This is not true for the proposed age verification schemes for the internet and that is a big problem. Unless this is solved, these schemes deserve every level of resistance we can muster.
This is not true for the proposed age verification schemes for the internet and that is a big problem. Unless this is solved, these schemes deserve every level of resistance we can muster.
Not well-designed ones. I think you overestimate how much retailers want to even possess sensitive information like that.
What's going to be stored is the fact that an of-age ID was scanned, and possibly the DOB. This is to protect honest cashiers and to have a way to punish ones who might sell to the underage. If an underage sale is reported, they check the audit log and it says the transaction had an ID scanned the cashier can be cleared of wrongdoing. Unless it's the same DOB always being scanned, which seems like some kind of dishonesty.
I do not buy that the supermarket chain wants to use your ID card data for any purpose. First of all, they don't need to, they have (most people's) loyalty cards that do a much better job as they're swiped or entered even without buying any beer. Second, again, only downsides come from saving it. If they were to sell the data and be caught, terrible. If they were to get hacked, terrible.
It's a several hundred billion dollar industry, in the US alone. Retail is definitely a source: https://market.us/report/data-broker-market/
Someone was on here a couple of years ago stating that even "line item" level data on your receipt is now being transmitted in a lot of cases, and growing.
The bottom line today—never expect a company to default to respect of your privacy. Simply too lucrative.
The store isn't tying your drivers license number and specific DOB to your purchases because you show an ID to buy beer -- that's a different kind of data and carries with it way too much potential for identity theft. Thinking that they want that is tinfoil-hat thinking. You can ask every single supermarket company if they do that and every one will tell you no. You can ask the companies which make the POS software if the scan ID functionality ties into data brokers and they'll say no. But go ahead and think that there are like 15 Fortune 500 companies all secretly doing this, even though not a single whistleblower has ever come forward. Of every engineer at those companies, I am not aware of anyone who has alleged this from a position of actual knowledge.
Pot industry needs to anonymize their customer records or stop using SaaS packaged solutions.
Now if China hacks Meadows or something, they have customer and purchase lists which may include security cleared personnel who can now be blackmailed.
If you run a pot shop, or an SaaS solution for them like Meadows, you really have to figure out how to divorce customer PII from purchases.
I am back to the black market in Oregon for this reason!