Jump to content

Recommended Posts

Posted

More and more CCTV solutions are including AI features and facial recognition technology now than ever. The ability for an operator to feed a photo into a system and find where somewhere has been is a fairly easy task, or natural language search such as "I'm looking for a tall man wearing a red jumper" is becoming more common. However, one thing I have not seen is any up to date guidance in regards UK GDPR with such tech. It seems somewhat pointless for us to be buying new systems with these capabilities, only for us to totally disable them, and then have to spend hours manually searching when the built in features could do the same search in seconds.

 

Does anyone know if there has been any updated guidance on CCTV? The ICO seems not to have updated its guidance in some time. Facial recognition in schools would come under the Protection of Freedoms Act 2012 as far as I can tell, as it would be processing biometric data, so consent would be needed?

 

What are people's thoughts on this technology, as I can see the major advantages of it, but also the privacy implications.

Posted
Interesting question, I am keen to see responses from people who know what they're talking about, but in my mind your two examples are different as "find me a tall person in a red jumper" isn't biometric data, but "find me this face" is.
Posted
But is it necessarily about the biometric data as such? Both the source image and actual CCTV footage (which you'd have anyway) should fall under the same access control and retention polices anyway. It would be more about the ability to track or remotely ID someone.
Posted
But is it necessarily about the biometric data as such? Both the source image and actual CCTV footage (which you'd have anyway) should fall under the same access control and retention polices anyway. It would be more about the ability to track or remotely ID someone.

 

Good point. There is also a difference between uploading an jpg and saying "is this person on camera?" and screen-grabbing a face from your CCTV and asking "find me other footage of this person".

  • Thanks 1
Posted

My interpretation, which may be wildly wrong, is that you are not storing facial biometric data for each person. For the systems I have dealt with so far, you are picking an image and saying find more of these. It doesn't then reference a DB and tell you who the person is. It is just shape recognition. I agree with enjay, the natural language searches is different from facial recognition and not a DPA issue as it isn't using personal data.

 

There is a Code of Practice for surveillance cameras that was updated in 2022 to cover facial recognition, but geared towards automated facial-recognition:

• Use of a surveillance camera system must always be for a specified purpose which is in pursuit of a legitimate aim and necessary to meet an identified pressing need.

• The user of a surveillance camera system must take into account its effect on individuals and their privacy, with regular reviews to ensure its use remains justified.

• There must be as much transparency in the use of a surveillance camera system as possible, including a published contact point for access to information and complaints.

• There must be clear responsibility and accountability for all surveillance camera system activities including images and information collected, held and used.

• Clear rules, policies and procedures must be in place before a surveillance camera system is used, and these must be communicated to all who need to comply with them.

• No more images and information should be stored than that which is strictly required for the stated purpose of a surveillance camera system, and such images and information should be deleted once their purposes have been discharged.

• Access to retained images and information should be restricted and there must be clearly defined rules on who can gain access and for what purpose such access is granted; the disclosure of images and information should only take place when it is necessary for such a purpose or for law enforcement purposes.

• Surveillance camera system operators should consider any approved operational, technical and competency standards relevant to a system and its purpose and work to meet and maintain those standards.

• Surveillance camera system images and information should be subject to appropriate security measures to safeguard against unauthorised access and use.

• There should be effective review and audit mechanisms to ensure legal requirements, policies and standards are complied with in practice, and regular reports should be published.

• When the use of a surveillance camera system is in pursuit of a legitimate aim, and there is a pressing need for its use, it should then be used in the most effective way to support public safety and law enforcement with the aim of processing images and information of evidential value.

• Any information used to support a surveillance camera system which compares against a reference database for matching purposes should be accurate and kept up to date.

  • Thanks 1
Posted (edited)

I've kept that parked in the "lets keep that can of worms/pandora's box firmly closed" category. I do this by inviting the person who raised it to take on the project to work through and take ownership of the legal and local/external "political" issues that may arise from enabling that technology.

