marks C0–C6).
  • Specific-category routes: an operational authorisation based on a risk assessment (SORA 2.5 or SORA 2.0, or a PDRA), a declaration under standard scenario STS-01 or STS-02, or a Light UAS Operator Certificate (LUC).
  • Always required: operator registration, and in the specific category an active remote identification system on every drone.
  • Around the flight: GDPR and EDPB Guidelines 3/2019 for video, NIS2 and CER for essential and critical entities, the AI Act for biometric features.
  • National layer: zones, procedures and transition dates are set per Member State (in Czechia: ÚCL).

Status as of 5 October 2026. This page is general information, not legal advice.

Which EU regulations govern drone operations?

Commission Implementing Regulation (EU) 2019/947 sets the operating rules and has applied since 31 December 2020. Commission Delegated Regulation (EU) 2019/945 sets aircraft requirements, including class labels C0 to C6 (C5 and C6 are used in the standard scenarios).

Article 3 of 2019/947 puts every operation into one of three categories:

  • Open: no prior authorisation. Requires a class-marked (or privately built or legacy) aircraft under 25 kg, kept away from people and assemblies of people, in VLOS at all times (narrow exceptions), within 120 m of the surface, carrying no dangerous goods and dropping nothing (Article 4).
  • Specific: anything that breaks one of the open-category requirements. It needs an operational authorisation under Article 12, a declaration for a standard scenario, or an LUC with the right privileges (Articles 3 and 5).
  • Certified: certified UAS over assemblies of people, transporting people or carrying high-risk dangerous goods, or where the authority finds the risk cannot be mitigated otherwise (Article 6).

Perimeter patrols launched from a dock with no pilot watching do not meet the open category’s VLOS condition, so they sit in the specific category. The regulation anticipates this: UAS.SPEC.050 requires operators of “autonomous operations” to allocate the remote pilot’s responsibilities properly in every phase of flight.

How do you get permission for specific-category flights?

1. Operational authorisation based on a risk assessment (SORA)

The default route: the operator carries out a risk assessment under Article 11 and applies to the competent authority of the Member State where it is registered (Article 5). The EASA acceptable means of compliance for this assessment is the Specific Operations Risk Assessment (SORA). On 15 September 2025 EASA adopted ED Decision 2025/018/R (published 29 September 2025). It added SORA 2.5 to the AMC and GM to Regulation (EU) 2019/947 and states that the earlier SORA 2.0 material “shall remain in force”. National authorities manage the switchover. In Czechia, ÚCL says SORA 2.5 took effect on 30 September 2025 and that it will accept SORA 2.0 applications alongside SORA 2.5 until 31 December 2026. After that date it accepts only SORA 2.5.

2. Predefined risk assessment (PDRA)

A PDRA is a scenario EASA has already risk-assessed and published as an AMC to Article 11, so operators who fit it skip a full SORA. EASA lists PDRA-S01, S02, G01, G02 and G03; S02, G01, G02 and G03 cover BVLOS flights over sparsely populated areas or in segregated airspace, and EASA names surveillance as a typical use for S02 and G01.

3. Declaration under a standard scenario (STS-01 / STS-02)

Instead of an authorisation, an operator can declare compliance with an EU standard scenario (Article 5(5), UAS.SPEC.020), possible since 1 January 2024; declarations under national scenarios ceased to be valid on 1 January 2026. Flying can start once the authority confirms the declaration is complete. Limits:

  • STS-01: VLOS over a controlled ground area in a populated environment, class C5, ground speed below 5 m/s, active direct remote ID.
  • STS-02: BVLOS with or without airspace observers, over a controlled ground area entirely in a sparsely populated environment, class C6 aircraft with an active system that keeps it inside the flight geography, flight visibility above 5 km, VLOS at launch and recovery. Without observers the aircraft may fly at most 1 km from the remote pilot, on a pre-programmed trajectory when out of VLOS. With observers the limit is 2 km.

