5 ms·
Google Sued Under Illinois Biometric Information Privacy Act
- lmkg 7y agoTo save y'all a click: The alleged biometrics in question are the use of facial-recognition software on photos uploaded to Google Photos (without informed consent from the user).
- rygxqpbsngav 7y agoI remember google popping up a consent to store the AI models for the facial recognition locally on my phone (not in the cloud)! If this is the case, the lawyers are wasting their time, I guess.
- bogwog 7y agoI've never received a popup like that, nor ever heard of anyone receiving one. Are you in Illinois?
- rygxqpbsngav 7y agoUK. I recently bought a new phone and when I opened google photos app for the first time, it asked to store local trained models to enable AI features for the app.
- advisedwang 7y agoThat gets the event of the person who's phone it is, not the people in the photos.
- rickncliff 7y agoProfiteering lawyers as middlemen to technology application is what these overly strict privacy laws are trying to establish and that's a shame.
- dmitryminkovsky 7y agoThat’s what all this stuff inevitably becomes unfortunately. It’s a shame that lawyers have to mediate our access to our rights. I sincerely believe if we replaced high school with law school we’d all be much better off.
- rayiner 7y agoThe barrier here isn't really the need for a law degree. Prosecuting these kinds of cases against deep-pocketed defendants like Google doesn't only take expertise in the law, but the resources to review millions of pages of Google emails to establish how the system works and what Google's intentions were, as well as experts to opine on technical aspects as well as calculation of damages. There is no practical way for individuals without significant resources to prove up this sort of case on their own. The realistic alternative is having government agencies prosecute these sorts of cases. It's a very good alternative, and is used in most other countries. It's an odd confluence of factors that results in private class action litigation being more popular in the U.S. (From the left, trial lawyers are major supporters of Democrats. From the right, Republicans would rather have these class actions than new government agencies.)
- dmitryminkovsky 7y ago> The realistic alternative is having government agencies prosecute these sorts of cases. I wasn't saying the result would be that we each tend to our own legal matters instead of having regulatory agencies. I was saying that when only a tiny fraction of the citizens is legally literate, and only a small fraction of those people are actual trained lawyers, not many people are going to be looking out for our rights, muchless even know what those rights are or should be.
- asdfasgasdgasdg 7y agoWhose consent is needed, according to the law? The person who took the photos, or the person being photographed? And is the consent required only if the product is used in Illinois? Or if the photo is taken in Illinois? Or if the person photographed is a resident of Illinois? (I read the law, and it appears to cover the person being photographed, if the photograph is taken in Illinois. So basically according to the law Google ought not build face models from photographs taken in Illinois, except of people who have consented.) I wonder if in the broadest configuration (basically any configuration other than "consent of the user, who is a resident of Illinois"), this law would probably be struck down as an unconstitutional restraint on interstate commerce? I guess we'll see! Should be exciting.
- deleted 7y ago[deleted]
- voxic11 7y agoBIPA requires the consent of the person that the biometrics identify. However it specifically excludes photographs from the definition of biometric information so its not clear how it applies in this case.
- lmkg 7y agoIt excludes photographs, but includes certain data derivable from photographs. Storing the photograph is not a violation, but the lawsuit alleges that the facial recognition software that Google runs constitutes a violation.
- rahuldottech 7y agoIf a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.
- dgellow 7y agoHow do you even start to write a law for something like this? And I mean a law that makes sense and takes in account the reality of the situation, not one used as grandstanding. It becomes really messy really fast. A law is established at some local level (local to a borough, state/canton, country), it will surely contradicts with laws from other places while overlapping with them. From a very abstract view, companies will need to identify the person uploading the picture, the person in the picture, somehow determine which law to follow in the given circumstances (which depends on the context), determine if a consent exists at the correct local level for each person in the picture, then and only then they can train a model.
- shadowgovt 7y agoCorrect. And the answer is "You don't," and it doesn't appear BIPA should cover the situation in question.
