Earlier quoted context omitted.
They're not surprised by that. They are surprised when one of the rules that has held true for the eternity of cities: that you can be semi-anonymous in a crowd, is no longer true.
In my opinion you still can. What makes this possible? You need a database linking images to names, as well as the face-recognition data. People are freely giving away the images for the database linking it all to further personal data. If they did not do this, creating such a database would still be a massive surveillance effort, albeit probably still possible if someone really wanted to do it and had the sufficient…
When I spot such a camera I stand to the side so they have to ask me to move in front of the camera. Which is when I politely refuse to participate. They don't like that very much. Last time, the person made a "well you might not be able to refuse next time" remark. He may be correct, or not, we'll see.
These are cases where the images should never be uploaded to a public database or shared with any other parties. However, given the increasing use of SaaS and cloud providers, exposure to some third-parties is highly likely. Any consumer information hitting the cloud is at high risk of abuse.
In addition to those scenarios you have cameras behind ATMs, cameras embedded within grocery store self-checkout lines, etc and so forth. It has already become difficult to control your image and, in some cases, prevent that image from being combined with other personally identifiable information.