Hello friends,
I lied. I had at this one last post in me.
After writing about that creepy surveillance “intelligence” company over on Webworm (hi Phil 👋), a couple of people pointed out Te Mana Mātāpono Matatapu / The Office of Privacy Commissioner, was asking for feedback on its draft Biometric Processing Privacy Code of Practice.
TL;DR I think the code is pretty okay (as a first step).
The code will help curb the creepiness of the rampant collection of very personal information about people. But it doesn’t go far enough. There needs to be a broader reevaluation of privacy law to ensure privacy is the default setting.
Everyone has a GPS connected high resolution camera and recording device in their pocket which sends screeds of data (and metadata) to fuck knows who, and we all kinda have to give over if we want to lead a normal existence.
The cost of surveillance hardware is so low you can’t go more than 5 metres in some places without falling under the gaze of another camera. And there has been a proliferation of private surveillance and intelligence companies — as well as advertising companies — which skirt privacy laws and are, at best, ethically dubious.
They’re all hoarding databases full of photos, videos, descriptions, license plates, names, addresses and much more. Cross-referencing all this with your browsing history, your credit card purchases, your location, and who you came in contact with just before you binge watched all nine seasons of Seinfeld in one week and ordered a suspiciously large amount of ice cream via Uber Eats.
On top of that, we know there are multiple data breaches of this very personal information. Every. Single. Day.
I could keep ranting, but I’d rather you read my submission and then and wrote your own. You have until 14 March 2025 to get yours in.
All the Privacy Commissioner documents and information about how to submit is here.
Until next time,
Stay safe, stay sane
<3
JJW
PS: if you haven’t already subscribed, please do — or consider adding notagrift.com to your RSS reader. Promise I’ll treat your email address with the respect it deserves ✌️
Submission to Te Mana Mātāpono Matatapu / Privacy Commissioner regarding the draft Biometric Processing Privacy Code of Practice
Kia ora,
Thank you for the opportunity to submit on the draft Biometric Processing Privacy Code of Practice.
We are at an important crossroads in terms of the nexus of machine learning, artificial intelligence, facial recognition and other technologies which can mine the already ubiquitous and cheap surveillance technology for biometric data.
All the massive amounts of other data which normal citizens are essentially forced to give up — to do anything via The Internet, purchasing things via a credit card, interacting with friends, family and community via social media, and other funnels which skim information about us so it can be monetised — means the companies who store this data have creepily good datasets including images, videos, and more about folks just going about their everyday lives.
These guidelines go some way to limiting the collection, storage, and use of biometric data — some of the most personal information about a person an organisation can collect. I generally support the Code of Practice as it stands but think it can be clarified and strengthened in order to further protect New Zealanders privacy.
Regarding the three main questions you are seeking feedback on, my answers are as follows.
Should organisations assess whether using biometrics is proportionate, and be required to put in place privacy safeguards if they do use biometrics?
Yes on both counts. There should be a defined process by which organisations need to assess the collection of biometrics before they start collecting. This document should also be required to be made public by the organisation. There should be auditing of their plan for implementation of biometric collection and if the organisation is doing everything it can to comply with the code and relevant laws. There should be significant penalties if organisations are found to not be adhering to their own processes, the code, and other relevant rules and laws. When an organisation decides to collect biometric information, all staff who will be required to engage in its collection should be given comprehensive privacy training. The platforms which organisations use to capture and retain biometric information should have the highest level of privacy safeguards built into them, including tools which monitor potential misuse of the information.
Should people know about the use of biometrics beforehand, and should organisations have to provide additional information about the processing?
Yes on both counts. Any organisation which collects, stores, processes, or helps other organisations use biometric information should have to visibly and clearly communicate with the people whose biometric information they are collecting and storing. There needs to be clear guidelines about what level of communication is needed. A small sign, a section on a website, or a line in a lengthy Terms of Service agreement is not good enough. The collection of biometric data, and the ramifications of an organisation capturing that information and storing it, should have to be made abundantly clear to people and people should have to actively agree to its collection. As should the pathways to ensuring an organisation does not capture a person’s biometric information — or deletes it if requested. Asking for your biometric data to not be recorded should be an option, and asking for it to be deleted should be easy. Once again, there should be significant penalties if organisations are found to be collecting biometrics without the enthusiastic knowledge of the people whose information is being collected. Organisations which collect biometric data should also have to make it clear exactly how that data will be processed, who is processing it, and what technology is being used to do the processing.
Should there be limits on some uses of biometric information, like biometric emotion analysis and types of biometric categorisation?
Yes. While there are some specific instances where these might be useful — for example the recent story about how AI is being used to save lives in swimming pools — for the most part, further analysis of people should not be able to be used unless a very high bar has been cleared. Organisations which can do this should have to adhere to the highest levels of privacy and data security to ensure the biometrics are not misused, hacked, or used to target people.
Review of the draft code
Overview
- I generally support the draft Biometric Processing Privacy Code of Practice.
- There are instances where rules need to be further clarified or additional resources developed to help organisations navigate these rules.
- Biometric data, its collection, storage, processing, and use should be treated as some of the most confidential information an organisation can collect about a person.
- Given the state of technology around biometric information and the rapidly encroachment of surveillance and large data sets of crowdsourced “intelligence” being used to combat theft from stores, these rules need to recognise the companies operating in this space will be very good at sticking to the letter or the rules, but not necessarily the intent.
- Given any video or image of a person can now — through machine learning, facial recognition, and/or artificial intelligence — be easily turned into biometric data, and surveillance technology is cheap and ubiquitous, the rules need to treat any image/video gathering as the collection of biometric data.
