- you can record all manner of video in your store...
- but you can't process it in this particular way.
- you can record all manner of video in your store...
- but you can't process it in this particular way.
Similarly it seems reasonable that shops should be able to record for some purposes but not all.
I don't think it does, because it is completely unverifiable. It's like allowing people to buy drugs, but not to use them.
I'm not worried about people collecting IPs, I'm worried about people who collect IPs being able to send those IPs out and get them associated with names, and send those names out and be supplied with dossiers.
When they start putting collecting IPs in the same bag as the rest of this, it's because they're just trying to legitimize this entire process. Collecting dossiers becomes traffic shaping, and of course people should be allowed to traffic shape - you could be getting DDOSed by terrorists!
edit: I'm not sure this comment was quite clear - it's 1) the selling of private, incidentally collected information by service providers, and 2) the accumulation, buying, and selling of dossiers on normal people whom one has no business relationship that is the problem. IPs are just temporary identifiers, unless you can resolve them through what are essentially civilian intelligence organizations.
Like, I thought a big part of why some stores do loyalty cards is because they enable tracking things that they'd get their credit card privileges revoked if they tracked that way.
Well, since you mention it: I have prescription drugs that I am allowed to buy, but I am NOT allowed to abuse them. I must take exactly 1 each day.
Thus I’m regularly allowed to buy drugs I’m not legally allowed to use. “Using a prescription medication that was not prescribed to you is illegal under both federal and state laws.” https://legalclarity.org/is-it-illegal-to-use-someone-elses-...
But this is exactly what is covered - incidentally collected information cannot be used for other purposes. That's rather the point - you must collect things for a specific use case and you can't use it without permission for other cases.
> I don't think it does, because it is completely unverifiable.
It's no less verifiable than "don't collect the data", and hiding it requires increasingly larger conspiracies the larger organisation you are looking at. People are capable of committing crimes though, sure.
And less restricted does not mean no restriction.
I have data on Google. Google has a TOS that says they can use my data. This could cover even future use cases, even though those future use cases I did not anticipate. So does Google have the right to use my data in this particular way?
It's seems silly to me that you can have a human being eyeball someone and claim it's so and so, but you can't use incredibly accurate technology to streamline that process.
I personally don't like the decay of polite society. I don't like asking a worker for a key to buy some deodorant. Rather than treat everyone like a criminal, why don't we just treat criminals like criminals. It's a tiny percentage of people that abuse polite society and we pretend like it's a huge problem that can only be attacked by erecting huge inconveniences for everyone. No, just punish criminals and build systems to target criminals rather than everyone. If you look at arrests, you'll see that among persons admitted to state prison 77% had five or more prior arrests. When do you say enough is enough and we can back off this surveillance state because we're too afraid to just lock up people that don't want to live in society.
https://mleverything.substack.com/p/acceptance-of-crime-is-a...
For instance, Costco has a much lower theft rate (0.11–0.2% of sales) compared to other supermarkets (1-4%) simply because they manage to keep criminal out through membership fees. Control the entrance, target the known criminals and we can go back to a high trust society.
We are all potential criminals under tomorrow's government. Remember that!
The root comment is precisely right. Deriving data from filmed content -- the illusory private biometric data that we are leaving everywhere, constantly -- is what the purported transgression was.
Me. Unless it's clearly stated outside. It's why I wear a covid mask when shopping.
At best it degrades overall recognition but doesn't fully prevent it
Why are they covid masks anyway? Medical personnel wears them during surgery, and there were those photos of ... some asian people i think ... wearing them outdoors to protect themselves from air pollution in their city too.
Because the world is bigger than just the wishes of private businesses. I don't think there is anywhere on this planet where you as a private business can do literally whatever you want, there are always regulations about what you can and cannot do. The first thing is usually "zoning" as one example, so regardless if you own the land, if it isn't zoned for industrial/commercial usage, then you cannot use it for industrial/commercial usage.
What libertarian utopia do you live in that would allow land owners to do whatever they want?
The Australian Privacy Act falls well short of European standards, but it does encode some rights for people that businesses must abide by.
Unless you think a grocery store should be allowed to grab you and sell your organs then you agree that this private organisation should be subject to some limitations about what it can do on its own land. The question is then where the line should be between its interests and the interests of those who go on the land.
You can be absolutist about this, that’s certainly a position, but it’s extremely far from mainstream.
It generally owns more weapons than your average deluded shop owner.
The specific difference is "sensitive information". General filming with manual review isn't considered to be collecting privacy sensitive information. Automatic facial recognition is.
The blog post makes this point about how the law is applied:
> Is this a technology of convenience - is it being used only because it’s cheaper, or as an alternative to employing staff to do a particular role, and are there other less privacy-intrusive means that could be reasonably used?
https://www.oaic.gov.au/news/blog/is-there-a-place-for-facia...
Say I implement facial recognition anti-fraud via an army of super-recognizers sitting in an office, watching the camera feeds all day (collecting the sensitive information into their brains rather than into a computer system). It'd be more expensive and involve employing staff (both the "technology of convenience" criteria. From a consumer perspective the privacy impact is very similar, but somehow the privacy commissioner would interpret this differently?
Maybe that is the point the privacy commissioner is trying to make, that collecting this information through an automated computer system is fundamentally different than collecting this information through an analog/human system. But I'm not sure the line is really so clear...
At some point the numbers get big enough that you wouldn't be able to get the pictures of faces in front of the people who would recognize them fast enough.
But is a non-indiscriminate, privacy friendly solution possible? The problem is people walking in with a valid receipt for a purchased item, grabbing a matching item off the shelf, and wandering over to the returns counter and requesting their money back. The usual solution most shops use is locating the returns counter past the security controls (checkout counter). But more and more of these types of stores are putting their service counters in the middle of the store for some reason.