Jump to content

Recommended Posts

Posted
I would be hesitant of any plan to introduce facial recognition with CCTV in schools, never mind adding in any form of AI with it.

If someone has done a risk assessment I would be very interested to see the results.

This is kinda why I posted. Its a topic that is just on the edge of use now - so many systems now have these capabilities built in out of the box, and some schools will start wanting to use these features. Especially as we have a government who is actively encouraging the use of AI to reduce workload across all areas of the public sector.

  • Thanks 1
Posted

Interesting discussion. I have recently installed another camera at home and making use of AI features. I have a camera that also captures the street. For the purposes of recording, I have configured it to ignore motion events in the street, apart from humans in the area of my mailbox. If anyone is tampering with it I should get them recorded. If a car drives past it won't record.

 

If you use these features that aren't actually used to profile people, I assume it would be a different matter.

Posted
Interesting discussion. I have recently installed another camera at home and making use of AI features. I have a camera that also captures the street. For the purposes of recording, I have configured it to ignore motion events in the street, apart from humans in the area of my mailbox. If anyone is tampering with it I should get them recorded. If a car drives past it won't record.

 

If you use these features that aren't actually used to profile people, I assume it would be a different matter.

 

Personal use.

Posted
Isn't that the same in any CCTV system.

 

We are talking about facial recognition, which is using biometric data. Regular CCTV does not do that, it is just an image recording system and any recognition of individuals is done by human eye, nothing else.

 

The use of biometrics in public areas has been successfully challenged in the past, and the use of facial recognition in schools has also been successfully challenged.

  • Thanks 2
Posted
Personal use.

 

I am in Australia as well so GDPR doesn’t apply. 🤷♂️

 

My point was, the same or similar use case could apply in the UK for a school or business. Maybe a school isn’t interested in passing cars but would like to record any human activity at the bike shed.

Posted
I am in Australia as well so GDPR doesn’t apply. 🤷♂️

 

My point was, the same or similar use case could apply in the UK for a school or business. Maybe a school isn’t interested in passing cars but would like to record any human activity at the bike shed.

 

But use in a school in the UK is covered by GDPR and so any use of personal data needs to comply. Also, is there a less intrusive way of monitoring? Yes, motion sensors can be calibrated against speed (and have been in many circumstances over the years), and so you can have a buffer on the camera that only writes back to storage if the speed of a passing object is below a certain speed.

Posted
But use in a school in the UK is covered by GDPR and so any use of personal data needs to comply. Also, is there a less intrusive way of monitoring? Yes, motion sensors can be calibrated against speed (and have been in many circumstances over the years), and so you can have a buffer on the camera that only writes back to storage if the speed of a passing object is below a certain speed.

 

In the hypothetical system I described, it would be a CCTV system as normal - and it would scan faces against a database of known faces and keep track of those locations/cameras. It wouldn't keep track of unknown faces. But of course I guess it would have to "scan" those faces to determine if they are known or not. If they are not matching then no data would be stored.

 

But - would such a system be legal - would you need consent of everyone who visits the site (say a contractor to fix a lift) - or would you only need consent of those "known faces" you have entered into the system? would you be able to mass import from a MIS and the consent from that and the normal CCTV consent/warning policy cover it? (obviously excluding the students with no image consent)

 

It's more a thought experiment as I doubt the technology for this even exists, or would be reliable with current 1080p cameras - it's nothing we could ever implement. But something for the future to consider e.g. an unknown face who has not signed in using the sign in system is on site - kind of thing.

  • Thanks 1
Posted
would you be able to mass import from a MIS and the consent from that and the normal CCTV consent/warning policy cover it? (obviously excluding the students with no image consent)

 

IANAL but possibly. "You can use my photo in the newsletter" consent is different since we're talking biometric data here, but it depends on the wording used on your biometric consent form. Does it say "I give consent for my child's biometric data to be used for the catering system" or is it wider consent for use of their biometrics in general?

  • Thanks 1
Posted
IANAL but possibly. "You can use my photo in the newsletter" consent is different since we're talking biometric data here, but it depends on the wording used on your biometric consent form. Does it say "I give consent for my child's biometric data to be used for the catering system" or is it wider consent for use of their biometrics in general?

