Mall real estate company collected 5M images of shoppers
cbc.ca
cbc.ca
Do what now? Physical spaces have privacy policies? We're really sleepwalking into a dystopia. If you don't like the privacy policy of your shopping mall, you're free to shop... online, where they get even more behavioral data on you. Yikes.
Very abstractly, legal precedent exists for the general implementation. Texas has what's called "the 30.07 sign" codified in the penal code (30.06 concealed, 30.07 open carry)[1] which prohibits firearm carry on that property with nothing more than a proper/legal sign. The responsibility lies on the entrant to notice and comply with the sign prior to entering the establishment, no explicit acknowledgement is required by that place of business for it to be enforced.
(not saying I agree with what's going on here, only that I can see lawyers using laws like this to support the action in the face of no laws saying it can't be done like this - a judge may throw the argument out, but it could be made as a good faith argument? My mind is thinking about how in the 90s "shrink wrap acceptance" was just a given - you opened he box so you accepted the license, but in 2020 many new laws have been developed to curtail that design and now require explicit acceptance by the end-user.)
[1] https://statutes.capitol.texas.gov/Docs/PE/htm/PE.30.htm
Not super familiar but that’s a licensed activity right? As in there’s some training and/or test administered upon gun purchase? Sorry if that’s not the case. But that feels marginally different because if you had a handgun and you knew this door sign governed whether or not you could bring it into a premise, you would look out for it.
No one is staring at the door of the drug store, because we are not trained to do that.
Yes, you do, because while a shopping mall might be considered a "public space," it is private property owned by a private organization. In Canada the PIPEDA [1] covers this federally, though the law is written such that it is a backstop, and provinces are free to enact their own "substantially similar" (or stricter) laws if they choose. For example, in Alberta the PIPA [2] covers these issues.
And as the article states, both federal and provincial privacy commissioners found CF in violation of those laws.
[1] https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-can...
[2] https://www.alberta.ca/personal-information-protection-act-o...
age, name, ID numbers, income, ethnic origin, or blood type;
opinions, evaluations, comments, social status, or disciplinary actions; and
employee files, credit records, loan records, medical records, existence of a dispute between a consumer and a merchant, intentions (for example, to acquire goods or services, or change jobs).
How does video of people passing by meet such a definition?That's how I understand things.
It wasn't some security camera overlooking the concourse from 30 feet up or anything like that.
Indeed there's a huge glaring problem here: many of these malls have branded entrances (Shoppers Drug Mart, Best Buy, etc) through which a large portion of consumers walk into the mall, and these alleged decals are not present in those entrances. Here's an example [1]. Frankly I don't see said decals even in the non-branded entrances[2]
They're going to have a very hard time convincing the commissioner that people were in fact aware of these decals AND any "privay policy" therein. A simple survey would easily show that people are completely clueless about it (anecdote: I used to frequent CF malls quite a bit when I was in Toronto and never saw anything of the sort, even despite being the type of person that might actually read random stuff posted at entrances).
[1] https://www.google.com/maps/@43.7788812,-79.3447734,3a,75y,1...
[2] https://www.google.com/maps/@43.7789409,-79.3444783,3a,75y,1...
>CF suspended its use of cameras back in 2018 [...]
Don't get side tracked.
This implicit agreement can be used to obtain quite literally anything without the other party ever knowing.
Taking the argument at face value is probably not the right conclusion [1]. The linked court case establishes what we would call in American law Informed Consent. If you can't read disclaimer at the door until you are in camera range, is that really informed consent? And if the disclaimer does not actually list the policy in question, but refers you to a website to read it, can it be considered sufficient? A quote from the ruling is relevant here - "The more onerous the exclusion clause the more explicit the notice must be". Now, this case was related to legal liabilities related to injury in a ski resort, but it's the closet thing I've found. I suspect a judge won't take long to rule in favor of the plaintiff.
[1] - https://www.canlii.org/en/bc/bcca/doc/2020/2020bcca78/2020bc...
We asked why they couldn't use other biometrics which were much more established at the time (eg fingerprint scanners at the doorway), they said because other biometrics required consent. They wanted to track people without their knowing or agreement.
When asked about the ethics they said something along the lines of "this is what our customers are asking for."
Point being you don't need a privacy policy when you don't have a reasonable expectation of privacy in the first place. They can take pictures of you, store them in a database, sell them if they want. You don't have a right to be forgotten. And there are people that don't see anything wrong with that.