Both cap height at 120 m and require certified remote pilot training. Because of the VLOS-at-launch condition and distance limits, STS-02 rarely fits a fully remote dock, so most dock operations go through an operational authorisation.

4. Light UAS Operator Certificate (LUC)

An operator holding an LUC with the right privileges needs no separate authorisation or declaration for operations within them (Article 5(6), Annex Part C).

Flying in another EU country (Article 13)

Your authorisation comes from your state of registration. To fly in another Member State, you send that state’s authority a copy of the authorisation, the locations and any updated mitigations for local airspace, terrain, population and climate, and start once it confirms they are satisfactory.

What do operators have to show for BVLOS dock operations?

Details depend on the SORA outcome and the authority, but Article 11 and SORA ask for the same core evidence:

  • Concept of operations: purpose, area, planning, personnel and technical means (Article 11(2)).
  • Operational volume and ground risk buffer: the flight geography, a contingency volume and a ground risk buffer sized so that an aircraft leaving the operational volume ends its flight inside the buffer. In SORA this is either a 1:1 rule (buffer equal to the height) or a calculated value.
  • Ground and air risk: population density in and next to the area, airspace class and encounter probability, which set the air risk class (ARC) and the SAIL.
  • Containment: how the drone stays inside the operational volume (SORA 2.5 lowered some containment requirements).
  • Operational safety objectives (OSOs): procedures, maintenance, training and robustness at the level the SAIL requires.
  • Operator duties (UAS.SPEC.050): security procedures, “measures to protect against unlawful interference and unauthorised access”, GDPR procedures including a DPIA where required, and competent remote pilots.

Authorities approve operations by a named operator, not products. Geofencing, return-to-launch and command logs are evidence an operator can cite in its SORA, not a substitute for it.

Remote ID, registration, geographical zones and U-space

Registration. Any operator in the specific category must register, whatever the aircraft weighs. Registration happens in the Member State of the operator’s principal place of business, and an operator can be registered in only one Member State (Article 14).

Remote identification. In the specific category every aircraft must have “an active and up-to-date remote identification system” and a green flashing light for night visibility (UAS.SPEC.050(1)(l)). The remote ID requirement has applied since 1 January 2024. Regulation 2019/945 defines direct remote identification as local broadcast of information about the aircraft in flight, including its marking, so that it can be received without physical access to the aircraft.

Geographical zones (Article 15). Member States can prohibit flights, set conditions, require prior flight authorisation, or admit only certain classes or aircraft with remote ID or geo-awareness, for safety, security, privacy or environmental reasons. Zone data must be published in a common digital format, so check the national map before planning patrol routes.

U-space (Regulation (EU) 2021/664). Applicable since 26 January 2023. Operations in designated U-space airspace must use four mandatory services: network identification, geo-awareness, UAS flight authorisation and traffic information. It only matters where such airspace has actually been designated.

GDPR: what applies to security drone video?

Video in which people can be identified is personal data under the GDPR (Regulation (EU) 2016/679). The EDPB’s Guidelines 3/2019 on processing of personal data through video devices (version 2.0, adopted 29 January 2020) are the main reference:

  • Lawful basis. Private site owners usually rely on legitimate interests (Article 6(1)(f)), which the EDPB says must be real and present and balanced against the rights of people filmed.
  • DPIA. Article 35(3)(c) requires one for “systematic monitoring of a publicly accessible area on a large scale”; the EDPB expects many video surveillance cases to need one, and national authorities publish lists.
  • Transparency. The EDPB recommends layered information starting with a warning sign before people enter the monitored area. For a moving camera, that means signage at site entrances and clear patrol boundaries.
  • Retention. Footage should usually be erased, ideally automatically, after a few days. The longer it is kept, especially beyond 72 hours, the more justification is needed.
  • By design. Article 25 requires data protection by design and by default, e.g. minimal coverage beyond the site and short default retention.