- dgellow 7y agoJust to be sure, are you saying that "you don't create such a law", or "you don't train models on human faces"?
- shadowgovt 7y agoIn the sense of covering photographs in general, you don't create such a law. It's completely impractical to enforce (since photographic capture of faces is already ubiquitous in American society). One could, hypothetically, make a law against training models on human faces. Good luck crafting that carefully enough to enforce it without undesired consequences (did we just ban training doctors on how to recognize stroke victims, or---worse---ban someone from making an automatic stroke detector that could be run on incoming patients in an ER to accelerate them to the front of the line?), but it's a better starting point than banning photographic collection of data.
- shadowgovt 7y agoThis lawsuit seems dead on arrival. From the article (emphasis my own): """ The suit alleges that Google is violating BIPA because it is “actively collecting, storing, and using—without providing notice, obtaining informed written consent or publishing data retention policies—the biometrics of millions of unwitting individuals whose faces appear in photographs uploaded to Google Photos in Illinois """ From the text of the BIPA law (again, emphasis my own): """ Biometric identifiers do not include writing samples, written signatures, photographs... """ This interpretation of BIPA would seem to require complex written consent for every corner store running a security camera and every wedding photographer, which clearly isn't the intent of the law. Since the law explicitly carves out photographs, the use to which Google is putting the material in question should be irrelevant; it's explicitly excluded from this law's coverage.
- throwaway_tech 7y ago>""" Biometric identifiers do not include writing samples, written signatures, photographs... """ BIPA specifically includes facial geometry scans obtained through photographs...so a photo on its own may not fall under BIPA, but once Google begins to obtain the facial geometry scans from the photos that is covered by BIPA. Edit: the penalties are: For negligent violations, individuals can recover the greater of $1,000 or their actual losses. For reckless violations, the baseline award increases to $5,000. Seems to me at a minimum this is reckless if not intentional, and I should expect to see Google try to settle this before that get smacked with $5k penalty per violation times millions of (alleged) violations.
- voxic11 7y agoI have to point out that his exact argument has been made and rejected by the courts in multiple cases already. > Shutterfly maintains that by excluding data derived from photographs from the definition of “biometric information,” the Illinois legislature intended to exclude from BIPA’s purview all biometric data obtained from photographs... As Shutterfly acknowledges, if biometric identifiers do not include information obtained from images or photographs, the definition’s reference to a “scan of face geometry” can mean only an in-person scan of a person’s face. Such a narrow reading of the term “biometric identifier” is problematic in many respects... The definition of ‘biometric identifier’ does not use words like ‘derived from a person,’ ‘derived in person,’ or ‘based on an in-person scan,’ whereas the definition of ‘biometric information’ does say that it is information ‘based on’ a biometric identifier.”); The Illinois General Assembly clearly sought to define the term “biometric identifier” with a great deal of specificity: the definition begins by identifying six particular types of biometric data that are covered by the term (i.e., retina or iris scans, fingerprints, voiceprints, scans of hand or face geometry); it then provides a long list of other specific types of biometric data that are excluded from the definition. If the legislature had intended a “scan of face geometry” to refer only to scans taken of an individual’s actual face, it is reasonable to think that it would have signalled this more explicitly. https://www.courthousenews.com/wp-content/uploads/2017/09/ShutterflyRuling.pdf https://www.courthousenews.com/wp-content/uploads/2017/09/Sh...
- tonymarks 7y agoWe have a large client/customer in Illinois who has decided against using our voice sdk in their iOS/Android app because of the fear of getting sued for BIPA violation. It's not that they think we're creating voice prints without consent, it's just that their legal team has warned them that if they get sued, it could be very costly to defend. We even changed our privacy policy to note that "biometrics" are not obtained, and even went to on-device speech recognition apis provided by Google and Apple.
- ocdtrekkie 7y agoWhat about using truly on-device options that aren't connected to cloud services at all? Picovoice, DeepSpeech, etc.?
- deleted 7y ago[deleted]