 

Same with any cameras that might have microphones.

 

Our DPIA for the system states that we do not and will not make use of these features.

 

I would observe though that the utility of facial recognition is limited in schools - you are usually looking at an incident and so SLT/Admin support do the facial recognition using that which lies betwixt their ears. If we are trying to trace a student's movements we almost always know a point in time where they were, and then work through from that.

Edited by psydii
Posted
I've kept that parked in the "lets keep that can of worms/pandora's box firmly closed" category. I do this by inviting the person who raised it to take on the project to work through and take ownership of the legal and local/external "political" issues that may arise from enabling that technology.

 

That's where it sits with us too, and for now that's fine because our CCTV system can't do it anyway. There is only so long we can both do that though, at some point we'll need to upgrade our CCTV systems, and chances are high the new ones will include this functionality, although of course we don't have to use it just because its there. There is also the possibility the new system will enable it as standard; we found that with a newer model of camera which could send audio down the Ethernet cable rather than needing a separate cable.

 

The legal side is definitely something to sew up before implementing - we've already have FOIA requests asking whether we use facial recognition, gait analysis, etc. on our CCTV.

Posted

"tall person in a red jumper" can be personally identifiable data in a narrow enough context.

 

The example I use is that:

 

"Mr Smith, 123 Fake Street, Little Worthington, UK."

 

and

 

"The tall chap who walks the sausage dog at lunchtime"

 

both equally identify the same person in a local enough context.

 

See also: "Er, I don't know the new teacher's name Sir, but they've got massive ears".

Posted

From ICO personal identification page:

 

The UK GDPR provides a non-exhaustive list of identifiers, including:

name;

identification number;

location data; and

an online identifier.

 

No mention of jumper colour or ear size in there I think it's a bit of a stretch to say red jumper person is personally identifiable especialy if the school uniform is a red jumper...

 

"tall person in a red jumper" can be personally identifiable data in a narrow enough context.

 

The example I use is that:

 

"Mr Smith, 123 Fake Street, Little Worthington, UK."

 

and

 

"The tall chap who walks the sausage dog at lunchtime"

 

both equally identify the same person in a local enough context.

 

See also: "Er, I don't know the new teacher's name Sir, but they've got massive ears".

Posted

 

No mention of jumper colour or ear size in there I think it's a bit of a stretch to say red jumper person is personally identifiable especialy if the school uniform is a red jumper...

 

If you can cross reference it with other data you hold to identify an individual then it falls into scope as pseudoanonymised data.

So "red jumper" probably requires human knowledge not recorded anywhere, but physical characteristics (big ears) are likely recorded in the MIS as a photo.

Posted
"tall person in a red jumper" can be personally identifiable data in a narrow enough context.

 

Yes, but... by that same logic, using student initials in documents rather than full names is also personally identifiable information as you could still potentially work out who it is, especially with some initials and/or context of knowing the year group or which staff member sent the email. You have to draw a line somewhere.

Posted
Yes, but... by that same logic, using student initials in documents rather than full names is also personally identifiable information as you could still potentially work out who it is, especially with some initials and/or context of knowing the year group or which staff member sent the email. You have to draw a line somewhere.

 

Yes initials are personally identifiable and in scope when someone asks for all the email that talks about them.

Posted
(big ears) are likely recorded in the MIS as a photo.

 

Kinda Disagree (but then I am not a lawayer...so... )

 

That's just a personal opinion. Someone else might think their small ears or normal ears. "Guy that looks like a woman" is not personally identifiable data eithe that's just a (pontitally offensive) opinion too.

Posted

If you can look through the staff photos and identify the member of staff then it was pseudo-anonymous but has now become (by virtue of you actually preforming the cross referencing) personally identifiable in the scope of the record of that event.

 

In the written record you might see the the student statement "teacher with the big ears", and in the comms trail after that you would see "..do you thing they mean Mr X?", and later "yeah it was Mr X"... so if you ask the AI to find the adult with the big ears, it will return imagges of who it thinks matches, and then you take action (producing an audit trail) the "big ears" has become personally identifiable :shrug:

Posted
Yes initials are personally identifiable and in scope when someone asks for all the email that talks about them.

