Clearview AI challenges B.C. privacy watchdog order
piquenewsmagazine.com
piquenewsmagazine.com
> What the commissioners recommended was that Clearview:
> • cease offering facial recognition services to Canadian clients;
> • cease collecting, using and disclosing images and biometric facial arrays collected from individuals in Canada, and;
> • delete images and biometric facial arrays collected from individuals in Canada.
> The company said those recommendations were impossible to execute.
Clearview claims that they have stopped selling to Canadian clients but they don't know where the people in the images are from. Probably true if they're just scraping images, but their argument seems to be "innocence by ignorance".
We don't usually allow that sort of argument in other areas. Stores cannot sell cigarettes/alcohol to minors and banks cant unknowingly launder money, and it is on them to make sure they collect enough data to comply with those laws. It may be hard or even impossible for Clearview to operate while following the law.. but maybe that just means they shouldn't.
This part of their defence is outright laughable. What's the point of having this sort of database without the associated metadata?
I'm not a fan of Clearview AI, but I understand it's still useful even for faces that aren't explicitly tied to an identity in the system, because the if the police know where the matched photo is from, they can do the legwork to fill in the missing details.
I think one of the examples in an early article about it had the police feeding a suspect's face into it. The system found a match in the background of some photo taken at a trade show (the guy was working a both). It only knew the website the photo was from, which allowed the police the identify the trade show, which allowed them to track down the people working at that booth to find their suspect.
In most cases they probably only know the URL, and it's far from trivial (or even possible in a general case) to mechanically derive if photo was taken in Canada from that.
Personally I hope they're forced to overshoot and delete far more than necessary to ensure compliance (e.g. only keep photos they can positively determine were taken outside of Canada).
Even if it's from a social network, you still can't be sure. Especially, if a photo have multiple persons.
" The system found a match in the background of some photo taken at a trade show (the guy was working a both). It only knew the website the photo was from, which allowed the police the identify the trade show, which allowed them to track down the people working at that booth to find their suspect."
With that said: the order is clearly impossible to execute. There's a huge difference between police clicking on a URL in a result and manually investigating to determine the location and having their system automatically determine the location of all photos and delete the ones that are in Canada.
It is clearly possible to execute, it would just require much higher costs per image that ClearView processes and the probable need for ClearView to avoid using any images that they can't verify the location of in am economical fashion.
Saying it is "impossible" is different from saying that the costs of compliance would fundamentally change ClearView's business model.
You don't need the Internet or AI to collate pictures and the data on them into a database.
If the answer is 100%, then yes, all user-generated content on the internet will have to be banned unless subject to manual human review before allowing the post to be seen, and even that is probably not perfect.
"if the police know where the matched photo is from"
The "matched photo" is the right argument in the function
match(photo_scraped_by_clearview, photo_of_interest)
The matched photo is some piece of evidence the police already have from some investigation, e.g. surveillance camera or whatever. They know exactly where they got it. This is matched against the Clearview AI database. So then that match attaches information to the Clearview AI photo. They may be able to figure out where that was taken, since it is narrowed down.How is this fundamentally different from Google image search? [0]
Did Clearview do something to be investigated? The commission essentially claimed they read about the company in the news and decided to act based on that. [1] It seems odd that haven't they investigated Google for the same. [2]
0. https://www.google.com/search?tbs=sbi:AMhZZivCGA7FJZHmFkT5r4...
1. https://www.priv.gc.ca/en/opc-actions-and-decisions/investig...
2. https://www.priv.gc.ca/en/opc-actions-and-decisions/investig...
You don't stop going after one criminal because there are others.
A government that governs without consent of the governed is illegitimate. A government that governs inconsistently is not necessarily illegitimate. The legitimacy of a government is not determined by any particular small-large business axis. Viewing the world through that axis is not helpful in this case.
And while we're at it, just because your government is unfair doesn't make it illegitimate. There are plenty of state governments[1] that were, and are incredibly unfair in their enforcement of their laws, but when they aren't actively stealing elections, I wouldn't call them illegitimate.
[1] For a crystal-clear example, the south under Jim Crow. Unfair laws, unfair enforcement of laws, but I'd be hard-pressed to argue that many of those governments did not have the consent of most of who they governed.
This is not exactly a mainstream viewpoint.
> For a crystal-clear example, the south under Jim Crow. Unfair laws, unfair enforcement of laws, but I'd be hard-pressed to argue that many of those governments did not have the consent of most of who they governed.
