Clearview AI fined millions in the UK: No 'lawful reason' to collect Brits' images
- Reference: 1653304629
- News link: https://www.theregister.co.uk/2022/05/23/clearview_ai_ico_fine/
- Source link:
The company, which is headquartered in New York, claims to have over 20 billion facial images on its databases, mostly [2]culled from YouTube, Facebook, and Twitter. Clearview AI has developed a facial recognition tool – which it is [3]attempting to patent – that is trained on these images. The tool attempts to match faces fed into its machine learning software with results from its enormous image database, which it claims is the largest of its kind "in the world" and which it sells (to law enforcement bodies, among other clientele) across the globe.
The move from the Information Commissioner's Office (ICO) comes after an [4]investigation launched [5]in 2020 in conjunction with the Australian Information Commissioner to see if Clearview had breached the Australian Privacy Act or the UK Data Protection Act 2018.
[6]
Handing [7]down a fine that is less than half of the £17 million+ ($21.3 million+) originally [8]envisaged , the ICO also said it was not impressed that the company had no "process in place to stop the data being retained indefinitely."
[9]Bosses using AI to hire candidates risk discriminating against disabled applicants
[10]Clearview AI promises not to sell face-recognition database to most US businesses
[11]Research finds data poisoning can't defeat facial recognition
[12]Clearview AI plans tech to ID faces as they age, seek big government deals
[13]Clearview's selfie-scraping AI facial recognition technology set to be patented
In addition to the fine, the selfie-scraper was also slapped with an enforcement notice ordering it to stop collating the data and delete all information of British residents from its systems.
In defense of its business model, Clearview AI's boss has previously [14]said that the images, mostly uploaded by the data subjects themselves, were publicly available, and that it didn't see why it couldn't collate and search them, comparing its actions to that of web search giant Google. CEO Hoan Ton-That remarked at the time: "If it's public and it's out there and could be inside Google's search engine, it can be inside ours as well."
[15]
[16]
John Edwards, UK Information Commissioner, said of the action:
Clearview AI Inc has collected multiple images of people all over the world, including in the UK, from a variety of websites and social media platforms, creating a database with more than 20 billion images. The company not only enables identification of those people, but effectively monitors their behavior and offers it as a commercial service. That is unacceptable. That is why we have acted to protect people in the UK by both fining the company and issuing an enforcement notice.
The ICO found it had had breached UK's GDPR by "failing to meet the higher data protection standards required for biometric data" (classed as "special category data" under the GDPR and UK GDPR); failing to use the info in a way that is "fair and transparent"; failing to have a lawful reason for collecting it; and failing to have a process in place to stop the data being kept "indefinitely."
Finally, the ICO said the company had illegally requested "additional personal information" (including photos), when members of the public approached it to ask if they were on their books – presumably to check against images it already has. "This may have acted as a disincentive to individuals who wish to object to their data being collected and used," noted the regulator.
Privacy and cyber lawyer James Castro-Edwards, of law firm Arnold & Porter, said of the ation: "The GDPR (and the UK GDPR), which will be four years old this week, includes a number of specific requirements in relation to new technologies such as AI, which process personal data.
[17]
"As with any other processing activity, companies must ensure these systems comply with the principles, such as lawfulness, fairness and transparency, as well as those of privacy by design and by default."
We have asked Clearview AI to comment and will update when it responds. ®
Updated to add on May 23:
[18]
Clearview AI provided a statement from Lee Wolosky, a partner at Jenner and Block, who said: "While we appreciate the ICO's desire to reduce their monetary penalty on Clearview AI, we nevertheless stand by our position that the decision to impose any fine is incorrect as a matter of law.
"Clearview AI is not subject to the ICO's jurisdiction, and Clearview AI does no business in the UK at this time."
The company's CEO, Hoan Ton-That, also provided a statement, saying he was "deeply disappointed that the UK Information Commissioner has misinterpreted my technology and intentions. I created the consequential facial recognition technology known the world over. My company and I have acted in the best interests of the UK and their people by assisting law enforcement in solving heinous crimes against children, seniors, and other victims of unscrupulous acts."
