I imagine that it would be possible to cover the camera when you're using the cooler.
My plan is to avoid buying anything from these things in the first place (there's always another store), but if/when the day comes when that is impossible, my backup plan is to cover the camera.
I also really hate the idea of replacing the glass with a display. If that happens, I'll have to stand there with the door open while I decide.
It's all about storing or working with data about other people. No matter how it's done.
If you reply it doesn't apply because the stored information is anonymized, I quote UK's ICO:
"You should also note that when you do anonymise personal data, you are still processing the data at that point."
As an American who isn't too familiar with GDPR, I'd like to know: Why does GDPR prevent this? Can you, being charitable in your assumptions, guess why the above commenter believes GDPR does not prevent this? Why is that argument wrong?
If the stores tie the facial data to a credit card or store rewards card then the GDPR might stop them retaining or sharing the information.
Applying some ML algorithm to personal data certainly fits.
I get it in the sense it's just a picture, but when you run credit cards in a store, and can temporally associate cards to faces via temporal proximity, you're just elevating the "not that personally identifiable" to "definitely so".