Live data from Hacker News

Facial recognition: School ID checks lead to GDPR fine

bbc.com

21–30 of 182 posts

Re: Facial recognition: School ID checks lead to GDPR fine

#21

Earlier quoted context omitted.

The issue with the GDPR as worded and this ruling is that they remove the possibility of informed individual decisions. In this case it seems that all involved were informed and OK with it but that did not matter. I would also think that knowing where pupils are at all times is quite a legitimate aim for a school.

Everybody was informed and OK.... Except for the students they tracked, nobody asked them. Sure, they are still minors, and it's up to the parents to decide what goes and what not. But by law the parents in Sweden (and a lot of other places around the world) have an obligation to act in the best interest of their children to their best ability. I'd argue exposing their children to mass surveillance in school and face…

> Everybody was informed and OK.... Except

It's not clear (and honestly, not likely) that that was true either, but if it was:

> I'd have fine the parents a minor fine, too

This is child abuse, and should be prosecuted accordingly, including jail time.

Re: Facial recognition: School ID checks lead to GDPR fine

#22

Earlier quoted context omitted.

The issue with the GDPR as worded and this ruling is that they remove the possibility of informed individual decisions. In this case it seems that all involved were informed and OK with it but that did not matter. I would also think that knowing where pupils are at all times is quite a legitimate aim for a school.

Recital 38: "Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data." Recital 43: "In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imba…

Thank you for surfacing this language.

In the more general case, I was under the impression that informed consent was sufficient to authorize a data controller to collect/process private information and so the ruling didn't make sense to me. I'm using "informed consent" here as a short hand for all the applicable GDPR requirements on consent (reasonable language, etc).

It isn't clear to me from this language in Recital 43 though how a data controller with an "imbalance" relative to the data subject could easily get clarity on any particular use case. It also seems strange that in this case there was deemed an imbalance between the schools and the parents (I'm assuming here that parents are indeed authorized to give consent in their role as parent/guardian). If parents are in an imbalanced situation regarding school attendance, then pretty much all government relationships are imbalanced.

If the school/parent relationship is considered imbalanced and the imbalance language isn't specific to a government data controller, then it would appear that every data controller (government entity or not) is in danger of having their relationship deemed "imbalanced" and the data collection subject to analysis by the data authority at any time.

It seems like this ruling destroys the clarity of "consent" and replaces it with "(consent AND balanced relationship) OR (imbalanced relationship AND legally adequate reason AND prior approval from regulator AND consent)"

Re: Facial recognition: School ID checks lead to GDPR fine

#23
post #19

What is the personal data being unnecessarily collected here? Reference pictures for facial recognition? Cause attendance would be collected regardless...

The biometrics of the face.

Linked article states: "The General Data Protection Regulation, which came into force last year, classes facial images and other biometric information as being a special category of data, with added restrictions on its use."

Re: Facial recognition: School ID checks lead to GDPR fine

#24

Earlier quoted context omitted.

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

I don't think the argument was that it was not in line with GDPR. The argument is that GDPR is wrong itself in not allowing people to consent to anything which goes beyond "minimal" data collection for the purpose needed, because whether it is "minimal" is, in some sense, a value judgment as to how much convenience and innovation matter. It seems to me that the principle should be personal "ownership" of personal dat…

The reason that the GDPR is so expansive is that 'voluntary' consent means nothing when your only alternatives to not 'voluntarily' consenting are moving to a different city or going completely without a given service. See how, for instance, literally every major internet provider in the US have contract clauses that amount to 'we can do whatever we want with your personal information forever, neener neener'.

Re: Facial recognition: School ID checks lead to GDPR fine

#25

Good. Not only does this ensure that the students enjoy privacy, monitoring children in school with surveillance systems could have come straight out of foucault's discipline and punish. Maybe we should think about how we make schools spaces of freedom for our children rather than turning them into the next panopticon.

Agreed, and I would also like to see punishment for the administrator, Jorgen Malm, who put this into place. At the very least, he should be removed from his job due to his obvious and public disregard for the privacy and safety of the children under his care. If I was on a jury, I would happily vote to put him in prison.

Re: Facial recognition: School ID checks lead to GDPR fine

#27

Good! I was forced to use biometric data (fingerprint) to purchase food and read books in the library (yep) for seven years at my UK school. That was already too much. Facial recognition has zero place in a school.

The only time I liked to give my fingerprint is for the fitness lockers. Not needing a key or remember a pass code is great.

Re: Facial recognition: School ID checks lead to GDPR fine

#28
post #2

> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data. It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation. Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is do…

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

Choosing between European internet laws and having a tech sector, I'd pick having a tech sector any day. It's all totally unnecessary strangling of innovation. The entire idea that you own data pertaining to you is absurd.

Re: Facial recognition: School ID checks lead to GDPR fine

#29

Earlier quoted context omitted.

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

Choosing between European internet laws and having a tech sector, I'd pick having a tech sector any day. It's all totally unnecessary strangling of innovation. The entire idea that you own data pertaining to you is absurd.

This is not a dichotomy. We can have a tech sector that’s also compliant with laws like GDPR.

Re: Facial recognition: School ID checks lead to GDPR fine

#30
post #2

> According to the DPA ruling, although the school secured parents' consent to monitor the students, the regulator did not feel that it was a legally adequate reason to collect such sensitive personal data. It’s this kind of second-guessing which is extremely concerning about GDPR-type regulation. Not that the information was not secure, or leaked, or mishandled, or consent wasn’t obtained, but even if all that is do…

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

This fine is precisely in line with the intentions of the European Parliament when they signed the GDPR into law.

That is certainly a statement that no one could argue with. I think the argument is whether those intentions are actually good, logical, or workable.

For example, the fine structure is explicitly designed so that they could take all of the assets of a small business and wipe it off the face of the map, but only take 5% of annual revenue of a large business. Does that reflect an intention to consolidate market power in the hands of a very few companies? That would be a bad intention in IMO.

Post reply on HN