AI AND FACIAL RECOGNITION: PRIVACY VS. PUBLIC SECURITY
Vaidehi Sharma
INTRODUCTION
In big airports, downtown areas or big sports venues, right now it's very likely a camera with facial recognition software has already taken a picture of your face. Sometimes without you even knowing about it. What used to seem like something from a movie has slowly become part of the everyday setup when it comes to police work checking people at borders keeping stores safe and even making sure students are at school. Facial recognition uses more advanced artificial intelligence to help find people who are criminals missing people or potential dangers. That same ability also brings up one of the biggest arguments about laws and morals today: how much should the government or private businesses be allowed to do when it comes to recognizing and following people, in public places and what does that mean for the privacy of individuals?
This conflict. Between the security advantages of facial recognition and the clear privacy dangers it brings. Is at the centre of ongoing legal battles around the world. Courts, lawmakers and officials are being asked to create boundaries that keep people safe while respecting freedom often without any clear examples to follow. For anyone thinking about becoming a lawyer and, for those who care about technology, human rights or constitutional law this is one of the most important legal issues of this time. This blog looks at how facial recognition technology functions the laws currently controlling its use the important cases and laws affecting the discussion and the tough choices that lawmakers and courts will have to make in the future.
UNDERSTANDING THE TECHNOLOGY
Facial recognition systems work with computer programs to look at a face in a picture or video. They check out the face. Find the things that make it unique like the space between the eyes the shape of the jaw, the nose and a lot of other things. They use all these things to make a set of numbers that is, like a map of the face called a faceprint. This faceprint is then used to see if it matches any faces in a list of known faces. Facial recognition systems are used in two ways:
1. One-to-one verification - This is when we check if someone is really who they say they are, like when you unlock your smartphone or go through one of those gates at the
airport. People usually do not mind this process because they have already agreed to let us compare the information. It is not as personal and that is why using identity verification, for things like unlocking a smartphone is generally considered less invasive because the individual has typically given their consent to the identity verification comparison.
2. One-to-many identification - Scanning a crowd or a live video feed. Checking each face against a big database to find out who unknown people are. This is the disputed use because it usually happens without the people knowing or agreeing and it allows wide ongoing watching instead of one time chosen action.
Law enforcement agencies are using the category more and more. They do this in time with networks of CCTV cameras. This is what people call " facial recognition". It is a practice that raises a lot of concerns. The concerns, with facial recognition are really serious.
THE PRIVACY CASE AGAINST FACIAL RECOGNITION
Mass Surveillance and Chilling Effects
Civil liberties advocates say that using recognition everywhere changes public places into areas where people are always being identified. This breaks the idea that you can walk down a street or go to a public event without being recognized. Law experts compare this to worries from cases involving surveillance technology. They say just knowing you are being watched and can
be identified might stop people from doing things that're legal like going to a protest a religious event or a political meeting. This is called an “effect” on free speech and the right to gather.
Accuracy and Bias
A large amount of research including studies done by the U.S. National Institute of Standards and Technology (NIST) has shown that many facial recognition algorithms make mistakes when identifying women and people with darker skin tones than when identifying white men. These differences have caused problems in the world: there are several cases in the United States where people. Mostly Black men. Were wrongly arrested because facial recognition software incorrectly said they were suspects in crimes they did not commit. These cases are important in arguments that the technology, as it is now and, without rules to prevent mistakes is more likely to hurt communities that are already struggling.
Function Creep
Privacy advocates also warn of "function creep" technology introduced for a narrow, justified purpose (such as identifying terrorism suspects) gradually expanding into broader, less justified uses (such as monitoring general public behaviour, tracking political dissidents, or enabling commercial tracking of shoppers). Once a surveillance infrastructure exists, the argument goes, it becomes difficult to constrain its future use through policy alone.
The Security Case for Facial Recognition
People who like facial recognition technology like the police and security experts think it is really helpful. Facial recognition technology has helped find kids and kids who are being treated badly. It has also helped figure out who did things in terrorism cases. It makes getting through airport security a lot faster. When something big and bad happens the police say that facial recognition technology helps them find out who did it by looking at videos of crowds. This is a lot faster than if they had to do it all by hand. The government and security people think that if they use facial recognition technology in the way it is a good tool that helps the police do their job better and keep people safe. Facial recognition technology is a thing because it helps the police catch bad people and it makes the world a safer place. The police like facial recognition technology because it helps them solve crimes and find missing people, like missing and children.