That's a lot different than companies tracking me via facial recognition, storing the data in databases that never get deleted, and combining it with behavioral data. It's going to lead to all kind of abuse. We'll end up with many variants of redlining, but digital.
What happens when that type of data is collected for today's youth and 20 years from now employers start using it to screen job applicants? What if the machine learning algorithms can't distinguish between correlation and causality? Does the "profile" of a successful person become someone from a rich neighborhood as a result of naive correlation?
I'm sure it'll be amazing for wealthy people and terrible for poor people. If I'm rich and walk into a mall, I get treated like a VIP. If I'm poor, maybe the doors don't even open.
I wonder if they stopped in response to complaints, or decided the notification was unnecessary. At the time, I figured their system judged me for browsing $800 jeans and not making a purchase.
I've seen TOSes on mall doors before. They've been white letters on clear glass at just about foot level written in letters about 1cm tall. They were usually about violence and guns and shoplifting being grounds to ejection and banning.
The only people who ever see them is the decal printing company, the guy who installs them, and mice.
I'll take that one further! Every street that enters the city I live in, has a sign with text that you'll only be able to read if you park your car, get out, and walk up to it. I've lived here 5 years and I still don't know what the heck those signs say lol. My guess is it's something about parking enforcement? Sigh. It's completely absurd lol.
Maybe some, but most people are aware. They have very little to zero power to fight back the abuse.
The novelty here is not the collection, it's the analysis. And that makes for a kind of interesting legal distinction that hasn't been made in any other domain, as far as I know. A distinction whereby the collection is legal, the retention is legal, but certain types of analysis may not be.
It is possible, though not well documented, that in China they actually do analyze[0] the image data from video cameras. That said this would be a case study in what that means from a free and open society.
[0] - https://www.theatlantic.com/magazine/archive/2020/09/china-a...
From a retailer's point-of-view I totally get the rational and value behind collecting these metrics... from a privacy point-of-view it is a bit disconcerting.
[i] https://www.cbc.ca/news/canada/calgary/cadillac-fairview-mal...
They were clearly working and doing some kind of scan of the mall. Unfortunately I didn't notice soon enough to take their picture or chat with them. Would have been nice to know what they were doing.
Just so I'm clear, the argument against this is:
- Merchants should be able to hire humans that sit around looking at camera screens all day trying to find shopping patterns, shoplifters, etc.
- Any attempt to automate this tedious task is dystopian and evil
?
Attempting to automate the task of constant observation makes constant observation easier, which isn't necessarily a desirable state.
An example of data that is harmless on its own but harmful at scale is license plate reading. https://arstechnica.com/tech-policy/2015/03/we-know-where-yo... a few points tells you that a person is in a city, a few more tells you where they live, a few more tells you where they work, a few more tells you where the shop, a few more tells you who their friends are, who their associates are, if they're seeing someone on the side, if their going to any gatherings, if they tend to frequent red light districts... ect.
In this way, as data is aggregated, the picture of a given person slides from blurry to clear. And a clear picture of someone is an invasive and dangerous picture of someone.
As a result, aggregation of "public" data like this is something privacy advocates generally resist. It's not that there's is some line that's been crossed.
However, I do care if the cameras are feeding into a huge system for analytics and data sharing. What if I cough 2x more than the average person? Does that get tracked, stored, and sold to a health insurance data supplier that ranks me as high risk for respiratory problems?
Does the machine learning algorithm that analyzes footage rank me as a potential thief if the database says I hang out in a lot of poor neighborhoods?
These will turn into class profiling systems that will amplify everything in your life so much that whatever your economic status is when you're born is what it'll be when you die.
Honest question.
Having a card is just as unavoidable as needing to go to the shopping centre to buy groceries, so this isn't even a case where "if you don't like it don't use it" applies
I'd presume if umvi had rejected the groundwork reasons for privacy, they would have made a comment more like:
"What bad thing are we asserting would happen if they created this data set? What demonstrable harm can you show from even an omnibus dataset? Let alone what this mall is creating?"
As just one example, I'd expect the emergence of semi-automated blackmail - you can infer a lot from peoples' public activity.
There is no identification part in what you describe. Generic stats (how many person in the queue, etc.) are okay.
The issue is not facial detection but facial recognition.
They stored model of faces associated with data which mean they could point a camera at anyone in the street anywhere in the world and find back what is the data associated with that person.
Hiring humans would not result in creating and storing models of faces
In scenario 2, if the technology is widespread, police can be searching all stores records country wide within minutes.