But in the other direction, it's trivially easy to argue that many major governments did not have the consent of the governed. e.g. the Qing dynasty was hated by the Chinese people it ruled.
The consent of the governed is not even a theoretically valid concept as applied to large groups. You rule through force.
My point is that it doesn't make much sense to contract the definition of legitimacy. At a minimum, if a government has the consent of the governed, it is legitimate.
If it does not, well, we can split hairs about whether or not being a warlord, a king, or some other kind of despot counts.
Fair enough, I suppose legitimacy is in the eyes of the beholder, which happens to be itself.
Of course, I also think we should make this business model illegal in any country. But that's a different thread.
BC and Clearview both have a point. But which jurisdiction is in play? Is it the one where the person lives or where the picture was taken? Was it the company that took the picture, one of a dozen networks in play, the one that transmitted it to a server, or the one that aggregated it into a database, or the one that sold the data? There could be 20 countries involved.
Laws really need to catch up to the tech which has far outpaced them.
It's easy to reconcile. If you want to operate in a jurisdiction, you are subject to that jurisdiction's laws, and legal injunctions. This is a very basic thing, on the level that a school-child can understand it. Just because you're operating using computers doesn't change a damn thing.
When a jurisdiction tells you that you can't operate in it, unless you change your behaviour, you either change your behaviour, or stop operating in it. Or keep operating, and be treated by it like a criminal. Or appeal.
If you don't like Canadian internet laws, don't do business in Canada. If you don't like Russian speech laws, don't do business in Russia, or plan a vacation in Leningrad. If you don't like Quebec language laws... Don't operate in Quebec.
You're not entitled access to every market in the world, if you can't comply with their rules. If the rules are contradictory, pick the ones you care about more.
What defines "operating"? Does it mean you are physically based there? Your infrastructure being there? Your company registration? Your bank account? Etc.
Back in the day these weren't problems in practice; for physical goods/services you typically were based in a single jurisdiction. If exporting goods, customs take care of it.
The internet has no "customs" equivalent though, so you can very well be based in one jurisdiction and yet process personal data of residents of another. Sometimes you may not even know where the data subject actually resides.
But that same picture should then not be used for that purpose in the EU where it's illegal.
It's not dissimilar to how public drinking in The Netherlands would get me drunk, but doing the same in Saudi Arabia gets me 100 lashes.
For globally distributed businesses governments can and will target payment processors.
> The internet has no "customs" equivalent though
We can thank regulators for not understanding this "computer" thing. This environment gave the industry 20 years of innovation. Nothing more depressing than dealing with custom and special snowflakes regulations (most of the time, to protect some local rent-seeker!).
In this case, BC can do whatever it wants, they have no jurisdiction. They might as well claim ownership of the moon.
If some aspect of an operation can be detained, expropriated, or extradited, now or in the future, then it operates in that jurisdiction. Otherwise it is just talk. Hence Assange is slowly on his way to the US; Snowden is just cold until the US has something to offer.
The jurisdiction decides, and you play by their rules... or leave
Whether or not I do any business with anyone controlled by the jurisdiction.
It's not a problem in practice.
I can host a website that pisses on Putin in the United States. I have no intentions of ever going to Russia. I don't rely on any Russian services. A Russian may visit it, because, well, Russia has access to the internet. I may be breaking Russian law, but I don't care, because I'm not operating in Russia. Russia can tell their ISPs to block me, or can ask for my host to cut me off. My host isn't likely to comply, because it too, is unlikely to have ties to Russia.
I put up an ad from a Russian company on it. I'm now operating in Russia, and Russia can shut that part of my business down, by forcing the Russian company to stop doing business with me. Once they do, I'm no longer operating in Russia.
Some jurisdictions reach further than others. Russia (or Canada) has jurisdiction over its corner of the world, and little else. The United States has jurisdiction over a very large part of the world, because a lot of businesses that I would partner with have an American presence, and will comply with American requests. China is somewhere in the middle. Its reach extends somewhat beyond its borders, but doesn't straddle the world.
If I start advertising my store in Saudi Arabia, or move my money into a Saudi bank, or visit their kingdom, then I'll have a problem. Because it can do something to me. It can tell my business partners to cut me off, or seize my money, or, in the latter case, arrest me as a drug kingpin.