The EDPB also notes that a system which detects physical characteristics to classify a person, without creating biometric templates to identify them, does not on that basis fall under Article 9’s rules for biometric data.

NIS2 and CER: what changes for energy and critical sites?

The NIS2 Directive (EU) 2022/2555 and CER Directive (EU) 2022/2557 were due for transposition by 17 October 2024. Both bind the regulated entity, not suppliers’ products, but a security drone system can fall within the entity’s obligations:

  • NIS2 Article 21 requires “all-hazards” risk-management measures, including supply-chain security, access control, cryptography and multi-factor authentication. An on-site networked drone platform is one of the systems covered.
  • CER required Member States to identify critical entities by 17 July 2026. Article 13 requires those entities to ensure adequate physical protection, “duly considering, for example, fencing, barriers, perimeter monitoring tools and routines, detection equipment and access controls”.

In Czechia NIS2 is transposed by Act No. 264/2025 Coll. on cybersecurity (NÚKIB), in force since 1 November 2025. Scope depends on national law.

Does the AI Act apply to drone video analytics?

The AI Act, Regulation (EU) 2024/1689, regulates by use case. Its prohibitions have applied since 2 February 2025. They include real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions), untargeted scraping of facial images to build facial recognition databases, and biometric categorisation that infers sensitive traits such as race or political opinions. Annex III lists remote biometric identification, biometric categorisation and emotion recognition as high-risk, along with AI used as safety components in managing certain critical infrastructure.

The Digital Omnibus on AI, Regulation (EU) 2026/1744, published on 24 July 2026, moved the start date for Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and to 2 August 2028 for AI in products covered by Annex I.

The Act defines “biometric identification” as establishing a person’s identity by comparing their features against a database. Detecting that an object is a “person” or “vehicle” identifies no one, so it is generally not biometric identification, though classification depends on intended purpose and GDPR still applies.

Country notes: Czechia, Germany, Poland, Slovakia, Austria

Czech Republic: ÚCL

  • Authority: Úřad pro civilní letectví (ÚCL), caa.gov.cz; routes: SORA authorisation, STS, PDRA or LUC.
  • Registration: operators register on the ÚCL portal dron.caa.gov.cz and receive a registration number by email.
  • SORA transition: SORA 2.0 applications are accepted until 31 December 2026. After that, only SORA 2.5.
  • Geographical zones: since 1 September 2025 the official map is DroneMap (dronemap.gov.cz), run by ŘLP ČR for ÚCL, replacing DronView.
  • Cybersecurity: NÚKIB, Act No. 264/2025 Coll. (see above).

Neighbouring countries (one line each)

  • Germany: the Luftfahrt-Bundesamt (LBA) handles specific-category operational authorisations, with SORA 2.5 forms and a simplified “FastFlight” procedure for low-risk VLOS operations.
  • Poland: the Urząd Lotnictwa Cywilnego (ULC) handles STS declarations, operational authorisations and LUCs.
  • Slovakia: the Dopravný úrad (Transport Authority) issues specific-category authorisations for at most 2 years, with risk assessments under SORA 2.5.
  • Austria: Austro Control (dronespace.at) handles specific-category applications, STS declarations and LUCs.

Summary table: which rule applies when?