[1] https://www.sciencedaily.com/releases/2019/05/190501114602.h...
More importantly though it sets a precedent for the future. We now know how easy it is for an airborne virus to decimate us, so even when this virus is over it'll be acceptable for people with immune issues to keep wearing masks "just in case" (similar to Japan/etc, although I know some of that is about stopping other people from getting sick).
Think of what a PR coup it would be for the camera company if they resolved a notorious cold case using their tech.
I think that it is safe to assume that if you are outside, you are being recorded, either by a check point camera , a store’s security camera , streetlight camera or even your neighbor’s ring device.
You should not have any expectation of privacy once you are outside the confines of your house.
"Shoppers had no reason to expect their image was being collected by an inconspicuous camera, or that it would be used, with facial recognition technology, for analysis," said federal Privacy Commissioner Daniel Therrien in a statement.
My default is the opposite, I expect I'm being tracked all the time and that my image, cell signal, and whatever else is being used to try and sell me stuff I don't need.
My first reaction was “what a sad dystopian position.” But then I thought further and while I agree in general, I think “privacy” needs a bit more nuance to it. If you are outside should it be against the law to have a camera that films you for security? No I don’t think so. There is a reasonable expectation that business and home owners will have security cameras to protect their property. But in the case of filming you in order to monetize your likeness and shopping habits, I think this goes a step too far, and becomes broadly unacceptable as too intrusive. Should I only be able to retain my information (likeness, shopping habits) by hiding in my home? That’s the dystopian part.
I believe shopping malls are private spaces open to the public. The point is that I would not be shocked to see that there are different rules regarding public spaces vs private spaces open to the public.
And if you are walking in the middle of a mall with lots of people around you, that would be an example where there is no expectation of privacy.
-- OP argument put more simply, if you are in a bathroom, everyone expects that that is private. In fact bathrooms have doors and urinals have privacy screens. If you are taking your clothes off, a reasonable person expects to be private
Whereas, in the middle of the mall where there are tons of people, there are surveillance cameras, and other people taking pictures of each other. That would be somewhere with no expectation of privacy
The idea was people can see you in the street, maybe exceptionally a wierdo would take a photo of you but nobody could find your identity back from that photo. In case of a crime in the street the police could exceptionally access surveillance cameras to investigate. That's it.
This is what "no privacy in public" meant in 2000/2010, and I was totally fine with that. I was totally pro video surveillance at that time .
Now we're in 2020 and facial recognition is happening. Everything changes.
Today, taking the picture of someone = taking biometric data like fingerprint or DNA. This allows you to have a total control over that person. Law were made at a time when a cameras were not such devastating weapons.
Everywhere you go, everything you eat, each item in the store you look at, each person you look at, heartbeat & stress level, which house you're at, who are you talking to, what did you bought, when, with who, what ads did you watch in the street, which part if the ads, with which emotion, we can find your identity, social posts, private data, health data, intimate message, browsing history, emotions, stress level, etc just by pointing a camera at you because of facial recognition. All this is anaylzed, sold and stored forever.
We're getting in a dystopia the worst case-scenario dystopic sci-fi movie couldn't even imagine and people are like "nah we shouldn't expect privacy anyway ya know"...
How does a picture grant total control? Let's say I have a picture of you right now. How do I use that picture to either force you to do something against your will, or prevent you from doing something?
Looking at China it's pretty clear how having a model of peoples face with facial recognition has been key for their total control of the population
The NSA spies on its own citizens, and won't even tell congress how.
https://ca.reuters.com/article/ctech-us-usa-security-congres...
The CBP is buying location data on US citizens, tracking them without a warrant, country wide (not just at borders), and won't say why/how:
https://ca.news.yahoo.com/dems-call-for-cbp-location-data-in...
Police, the FBI, and more use stingrays without warrants. The NSA works extensively to destroy encryption, and even have back doors into products for full, unlimited, real-time breaking of encryption.
I could post endless stories about this. Different US agencies, different data, different purposes for that data.
Put them all together.
Now consider that some of these agencies are "fighting" with democratically elected officials. Refusing to comply with democratically elected senators, congressmen, officials. State officials have even less sway.
This data is quite simply too powerful to be in anyone's hands. Literally, too powerful.
Data should be legally made in to toxic waste we all know it should be treated as.
Yes, regulation is great with a just and fair government. If the government can't be trusted, then neither can the regulations. If we can't trust the government, then we need to replace it with one we can trust.
