Bias by the EDPB in its “facial recognition in airports” Opinion? “[T]he data storage period [= 48h] is not a decisive factor, on its own merit, for the overall compatibility of said architecture, as such retention periods may be subject to changes by the controllers” (para. 72, page 30).
Surprising that they should stress this, as the point of “controllership” is that you are able to influence the purposes and means – which usually implies being able to change course also at one point. It’s not like it is impossible for controllers to change the structure of a database or the data points being collected, or the processors with whom a controller works.
Why did the EDPB feel the urge to point this out in relation to storage periods?
The context is that the EDPB is comparing various scenarios of use of facial recognition technologies to facilitate passenger verification. In short, two of the scenarios it examines are good, and two variants of a third scenario are bad, according to the EDPB.
The biased drafting of this Opinion means that contradictions appear and some things are presented as obvious consequences in one case, but that aspect is not mentioned in another. For instance, a retention period of one full year in scenario 2 seems to be acceptable if “the controllers [are] able to justify why this retention period is necessary for the purpose in specific cases”, while 48h in scenario 3.1 is clearly unacceptable because retention periods “may be subject to changes by the controllers”.
And that retention period discussion is just one example of the flaws of this Opinion.
You may be for or against the technologies being discussed in the EDPB’s Opinion 11/2024 “on the use of facial recognition to streamline airport passengers� flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR” (and probably the most vocal readers here are against them), but let’s be clear: double-standards should not be the norm when it comes to policy-making at the level of regulators.
Link to the Opinion: https://lnkd.in/dRVsXYg7
GDPR data protection privacy
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