Get our [19]Tech Resources
[1] https://www.theregister.com/2021/11/30/uk_clearview_fine/
[2] https://www.theregister.com/2020/01/20/ai_roundup_clearview/
[3] https://www.theregister.com/2021/12/11/in_brief_ai/
[4] https://www.theregister.com/2021/11/03/uk_australia_clearview_probe/
[5] https://www.theregister.com/2020/07/09/clearview_privacy_stop/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Youvp5-OEdnmrxiazVxe5wAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2022/05/ico-fines-facial-recognition-database-company-clearview-ai-inc/
[8] https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2021/11/ico-issues-provisional-view-to-fine-clearview-ai-inc-over-17-million/
[9] https://www.theregister.com/2022/05/14/recruitment_ai_disabled_discrimination/
[10] https://www.theregister.com/2022/05/10/clearview_ai_alcu/
[11] https://www.theregister.com/2022/03/15/research_finds_data_poisoning_cant/
[12] https://www.theregister.com/2022/02/28/in_brief_ai/
[13] https://www.theregister.com/2021/12/11/in_brief_ai/
[14] https://www.cbsnews.com/news/clearview-ai-google-youtube-send-cease-and-desist-letter-to-facial-recognition-app/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Youvp5-OEdnmrxiazVxe5wAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Youvp5-OEdnmrxiazVxe5wAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Youvp5-OEdnmrxiazVxe5wAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Youvp5-OEdnmrxiazVxe5wAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://whitepapers.theregister.com/
Re: Please fine them until the pips squeak.
And keep on doing it until the data is removed.
The problem for Clearview is that this will probably mean re-creating their databases from scratch from the new input datasets (with removed images), which is a huge amount of processing work, assuming they iteratively add new images over time.
And yes, people giving personal images to Google/Facebook does not mean they ever consented to this use which is very different from why people upload to social media.
And also why we shouldn't upload to social media, unless we have locked things down massively, which unfortunately the social media businesses don't want to make easy.
As good as a win as this is...
I can see clearview trying to resist this with a "how are we supposed to know who's British?"
Re: As good as a win as this is...
They'll know, they've been training the AI with our data after all
Re: As good as a win as this is...
"The question of whether computers can think is like the question of whether submarines can swim." - Edsger W. Dijkstra
Re: As good as a win as this is...
Yeah, I don't think that's going to fly. It's their problem. If they can't figure out how to operate their business without breaking the law, then they don't get to operate their business.
Re: How are we supposed to know who's British?
Don't need to. Just delete the data for everyone you cannot prove is some other nationality.
The same goes for Google. They do not need to know who I am to delete what they know about me. They can simply delete records for all people they cannot identify. These days, that list must consist almost exclusively of people who do not want to be tracked by Google.
Re: As good as a win as this is...
"how are we supposed to know who's British?"
The images will show our famous stiff upper lips. (Admittedly used to hide our awful teeth).
Just because I make a piece of data freely available on the Internet, that does not make it public domain. It can still be legally protected in all kind of ways, even if it's not protected by technical means.
Companies that gather data from the Internet ought to be made painfully aware of this fact: you still need a license to use any data that's not yours, and if it's not clear whether there is a license to be had, that doesn't mean the piece of data is up for grabs; it means that if you grab it you're in an ambiguous situation at best, and could very well land in court.
And the enforceability of this fine is done how?
Seems a pointless headline grabber by the ICO - I'm assuming that by design this company has no UK/EU assets or presence.
So the ICO is going to make them stop HOW exactly?
Re: And the enforceability of this fine is done how?
If they ever want to do business in the UK, they'll care.
Re: And the enforceability of this fine is done how?
In other words they can't right now legally sell to ANY business in the UK, or that has a UK subsidiary that would use their technology without automatically becoming liable to pay the fine.
NSA laughs....
...and adds data source to existing library
I'm in two minds about this, because it ignores the elephant in the room
-> failing to have a lawful reason for collecting it
Why is it lawful for Google to collect this and Clearview not? It seems that the ICO is ignoring the elephant in the room. I have never had much time or respect for the ICO. It is a chair-polishing unit of government.
Re: I'm in two minds about this, because it ignores the elephant in the room
The distinction is between indexing for search, and capturing/saving process to derive a biometric class of identifier. Google can still do the latter of course, but if they do it's just not public knowledge yet.
Re: I'm in two minds about this, because it ignores the elephant in the room
Given Google's history I would be surprised if they weren't doing this.
Re: I'm in two minds about this, because it ignores the elephant in the room
Consent. If I put a photo on Google's site, I give consent under Google's terms for its use there. I do not give carte blanche to every random company to take it and use it how they see fit.
And, if Google were to sell that data, they'd still need explicit, informed consent for that particular use too.
Re: I'm in two minds about this, because it ignores the elephant in the room
unless, usually, you consented to allow you data to be shared "with trusted and carefully selected third parties".
Bit like signing up to virtually any UK government system ... to paraphrase "we will share you data with anyone from any security organisation, local council, pet rescue organisation, private parking mafia and anyone else who knows and will pay us for your data ..."
