Facebook to Pay $550M to Settle Facial Recognition Suit
nytimes.com
nytimes.com
If the story was “judge declares entirety of Facebook enterprise illegal, punishment is $550M fine” I would get the outrage.
If Facebook gets a company-destroying fine for each act of wrongdoing, then it’s just a race where the first victims to prosecute get compensated. The slowpokes are screwed because the company has nothing left to pay out. This seems like a less fair system than one where fines are proportional to the value extracted or damages caused by the illegal conduct.
if we see it just like that then the breaking a law is just a calculated risk. And companies take calculated risks all the time, they will take it. There is my mind no way that facebook did not know that they are breaking the law.
if we allow that the law is just one parameter in the strategy, then the law is just a tax that you have to pay if you get caught.
If I was Facebook I would become quite uneasy by that.
Please, be specific.
But it's not like there's a lack of other issues to pick from [1], of course, one can insist on it all being "alleged", but let's be real here on hackernews: If it's technically feasible, then it's most likely being done, legalities are regularly just an afterthought to the actual product, particularly when it's about the monetization of user data.
A lot of that might be completely legal in the US with law-doctrines that undermine privacy expectations on a fundamental level [3], but the US isn't the whole world.
[0] https://www.reuters.com/article/us-facebook-privacy-tracking...
If we assume the 7mm Illinois resident incidents number is correct, Facebook settled for about $79/incident.
On the one hand Facebook would obviously not want to pay any amount in a lawsuit over their facial recognition feature, but on the other hand the law was about 1% as impactful as it had been written to be.
In comparison, a fine that you'll make up in no time is not a punishment at all, just a fee for the privilege of being allowed to ignore the law.
This fine for facebook is comparable to a speeding ticket price for a minimum wage worker. Is the crime on the level of speeding?
Fines towards individuals tend to be associated to the crime committed , not to the persons paycheck. Why should it be different for companies?
Fixed financial penalties are inherently regressive; they disproportionately punish the poor and provide no disincentive to the sufficiently rich.
I believe this has been implemented for speeding fines in some countries.
If you as an individual perform an action that is punished by 6 months' jail time then all of your activities are curtailed. You're not just prevented from like, picking up a kitchen knife, you're locked in a box.
They’ve been sued in IL as well under the same auspices, and Clearview’s defense that they aren’t a private entity because they "only" do business with public entities (e.g., law enforcement) is definitely not going to fly here. This settlement establishes how seriously the state of Illinois is taking non-consensual biometric information gathering, especially facial recognition.
Making data publicly accessible does not grant users of it carte blanche to use it however they wish. The data may be copyrighted: Viewing it does not grant the viewer rights to republish it or claim it as their own work. An image may contain a likeness: Viewing it does not grant the viewer rights to claim endorsement by that individual, or to use their likeness in ways of which the individual does not approve.
Beyond copyright and likeness rights, a likeness contains biometric information. Having access to that likeness, at least by the laws of the State of Illinois, does not grant the user rights to biometrics derived from that image.
But that's not the question here, right?
The question is whether I can use my high school yearbook pictures to look for information about my classmates.
I mean, say you and I are at a neighborhood kid's birthday party with our own kids. Suppose further that you take some pictures, and then post them publicly. Maybe to your FB?
Well, I never really gave you permission to use my image on your FB. Let alone publicly. I know that I certainly would never consent to publishing images of my children publicly. Further, I suspect the birthday party's host wouldn't give you permission to post his/her family's images on FB either.
So here we are, with all of these people on your public FB. None having signed or even given verbal authorization for any sort of release. And now FB starts running FaceRec on all the information you just gave them. To top it all off, my family and I don't even use FB. Never have. So it really can't even be claimed that we consented to facial recognition via the terms and conditions of service.
I only outlined all of that to outline this, just because a person's image is in public doesn't mean that the person consented to the image being public. Especially images taken from private spaces, (like bday parties at some kid's house).
> I only outlined all of that to outline this, just because a person's image is in public doesn't mean that the person consented to the image being public.
But what part of this would, even hypothetically, give you a cause of action against Facebook? What's Facebook supposed to have done wrong? You have a cause of action against your friend who illegitimately provided your photos to Facebook, not against Facebook who relied on the legal assurance your friend provided that he had the right to post those photos.
Comically, once they run the scans, they should be able to certain that they don't have consent because it doesn't match one of their users, and should throw the data away.
