Some of the stuff you listed under “in-store analytics” is more like “in-store statistics”, the kind of privacy problems addressed by this bill/proclamation don’t seem related to analyzing CCTV footage to optimize store layout or determine which products are popular, and it doesn’t seem like either the reporting or the politicking here is concerned with that. If they are
then taking that information and trying to tie it to an identity based on credit card purchases, I do agree that’s gross and I wouldn’t object very hard if governments tried to stop that from happening (though I’m skeptical that facial recognition is doing much of the work in this paradigm, and I’m also skeptical that it works at all - most of this “know your customer” stuff is compelled by regulatory compliance, and the other stuff that is sold as improving conversion tends to be vaporware that fails to materialize real benefit).
>If an image … is used in the process to identify a person, then you are doing facial recognition
This is an easy definition of facial recognition that is very hard to ban! Police departments are doing facial recognition to catch criminals by this definition, and I don’t mean this in some narrow technical “well actually” sense: I mean that e.g. detectives in metro cities are given large binders of face pictures of many pickpockets and other criminals, they study these faces and train to recognize them in a crowd, and they go out in public aiming to recognize them. But my point was not that facial recognition is hard to define, my point was that “facial recognition technology” and “private facial recognition databases” and “predictive policing” are weird categories or distinctions to make.