 

yeah I am not our schools policy guy but I'm sure we only really have a CCTV policy and our "biometrics" policy pretty much only covers MIS and "promotional material" e.g. newsletter. We don't use biometrics for canteen/sign in here (LEA handles that anyway). In Wales the LEA's seem to work closer with schools for better or worse so they'd probably provide us a template. But I can just see there being another page of legalese half the parents can't understand about biometrics that they'll just sign anyway because they have to, then we'll have a Chinese style system that automatically monitors students, detects when they drop litter/push another student/are out of lesson without a pass, and adds/deducts points accordingly. Until the kids smash it up and we end up like the school in Akira. (actually a pupil did run up and slap a camera and it seems it broke the horizontal PTZ, the pupil is being billed for it!)

Posted
But use in a school in the UK is covered by GDPR and so any use of personal data needs to comply. Also, is there a less intrusive way of monitoring? Yes, motion sensors can be calibrated against speed (and have been in many circumstances over the years), and so you can have a buffer on the camera that only writes back to storage if the speed of a passing object is below a certain speed.

 

I can't see how that would be any less intrusive. The fact you are being recorded is the most intrusive part. Using technology to recognise (not track) is neither here not there.

Posted
I can't see how that would be any less intrusive. The fact you are being recorded is the most intrusive part. Using technology to recognise (not track) is neither here not there.

 

Its a slippery slope though isn't it? There are specific clauses in DPA/GDPR around automated processing of data. The more AI is picking up and reporting on transgressive behaviour seen by the networked cameras, the more SLT are going to need automated support to handle the additional load created by these reports.... and round and down we go until having the AI issue detentions seems like a sane idea.

Posted
Its a slippery slope though isn't it? There are specific clauses in DPA/GDPR around automated processing of data. The more AI is picking up and reporting on transgressive behaviour seen by the networked cameras, the more SLT are going to need automated support to handle the additional load created by these reports.... and round and down we go until having the AI issue detentions seems like a sane idea.

 

In addition, there would be a big difference to something being processed locally than something processed in the cloud.

Posted (edited)
Its a slippery slope though isn't it? There are specific clauses in DPA/GDPR around automated processing of data. The more AI is picking up and reporting on transgressive behaviour seen by the networked cameras, the more SLT are going to need automated support to handle the additional load created by these reports.... and round and down we go until having the AI issue detentions seems like a sane idea.

 

It feels like it is time for a school AI policy, if only to centrally list all the AI processes we have, especially any decisions which AI is making (anyone put students in sets based entirely on Lucid/Midyis tests?).

 

As for AI issuing detentions, we're (almost, sort of) there already, as ClassCharts will automatically issue a detention to someone who gets 3+ low-level behaviour points in a day. This is a straight if-this-then-that ruleset, so is just the sofftware doing something an admin person could, which means it isn't an AI-based decision, but it is an AI-generated action.

Edited by enjay
  • Thanks 1
Posted
in the USA there are apparently AI applications setting prison sentences, handling immigration - not sure how strictly you could call it "AI" if it is based off a fairly simple points system, but it's still ultimately a machine deciding somebodies fate. But I'd think an AI policy should come under a data policy - how we are using the data
Posted

You should have a DPIA for any significant change in processing of data. Automation, or running it through an AI where previously it was pure human review I think counts.

 

Whether the basic "if this then that" sort of logic that you have in classcharts would qualify, I think are arguably pretty firmly into the grey area that exists around that particularly line. Given (in my experience) there are always some students / mitigating circumstances where the hard-and-fast if "this-then-that" logic needs to be overridden with information that is not readily incorporated to the automated workflow, final say is always with a human.

Posted
in the USA there are apparently AI applications setting prison sentences, handling immigration - not sure how strictly you could call it "AI" if it is based off a fairly simple points system, but it's still ultimately a machine deciding somebodies fate. But I'd think an AI policy should come under a data policy - how we are using the data

 

AI is used in passport control gates to confirm if the person in real life matches the photo inside the passport.

  • 2 weeks later...
Posted
In addition, there would be a big difference to something being processed locally than something processed in the cloud.

 

Nope, the location of processing is a small part of a much bigger issue. The fact that you are making a choice to do the processing it is the problem. A key factor is the question, “can you do it in a less intrusive way?”

When you also consider that this is special category personal data … under GDPR line you need to have a good reason for that and this exemptions are clearly outlined.

 

Block processing when looking for an individual is excessive. That has been established by the courts already.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...