It is not "the government is corrupt, therefore all is pointless". Instead, there are scenarios such as:
- the government is comprised of people, running different departments - those people seem to think they are doing things for the common good - courts determine otherwise, and point to laws passed by legislative bodies as validation - activity stops
"Spy agencies", and "policing agencies" are constantly under these checks and balances. Cases are thrown out, individual careers are axed, when warrants are not used when they should, for example, when searching homes.
Without the laws, and court cases as they are, then the police would simply enter without those warrants, get convictions, and carry on very happy with themselves.
The real problem here is that technology grows so very fast, and that the world is changing quite rapidly. Don't even get me started on bio-tech, or near-Earth space changes over the next decade. Or Interplanetary law!
Legislative bodies, and law, are literally meant to deal with things over the course of decades or more. Legislative bodies tend to sit for 4 years or more! Change is slower, and of course, we like slower change for many things.
But this means that laws much 'catch up' to faster moving change.
Hell just crafting a law, going through the committees, hearing from experts, at least in Canada, then crafting the law, reading it in both houses, and more experts can take more than a year or two.
And that's after the will is in place to enact change.
This is part of the reason I deem the executive branch as having value, but, that is another discussion.
All said, I fear governments with this power most, and private corps next. One law takes care of both of these scenarios.
Lastly?
Never ignore the interest in something. Any old horse trader will tell you, if everyone clamours for something, it has immense value!
Knowing if I farted last week on Tuesday, is of immense information to everyone. Wha? Yet it is! And if it is of such value, if everyone climbs over each other to get that data, to hold it exclusively, to sell it, trade it, there is likely some import to such things.
If this info is so insanely valuable, then shouldn't the creator control it? Control what happens to it?
We have copyrights, patents, trade secrets, and even things like labour laws, acts to protect safety!
The entire purpose of law, is to protect "my stuff" from "that other guy". My life. My belongings. My health.
Yet this? This is all just "OK"?
The current laws surrounding data, are like period of times before labour laws, before human rights legislation, before food safety acts, and on and on.
This period of time is ending. Legislative bodies are catching up.
The question is, what will happen during the transformative period, where law catches up, and passes more and more laws about personal privacy, and control over personal data?
If someone sees you in public, does the fact that they see you belong to you or them?
This is important. If you see me, does your memory of seeing me belong to me? Can you own memories inside someone else's brain?
Personally, I think not.
To some extent, your appearance in a public place does not constitute "your stuff".
Yes, your health and safety should be protected. Someone seeing you in public is not, in and of itself, a threat to your health or safety.
If you go out in public, you must come to terms with the fact that other people can see you.
What's happening is, effectively, stalking. Stalking laws exist, even if the person is following another in public.
There are limits, you see.
Further, as others have eluded to, this is not about "a person seeing another person". Instead, this is about:
- a non-entity, a device, 'watching' you - exporting that data from the locality it was taken in - storing that information forever, if desired - also scanning you directly, looking for RF signals
To claim that "a person seeing you walking down the street" is the same as this, is not valid.
For example, "stalking" entails following a person, where ever they go.
What else is all of this surveillance, if not 'following' a person where ever they go? And in most legal jurisdictions, this is a crime.
Try this same behaviour as a person? And individual? Follow a person where ever they go, take notes, never leave them alone? Bam! Stalking.
But because it's a corporation doing it, that's OK I suppose?
You keep trying to say that "a person seeing you in public" is the same as "mass surveillance being leveled against you".
It's not. Full stop.
So why not discuss this as it truly is? Please stop this conflation.
If you go to Joe's house and Joe makes a note that you came to his house, then you go to Bob's house and Bob makes a note that you came to his house, nobody is stalking you. Each individual is keeping track of who visits them. That is not stalking.
Yes, maybe later on, the government or someone else could come along and ask to see each person's records of who visited them. But that is their information to share or not share. You went to their place! If someone comes into your place of business or residence, does the record of that person visiting you not belong at least partially to you? Are you not allowed to keep track of who enters your own property?
This is how you get torrent sites taken down, even though they host absolutely nothing. Intent, you see, is key.
And what is the intent of all of this data collection? Is it to just randomly, happen-stance note someone in passing?
Or is it a dedicated, planned, targeted collection of data on individuals?
What is the purpose of the data collection? Hmm?
This is what counts.
That's where all this hyperbolic "OMG they took my picture and now they have total control of my life!!1!1" hand-wringing falls flat.
I care about privacy too, but come on. It's not voodoo. If you're not going to be serious about the real risks it's hard to take seriously.
