Google Translated from German to English:

GDPR vs. Smart Glasses: Why Ray-Ban Meta Carriers Can Be Held Liable

A new data protection report teaches: Anyone who films uninvolved third parties with smart glasses or allows Metas AI training loses the privilege of the budget exception. reading aloud Print view 53 Read comments Close-up of a black Ray-Ban-Meta-Smart glasses with integrated camera in the eyeglass frame and mirrored lenses on a wooden table. Close-up of a black Ray-Ban-Meta-Smart glasses with integrated camera in the eyeglass frame and mirrored lenses on a wooden table.

(Picture: Tada Images/Shutterstock.com) 13:54 Clock Reading time: 4 min. From Stefan Krempl

The dispute over smart glasses in everyday life continues. After prohibition demands occupied the policy and the Federal Network Agency fit in due to lack of handling, the Hamburg data protection officer Thomas Fuchs has followed up with an investigation by the Ray-Ban Meta AI Glasses. The analysis is clear: For the everyday use of data glasses in public spaces, there is therefore hardly a legally compliant basis, as long as Meta does not improve on construction method and presets.

In the laboratory, the Hamburg data protectionists dismantled the first-generation Meta Wayfarer model and analyzed the traffic. They quickly reached their limits: The 32-gigabyte flash memory had no standardized connections, the data transmission of the app remained encrypted. In the application memory of the smartphone, however, the examiners came across a discovery: In the internal SQLite database, there are table structures with designations such as “face”, “face_group” or “face_low_confidence_pair”.

Although these tables remained empty in the tests and currently no biometric facial recognition takes place, the substructure for automated person matching is already anchored. The authority also refers to security researchers who briefly managed to unlock a facial recognition function. Meta responded with a covert update. The fact that the Group is technically providing for the identification of people in the future by comparison is a bad blow to the inspectors.

Another point of criticism concerns transparency towards third parties. Externally, the data glasses hardly differ from the Wayfarer classic from the 1950s. Passers-by do not realize that they are captured by video camera, five microphone systems and AI assistant. The signal light proves to be largely ineffective: In daylight, the white LED is barely perceptible and sometimes does not signal direct AI interactions at all. When spectacle wearers become data processors

In addition, there is the vulnerability to manipulation. The protective mechanism, which is intended to prevent images when the LED is concealed, can be tricked with foils or caps. Video recordings launched once continue, even when the signal light is subsequently taped off. This means that the glasses miss the European privacy-by-design requirement. According to the report, this allows for secret surveillance that is incompatible with the General Data Protection Regulation (GDPR).

The classification of data protection law is of serious consequences for the buyers themselves. The budget exception protects private individuals from the GDPR obligations when taking up in a private environment. Anyone who films strangers in public spaces or publishes recordings on social media loses this privilege. The authority clarifies that carriers then become fully responsible data processors. Intractable hurdles in everyday use

The situation becomes even trickier if users do not object to the meta default setting and train the AI model with interaction data. If images and audio signals of third parties are transmitted to the USA for AI training, the data leaves the private purpose. Users thus slip into joint responsibility with the US group pursuant to Article 26 GDPR. Since Meta does not offer an agreement to divide the duties, spectacle wearers move on thin ice.

In order to lawfully process images or conversations of third parties, institutions would either have to obtain informed consent or prove an overriding legitimate interest. Both fail because of everyday realities: effective approval requires prior enlightenment, which is in fact impossible in the face of the inconspicuous glasses. It doesn’t look like a common camera. Video recordings in public spaces can exceptionally be based on legitimate interests. With activated AI functions, however, the rights of the filmed almost always outweigh the rights.

Anyone who walks through the city with the glasses would have to inform passers-by in advance orally or even wear safety vests with inscriptions in order to meet the requirements of the European Court of Justice. Particularly sensitive are medical practices, demonstrations, women’s shelters or playgrounds. The use of the Ray-Ban Meta AI Glasses in public space is thus difficult to legally design under data protection law.

  • steelplatedmech@piefed.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    10 hours ago

    I personally wouldn’t consent to being part of facial recognition even if it were friends and family in control of the data.

    Maybe there will be some opt out tech in the future so people just show up blurred or a silhouette and distorted audio when people attempt to record or take pics of them, and it requires enabled consent before hand for them to be able to be recorded normally.

    • Midnight Wolf@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 hours ago

      I was thinking that face scans would be opt-in and local only, and you’d need to ask them to do something like wave as a method of consent. Then it only pops up when Jim or Bob or Jean is recognized, and unrecognizable faces just get ignored. Something along those lines. I haven’t thought about it too much but something similar for pictures and video. Maybe always-on at home but then switching to standby when you leave home, with just recognized faces and certain events triggering action.

      • steelplatedmech@piefed.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 hours ago

        I think that is probably the difference between those who are for the idea and against. Compared to even the average person it seems like you want constant surveillance and recording under the condition you control it. And then others just don’t find the need for constant ever present recording even if it is under their complete control.

        Which is probably why some don’t find the idea of recording glasses appealing at all, since it’s not something they find a desire for. While those who want everything thing to be documented do.

        • Midnight Wolf@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          … what makes you think I’m for constant surveillance? I’m wanting it at home for ‘where did I put my keys’ and ‘I don’t know if I’ve taken my medicine and forgot to note it down (overdose danger!), or forgotten it entirely’ at home; and in public for notes about family and friends (‘how is little [I forgot his name, but I have it under Bob’s notes] Joey?’, or ‘it’s your birthday next week, isn’t it? [holy crap, I completely forgot]’), or for things like if I trip and fall, smack into a wall (yay blindness), perhaps the route back from the doctors office, or showing me reminders to pick up medication on the way home, stuff like that. At home, it would act as another memory and eyes, and away it’s just another knowledge base.

          Since I don’t consider my home space as being surveilled - since it would be a device that has no persistent outside connection, only to pull data on/off like notes or med history, and event pictures or clips - so because I’m already there in my home, I don’t see the issue. To me, what I have explained and want in this thread is just a helper to keep myself in check (appointments, reminders, birthdays, names, pill dose tracking, physical safety, easy medical log extraction…). And I already have to wear glasses, so… why not? There just needs to be a device that fits my requirements.

          I should note that before my stroke, the Google Glass had just hit the market, and I was intrigued but nothing more. After it happened and I came to the realization that I suffer a bit of cognitive… loss? Degradation? The idea of using wearable tech to save me from myself became pretty desirable. That may be why I’m basically the only one here who is even remotely positive about this; I will never be 100% that I once was, physically or cognitively. But if I were to brush away possible systems to help me, and possibly hurt myself because of it, I would be an obvious idiot.

          • steelplatedmech@piefed.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            All that second to second record keeping that happens passively requires surveillance.

            Difference is that you are in control of the data instead of entrusting it to a third party.

            • Midnight Wolf@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 hours ago

              Ehh, that’s like saying ‘close your eyes, you’re watching me’. Sure on a technicality, but that’s a weak argument.

              E: I can’t spell

      • steelplatedmech@piefed.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 hours ago

        Yes so only a memory will remain that will glitch out over time like a still life from the backrooms, so it becomes hard to deciper what the original looked like.