https://www.schneier.com/blog/archives/2021/10/the-european-parliament-voted-to-ban-remote-biometric-surveillance.html Schneier on Security Menu * Blog * Newsletter * Books * Essays * News * Talks * Academic * About Me Search Powered by DuckDuckGo [ ] [Go] ( ) Blog ( ) Essays (*) Whole site Subscribe Atom FeedFacebookTwitterKindleE-Mail Newsletter (Crypto-Gram) HomeBlog The European Parliament Voted to Ban Remote Biometric Surveillance It's not actually banned in the EU yet -- the legislative process is much more complicated than that -- but it's a step: a total ban on biometric mass surveillance. To respect "privacy and human dignity," MEPs said that EU lawmakers should pass a permanent ban on the automated recognition of individuals in public spaces, saying citizens should only be monitored when suspected of a crime. The parliament has also called for a ban on the use of private facial recognition databases -- such as the controversial AI system created by U.S. startup Clearview (also already in use by some police forces in Europe) -- and said predictive policing based on behavioural data should also be outlawed. MEPs also want to ban social scoring systems which seek to rate the trustworthiness of citizens based on their behaviour or personality. Tags: biometrics, EU, privacy, surveillance Posted on October 11, 2021 at 7:49 AM * 10 Comments Comments Winter * October 11, 2021 8:31 AM This actually follows fairly directly from the GDPR. The GDPR prohibits the collection and storage of personal data without consent. "Remote Biometric Surveillance" is just that: the collection and storage of personal data without consent. Tech Wannabe * October 11, 2021 9:51 AM Of course something being banned doesn't mean it won't happen. Is anyone really naive enough to think a government entity(any country) will suddenly stop because it's outlawed? JPA * October 11, 2021 10:05 AM @Tech Wannabe My sense is that while a country may continue to use outlawed methods, outlawing those methods has a couple of benefits. First is means that it will take more effort to use those methods as they must be concealed. Second it provides the defense an argument as if they can raise suspicion that outlawed methods were used to obtain the data then the case may be dismissed. Maybe I'm just being overly hopeful though JonKnowsNothing * October 11, 2021 10:35 AM This was reported 10 09 2021: Clearview scraped '10bn' selfies for facial recognition Bio-metrics maybe banned but getting the data retracted, deleted, removed isn't going to be easy. Jurisdiction hopping will prevent it. Anonymous * October 11, 2021 11:11 AM Very good news and uplifting to read this when we are living in an age of mass surveillance. This gives me hope that someday surveillance capitalism will be reined in too. dearmadfiacha * October 11, 2021 11:28 AM Isn't the real issue that is being skirted here- defining what is "genuine" (or even "not genuine", ingenuine, disingenuine...) remains absent? What makes anyone believe that the barn door hasn't been open for far too long and 'the cows have already gone to pasture'? Even if the EU passes regulations targeted at IT technology, the remote sensing genie has been out of the bottle- for decades. Pandora's box has already released AI to the general public. Duchess Gloriana XII of Grand Fenwick * October 11, 2021 11:53 AM "MEPs also want to ban social scoring systems" Please don't tell this to Klaus Schwab and the Davos Crowd, they might get upset. SpaceLifeForm * October 11, 2021 3:54 PM Pure Security Theatre. See Apple CSAM. You can have all of the Laws you want, but when the rubber meets the road, there will no way to prevent, and, certainly, when detected, it will just result in trivial fines. Clive Robinson * October 11, 2021 5:26 PM @ ALL, Sadly the UK is nolonger part of the EU, especially as the UK still has the reputation of having the most surveillance in public places of all the nations in the world. Whilst people scoff at US fines and inhibitory regulation and lack of legislation, the EU on the other hand realy has scared Silicone Valley a number of times. The big problem is coming up with legislation that is balanced, especially when the likes of Silicon Valley corps are about as unbalanced as you can get. One issues is "consent" yes you can legislate against "presumed consent" but you can not realistically insist that anyone has access to content against the IP holders wishes. So you get the "gun to the head" "explicit consent" rules comming out of Silicon Valley Corps because they assume they have the "whip hand". So you need a "right of access" legislation to stay the whip hand. Usually for this sort of legislation to fly you have to play the "Public Interest" card. That is you have to in effect not just claim but demonstate that what is being offered is a "societal good" thus should be available to all without let or lien. Think in terms of a "Common Service Provission" where by a private organisation becomes a "common carrier" setvice. As such they have to, 1, Make service available to all in a non discriminatory way. With often further provission in the legislation to make, 2, Service at the same price to all. 3, Service provider has a "nobody left behind" provison put on them. That is a Service Provider has to make service available even in areas where the costs would be prohibitively high at a proportional rate to the provision in highly profitable areas. Whilst such legislation can be made for "national" / "state" providers the Internet is currently still International -though many governments want it to be otherwise- which makes "policing" and "enforcment" extreamly problematical. JonKnowsNothing * October 11, 2021 5:30 PM @JPA, @Tech Wannabe re: Illegal Evidence Collection vs Commercial Data Collection There maybe a hindrance in collecting commercial data but every EULA/ TOS has a mandatory ACCEPT with some cosmetic overlays about what can be collected. The veneer of what is OPTOUT is pretty thin. Lots has been written about OPTIN vs OPTOUT and the percentages of selection. The hindrance may be in the back end collection systems or data warehouses-data brokers. But as they primarily purchase their data from the collecting parties it's hard to see how there will be any significant impact. Even LEOs just buy vast quantities of data to by pass restrictions. A good number of countries have SECRET EVIDENCE rules, including the USA. Data collected "when suspected of a crime " is known in the USA as "RELEVANT" defined as "ALL". The theory being LEOs don't know if it's "relevant" until "it IS relevant" so they can harvest until the sun goes down. Plenty of room at Bluffdale. Secret Evidence in US is often Ex Parte evidence where only the prosecution and judge can see whatever it is. The defense never sees it but the accused can be convicted on it and sentenced on it. Only the LEOs assertion about what the information is and how it was collected may (or may not) be given to the judge(s). Don't Ask, Don't Tell. Mostly Don't Tell. Atom Feed Subscribe to comments on this entry Leave a comment Cancel reply Login Name [ ] Email [ ] URL: [ ] [ ] Remember personal info? Fill in the blank: the name of this blog is Schneier on ___________ (required): [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comments: [ ] [loader] Allowed HTML * * * *
    1. *
       Markdown Extra syntax via
      https://michelf.ca/projects/php-markdown/extra/
      
