In the US, bars often ask for photo ID to verify that customers are old enough to be served alcohol. That doesn't seem to lead to widespread customer tracking.
1. This is a subset of all customers so it is not as useful as all customers
2. I’ve never seen a bartender or waitress scan my photo ID or record the data on the ID; without that it isn’t highly unlikely the data is being stored.
Your comparison is just not valid.
It is extremely creepy.
But Yanks screech about European surveillance states, and denounce the evil EU and its "sheeple" citizens... Much better over there, of course, where it's just corporations and not the eevul gubmint that's doing it.
___
[1]: That she borrowed off her elder sister...
In my experience, both statements are accurate.
If I saw the person pull out a notebook and write my information down I would physically take my ID back and walk away. I'm pretty sure most people would be put off by this action.
I've seen this exact setup before, in an entrance to a club, but no one seems to care.
I'd wager that the vast majority of people think the machine only checks if the ID is valid and doesn't do anything else.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
Article 10
Protection of personal data
1. Regulation (EU) 2016/679 shall apply to the processing of personal data carried out when implementing this Regulation.
2. For the purpose of this Regulation, the personal data contained in the certificates issued pursuant to this Regulation shall be processed only for the purpose of accessing and verifying the information included in the certificate in order to facilitate the exercise of the right of free movement within the Union during the COVID-19 pandemic. After the end of period of the application of this Regulation, no further processing shall occur.
3. The personal data included in the certificates referred to in Article 3(1) shall be processed by the competent authorities of the Member State of destination or transit, or by the cross-border passenger transport services operators required by national law to implement certain public health measures during the COVID-19 pandemic, only to verify and confirm the holder’s vaccination, test result or recovery. To that end, the personal data shall be limited to what is strictly necessary. The personal data accessed pursuant to this paragraph shall not be retained.
Both are in the repo.
The check app validates the pass in-app, and, as far as I can tell, doesn’t phone home or report any data. IE there is no logging of the scanned persons data
Apps can also be configured to prohibit (or at least make it harder make) screenshots/screen-recordings. It can of course be circumvented, but still. It's illegal.
I would consider it as safe as showing my ID to a bartender/bouncer. Safer, even, as they don't get as much data.
* Famous last words, I know
And even if we don't have the need to check for our vaccination state when going to restaurants soon enough, it would be good if those certificates could be used to track any other vaccination you get. Just as the replacement or digital alternative for the usual yellow vaccination booklet. It would make checking your vaccination status for your doctor much easier than trying to decipher what a colleague has scribbled many years ago.
To exactly prevent this from happening.
Either way, the official apps that let you check the record do not allow tracking, only verification. The simple solution is that if you don't see them using the official app, simply leave.
So why are name and date of birth included in the QR code?
It'd be easy to make something that looks like the official app but does store the information, especially if that app is open source (is it?).
Basically even if they collected the data they wouldn't be able to use it. If they just collected your name to personalize your experience they'd be literally in deep shit if someone asked: "where did you get this information from?" - which to you may sound a weird question, but since 2018, at least in my country, more and more people ask this question.
When in doubt, report. They'd need to show to authorities that the person gave explicit consent to store that data and to be used for personalized experiences.
It's about consent. If the user didn't give consent you have no use for the data, and you'll be storing toxic material to get you fined.
this has never been a thing in any European country I've been in. Maybe if you look underage, but definitely not the norm.
(Twelve, I think.)