This article is written by Rosalind Kennybirch, Consultant covering tech policy, Lexington Communications


As Black Lives Matter protests have swept countries across the world, activists have highlighted the ways discrimination embeds itself in various facets of society, including in the technology sector.

Facial recognition technology is sometimes purported to be a useful tool which can help law enforcement bodies solve crimes more easily and quickly. Others have asserted that the software has the potential to benefit consumers more widely, for example by applying the software to payments authentication (ensuring only the facial ID linked to a bank account can serve as an approval for a payment).

However, several studies have shown that the technology is less accurate at correctly identifying individuals with darker skin, giving it the potential to be weaponised as a tool of discrimination. Worryingly, individuals also may not be aware that their face has been uploaded into a company’s software system, therefore depriving them of the opportunity to grant consent.

Countries are taking different approaches to facial recognition technology, both in its application and in regulating its usage. While there are clear benefits to the software, cities and nations are discovering that these may come at an unacceptable cost to people’s right to privacy and safety. Last year, San Francisco became the first major American city to ban the use of facial recognition software by the police and other agencies.

Cases from the United States, Brazil and Australia help explain why governments and companies alike have flocked to this new technology, but also reveal the pitfalls and privacy headaches that are likely to only worsen in the years ahead.

Facial Recognition Technology in the United States: 20 minute cases and 35% misidentification

Police forces across the United States have been testing facial recognition technology to assess its potential to solve cases more quickly.

In February 2019, the Indiana State Police trialled facial recognition software from Clearview AI, an American tech company, and were able to solve a shooting case within 20 minutes of using the app. A former Indiana State Police Captain, Chuck Cohen, explained the perpetrator “did not have a driver’s license and hadn’t been arrested as an adult, so he wasn’t in government databases”, asserting that the force likely would not have been able to identify the offender without the ability to search social media for a facial match. The force became Clearview’s first paying customer.

Facial recognition software can be used to help citizens, but without proper consent, the use of this technology can breed distrust

However, accuracy errors within the technology risk misidentification and have the potential to implicate innocent people. In a M.I.T. study on facial recognition software, Researcher Joy Buolamwini found that if a person in a particular image is a white man, software correctly identifies the individual 99% of the time. But Buolamwini also discovered that the amount of identification errors increased for people with darker skin, by almost 35% in photos of darker-skinned women. A more recent study from the US Department of Commerce, published in December 2019, concluded that when using higher quality application photos in facial recognition software, “false positive rates are highest in West and East African and East Asian people, and lowest in Eastern European individuals [and] this effect is generally large, with a factor of 100 more false positives between countries”. While police forces in the United States have asserted the benefits of the software, including Cohen, these studies signal that the high rate of misidentifications poses an unacceptable risk to minority groups.

Facial Recognition Technology in Australia: A controversial lifeline

Facial recognition technology, including from Clearview AI, has also been controversially used in Australia. Following forays into the Australian market from Clearview, the Australian Privacy Commissioner Angelene Falk launched an inquiry into the company to ascertain the details of its usage.

Australian Privacy Foundation Surveillance Committee co-chair Dr Monique Mann asserted that the fact Clearview is being used in Australia is worrying, explaining “facial recognition is really dangerous because it collects biometric information, which is sensitive personal information…it enables tracking through public places and identification in public places, and we already have a widespread surveillance system that supports this in CCTV”. It was subsequently revealed that several police forces were using Clearview’s software, but had initially denied this.

Australia has also deployed facial recognition software to assist people who lost key documents as a result of recent bushfires. When the bushfires ravaged the country last year, the country’s national facial biometrics matching database was instrumental in verifying the identities of people who had lost their personal documents. Services Australia Deputy Chief Executive Michelle Lees explained that a webcam was set up to take photos of people who no longer had their documents. Upon consent, the photos were then compared with images from passports, visas and driver’s licenses. Lees said the matching process “involved, firstly, explaining to the person that was making the claim what the face verification service meant…there were a small number of instances where the individuals did not give consent, and so we went through the usual proof of identity mechanism for those individuals”.

Organisations using facial recognition software are not always securing user consent before deploying the technology. This is a breach of data protection laws in many countries and raises questions about human rights

Lees confirmed the agency is exploring how the technology could be utilised in the future. The experience of Australia demonstrates that facial recognition software can be used to help citizens, but without proper consent, the use of this technology can breed distrust.

Facial Recognition Technology in Brazil: Aiding or exploiting the consumer?

Facial recognition software is not exclusively being used by public sector bodies: the private sector is also working to harness its potential.

The Brazilian bank Banco Original and the digital wallet app PicPay plan to launch a large-scale facial recognition system for payments authentication by December 2020. Brazil’s General Data Protection Law (LGPD), which is expected to come into force in the country next year, prohibits facial recognition from being carried out unless an individual has consented. The bank is therefore taking careful steps to comply with data protection law. A café at Banco Original’s headquarters in São Paulo is the first place the technology will be tested and in order to comply with the law, the bank has requested permission to trial the software from approximately 2,000 customers.

Despite some companies’ steps to harness the potential of facial recognition technology, there is still significant controversy over the software in Brazil. In 2018, the Brazilian Institute of Consumer Protection (IDEC) took the decision to sue São Paulo Metro operator ViaQuatro for launching the Digital Interactive Doors System for crowd analytics, developed by AdMobilize, a US company. The system consists of interactive doors which display ads — cameras in the doors allow them to identify human faces and analyse emotion, gender and age while people are viewing the ads. A ruling on the case has not yet been made. The work of ViaQuatro, as opposed to Banco Original, again demonstrates the importance of gaining user consent in undertaking projects which use facial recognition software.

What’s next for facial recognition software?

While facial recognition technology has the potential to benefit consumers, it also poses key risks to the public.

Firstly, the technology itself can misidentify individuals. This has the potential to result in people being wrongly accused of crimes, particularly when the software is used by police forces.

Secondly, organisations using facial recognition software are not always securing user consent before deploying the technology. This is a breach of data protection laws in many countries, but more broadly, it raises questions about human rights, including an individual’s right to privacy. As the public and private sector alike explore uses for facial recognition technology, they must bear in mind the severe consequences which could arise if the public is not consulted. — Rosalind KennyBirch

(Picture credit: Unsplash)


Make sure to share your own thoughts with the author by leaving a comment below