      [Preview] [Edit]
      
      [Submit] 
      
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
      D[                                             ] 
      
      - Friday Squid Blogging: Strawberry Squid
      
      Sidebar photo of Bruce Schneier by Joe MacInnis.
      
      About Bruce Schneier
      
      [Bruce-Schn]
      
      I am a public-interest technologist, working at the intersection of
      security, technology, and people. I've been writing about security
      issues on my blog since 2004, and in my monthly newsletter since
      1998. I'm a fellow and lecturer at Harvard's Kennedy School, a board
      member of EFF, and the Chief of Security Architecture at Inrupt, Inc.
      This personal website expresses the opinions of none of those
      organizations.
      
      Related Entries
      
        * Identifying Computer-Generated Faces
        * Designing Contact-Tracing Apps
        * Friday Squid Blogging: Possible Evidence of Squid Paternal Care
        * ProtonMail Now Keeps IP Logs
        * Surveillance of the Internet Backbone
      
      Featured Essays
      
        * The Value of Encryption
        * Data Is a Toxic Asset, So Why Not Throw It Out?
        * How the NSA Threatens National Security
        * Terrorists May Use Google Earth, But Fear Is No Reason to Ban It
        * In Praise of Security Theater
        * Refuse to be Terrorized
        * The Eternal Value of Privacy
        * Terrorists Don't Do Movie Plots
      
      More Essays
      
      Blog Archives
      
        * Archive by Month
        * 100 Latest Comments
      
      Blog Tags
      
        * 3d printers
        * 9/11
        * Aaron Swartz
        * academic
        * academic papers
        * accountability
        * ACLU
        * activism
        * Adobe
        * advanced persistent threats
        * adware
        * AES
        * Afghanistan
        * air marshals
        * air travel
        * airgaps
        * al Qaeda
        * alarms
        * algorithms
        * alibis
        * Amazon
        * Android
        * anonymity
        * Anonymous
        * antivirus
        * Apache
        * Apple
        * Applied Cryptography
        * artificial intelligence
        * assassinations
      
      More Tags
      
      Latest Book
      
      We Have Root
      
      More Books
      
      Support Bloggers' Rights! Defend Privacy--Support Epic
      
        * Blog
        * Newsletter
        * Books
        * Essays
        * News
        * Talks
        * Academic
        * About Me