Back in the early days this wasn't a problem in practice because internet-based entities were operating in good faith, so even if the legal landscape was murky, nobody had a need to resort to it. This has now changed as companies are now acting in bad faith doing things many find reprehensible, and a legal precedent and/or a change in law is needed to effectively deal with those bad actors.
I wonder what the major impetus for the change has been. Is it akin to having a million monkeys guided by money on computers, eventually one of them will write code enabling a fascist internet?
None of this is new, or specific to tech, this is just how companies try to end-run the law.
How exactly would you propose changing jurisdictional boundaries and/or rules? Subjecting people to more governments that are not the ones for the areas in which they're operating? Removing the ability for some local areas to have control over the business that occurs in it?
Certainly, they can prevent Clearview from doing business inside Canada. Maybe even from accessing Canadian servers (though that would be tricky to implement and enforce). But from using images posted by Canadians to international platforms? Doubtful.
That's a perfectly reasonable request.
Just like Google is not allowed to provide street view of certain locations due to local privacy laws. Exact same thing here.
Even worse: by being able to correlate that to Canadian individuals (using metadata or facial metrics, etc), the company can't pretend they don't know who these pictures are from, or where they come from: they know damn well, which makes the court requests limited scope even more acceptable.
Also, claiming to be ignorant of Canadian law may not be a good excuse. They should have known, if only to start doing business there.
Let's construct an equivalent: if in ISIS or Afghan territory, a terrorist group had scraped pictures of people living in the EU or US, and known by them to be "enemies of the caliphate" or something equivalent and that's it's totally A-OK within their legal system to publish that on a website say to call for their murder (I must confess my ignorance on these matters but you get the idea), we'd all say "no it's not". This is just the same. What's legal for us to do domestically with domestic pictures of citizens may not be legal to do somewhere else, and importing the pictures to do it domestically doesn't magically make it legal.
There is an area of customary international law that deals with the proper exercise of extraterritorial jurisdiction. Encyclopedia entry here (paywalled) https://opil.ouplaw.com/view/10.1093/law:epil/9780199231690/... Someone seems to have mirrored the first page of the entry here https://ilcfhuns.wixsite.com/ilcfhuns/single-post/2018/03/07...
A country that issues a judgment beyond the scope of its jurisdiction under international law is violating international law. There's no international police to come get you, but you're not operating by the rules of the road and foreign countries will start to look at judgments originating in your country with suspicion. If you aggressively enforce illegally extraterritorial judgments, such as by seizing the assets of foreign actors that are just passing through your company, you might even get into tit-for-tats with other countries.
Extraterritorial jurisdiction is not totally illegal, but there are limits and this would seem to be outside of those.
Having another countries court enforce a judgement is the exception, it usually only happens if there's a treaty to that effect (like with copyright law).
And it's simply not the case that foreign judgments are generally unenforceable. See the discussion here https://en.wikipedia.org/wiki/Enforcement_of_foreign_judgmen... . No treaty is necessary, though it certainly helps the person seeking enforcement if there is one.
Arguably, tech companies could just disregard GDPR, at the expense of all business, offices, and access to the European Union. However, if they want to continue to have that access, they need to comply with the EU's laws, even if someone could argue that those laws extend in dubious ways outside the borders.
The thing about national sovereignty, of which each EU member state has, and to some degree, the EU as a whole is capable of exacting, is that you can't decide whether you think their laws are reasonable or not, you can only decide if you're willing to comply in exchange for access to that market.
Bear in mind, the US literally tells people "you can't do business in Iran", and everyone accepts it, because the alternative of "you can't do business in the US" is way worse for business.
Customary international law is best thought of as widely accepted norms of fairness between sovereign states. There is no international police to come get you when you don't play nice, but staying within the dictates of international law generally protects you from accusations of unfair play and the consequences that can bring.
And yeah, the US maybe does violate international law in the specifics of its sanctions policies, though they are usually carefully crafted to only apply to people who somehow participate in the US financial/payments system. It's very possible that one day the US will pay the price for this overreach/maximalism when countries eagerly jump ship to an alternative international financial system, should a viable one emerge. But for now, the US is the only real game in town. The strong take what they can, and the weak suffer what they must.
PS: I have no intention of condoning the behavior of building censor networks like the GFW, but until there is some international court to adjudicate Internet jurisdiction cases, my prediction of the future is that there will be more and more countries adopting technological countermeasures and the Internet will be increasingly fragmented.
