A college is removing its vending machines after a student discovered they were using facial recognition technology

L4sBot@lemmy.worldmod to Technology@lemmy.world – 256 points –
A college is removing its vending machines after a student discovered they were using facial recognition technology
businessinsider.com

A college is removing its vending machines after a student discovered they were using facial recognition technology::A photo shared on Reddit showed one of the vending machines with an error code suggesting it used facial recognition tech.

39

You are viewing a single comment

Their corporate website mentions that they use the data for marketing purposes. Whatever type of face they see - e.g. male or female, large or skinny, etc. - gets correlated with what was purchased, and then they sell that data for marketing purposes. Exactly like Google selling your search history, except with likely fewer restrictions in place.

Their website doesn't mention how often they get hacked to give away that data for free - to be clear, that data meaning A PICTURE OF YOUR ACTUAL FUCKING FACE. I don't know what resolution, or even what someone would do with it later, I am focusing here on the fact that the picture taking seems nonconsensual, especially for it to be stored in a database rather than simply used in the moment.

They claim to be GPDR compliant, and while I am not an EUian I think if that claim is accurate, they can't be doing any of those things you mention.

My point is, even if we take them at their word that the facial recognition is benign, it was still a dumb choice.

GPDR only applies in the EU, and this happened in Canada. They may actually be GPDR compliant in europe, but have they stated whether they are following those laws where they aren't legally required to?

Most companies who sell worldwide won't bother developing one set of firmware which is GPDR compliant for the EU, and another set for the rest of the world, unless there was an explicit business reason to do so. So when they replied about this incident in Canada with their GPDR status, I thought it was implied that they had only one codebase which was GPDR compliant, and they ship it in Canada, not because they have to but because it's all they have.