Possible GDPR loophole with machine learning???

Joined
Mar 30, 2010
Messages
637
Reaction score
568
With the imminent arrival or gdpr and all the bullshit its going to bring I think I've found a loophole in it with regards to special category data.

Special category data includes
  • race;
  • ethnic origin;
  • politics;
  • religion;
  • trade union membership;
  • genetics;
  • biometrics (where used for ID purposes);
  • health;
  • sex life; or
  • sexual orientation.
If you want to record it you have to ask for this data you have to jump through a tonne of extra hoops.

Well whats stopping me bypassing this completely and just asking for a face photo and then using Machine learning to asscertain race and ethinic origin via image recognition?

I'm pretty much coming to the conclusion that I am going to run my forums from a company which does not have any treaties with Europe but if this is a way to partly bypass GDPR then I will be greatful!
 
It depends whether GDPR is about the data you REQUEST from someone, or the data you HOLD for someone. I think possibly its the later, meaning perhaps that it doesnt really matter what you have actually requested, but its having the consent to actually hold that information on them that counts.
 
Exactly, even if you have already gathered any user data, it will be still against GDPR rules to keep them without the users' explicit consent.
 
Exactly, even if you have already gathered any user data, it will be still against GDPR rules to keep them without the users' explicit consent.

We took registrations last year for a couple of events we are running this summer, have a dozen or so delegates who have food allergies and informed us at the time of registering.

We now have to go back to those delegates to ask their explicit consent to pass this information onto the hotel who are doing the catering. Talk about a fucking nightmare thanks to all the extra work involved.
 
Talk about a fucking nightmare thanks to all the extra work involved.

Tell me about it..
There's no exact regulation for particular situations, so at our company we need to find out ourselves, what to do in order to be "GDPR ready"
Fuckin' nightmare it is..
 
It doesn't matter when you took information. "Processing" includes storing and even deleting data. If you create data about someone after 25th May, you have to have a ground for doing so.

It doesn't have to be consent.

@MisterF - if you have a contract with the delegates, you don't have to ask for their permission. You could process on the ground of "contract" because in order to fulfil your contract with them, you need to disclose that data. Or you could choose "legitimate interest" because if you didn't tell the hotel, the delegate would be at a loss.
 
It doesn't matter when you took information. "Processing" includes storing and even deleting data. If you create data about someone after 25th May, you have to have a ground for doing so.

It doesn't have to be consent.

@MisterF - if you have a contract with the delegates, you don't have to ask for their permission. You could process on the ground of "contract" because in order to fulfil your contract with them, you need to disclose that data. Or you could choose "legitimate interest" because if you didn't tell the hotel, the delegate would be at a loss.
I learnt something again.. Even asked some lawyers, and all of them suggested different things on how to handle customer data.
A friend of mine working at a small company is already making a fortune by selling paper shredders to midsize enterprises, offering them a way to get rid of any compromising data. :)
 
I learnt something again.. Even asked some lawyers, and all of them suggested different things on how to handle customer data.
A friend of mine working at a small company is already making a fortune by selling paper shredders to midsize enterprises, offering them a way to get rid of any compromising data. :)

Most lawyers specialise fairly early on in their careers. Few cover intellectual property law.

For businesses in the UK, most of the rules of the GDPR build on our existing Data Protection Act, but compliance with that law hasn't really been policed. My guess is that midsize enterprises don't have to worry too much about compliance with GDPR in the short term because the UK government doesn't have the resources to enforce it. It'll be one of those things that will be complied with over time.

I like the niche of paper-shredders.
 
Most lawyers specialise fairly early on in their careers. Few cover intellectual property law.

For businesses in the UK, most of the rules of the GDPR build on our existing Data Protection Act, but compliance with that law hasn't really been policed. My guess is that midsize enterprises don't have to worry too much about compliance with GDPR in the short term because the UK government doesn't have the resources to enforce it. It'll be one of those things that will be complied with over time.

I like the niche of paper-shredders.

Unfortunately I'm not in the UK anymore, and in here the gov most probably will try to enforce this on every single company regardless of their size.
 
We took registrations last year for a couple of events we are running this summer, have a dozen or so delegates who have food allergies and informed us at the time of registering.