RequirementApplies whenWhere it comes from
Operational authorisation (SORA or PDRA)Any flight outside open-category limits (e.g. BVLOS) not covered by an STS or LUCReg. (EU) 2019/947 Art. 5, 11, 12; EASA AMC (ED Decision 2025/018/R)
STS declarationOperation fits STS-01 (VLOS, C5) or STS-02 (BVLOS, C6, sparsely populated)2019/947 Art. 5(5), UAS.SPEC.020, Appendix 1
LUCOperator wants to approve its own operations within certificate privileges2019/947 Art. 5(6), Annex Part C
Cross-border applicationSpecific-category flight in a Member State other than registration2019/947 Art. 13
Operator registrationAll specific-category operations2019/947 Art. 14
Remote ID + green flashing lightEvery aircraft in the specific category2019/947 UAS.SPEC.050(1)(l); 2019/945 (definition)
Geographical zone conditionsSite lies in a zone set by the Member State2019/947 Art. 15; national maps (CZ: DroneMap)
U-space servicesAirspace designated as U-spaceReg. (EU) 2021/664
Lawful basis, transparency, retentionVideo captures identifiable peopleGDPR Art. 5, 6, 25; EDPB Guidelines 3/2019
DPIAHigh-risk processing, e.g. large-scale systematic monitoring of publicly accessible areasGDPR Art. 35; UAS.SPEC.050
Cyber risk-management measuresOperator or site owner is an essential or important entityNIS2 Art. 21; CZ Act 264/2025 Coll.
Physical resilience measuresSite owner identified as a critical entityCER Directive Art. 13
AI Act prohibitions / high-risk dutiesSystem performs biometric identification, categorisation or other listed usesReg. (EU) 2024/1689 Art. 5, Annex III; Reg. (EU) 2026/1744

How Nestua’s design maps to these requirements

Nestua is an autonomous security drone-in-a-box platform (drone, weatherproof base station, local edge node, optional cloud). The software platform is functional in development builds; the drone and base station are still being built. Nestua holds no aviation approvals, and nothing below is an approval or compliance certificate. These are design choices meant to support the evidence and procedures an operator needs:

  • Containment and geo-awareness: polygon and circle geofences and no-fly zones with block or return-to-launch (RTL) enforcement, and fail-safe RTL. These help operators build the containment and operational-volume part of a SORA, together with zone limits taken from national maps.
  • Controlled command chain: typed confirmation for critical commands; a command counts as successful only after the drone’s MAVLink acknowledgement. A policy engine adds local-only, remote-view and remote-control modes, local approval of remote commands, emergency-only mode, time windows and drone-state gates, supporting clear allocation of pilot responsibilities.
  • Unauthorised access and interference: admin, operator and viewer roles with least-privilege defaults; remote access off by default, with admin re-authentication to enable remote control. Video, telemetry and control use an encrypted link (X25519 key agreement, per-packet AES-256-GCM or ChaCha20-Poly1305, hard mutual pairing). The optional cloud uses per-node HMAC-signed commands, MFA and optional SSO. This relates to UAS.SPEC.050 security measures and NIS2 access-control and cryptography themes.
  • Records: an exportable event journal, command log and configuration change tracking. Every critical action is logged, including mission and AI-triggered actions.
  • Data protection by design: the control plane runs on site without internet; recording goes to a local ring buffer, and off-site upload is disabled by default. The operator still sets purposes, signage and retention.
  • Edge AI without identification: YOLO person and vehicle detection on the edge computer’s NPU, fully on site. It detects object classes and does not identify individuals; no face recognition. AI-triggered actions respect safety policy and geofences.

More detail: why offline-first matters for security drones, what drone-in-a-box means, and use cases. To discuss your site, request a demo.

Disclaimer. This page is general information, not legal advice. EU acts, EASA material and national implementation change, and authorities interpret them case by case. Check the current consolidated texts and your national aviation and data protection authorities before planning operations.

