Live data from Hacker News

Google Sued Under Illinois Biometric Information Privacy Act

lexology.com

21–30 of 39 posts

Re: Google Sued Under Illinois Biometric Information Privacy Act

#21
post #10

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

Just to be pedantic in the spirit of HN. Google isn't training models w/your face from your photo library. The way face recognition works is that Google would collect a dataset somehow and label that for the various feature and train a model for face recognition. Usually this is done with a carefully curated dataset that would be sure to include various ages, genders, ethnicities, lighting conditions, angles, and cam…

Google absolutely allows you to confirm it's tags and uses that for retraining, which means yes, my facial profile is collected, stored and used for model training (unless you disable it in preferences).

You can't do "celebrity" recognition from a generalized data set.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#22

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

Let's assume for a moment that the photo was taken in public.

Normally, you don't have much expectation of privacy in public spaces. Generally, a photographer is free to take photos in public and use those photos as they see fit. Why is Google's use of your photo different than the photographer's use of the photo?

Re: Google Sued Under Illinois Biometric Information Privacy Act

#23
post #20

This lawsuit seems dead on arrival. From the article (emphasis my own): """ The suit alleges that Google is violating BIPA because it is “actively collecting, storing, and using—without providing notice, obtaining informed written consent or publishing data retention policies—the biometrics of millions of unwitting individuals whose faces appear in photographs uploaded to Google Photos in Illinois """ From the text o…

I have to point out that his exact argument has been made and rejected by the courts in multiple cases already. > Shutterfly maintains that by excluding data derived from photographs from the definition of “biometric information,” the Illinois legislature intended to exclude from BIPA’s purview all biometric data obtained from photographs... As Shutterfly acknowledges, if biometric identifiers do not include informat…

Interesting. My plaintext reading of the law interpreted "scan of face geometry" as a full 3D mapping (i.e. photographic plus infrared rangefinding), and I stand corrected on the intended reading of the text.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#24
post #18

Earlier quoted context omitted.

I remember google popping up a consent to store the AI models for the facial recognition locally on my phone (not in the cloud)! If this is the case, the lawyers are wasting their time, I guess.

I've never received a popup like that, nor ever heard of anyone receiving one. Are you in Illinois?

UK. I recently bought a new phone and when I opened google photos app for the first time, it asked to store local trained models to enable AI features for the app.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#25
post #2

To save y'all a click: The alleged biometrics in question are the use of facial-recognition software on photos uploaded to Google Photos (without informed consent from the user).

I remember google popping up a consent to store the AI models for the facial recognition locally on my phone (not in the cloud)! If this is the case, the lawyers are wasting their time, I guess.

That gets the event of the person who's phone it is, not the people in the photos.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#26
post #16

Whose consent is needed, according to the law? The person who took the photos, or the person being photographed? And is the consent required only if the product is used in Illinois? Or if the photo is taken in Illinois? Or if the person photographed is a resident of Illinois? (I read the law, and it appears to cover the person being photographed, if the photograph is taken in Illinois. So basically according to the l…

BIPA requires the consent of the person that the biometrics identify. However it specifically excludes photographs from the definition of biometric information so its not clear how it applies in this case.

It excludes photographs, but includes certain data derivable from photographs. Storing the photograph is not a violation, but the lawsuit alleges that the facial recognition software that Google runs constitutes a violation.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#27

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

Let's assume for a moment that the photo was taken in public. Normally, you don't have much expectation of privacy in public spaces. Generally, a photographer is free to take photos in public and use those photos as they see fit. Why is Google's use of your photo different than the photographer's use of the photo?

> Let's assume for a moment that the photo was taken in public.

This is a wrong assumption to make. What if the photos were clicked in my house? In a private gathering?

Re: Google Sued Under Illinois Biometric Information Privacy Act

#28

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

Let's assume for a moment that the photo was taken in public. Normally, you don't have much expectation of privacy in public spaces. Generally, a photographer is free to take photos in public and use those photos as they see fit. Why is Google's use of your photo different than the photographer's use of the photo?

Why is Google's use of your photo different than the photographer's use of the photo?

The law doesn't protect your image, it protects your biometric information.

To extend your flawed analogy, a photographer isn't allowed to take a gigapixel photograph of someone in public and then use the data from their fingerprints or iris to uniquely identify them.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#29
post #10

Earlier quoted context omitted.

Just to be pedantic in the spirit of HN. Google isn't training models w/your face from your photo library. The way face recognition works is that Google would collect a dataset somehow and label that for the various feature and train a model for face recognition. Usually this is done with a carefully curated dataset that would be sure to include various ages, genders, ethnicities, lighting conditions, angles, and cam…

Google absolutely allows you to confirm it's tags and uses that for retraining, which means yes, my facial profile is collected, stored and used for model training (unless you disable it in preferences). You can't do "celebrity" recognition from a generalized data set.

Logically, that doesn't seem likely because that would mean any individual or set of individuals, could enter false data and poison Google's model going forward.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#30
We have a large client/customer in Illinois who has decided against using our voice sdk in their iOS/Android app because of the fear of getting sued for BIPA violation. It's not that they think we're creating voice prints without consent, it's just that their legal team has warned them that if they get sued, it could be very costly to defend. We even changed our privacy policy to note that "biometrics" are not obtained, and even went to on-device speech recognition apis provided by Google and Apple.
Post reply on HN