It seems they are simply asking for identify verification by sending the photo to a remote DHS server for verification. How is this different than showing a ticket agent your passport and having them scan it? That’s the same photo in question. GDPR doesn’t get you out of having to verify your identity in person against a government photo for boarding a flight.
In fact, one could argue the method in question is actually more secure and private because you never actually have to share your passport photo directly with JetBlue.
But surely, the government has plenty of cameras in customs areas and face recognition has been a thing for a decade.
Maybe the TSA does it, of course.
AFAIK it should apply to entities that share personal data with third parties, for instance.
They got the images from CBP.
The airline isn't taking or storing photos of passengers who don't opt into this process, but it is presumably sending the government a list of all passengers prior to boarding so that photos of passengers who opt in can be verified. Would this violate the GDPR?
I absolutely do not believe the tweets from a company PR representative as to how their technology actually works.
They could also build the same database 10 years ago by taking your picture as you scanned your boarding pass.
I can't say I'm certain it is fail-proof, and it defiantly can feel spooky but not everybody is lying to you all the time.
From the article the PR quoted, I arrived to the relevant executive order that facilitated this, section 8: https://www.whitehouse.gov/presidential-actions/executive-or...
But you're right, and the process is surprisingly reasonable as long as the implementation is safe