Re: I'm in two minds about this, because it ignores the elephant in the room
That would fail the informed consent test, because the list of partners is not enumerated...
Re: I'm in two minds about this, because it ignores the elephant in the room
This is all too true. There is always a 'need' word in their too - if it is necessary we will share your data. Need for who? Not me.
Re: I'm in two minds about this, because it ignores the elephant in the room
You forgot they will sell it to Palantir and its evil boss Peter Thiel.
Re: I'm in two minds about this, because it ignores the elephant in the room
Er hello? Google scrapes the web. That is what it does.
Re: I'm in two minds about this, because it ignores the elephant in the room
Consent. If I put a photo on public internet, I give consent to everybody and his cat... erm, dog, to see it and do whatever he wants with it.
If you don't like it, don't make the photo available on public internet. Use a private cloud under your control.
Re: I'm in two minds about this, because it ignores the elephant in the room
Rubbish. Otherwise you could create a news site by just scraping and collating other news sites, for example.
The principle that content on the web can only be consumed in accordance with the license, and not freely copied and republished is well established.
See for example [1]here .
[1] https://www.stockphotosecrets.com/questions-answers/can-i-use-photos-from-facebook.html
Re: I'm in two minds about this, because it ignores the elephant in the room
It's a difficult question. As a society, we don't really yet have a universally-accepted consensus on how privacy works on the Internet. And legislation usually trails societal consensus, for good reasons.
In this case, the difference is that while it's fairly obvious that nobody wants other people to be able to run face recognition on them without their consent, it's not obvious at all what exactly people want Google to index - even though a reverse GIS looks a lot like what Clearview is doing. I'm fairly sure that everyone at the ICO is well aware that this distinction is rather nebulous, but what can they do about that? Come up with arbitrary rules that would likely discontent everyone?
Until we, the everyday people of the Internet, get into some kind of agreement on exactly what's acceptable and what isn't, I wouldn't blame governments too much for failing to evict elephants from rooms.
Re: I'm in two minds about this, because it ignores the elephant in the room
"Why is it lawful for Google to collect this and Clearview not?"
Simple answer is that it's not lawful for Google to collect this type of data either
Re: I'm in two minds about this, because it ignores the elephant in the room
I agree. Yet the chair polishers don't do anything about it.
Re: I'm in two minds about this, because it ignores the elephant in the room
But they're doing it anyway. The law? We've heard of it and we'd gladly pay the fine. It's the cost of doing business.
I am not an idiot. Sadly some of my friends are
I have never uploaded my image to the internet, but I have been tagged in photo's by friends and family. They are all very aware now that they were out of order for doing that. The damage was done though and cannot be undone.
It's a bit of a stretch for Clearview to consider that all of the images they gouged from the internet had an implicit agreement behind them, as many like me had no say in whether they could be uploaded. They assume too much.
And if they had approached the custodians of the original images offering money for them, I guess £7 million would be a snip. More like £7 billion for that kind of data.
Re: I am not an idiot. Sadly some of my friends are
-> I have never uploaded my image to the internet, but I have been tagged in photo's by friends and family.
This point you are raising here is crucial, and it doesn't even occur to many people. Your name and your photo is now in Clearview's database (and other databases which you are unaware of). The surveillance state is built on this. Just because it is a private company that has this data, do not think that the state does not have access to it. At the drop of a hat if the state comes round to Clearview and says 'can you match this photo?', Clearview is not going to say 'we do not do that sort of thing'. They are now party to the surveillance state.
Re: I am not an idiot. Sadly some of my friends are
Yup.
I had a FaceMelta account with a pseudonym. A friend published a picture of me and tagged it with both my real name, and my pseudonym, enabling both to be linked. Assuming Clearview stole that, it could now find me in random images that just happen to contain me. I have no idea if those images exist, so cannot have given consent.
It's an interesting legal challenge. I remember years ago, a German fellow was at a motor race with a lady that was not his wife. His wife saw the image, wasn't impressed, and filed for divorce. The man sued the broadcaster, and won for infringing his privacy. From memory, case relied on what's a reasonable expectation of privacy at a public, or semi-public event.
But this is a good step by the ICO. Now it just has to repeat the process against every data slurper and aggregator that thinks privacy is less important than profit. Personally I think there's a couple of quick fixes. Data controllers are legally responsible for data accuracy, so should automatically send their records to data subjects to check. Obviously this would cost them, and reveal the amount of data held. All executives at the slurpers should also be required to maintain public profiles detailing every class of data held and processed. If they think it's ok to spy on our browsing habits, they should have no problem with publishing their own.