FB offers a service that allows you to share your pictures with your friends among other things. Before you upload a picture Facebook asks you if you have all of the rights to the pictures you are uploading (albeit they ask that in the fine print of their TOS.) FB offers ancillary services based on those images you shared. If you are uploading images you don’t have the rights to how is this FB’s problem?
There is a disparity here between real world and software services I think. When my real estate agent's software asked me to put in my room mates details, I just had to check a checkbox that said he consented. Yet when it came to the paper contracts, we all had to sign individually. We need the latter for software, else PII is going to keep spilling all over the place and we'll forget we ever had privacy.
I don't think it's unfair to scrutinize a company in such a powerful position as FB either. They know they have unconsenting people in their photo database, it's just inevitable, and they are hiding behind their T&Cs hoping it's enough in the court of law. Ethically, they've failed already, and clearly in some states they're breaking the law too.
It was reasonable in 1990 that the mechanism that you suggest here would be highly effective in most cases. We are in uncharted waters now and unlike the titanic, I think we should proceed with caution.
I'd like to hear your comments on why in particular that's an unfair characterization, if you're willing.
Assuming Facebook cannot legally host the media, and they choose to do so after being informed of its contention, they are choosing to say they are legally in the clear (or that they don't care about the law, which seems a lot more likely).
IANAL, but it seems simple enough on the surface. Of course Facebook will claim otherwise, and without being required to make it easy to report contentious media very few people will actually do so, and sharing a photo without permission is not the same as copyright protection. I still think the same basic logic applies though.
If I recall correctly, there is no such right, because it would effectively eliminate photography.
Further, it being a child's birthday party, at a private residence, the photographer's action becomes a tort in the vast majority of states. If you were a big enough pain in FB's butt, you could use that to stop distribution of the images at a minimum.
It's true that the easiest method of guaranteeing ironclad, legally enforceable privacy with respect to this facial recog stuff is to live in Illinois. But that doesn't mean the situation is hopeless for people who live in other states. It's just a matter of whether or not you want to do the legwork of making the claims. Which, depending on the state you live in, may have to be based on anything from privacy violation like Illinois, to contributory copyright infringement if you took the photo and forwarded to your friend who then posted it.
So it would depend on both the situation, and the state and municipality in which you reside. I can't give you one catchall, because there isn't one catchall right now these laws are uneven across the country. And very much in flux right now.
- is the data personal? Well, the point of running facial recognition is to identify the person, so yes.
- does the organisation processing the data have consent of the person? No.
- is there one of the other justifiable or necessary reasons valid for processing the data? No.
So it's a data protection infringement.
>> Specifically, when you share, post or upload content that is covered by intellectual property rights on or in connection with our Products, you grant us a non-exclusive, transferable, sub-licensable, royalty-free and worldwide licence to host, use, distribute, modify, run, copy, publicly perform or display, translate and create derivative works of your content (consistent with your privacy and application settings). This means, for example, that if you share a photo on Facebook, you give us permission to store, copy and share it with others. [..]
>> When you delete content, it's no longer visible to other users; however, it may continue to exist elsewhere on our systems where:
>> - your content has been used by others in accordance with this licence and they have not deleted it (in which case, this licence will continue to apply until that content is deleted);
The Privacy Policy states that you are responsible with whom you share your content, after which above license applies.
https://m.facebook.com/legal/terms/update
Edit: misread parent, adapted accordingly
Facial recognition tech, used in this way, seems to throw a bomb into a fragile peace where people can coexist with each other despite having incompatible values.
https://www.biometricupdate.com/202001/biometric-privacy-sui...
https://www.cnet.com/news/google-arts-and-cuture-photo-match...
People's opinion of what constitutes "private" varies wildly.
Pardon my take, but:
A large uprising is starting to swell in the name of privacy, but the swing voter is concerned about what is essentially the visual equivalent of the "Which Disney Princess are you?" quiz.
i think it's more of a tide that comes and goes. wait till there's another pokemon go.
It feels a little bit like the gun control debate. Taking away people's freedoms because of the possible worst case outcome can result in a worse overall situation.
If people aren't bothered by how facial recognition is used, stepping in and asserting we know better and they need a legal protection seems premature and overreaching.
There aren't technical limitations to the use (just as there aren't technical limitations to copying and freely distributing all digital media), so we either institute legal limitations or accept that it's allowed. There are many negative aspects of allowing it, so we should probably make sure we take the time to look at the repercussions of both stances carefully (that is, more carefully than "I don't have a problem therefore allow it").