Sources

  • Commission Implementing Regulation (EU) 2019/947, consolidated text (Art. 3–6, 11–15, 23; Annex UAS.SPEC.020, UAS.SPEC.050, STS-01, STS-02): eur-lex.europa.eu
  • Commission Delegated Regulation (EU) 2019/945, consolidated text (definitions, Art. 40, Parts 16–17 on C5/C6): eur-lex.europa.eu
  • EASA ED Decision 2025/018/R (SORA 2.5 in AMC & GM to 2019/947): easa.europa.eu
  • EASA, Specific category – civil drones: easa.europa.eu
  • EASA, Predefined Risk Assessment (PDRA): easa.europa.eu
  • EASA, SORA workshop presentation (operational volume, ground risk buffer, ARC, SAIL, OSOs): easa.europa.eu
  • Commission Implementing Regulation (EU) 2021/664 (U-space): eur-lex.europa.eu
  • Regulation (EU) 2016/679 (GDPR): eur-lex.europa.eu
  • EDPB Guidelines 3/2019 on processing of personal data through video devices: edpb.europa.eu
  • Directive (EU) 2022/2555 (NIS2): eur-lex.europa.eu
  • Directive (EU) 2022/2557 (CER): eur-lex.europa.eu
  • Regulation (EU) 2024/1689 (AI Act): eur-lex.europa.eu
  • Regulation (EU) 2026/1744 (Digital Omnibus on AI): eur-lex.europa.eu
  • ÚCL, Specifická kategorie (SPECIFIC), incl. SORA 2.0/2.5 transition: caa.gov.cz
  • ÚCL, Provozovatel bezpilotního systému (registration via dron.caa.gov.cz): caa.gov.cz
  • ÚCL, Nová digitální mapa DroneMap v provozu: caa.gov.cz
  • NÚKIB, Act No. 264/2025 Coll. on cybersecurity (presentation): portal.nukib.gov.cz
  • Luftfahrt-Bundesamt, Betriebsgenehmigungen (specific category): lba.de
  • Urząd Lotnictwa Cywilnego, kategoria szczególna: ulc.gov.pl
  • Dopravný úrad, osobitná (specific) kategória: letectvo.nsat.sk
  • Austro Control, dronespace.at – Specific: dronespace.at

EU drone rules: common questions.

Can a security drone-in-a-box fly in the EU open category?
Generally no. The open category under Regulation (EU) 2019/947 requires the remote pilot to keep the drone in visual line of sight at all times. Automated dock patrols usually fly beyond visual line of sight, so they fall into the specific category and need an operational authorisation, a standard scenario declaration or an LUC.
Which SORA version applies in 2026?
EASA added SORA 2.5 to the AMC and GM to Regulation (EU) 2019/947 with ED Decision 2025/018/R, published on 29 September 2025, while the SORA 2.0 material remains in force. National authorities manage the transition: the Czech ÚCL accepts SORA 2.0 applications alongside SORA 2.5 until 31 December 2026 and only SORA 2.5 after that.
Can STS-02 be used for automated BVLOS security patrols?
Only in narrow cases. STS-02 requires a class C6 drone, a controlled ground area in a sparsely populated environment, flight visibility above 5 km, the drone in sight of the remote pilot at launch and recovery, and a maximum distance of 1 km from the pilot (2 km with airspace observers). Most dock-based patrols therefore need an operational authorisation based on SORA or a PDRA.
Do security drones need remote ID in the EU?
Yes. In the specific category every drone must have an active and up-to-date remote identification system and a green flashing light, under UAS.SPEC.050 of Regulation (EU) 2019/947. The remote ID requirement has applied since 1 January 2024, and the operator must also be registered.
Is a DPIA required for drone video surveillance?
Often. GDPR Article 35(3)(c) requires a data protection impact assessment for systematic monitoring of a publicly accessible area on a large scale, and the EDPB says many video surveillance cases will need one. National data protection authorities publish lists of processing that always requires a DPIA, and Regulation 2019/947 also requires drone operators to carry one out where required.
Is person and vehicle detection high-risk under the AI Act?
Not by itself. The AI Act treats remote biometric identification, biometric categorisation and emotion recognition as high-risk, and biometric identification means establishing a person's identity by comparison with a database. Detecting the object class person or vehicle does not identify anyone, though classification depends on intended purpose, and GDPR still applies to the video.

Planning a drone security operation in the EU?

See how Nestua’s local-first platform is designed to support the evidence operators need. The software runs in development builds today; the drone and base station are being built.

Request a Demo