University vending machine error reveals use of secret facial recognition | A malfunctioning vending machine at a Canadian university has inadvertently revealed that a number of them have been usin…::Snack dispenser at University of Waterloo shows facial recognition message on screen despite no prior indication
Well this absolutely wouldn’t fly in the EU with GDPR
Can you lot in the states do something about your weird corpocracy, it’s looking a bit dystopian
Bad news, the manufacturer is located in Switzerland and, as stated in the brochure, they advertise their product as “Made in EU”. Probably to implicate that any data which will be collected and processed will be under the terms of GDPR.
I haven’t looked up the terms regarding GDPR, but I assume that their data collection is somewhat “compliant” with GDPR, which does not necessaryly mean anything. It can just mean that data is not stored locally, albeit it will be send to the manufacturer (but probably entcrypted). However, under GDPR you can enforce your right of deletion of the collected data - that is, if you know that data about you has been collected.
What makes this issue so severe is that it would have never been detected that data has been collected and processed, if it weren’t for a malfunction.
Edit: grammar, spelling
Under GDPR you also need explicit consent for data collection, right?
Correct. The said vending machine was collecting data without users consent. And because it was facial recognition data it means that the collected data can be tied to an individual.
It would have been different if the collected data was just a counter which indcated the number of users of that machine. These kind of data could not have been tied to a specific individual.