- Needs further clarification of who is able to hold biometric data. For example, if a shop uses a platform to collect a database of folks who are suspected of shoplifting, do they have to self host the data or is it okay for the platform to host it? The privacy problem really comes into play when a single store’s database is connected with other stores. This allows staff with access to the platform, the police, or potentially the platform itself to essentially track people in a way that is deeply creepy.
Detailed feedback on the rules
Rule 1
Needs to be clearer about when it is okay to collect biometrics. There needs to be specific guidance about what “necessary” means. Can an organisation just say it is necessary? An example of this in action might be a retail store, ostensibly the owner may claim collecting biometrics are necessary to prevent shoplifting, but there is no clear pathway to explain how this will reduce theft and there are other interventions which might better be able to prevent theft.
Rule one needs to be supported by a mechanism, framework, process, or toolkit to allow organisations which want to start collecting biometric information to determine whether it is necessary, no alternatives exist, and is proportionate.Without a clear framework there isn’t really anything to stop an organisation saying they did consider these things.
This framework should be provided by the Office of the Privacy Commissioner and not from a third party or the product which is the organisation’s technology for capturing biometrics. Organisations should have to make this document public before they start using biometrics.
Rules 2 and 3
I agree all biometric information needs to be collected directly from the individual.
However, there should be active consent needed by the individual.
A small sign or one section buried in a lengthy End User License Agreement or Terms and Conditions in an app or website should simply not be good enough to satisfy this rule.
Rule 3 should also include a section about how the data is stored and what metadata can be extracted. Some services claim they don’t use facial recognition technology, they just go off metadata and with enough metadata about a person it is also easy to identify them.
In some instances, CCTV footage, and other video and images are being collected and then loaded into platforms which then convert images to data/metadata about a person, and can be tied to profiles across stores, it is important this rule reflects that any surveillance in a store could be used to create biometric data.
Rule 4
Agree with this rule and echo the feedback for rules 2 and 3: there needs to be active consent for biometrics being collected.
Rule 5
Needs further clarification regarding who is able to hold biometric data. For example, if a shop uses a third party platform to collate a database of folks who are suspected of shoplifting, do they have to self host the data or is it okay for the platform to host it? If they’re just suspected of shoplifting, is that bar high enough to warrant disclosure?
The privacy problem really comes into play when a single store’s database is connected with other stores’ databases. This allows staff with access to the platform, the police, or potentially the platform itself to essentially track people in a way that is deeply creepy.
Rule 6
Needs to be strengthened to ensure accessing your own biometric information is simple, easy and accessible.
Rule 7
Needs to be strengthened to ensure correcting your own biometric information is simple, easy and accessible.
Rule 8
This needs to be strengthened to reflect that machine learning, facial recognition, and AI image identification — alongside surveillance technology — are now cheap, ubiquitous, and automated.
There are many concerns about these technologies misidentifying people.
Rule 8 should better reflect the need for humans to actually be the ones inputting data and information. This is especially important because there are platforms which disclose photos, videos, and other biometric data — linked to other identifying data — directly to New Zealand Police.
Rule 9
Needs to set a firmer length of time and circumstances for which biometrics can be held. It is likely organisations will argue they should be able to hold this data indefinitely, especially when it comes to the platforms being used in retail settings.
Rule 10
Broadly agree with this rule. Any organisation which collects and uses biometric data should have the highest level of scrutiny placed on its use. The use of biometric information should be limited to clearly defined instances and follow clearly defined protocols, which ensure the privacy of the person and the security of the data.
Rule 11
Needs to be made clearer in terms of when it is okay for an organisation to disclose biometric information. For example, some platforms currently allow retail staff to add images, video, and descriptions of people who they suspect of shoplifting to a database. The New Zealand Police have access to this database of folks who might just be using a tote bag in a store.
In this example, Rule 11 should also require the store to inform the person they have been added to the database and it is now accessible to the police and potentially other stores.
Rule 12
Given many of the providers of machine learning/AI/etc technologies are not based in New Zealand and the structure of cloud servers means biometric data might be stored in data centres outside of New Zealand, and thus accessible to foreign persons or entities, this rule needs to be significantly strengthened.
Biometric data about New Zealanders should be stored securely in New Zealand.
Organisations should only be able to disclose biometrics to a foreign person or entity if there is a legal obligation to do so.
Rule 13
This is good and will limit how folks can be tracked across different instances of biometric information gathering. Once again, there needs to be some monitoring of, enforcement of, and penalty for breaking this rule.
Conclusion
We have allowed an industry of private surveillance and intelligence gathering to skirt privacy laws for far too long, amassing a significant amount of information and data on New Zealanders. It’s creepy, it is disconcerting.
Recent stories about one such platform, and the response to them, show that while these companies might be complying to existing — and potentially out of date — laws and rules, they are perhaps not being particularly ethical about their practices. It is dubious as to whether these companies have the privacy or safety of New Zealanders at heart, and most New Zealanders do not know or understand the extent to which their biometrics are being collected, stored, and potentially used.
As we have seen, time and time again over the past 25 years, it’s not a matter of if, but when a data breach occurs. These rules need to make it clear biometric data needs to be stored securely. Given some estimates put the uptake of one particular platform which allows organisations to upload biometric data at roughly 90% of retail stores in New Zealand a data breach of their systems could have massive impacts for almost all New Zealanders.
A Code will go a long way to curbing the creepiness of the rampant collection of very personal information about people. This draft code, and privacy law in New Zealand, can and should be strengthened to ensure privacy is the default setting when it comes to the collection of biometrics. It will also help increase public trust for those organisations which do collect and use biometrics lawfully and ethically.
Thank you again for taking the time to consider this submission. I am happy to speak further about these issues and concerns I have raised here. I look forward to seeing the next iteration of this code soon.