Facial recognition — what is acceptable?
Be able to reason about when recognising people is acceptable and when it is not.
Prerequisites
Everyday explanation
Facial recognition is used for very different things, and the difference matters a great deal.
Two completely different questions:
| Verification | Identification | |
|---|---|---|
| The question | «is this the same person as in the picture?» | «who is this person?» |
| Compared against | one picture | a register with many |
| Example | unlocking your phone | finding somebody in a crowd |
| You know about it | yes, you chose it | usually no |
| The risk | low | high |
Unlocking your own phone with your face is your own choice, against a picture you registered yourself, which stays on the phone.
Being recognised by cameras in town is something else entirely: you did not choose it, you do not know about it, and you cannot opt out.
The question is not «is the technology good?» but «who has chosen, and what happens if it is wrong?»
Intuition
Three things that decide whether it is acceptable:
| The question | Why it matters |
|---|---|
| Has the person chosen it freely? | consent under pressure is not consent |
| What happens if the system is wrong? | a wrongful unlocking is one thing, a wrongful accusation another |
| Who has the power? | a pupil cannot say no to the school the way they can to an app |
The third is the decisive one in a school context. Sweden has a concrete case: an upper-secondary school in Skellefteå tested facial recognition for attendance checks in 2019. The school had collected consent from the guardians. IMY, the Swedish data protection authority, still issued a fine — among other things because consent cannot be free when it is the school that is asking, and because attendance can be checked in considerably less intrusive ways.
Two principles from that case:
- Consent requires an equal balance of power. If you cannot say no without consequences it is not consent.
- Proportionality. If there is a less intrusive way of reaching the same goal it should be used.
That the system is wrong at different rates for different groups makes it worse. Research has shown considerably higher error rates for dark-skinned women than for light-skinned men in several commercial systems — which means that those who already have the hardest time are also hit worst by the errors.
The EU AI Act counts remote biometric identification in public spaces as prohibited or heavily restricted, and emotion recognition in schools as prohibited.
Questions to ask when somebody proposes facial recognition:
| # | The question |
|---|---|
| 1 | Which problem does it solve? |
| 2 | Is there a less intrusive way? |
| 3 | Can the people concerned say no without consequences? |
| 4 | What happens when it goes wrong? |
| 5 | Does it work equally well for everybody? |
| 6 | Who has access to the pictures, and for how long? |
Interactive
Discuss six cases in a group. Judge each as acceptable, doubtful or not acceptable — and justify it.
| # | The case |
|---|---|
| 1 | You unlock your own phone with your face |
| 2 | The school uses facial recognition for attendance |
| 3 | A shop recognises people who have shoplifted before |
| 4 | The police look for a wanted person in cameras at a station |
| 5 | An app sorts your own holiday pictures by who is in them |
| 6 | A company recognises customers in order to give personal service |
Things to weigh in each case: Who has chosen? What happens on an error? Is there a less intrusive alternative? Who has the power?
Comments after the discussion:
- Acceptable — your own choice, your own device, verification against a picture of your own.
- Not acceptable according to IMY's decision — consent is not free in a school, and attendance can be checked more simply.
- Very doubtful — identification without consent, with serious consequences on an error, and a risk of the wrong people being singled out.
- Heavily regulated — it can be permitted in certain serious cases with a legal basis, but is sharply restricted in the EU AI Act.
- Usually acceptable — your own pictures, on your own device, you chose it. But: the other people in the pictures have not chosen.
- Doubtful — the customer has rarely chosen, and the benefit is small compared with the intrusion.
Case 5 is the one that usually surprises people. Even when you use your own pictures there are other people in them, and they have not given their consent to being facially recognised.
Finish with the question: where is your own line, and what would have to be true for you to move it?
Mastery means
- Distinguishes verification from identification
- Reasons about consent and the balance of power
- Knows the Swedish rules and cases
Sign in to do the exercises and build your mastery up.
Sources
- IMY — Integritetsskyddsmyndigheten — myndighetsmaterial
- EU AI Act (2024/1689) — EU legal act
- Buolamwini & Gebru — Gender Shades — PMLR open access