Live data from Hacker News

Facial recognition: School ID checks lead to GDPR fine

bbc.com

61–70 of 182 posts

Re: Facial recognition: School ID checks lead to GDPR fine

#61

Earlier quoted context omitted.

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

The issue with the GDPR as worded and this ruling is that they remove the possibility of informed individual decisions. In this case it seems that all involved were informed and OK with it but that did not matter. I would also think that knowing where pupils are at all times is quite a legitimate aim for a school.

> I would also think that knowing where pupils are at all times is quite a legitimate aim for a school.

For a prison, it is. A school's purpose is to educate.

Re: Facial recognition: School ID checks lead to GDPR fine

#62
post #51

Earlier quoted context omitted.

To be fair "checking attendance" fundamentally erodes privacy. That's not the issue (at least as I see it). The big questions in my head include "Who's storing the biometric data? How are they securing it? Who has authorized access to it, and what processes and mechanisms are n place to ensure they only use it in authorized ways? What are authorized uses of the data? How is it ensured that authorized uses will ot be…

Is that a thing, developers being personally responsible for the company that was not in compliance and that they, at some point, worked for?

I wouldn't be surprised if you could chase someone for gross negligence, if it was a result of, for example, consciously prioritising features over security, or "I know the rules but they are BS" thinking. You can do that with doctors, and they often make mistakes because the hospital overworks them, or simply allows bad behaviours to continue.

Re: Facial recognition: School ID checks lead to GDPR fine

#63

Earlier quoted context omitted.

Speaking purely on the technical side of this problem: if you had to design a system to take attendance without some sort of human in the loop (e.g. a teacher), what other workable solutions are there? ID scanned by itself? A student could scan multiple IDs for their friends. ID + PIN? Due to the bursty nature of entering classrooms, that would cause a jam up at the PIN reader. Short of an ID shackle (that's a joke),…

I've worked as a teacher before. I'm a bit confused as to the 17,000 hours time claimed to collect attendance information (and hence the justification that you need to automate it). Where is that number coming from? As part of my job, I had to be able to recognise and put a name to all of my students. This is legitimately difficult and I spent a lot of time doing it. However, it was not for doing attendance! If you a…

>They didn't want to record attendance, they wanted to know where the students were in every second of the day. They wanted to time home long they are in the toilet so that they can catch them smoking or dealing drugs. They wanted to see them leaving the school o that they can lie in wait and nab them as they cut class: students 2 and 5 are supposed to be in band class but they are headed in the opposite direction -- go all you zigs! For great justice!

GDPR explicitly prevents this. Data is collected for a purpose and that purpose only. Collecting data for attendance then using it for catching drug dealers is forbidden.

Re: Facial recognition: School ID checks lead to GDPR fine

#64
post #33

Earlier quoted context omitted.

This is not a dichotomy. We can have a tech sector that’s also compliant with laws like GDPR.

No, you can't. Since GDPR was rolled out, venture capital investments in the EU have dropped by a third.[1] According to that paper, the companies most hurt are early stage startups. 1. The Short-Run Effects of GDPR on Technology Venture Investment: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3278912

This is like saying laws against human trafficking are bad because it hurts business.

Re: Facial recognition: School ID checks lead to GDPR fine

#65
post #51

Good. Not only does this ensure that the students enjoy privacy, monitoring children in school with surveillance systems could have come straight out of foucault's discipline and punish. Maybe we should think about how we make schools spaces of freedom for our children rather than turning them into the next panopticon.

To be fair "checking attendance" fundamentally erodes privacy. That's not the issue (at least as I see it). The big questions in my head include "Who's storing the biometric data? How are they securing it? Who has authorized access to it, and what processes and mechanisms are n place to ensure they only use it in authorized ways? What are authorized uses of the data? How is it ensured that authorized uses will ot be…

To be fair, they did the following:

- Data and analysis was done at a server in the class room (locked in a cabinet) - All parents signed a consent form before the trial started. - All data was erased after the trial ended.

The Swedish DPA decided that:

1. Consent is not valid of there is a power difference between the subject and the requester. 2. They should have documented a PIA (Privacy impact assessment). 3. They should have contacted the DPA before starting the trial.

Re: Facial recognition: School ID checks lead to GDPR fine

#66

Earlier quoted context omitted.

