Live data from Hacker News

Facial recognition: School ID checks lead to GDPR fine

bbc.com

1–10 of 182 posts

Re: Facial recognition: School ID checks lead to GDPR fine

#2
> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data.

It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation.

Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is done, just, “We don’t think you had a good enough reason.”

Re: Facial recognition: School ID checks lead to GDPR fine

#5
post #2

> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data. It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation. Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is do…

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident.

The GDPR's fundamental principles are set out in article 5. You should collect the least amount of data possible, you should process it only for specific, explicit and legitimate purposes and you should delete it as soon as possible once you've finished.

Can anyone legitimately argue that a facial recognition system is the least intrusive way of collecting attendance data? Would any reasonable person believe that constant video surveillance with facial recognition technology is no more intrusive than taking the register at the start of class? I think not.

The actions of the school authorities were in flagrant breach of the GDPR and they fully deserve to be fined. There's no second-guessing in this case, no grey area, just an organisation that used advanced surveillance technology to monitor children without giving a moment of thought to the privacy implications. This fine is precisely in line with the intentions of the European Parliament when they signed the GDPR into law.

https://gdpr-info.eu/art-5-gdpr/

Re: Facial recognition: School ID checks lead to GDPR fine

#6
post #2

> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data. It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation. Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is do…

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

Afaik the ruling also stated that parents abd children dont have a resonable ability to consent towards a school.

Re: Facial recognition: School ID checks lead to GDPR fine

#8
post #2

> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data. It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation. Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is do…

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

I don't think the argument was that it was not in line with GDPR. The argument is that GDPR is wrong itself in not allowing people to consent to anything which goes beyond "minimal" data collection for the purpose needed, because whether it is "minimal" is, in some sense, a value judgment as to how much convenience and innovation matter. It seems to me that the principle should be personal "ownership" of personal data - and "ownership" of data should imply the owners have the right to alienate that data as the owner sees fit, with the right safeguards to ensure this isn't coerced or a result of fraud.

On the other hand, this type of scenario doesn't feel much like the consent given was really voluntary - (1) because noone wants to be the one person who stopped the school from doing something which everyone else was on board with and (2) because it involved adults consenting on behalf of children for something which the children may not be happy about in future when they are adults and it's too late.

Re: Facial recognition: School ID checks lead to GDPR fine

#9
post #2

> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data. It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation. Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is do…

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

The issue with the GDPR as worded and this ruling is that they remove the possibility of informed individual decisions.

In this case it seems that all involved were informed and OK with it but that did not matter.

I would also think that knowing where pupils are at all times is quite a legitimate aim for a school.

Post reply on HN