LEGAL FRAMEWORKS AROUND THE WORLD
The United States: A Fragmented Patchwork
The United States does not have a law that covers everything about facial recognition. This means that the issue is handled by a combination of what the constitution says, laws made by states and rules made by cities. The Fourth Amendment is supposed to protect people from searches that're not reasonable. This amendment has been used in court cases about recognition. However, courts have been careful about how protection they give to people’s privacy when they are in public. This is because people are usually expected to know they can be seen when they are out, in public. The courts have used a way of thinking about this issue that was established a long time ago which is called the "reasonable expectation of privacy" framework. Facial recognition is a part of this issue and the United States is still figuring out how to deal with it.
In the absence of action states and cities have gone in different directions. Illinois Biometric Information Privacy Act (BIPA) passed in 2008 and now one of the fought over biometric privacy laws in the country says private companies must get clear written permission before collecting biometric data like faceprints and gives people the ability to take legal action if the law is broken. This law was the reason for a settlement. A major facial recognition company had taken billions of pictures from the internet to create its identification system. That company agreed to limits on its work in the United States after being sued under BIPA and, by state lawyers.
The European Union: A Rights-Based Approach
The European Union has chosen a central and rights-focused way of dealing with things. With the GDPR, data that is used to identify a person is considered a "special category" of personal data. This type of data is usually not allowed to be processed unless there is a legal reason. For example, it could be allowed if someone gives permission or if there is a strong public interest as set by law. The EUs important Artificial Intelligence Act goes further. It deals directly with recognition as part of AI rules. It says that most time remote biometric identification systems used by police in public areas are not allowed. There are a few very specific reasons where this might be allowed. For instance, looking for victims of serious crimes stopping a possible terrorist attack or finding a suspect in a major crime. Each of these cases needs approval from a judge or an independent official first. Non-time biometric identification is seen as high risk, not completely forbidden but still has strict rules. It also needs to be open and clear. There must be human supervision. This way of handling things, with levels of risk shows the EUs main idea. They believe facial recognition is an important technology that needs careful control instead of being left alone.
The United Kingdom
After leaving the EU the United Kingdom has still allowed police to use facial recognition based on old common law and data protection rules. These rules are checked by groups like the Information Commissioners Office and the Surveillance Camera Commissioner system. The courts in the UK have dealt with this issue directly. In a case that got a lot of attention the Court of Appeal said that South Wales Police used facial recognition in a way that was not legal in some ways. This was because there were not protections for who could be added to watchlists and not enough checking for possible unfair effects. This made the police change their rules.
The case showed that human rights and data protection rules can be used to limit facial recognition even without special laws, for artificial intelligence.
India and Other Developing Regulatory Landscapes
India has experienced growth in using facial recognition for police work. This includes the Automated Facial Recognition System, also called AFRS, which was introduced by the National Crime Records Bureau. The system is also used at airports and railway stations. India has not created a law about facial recognition yet. However, the Digital Personal Data Protection Act, 2023 does set rules for protecting personal data. These rules could help limit the use of data once they are fully in place. Groups that work for the good in India are worried about problems similar to those in the West. These problems include the chance of identification no clear law allowing the use of this technology on a large scale and not enough information, about how lists of people to watch are made and used.
KEY LEGAL TENSIONS REQUIRING RESOLUTION
Several unresolved tensions define the current legal landscape:
Consent versus necessity: Facial recognition in spaces inherently involves scanning people who have not given their agreement, which creates a conflict with data protection rules that are based on individual choice instead of group or constant monitoring.
Proportionality: Courts are starting to ask more than if facial recognition is used for security. They also want to know if there are invasive ways to get the same result and if the level of tracking matches the specific danger being dealt with. A rule that is clearly shown in the EU AI Acts different types of exceptions.
Accountability for error: When facial recognition leads to an arrest question about who is responsible come up. Is it the company that made the software the police department that used it or the officer who acted on what the AI said? Most places don't have answers about who is accountable.