 

I wasn't suggesting use of initials excluded an email from a disclosure request, I just gave it as an example of steps we take to protect someone's identity but cross-referencing with another data source could still identify them.

  • Thanks 1
Posted
That's just a personal opinion. Someone else might think their small ears or normal ears.

 

Ah, now that depends on the particular ears in question. Some might be unquestionably big!

Posted

We would love a system where you could type in a students name and it tells you the last known camera and the students movements, it would make tracking certain students who run round the school so much easier, but I've always thought such a system wasn't legal - plus oftentimes the pupil is walking away from the camera or is too far away and so I'm not sure how reliable it would be. Our system technically supports facial recognition but I think you'd have to upload photos first and it would only work with a close up image of a person e.g. for an entry system - picking someone out of a crowd on a 1080p or < 4K camera just isn't technically feasible.

 

And yes when we have had SAR on people, we've had to search their initials too. Which makes things very hard if their initials are AM or something like that...

Posted
I wouldn't have thought tracking would be illegal in a closed environment like a school as long as it only covered the school site and you had consent from all the parents and it complied with GDPR, etc, etc. There's probably a lot of legal and regulatory hoops to jump through.
Posted
I wouldn't have thought tracking would be illegal in a closed environment like a school as long as it only covered the school site and you had consent from all the parents and it complied with GDPR, etc, etc. There's probably a lot of legal and regulatory hoops to jump through.

 

If consent is required to use that feature, it isn't just the students/parents - you'd need it for every visitor, including the postie, refuse loading operatives (as I believe they're officially called), plus anyone who hires the school in evenings, any shared use sports facilities, etc. And because the law is mad, you would probably also need consent from anyone who broke in!

Posted
If consent is required to use that feature, it isn't just the students/parents - you'd need it for every visitor, including the postie, refuse loading operatives (as I believe they're officially called), plus anyone who hires the school in evenings, any shared use sports facilities, etc. And because the law is mad, you would probably also need consent from anyone who broke in!

 

I'm assuming a system as described by mikes, where to be able to automatically track someone, you would have to have a "face" pre-loaded and linked to a name in the system, and tracking was a case of pick from the pre-populated individual you want to track. That way anyone who's not staff/student or who has denied consent wouldn't be automatically trackable and for them it's just normal CCTV.

 

But the whole thing is very theoretical and probably quite legally complicated right now.

Posted
I wouldn't have thought tracking would be illegal in a closed environment like a school as long as it only covered the school site and you had consent from all the parents and it complied with GDPR, etc, etc. There's probably a lot of legal and regulatory hoops to jump through.

 

Consent would be illegal in this case, as there is no way to avoid being in the system.

Posted

I would be hesitant of any plan to introduce facial recognition with CCTV in schools, never mind adding in any form of AI with it.

If someone has done a risk assessment I would be very interested to see the results.

  • Thanks 2
Posted
I would be hesitant of any plan to introduce facial recognition with CCTV in schools, never mind adding in any form of AI with it.

If someone has done a risk assessment I would be very interested to see the results.

 

What about redaction tools for footage to be exported?

 

"Redact all the faces but that *draws circle round particular face* one"

 

https://www.secureredact.ai/ for example.

 

Now admittedly sometimes that's just a matter of tracking a vague face blob as it moves across frames until it becomes something a police officer/pastoral lead can work with, but it's still using AI.

Posted
That would need to be subject to a DPIA for the redaction service. By the time you are redacting, you have processed the data for the purpose you recorded it without using AI. Using AI/Machine learning to streamline the completion of a compliance piece does not IMO need to be covered by the CCTV Policy DPIA per se. Pretty sure most modern video redaction software already is face tracking using ML algorithms, and until recently ran locally. When its sending footage to third party servers for analysis things become more murky.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...