GDPR applies to individuals located in the European Union, and citizenship is not a factor. EU citizens have no GDPR rights while abroad, and conversely non-Europeans have GDPR protection while in the EU.
Don't they know the identities of the people whose photos they're scraping and storing? Thus, don't they know if those people are Canadian or not?
Or is Clearview just lazily scraping photos from the web etc. and storing whatever random username or pseudonym is attached to it, giving _that_ in search results? In which case, they should 1000% expect to be taken to task by jurisdictions all around the world for their gross overreach.
Wait, plus, isn't the very premise of their business just 99.99% pure IP infringement? They don't even have the legal right to use images posted online just because they're accessible. They are protected by copyright unless CC or public-domain licensed...
I'm not sure what the legal situation is exactly but it seems to be more complicated than that. The LinkedIn case appears to have determined that scraping public content is legal. I don't think you can redistribute it after that but I guess you can freely analyze it?
As to distributing (possibly even selling) the result of that analysis, see the GitHub Copilot controversy.
There are large OCR datasets of public domain books and old governmental records that come with a "no commercial use" clause. I'm not sure what the legality of feeding those in to an ML algorithm that gets used commercially is.
To regulators: "Where did all these pictures come from? It's impossible to say."
clearview claims they can’t determine if a picture was taken in Canada or if the subjects are Canadian—if this is true, then they likely can’t determine if they have any legal right to be using the images in the first place.
It seems to me that the diligence should absolutely fall on clearview to determine if they’re lawfully using these images in every jurisdiction. I know there are many jurisdictions around the world and each will have their own laws but I mean, come on, this is common practice for every company in existence. For them to claim “we can’t follow the laws” is absurd.
Google? Facebook? Microsoft? Any cell phone company? Most ISPs? Any of the CRAs? Any credit card company? Any major bank? About a thousand companies most people have never heard of? Palantir?
Checks article
> Clearview AI
OK. You really gotta specify in the headline. There are a lot of possibilities with that vague a description.
maybe CSIS should DDoS and/or otherwise destroy the company's IT? US Laws do not apply to them.
Does this seem silly, or deliberately obstructive?
I don't think Clearview AI has any employees in Canada, so what do they stand to gain from this lawsuit? Does that tiny startup have any customers of note there?
They could be the ones pushing Clearview to fight this in Canadian court.
On the other hand, the scraping/facial recogniton they do would also violate European privacy regulations, and it could be they feel a win in a similar case would come in handy if they ever decide to offer their services to European customers.
It's like public photography. Some folks get really upset if their photo is taken out in public without consent, but those folks were out in public so zero expectation of privacy. Same exact thing for the Internet.
Someone snapping a photograph of a busy street is one thing. Someone snapping a photograph of a busy street, with a focus on you, because you are doing something that looks inappropriate, out of context, is another. Someone following you around, taking video, from the moment you step out of your front door, to the moment that you step back through it is a third.
That someone can be a stranger who doesn't know or care that you exist, a private individual with a deranged vendetta against you, who has threatened you with harm[1], a company that does this on a massive scale and aggregates data, a company that does this on a targeted, personal scale, a government agency that is lawfully investigating a crime, a government agency that is unlawfully acting out of vindictiveness, a government agency that is lawfully acting out of vindictiveness...
None of these things are the same, nor do they warrant the same "Oh, well, it's a public space, nobody owns it, everyone can do whatever they want."
It's a public space. We all own it. We all get to determine what kind of behaviour is acceptable, and unacceptable in it.
The solution to predators and bad actors in a public space is not expecting that everyone who can afford it move more of their life into a private one. That's how we lose our public spaces.
[1] Depending on your jurisdiction, you may not have any particular recourse against that. Some locales really don't like handing out restraining orders... Or enforcing them, when they are broken.
* What about looking at people with one's own eyes, without the express consent of other people?
* What about people with photographic memory, who are effectively walking cameras?
* What about artists who draw pictures of people they see in public?
Where does this nonsense ever end? While the question is hyperbolic, and I apologize, that's intentional use of the "Reducto absurdum" fallacy to help illustrate the absurdity of this kind of idea.
You can photograph people in public all you want, but you cannot publish those without their permission.
Blurring or the people not being in focus/center can allow you to do so without getting everyone's permission though (think of crowds, passersby in the background).
I wonder if someone could argue that using their photo as training data could make the model itself a derivative work? iirc those require royalty/license too.
Why would anybody have an expectation of privacy from aerial vehicles far above?