Re: I am not an idiot. Sadly some of my friends are
Yep, it's much like Whatsapp taking my number from other people's Contacts with their permission but not mine.
Re: I am not an idiot. Sadly some of my friends are
Exactly.
No - I'm sparticus
"I have never uploaded my image to the internet, but I have been tagged in photo's by friends and family. They are all very aware now that they were out of order for doing that. The damage was done though and cannot be undone."
That was your 1st mistake. What you should of done was get a total random picture of a person (preferable deceased) then upload it to as many sites as possible attached to your name. You could even ask your nearest and dearest to add some photoshopped images of them with your avatar.
It may not be possible to beat the man, but you can at least confuse the hell out of hime
Public images.
No problem.
Let's gets a group follow them taking photos 24/7 when in public, and post saying where they were, who they were with, what they ate, what time they went to the toilet etc.
No problem with that, it's public after all.
Re: Public images.
That sounds like a clear case of harassment.
Photographing people in public without their permission is allowed in the UK and the US. Following them around continually photographing them is materially a different thing.
Re: Public images.
There is, I believe a caveat to that which is whether you are using the picture for profit or not. If yes, then you should have the permission of the people in the picture, whether or not you are standing on public ground when you take the image.
Re: Public images.
I don't understand the thumb downs but it's a free world I guess...
"DO I NEED PERMISSION TO TAKE PICTURES FOR COMMERCIAL PURPOSES?
In order to sell your photos to a media library or to use your photos to promote or sell products or services, you will often be required to obtain a signed model release form from any identifiable person featuring in the image. Although it is not illegal in the UK to take an identifiable photo of a person in a public place, media libraries and agencies often require you to have had permission to take the photos regardless."
https://www.pauldavidsmith.co.uk/photographers-rights/
Re: Public images.
No, you don't. Otherwise there would be no pictures of celebs doing things they don't want pictured in the newspapers.
Picture of a footballer coming out of a restaurant with his mistress, sorry no permission. Picture of him beating up some bloke on the street because he looked at him funny, sorry no permission. ETC.
Re: Public images.
Yes you do. Journalism has an exemption to GDPR
https://bookdown.org/fede_caruso/bookdown/the-journalistic-exemption-in-the-gdpr.html
Re: Public images.
That sounds like a clear case of harassment.
Why would they feel harassed? I think we should crowd fund some private investigators to do this, and publish the results in near-realtime. Sure, it might be considered stalking, but it's not really any different to what these scumbags do. If they're concerned about their privacy being violated, stop violating ours.
New York
What are the odds that they won't pay the fine or do anything to rectify this since they're headquartered in NY?
What are they being ordered to delete?
Has anyone read the judgment? Are they being asked to delete the photos/images or are they also being ordered to delete the derived hashes etc that could still be used to later identify people in new photos?
Just because I make a piece of data freely available on the Internet, that does not make it public domain. It can still be legally protected in all kind of ways, even if it's not protected by technical means.
Companies that gather data from the Internet ought to be made painfully aware of this fact: you still need a license to use any data that's not yours, and if it's not clear whether there is a license to be had, that doesn't mean the piece of data is up for grabs; it means that if you grab it you're in an ambiguous situation at best, and could very well land in court.
failing to have a lawful reason for collecting it
The article says one of the reasons for the fine is "failing to have a lawful reason for collecting it". ICO's own article actually says "failing to have a lawful reason for collecting people’s information".
It is not 100% clear whether this is a reference to: (a) failing to have any valid/defined legitimate purpose(s) (GDPR Article 5(b)), or (b) failing to have any valid defined lawful bases/conditions (GDPR Articles 6(1) and 9(2)).
I assume the ICO is referring to GDPR Article 5(b) "legitimate purpose(s)".
You'd expect the ICO to use the correct legal terminology in their press release so as to be clear as to which of these they were referring to. Then again it is the ICO...
Only $7.5M?
It should be $7.5B. Then they might stop scraping images of all and sundry without a thought to the damage they are doing.
suck on this--> [see icon]
Contradiction
"Clearview AI is not subject to the ICO's jurisdiction, and Clearview AI does no business in the UK at this time."
"My company and I have acted in the best interests of the UK and their people by assisting law enforcement in solving heinous crimes against children, seniors, and other victims of unscrupulous acts."
Those two statements contradict each other
Please fine them until the pips squeak.
Rightly or wrongly, people knowingly and willingly give their photos to Google, Facebook etc, but not to this bunch.