After all this discussion, I've yet to hear an explanation of the actual mechanism by which, say, Macy's having a picture of me in their store allows them to exert control over any action I might want to take.
You seem to be implying that there's no difference between having a single piece of harmless information about someone, and having lots of personal and/or intimate knowledge of them, especially if they aren't the ones having given it to you, and even more so if you're strangers.
The vast majority of people do not care about privacy though, at least not to the extent that “tech” people seem to.
Please, explain?
This sounds like nothing more than hyperbolic nonsense.
If they were then taking the data and finding those people through Ring or youtube videos, sharing the pictures of people with companies to learn the earning power or tax history of a person, or using pictures of people and the store they visit to sell to Amazon or Facebook, then it would seem a step too far.
The ad-tech industry wouldn't exist if there was.
It seems however that in the case of the Canadian mall implementation (or more precisely their solution provider) they stored more than this number, losing the anonymous property of a system they sold as an "Anonymous Video Analytics".
In my opinion, something should be called anonymous if and only if you cannot go back from the stored data to a personally identifiable information.
For now. Give it a while and they'll be looking up your credit score as you walk through the door.
I don’t see this as a victimless act - just that the victimization is uncertain at present but almost 100% certain to occur the more this behaviour occurs.
the NYC subway system has big human sized iphone like map displays complete with a facetime camera, presumably capturing the same stuff.
Don't cell carriers already sell your "anonymized" location data to marketers?
"An individual would not, while using a mall directory, reasonably expect their image to be captured and used to create a biometric representation of their face, which is sensitive personal information, or for that biometric information to be used to guess their approximate age and gender," they wrote.
Genuine question - if mall had deployed people whose job was to look at people to guess their gender, age and then jot it down in a notebook, then would it have been a problem?
If not, then why this is a problem? Assuming that the 'biometric representation' is discarded by the system after guessing the age and gender.
It wasn't, it was stored in a third party database.
> Genuine question - if mall had deployed people whose job was to look at people to guess their gender, age and then jot it down in a notebook, then would it have been a problem?
I don't think these notes would ever come close to "a biometric representation of their face" which can tell you with certainty someone was there or not (when, what time, who they were with).
The privacy commission has no teeth, so nothing stops future abuse :/
PCA can transform an image into a set of unique components, where each component has a numerical degree of distance and relatedness from an agreed on centered component. The first component has the largest possible variance (it accounts for most of the variability in the group). Each succeeding component has the highest variance that is orthogonal to the preceding components. The transformation of the group proceeds linearly from a group with a high degree of dimensionality to a group with a low degree of dimensionality of which the components of the group with a low degree of dimensionality are uncorrelated.
PCA reduces the dimensionality of a complex group of possibly unrelated activities into a smaller group of principal components that accurately represent the entire group with minimum information loss and no loss of essential intrinsic information. PCA also reveals the internal structure of a group of possibly unrelated activities, it can be used to discover meaningful relationships based on commonalities the internal structure of the group shares with other activities that happened in the past. PCA is well known for forcasting with time-series analysis and regression analysis. In most cases the predictability of specific activities can be calculated with high percentages of certainity, by focusing the reconstruction of projected outcomes on the optimization/maximization of the variances of specific activities.
In addition by categorizing the images into age groups and gender groups that information would be very valuable beyond marketing in longer list of industries world-wide.
You've basically just asked why stock photo/video companies exist.
With the way most modern neighborhoods are designed it would take very few cameras on private property to capture everyone going in/out.
Is it legal in Canada to deny someome a service offered to the public because they didn't agree to this absurd policy?
It was a beta test run 2 years ago. Someone ran fast and broke things and were probably fired. Take off your tinfoil hat and relax.
CF doesn't care who the individuals are or their identities, though general demographics would probably be interesting. They certainly have signs up at every entrance clearly indicating that you are on camera, but I think they are actually surprised about the biometrics data being stored offsite. I suspect they didn't understand this when they setup the AVA trial.
They use analytics on the WiFi based on MAC as well as Internet use.
This data is used to determine the number of unique users that pass by different parts of the mall to identify high traffic and 'dead zones'. They use different marketing programs to increase traffic to dead zones and can justify higher rent in high traffic zones.
The images are not being persisted, just the metadata about the individual. Who is being harmed by this? If a person with a clipboard collecting this information without telling anyone, is there any outrage?
The harm ? With that data, any camera in the world pointed at you can find what you did in that store.