The GDPR doesn't specify what you can't do with personal data, it specifies what you can do. Personal data is private by default; you can only use my data if it is explicitly lawful for you to do so. If you're not absolutely sure that what you're doing is in line with the GDPR, you shouldn't do it. That's by design, not by accident. The GDPR's fundamental principles are set out in article 5. You should collect the le…

This fine is precisely in line with the intentions of the European Parliament when they signed the GDPR into law. That is certainly a statement that no one could argue with. I think the argument is whether those intentions are actually good, logical, or workable. For example, the fine structure is explicitly designed so that they could take all of the assets of a small business and wipe it off the face of the map, bu…

>but only take 5% of annual revenue of a large business

It's 4% global revenue and it's really a lot. Fines are issued based on the amount of data and amount of people affected. Small companies rarely need anything but contact information. Storing the data securely is no trivial task for any size of organization, though.

Small companies would have significantly less data and customers to be worthy of a hefty fine. Again, if you can't keep the data secure, don't go into such a business.

Re: Facial recognition: School ID checks lead to GDPR fine

#67
post #6

Earlier quoted context omitted.

Afaik the ruling also stated that parents abd children dont have a resonable ability to consent towards a school.

That makes sense. Opt out for even just one individual would be effectively impossible, otherwise how would the system know who's opted out without remembering them in some way.

A person who has not opted in has opted out. No tracking necessary.

Re: Facial recognition: School ID checks lead to GDPR fine

#68
post #46

Good. Not only does this ensure that the students enjoy privacy, monitoring children in school with surveillance systems could have come straight out of foucault's discipline and punish. Maybe we should think about how we make schools spaces of freedom for our children rather than turning them into the next panopticon.

I work in public digitalisation in Denmark, and I can’t think of a single reason of why you would ever even want this. What’s the use case? Automatic student registration? If it is, and I can certainly imagine some HR consultant going “weeeeeell we can squeeze five minutes of extra education in if we remove this teacher-student interaction of registration, that’s a gazillion hours of extra education a year!”. I know…

I would love to know more about how this discussion is in Denmark. Also how the Danish public sector is talking about GDPR/Cloud Act in relation to O365 and similar services.

Re: Facial recognition: School ID checks lead to GDPR fine

#69
post #40

Earlier quoted context omitted.

Recital 38: "Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data." Recital 43: "In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imba…

Does Google's et all EULA cater for this as fairly sure many childrens phones track them and fall foul of this. Oyster cards in London, your journeys are tracked, consent not asked for. Let alone giving special privilege for children. Then the whole aspect of under-age (children) commiting crime and evidence. A smart lawyer could abuse the whole aspect to squash any evidence that placed them at a scene of a crime as…

>Does Google's et all EULA cater for this as fairly sure many childrens phones track them and fall foul of this.

Google are subject to multiple GDPR investigations as we speak. They have already received a number of large fines.

>Oyster cards in London, your journeys are tracked, consent not asked for. Let alone giving special privilege for children.

TFL have a legitimate need to know where you tapped in and out in order to calculate fares. As long as they aren't using that data in an identifiable form for other purposes and they delete it as soon as practicable, they're compliant. A facial recognition system collects far more data than is minimally necessary to track school attendance, which is contrary to the principles set out in Art. 5.

>Then the whole aspect of under-age (children) commiting crime and evidence. A smart lawyer could abuse the whole aspect to squash any evidence that placed them at a scene of a crime as they never gave consent and if they did - they didn't know what they were doing.

That evidence is necessary for the purposes of mounting a prosecution so processing it (in accordance with the rest of the GDPR) is lawful under Art. 6. Consent is only one lawful basis for processing personal data; it is not always necessary, nor is it always sufficient. Consent does not give anyone carte blanche to do as they please under GDPR, particularly where that consent might not be fully informed or freely given.

https://gdpr-info.eu/art-6-gdpr/

Re: Facial recognition: School ID checks lead to GDPR fine

#70
post #68
post #46

Earlier quoted context omitted.

I work in public digitalisation in Denmark, and I can’t think of a single reason of why you would ever even want this. What’s the use case? Automatic student registration? If it is, and I can certainly imagine some HR consultant going “weeeeeell we can squeeze five minutes of extra education in if we remove this teacher-student interaction of registration, that’s a gazillion hours of extra education a year!”. I know…

I would love to know more about how this discussion is in Denmark. Also how the Danish public sector is talking about GDPR/Cloud Act in relation to O365 and similar services.

> Also how the Danish public sector is talking about GDPR/Cloud Act in relation to O365 and similar services.

"Microsoft says it. We believe it. That settles it."

Really, there's no other option: Even if they magically got the ability to audit source code, the whole point of a cloud service is that the code can be changed at any point. Even if you extract a promise from Microsoft that the code won't be changed... well, see Figure 1. You're operating on trust that Microsoft will abide the agreement, and trust that you'll be able to magically tell if they don't.

Post reply on HN