Watchlist governance: Cases like the South Wales Police case in the UK show that even if facial recognition is not banned the way watchlists are created checked and cleaned up of illegal data is a big legal issue.
Private sector deployment: Most of the discussion has been about police. Companies in the private sector. Like shops, stadiums and property managers. Are using facial recognition for
security or marketing more and more. They often have less rules, than government groups, which adds another part to the privacy conversation that isn't looked at enough.
TOWARD A BALANCED FRAMEWORK
A common idea in the strictly controlled areas is the shift to a level-based risk-focused way of handling things instead of a general yes or no. The EUs system. Stopping time large-scale identification except in very specific court-approved situations while controlling other uses as high-risk. Gives an example that other areas seem to be looking at. Also very important are steps to protect people: checking the accuracy and fairness of computer systems on a basis being open about when and how face recognition is used clear guidelines on how long data is kept and who is put on watchlists and easy ways for people who are wrongly identified or unfairly watched to get help. For people who are just starting out in law this field offers a lot of work that touches many areas like government laws, privacy rules, government actions and technology plans. Because the rules in this area are still not the same even in big countries. There are a lot of room for important work, in legal support writing rules and taking legal action in the coming years.
CONCLUSION
Facial recognition technology is at a point where two important things meet: keeping people safe and protecting individual privacy and freedom. We cannot ignore one of these things without causing problems. If we use facial recognition technology without thinking it through it could lead to people being watched all the time, unfair policing and taking away the right to be anonymous when gathering in public or expressing ourselves. On the hand if we completely reject facial recognition technology we might miss out on real benefits to safety and investigations like finding missing people and identifying serious criminals. Different countries have ways of dealing with facial recognition technology like the European Union’s rules for using artificial intelligence Illinois laws that require consent the United Kingdom’s approach of looking at each case separately and Chinas system that is controlled by the state. This shows that there is no one way that everyone agrees on to balance these things. However, people are starting to realize that we need to have rules and oversight, for facial recognition technology and individuals need to have ways to protect themselves. As facial recognition technology gets better and is used more lawyers and lawmakers will have to make sure that trying to be safe does not hurt people’s privacy and dignity which's what the law is supposed to protect. Facial
recognition technology needs to be used in a way that respects people’s freedom and privacy and facial recognition technology should not be allowed to hurt these values.
REFERENCES
1. National Institute of Standards and Technology (NIST), Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects, NISTIR 8280 (2019).
2. Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14 (2008).
3. Regulation (EU) 2016/679, General Data Protection Regulation, Article 9 (special categories of personal data).
4. Regulation (EU) 2024/1689, Artificial Intelligence Act, provisions on prohibited practices and high-risk biometric identification systems.
5. R (Bridges) v. Chief Constable of South Wales Police [2020] EWCA Civ 1058. 6. Digital Personal Data Protection Act, 2023 (India).
7. Federal Trade Commission, In re Rite Aid Corp. (2023), enforcement action concerning unfair use of facial recognition technology in retail settings.
8. Illinois Biometric Information Privacy Act litigation and settlement, In re Clearview AI, Inc., Consumer Privacy Litigation, N.D. Ill.
9. Human Rights Watch, "China: Big Data Fuels Crackdown in Xinjiang" (2019).
10. National Crime Records Bureau, Government of India, Automated Facial Recognition System (AFRS) policy documentation.
11. Katz v. United States, 389 U.S. 347 (1967) (foundational Fourth Amendment "reasonable expectation of privacy" doctrine).
AUTHOR(s): Isha Kumari, BBA.LL.B graduate from ITM University, intern at The Legal Lock
More to Read
ANALYSIS OF THE FAME SCHEME IN THE INDIAN ELECTRIC VEHICLES MISSION
blogs
CHILDREN'S DATA PROTECTION UNDER THE DPDP FRAMEWORK
blogs
REGULATION OF AI-GENERATED DEEPFAKES UNDER INDIAN LAW
blogs
DATA FIDUCIARY LIABILITY UNDER THE DPDP FRAMEWORK
blogs
The Corporate Secrets That Leave Thousands Broken: Inside the Mass Tort Battles You Never Hear About
blogs
High-Performance Hub: Streamlining Law Firm Intake
blogs