Images of my face created by other people may be a different story entirely. Does Donald Trump or Boris Johnson own every photo of them on the AP newswire?
Unless we want to be governed by faceless legislators or entertained by faceless celebrities. There should be some way to divide responsibility for person's images that isn't totalitarian in either direction (either "You cannot use a person's face without their consent," which kills visual news as a practice, or "every face is fair game for anyone to use at any time," which feels invasive to the individual).
In my view, it's more important to create a sort of symmetry with respect to images and other data than it is to preserve particular customs that are problematic in light of modern technology. That is, it's probably OK that every e.g. FBI agent has access to thousands of images of me, or even my complete genome, as long as I have access to thousands of images and the complete genome of every FBI agent. We learned in kindergarten that "knowledge is power". Like power, knowledge is not symmetrical. A federal prosecutor having power over me doesn't necessarily mean I have power over that federal prosecutor.
If we've learned anything in the decade just past (to be clear, that's an open question), it is that authoritarian structures are easily hacked by the authoritarians who run them. It may be that e.g. the Department of Justice wasn't always constructed to capriciously surveil and/or construct false cases against innocents (although, was that before or after they harassed MLK and other civil rights leaders?), but ISTM at least the cases of Aaron Swartz and Carter Page, to cover both ends of the political spectrum, show that to be the case now. If the tools of knowledge/power are increasing in power, we all need to have access to those tools.
It's my understanding scraping is legal, but as the OP states, you could be fined over a half a billion dollars if you use that information. What part of the law/article was unclear?
You don't need that in most other states.
Yes, many laws require consent. I'd caution against treating people's permission as a problem to be routed around.
This has been Facebook's general stance since it was established.
I find this notion slightly strange that the internet as a public space is some sort of voyeuristic free for all where one forfeits every right. If this was not stopped it would render the entire public internet hostile and borderline unusable which would be a shame for a medium with so much potential.
Some powers need to be checked.
???
As a (supposedly democratic) society we (supposedly) decide what is acceptable and what is not. These decisions are, in the eyes of the universe, quite arbitrary. You may be discovering that now, but some of us have known it for a while.
Same as for any business.
So he literally just framed this as a 'cost of doing business'?
The cost has to be classified into one of these buckets and so the CFO was probably just clarifying into which bucket they lumped it.
This is part of the point of generalized accounting is so everyone gets a similar basis compare companies.
Either PR was not consulted or they don’t understand how this comes off.
> Total expenses were $12.2 billion in Q4, up 34%.
> Cost of revenue increased 25% and the growth was driven primarily by depreciation related to our infrastructure spend.
> R&D grew 36% and was driven primarily by increased investments in core product as well as our innovation efforts, particularly in AR/VR.
> Marketing and Sales grew 23% and was driven primarily by consumer and growth marketing.
> Finally, G&A grew 87%, largely driven by higher legal fees & settlements. This includes charges related to a $550M settlement in principle we reached this month in connection with the Illinois Biometric Information Privacy Act litigation.
This is standard for earnings calls. The point is for the CFO to add detail to the generally accepted accounting principles (GAAP) financial numbers so that investors understand why they changed. As @joez mentioned, companies have to report financial numbers according to GAAP, which mandates that companies disaggregate costs into specific areas. Both good and bad companies face lawsuits all the time, and the legal fees and settlements will show up in G&A. If G&A expenses change in an unexpected way, it is expected that the company will communicate why.
There's definitely a lot that goes into crafting these calls, but having listened to and read more than a thousand of them, I don't think there was anything poorly done in this specific example.
This happens in all industries. Part of the reason many legal settlements lead to a massive jump in stock price is that companies reserve funds for expected litigation. If FB models the settlement cost to $1B and it turns out to be $550M, that's a good result
The theory has limits though. If, in discovery, prosecutors find out that the company intentionally did something illegal because it believed that the cost of the fine was less than the benefit of the illegal action, then the fine is usually much higher and the specific executives involved often face much stiffer penalties.
How would you prefer he frame it?
Maybe I'm jaded or cynical now
there's also the catch-22, that if an entity is pursuing legal collection outside of Illinois (for example of the Flickr dataset from the IBM case) it has no way of knowingly excluding Illinois residents without identifying them by using an (illegal) facial recognition dataset in the first place.
In any event, the main point was that the fine is 1/100 of yearly spending.
I'd love to see Facebook actually fight the case to the end but nope, number say settle and move on.