We now have to go back to those delegates to ask their explicit consent to pass this information onto the hotel who are doing the catering. Talk about a fucking nightmare thanks to all the extra work involved.
I read that it can go even further down the chain, so if the hotel uses any outside contractor it can cause problems there also
 
I read that it can go even further down the chain, so if the hotel uses any outside contractor it can cause problems there also
I used to work in a hotel, and still in contact with the IT dept. Question: What if the security system has a separate pc only for cctv and other purposes and the contractor who built that system needed remote access to that pc, so they can monitor it to see if everything's working properly. Is this a security breach now?
As they can see:
- CCTV live footage
- details of staff coming-going as they are using their rfid security cards

What to do? Scenarios:
1. If the hotel blocks this access, they breach the contract with the security company.
2. If they leave it as it is, they breach the gdpr law.
3. fuck this, we'll see what happens next. :)
 
I read that it can go even further down the chain, so if the hotel uses any outside contractor it can cause problems there also

You're right. The law applies to all people or businesses that process data down the chain. It would be the responsibility of the hotel to make sure that contractors were compliant.

The hotel can protect itself by requiring that the contractors indemnify them if a data breach is as a result of their actions. You'd probably also need to make sure that it was a contractual obligation for the contractor to take out insurance to be able to pay for the indemnity.

There won't be many contractors to a hotel that handle personal information where there is a big risk of that information being breached. GDPR wouldn't give much further obligation than current law anyway.
 
I used to work in a hotel, and still in contact with the IT dept. Question: What if the security system has a separate pc only for cctv and other purposes and the contractor who built that system needed remote access to that pc, so they can monitor it to see if everything's working properly. Is this a security breach now?
As they can see:
- CCTV live footage
- details of staff coming-going as they are using their rfid security cards

What to do? Scenarios:
1. If the hotel blocks this access, they breach the contract with the security company.
2. If they leave it as it is, they breach the gdpr law.
3. fuck this, we'll see what happens next. :)

Could the contractor identify individuals coming and going? Could they say "That's Joe."? If yes, then GDPR applies to the contractor. However, I'd guess that the contractor could see individuals, but not be able to identify them.

If GDPR did apply, then the reason to access the information would probably be "contract" between the hotel and the cctv provider. The cctv provider would need access to be able to carry out the maintenance contract.

The reason for the hotel to use cctv could be "legitimate interests" - it has a legitimate interest to protect its business (and its clients) by using a cctv system. It would have to make sure that data storage and use were reasonable for this ground (i.e. that it didn't store video indefinitely, and that video was stored safely etc).
 
I like the niche of paper-shredders.

Easy to get into even now, drop shipping them.

Back in 1997 leading upto and then 1998 when the Data Protection Act came into force I had my business selling office equipment and supplies, as I had direct accounts with Rexel and Fellowes I did some great pricing on shredders and made a nice earner from it. Ranging from 1 man businesses wanting a £25 machine to big businesses paying £2k+. This was all due to rumour mills and scare stories about inspections leading to fines from govt agencies for breaches of data etc.

GDPR will be a nightmare and until a first legal precedent is set after a test case in court, people will still be trying to guess / second guess.
 
Could the contractor identify individuals coming and going? Could they say "That's Joe."? If yes, then GDPR applies to the contractor. However, I'd guess that the contractor could see individuals, but not be able to identify them.

The reason to access the information would probably be "contract" between the hotel and the cctv provider. The cctv provider would need access to be able to carry out the maintenance contract.

The reason for the hotel to use cctv could be "legitimate interests" - it has a legitimate interest to protect its business (and its clients) by using a cctv system. It would have to make sure that data storage and use were reasonable for this ground (i.e. that it didn't store video indefinitely, and that video was stored safely etc).
Luckily it's not my responsibility as I'm not working there anymore, just trying to help those poor bastards who need to deal with this :)
Eventually the company's lawyers will figure it out how to deal with this situation.
Yes, they can identify individuals in the system, as all cards have been assigned to their owners, and it is logged in the system where they are going. Whenever someone opens a door with his/her card, it creates a log entry with the timestamp, the door's ID, and the person's card and name.
 
Easy to get into even now, drop shipping them.

Back in 1997 leading upto and then 1998 when the Data Protection Act came into force I had my business selling office equipment and supplies, as I had direct accounts with Rexel and Fellowes I did some great pricing on shredders and made a nice earner from it. Ranging from 1 man businesses wanting a £25 machine to big businesses paying £2k+. This was all due to rumour mills and scare stories about inspections leading to fines from govt agencies for breaches of data etc.

GDPR will be a nightmare and until a first legal precedent is set after a test case in court, people will still be trying to guess / second guess.
Any niche related to digital data protection would be good right now - reselling secure erasure software or storage.
 
Back
Top