← Blog
· 11 min read

Eight Things Nobody Asked You Before They Scanned Your Face

In January 2020 a man named Robert Williams was arrested on his front lawn in a Detroit suburb, in front of his wife and daughters, for a shoplifting he had nothing to do with. A facial recognition system had matched his old driving-licence photo to a blurry frame of someone else. Nobody had asked him whether his licence photo could be used that way. That is where this list really starts, so we will come back to him.

You have probably already scrolled down to see if the eight things are in bold. They are. But the order matters less than you would think, because these are really one question asked eight ways: did anyone check with you first? The framework below borrows its skeleton from an ISACA briefing, “Facial Recognition and Privacy: Concerns and Solutions in the Age of AI,” which lists eight concerns. We have turned each into the question it implies, and the writing from here is our own.

A shop entrance at dusk. A clipboard with a completely blank consent form and an unused pen hangs by the door, a dome camera glows faintly above it, and a shopper walks in without looking at either.
The form exists in theory. Nobody was ever handed it.

1. “May we scan your face?”

Nobody asks, because asking is the one step that would make the system useless. A camera that needed a yes from every passer-by would identify only the people who did not mind being identified.

So consent gets relocated. It moves to a sign by the entrance in nine-point type, or to clause eleven of the ticket terms, or nowhere. When Australia’s privacy regulator looked at the hardware chain Bunnings in 2024, it found the company had run the faces of everyone who walked into dozens of stores against a watchlist, for years, without telling them in any way a customer would notice. Bunnings said it was protecting staff from violent customers, which may well be true. Both things can be true. That is rather the problem.

2. “Can you trust us to keep it safe?”

The ISACA piece makes the point that matters most here in one line: unlike a password or a card number, a face cannot be changed. Everything else about biometric security follows from that.

In 2019 researchers found a database belonging to Suprema’s BioStar 2, a building-access platform used by banks and police forces, sitting open on the internet: fingerprints, facial recognition data, unencrypted usernames and passwords, some twenty-seven million records. In 2024 it was Outabox, a vendor that ran face-scanning kiosks in Australian clubs, whose collected faces ended up on a public website. After a breach like that your bank posts you a new card. Nobody can post you a new face.

A small thing worth knowing: many systems store the face as a template rather than a photo, and vendors like to say a template “cannot be reversed.” It does not need to be. A stolen template still matches you, which is the only thing it was ever for. We went into this in why removing a biometric is nothing like deleting a file.

3. “Does this work as well on you as on the person next to you?”

Back to Robert Williams. He is Black. In 2018 Joy Buolamwini and Timnit Gebru had published Gender Shades, which tested commercial gender-classification systems and found error rates of up to about thirty-five percent for darker-skinned women against under one percent for lighter-skinned men. A year later the US standards body NIST ran nearly two hundred algorithms and reported that false positives were ten to a hundred times more likely for some demographic groups than others, depending on the algorithm.

The best systems have improved a great deal since. It would be dishonest to pretend otherwise. But the question was never only “how good is the best algorithm in a lab.” It is how good the one your local police bought is, fed a grainy still, read by a detective who has been told the computer found his man. Williams spent thirty hours in a cell. When officers showed him the surveillance frame he held it next to his face and said, reportedly, “I hope you don’t think all Black people look alike.” Our running list of documented wrongful arrests has more names on it than it should.

4. “Do you mind if we watch who turns up?”

A large crowd in a city square seen from behind, with a camera on a lamppost angled down at them, a thin violet ring of light around its lens.
A crowd used to be the safest place to hold an unpopular opinion.

Francis Ford Coppola made The Conversation in 1974, and the paranoia in it depends on surveillance being expensive: a van, three men, directional microphones, days of tape. One couple, one afternoon. The economics are what changed. A camera network with face matching watches everyone at once for the price of electricity.

In March 2025 Hungary’s parliament passed a law banning Pride marches and, in the same stroke, permitting police to use facial recognition to identify those who attended anyway. The ISACA briefing flags it as a test of EU protections for free expression, and it is. It is also a plain demonstration of what the technology is for once it is installed. The cameras were not put up for Pride. They were just there.

It would be comfortable to file this under “authoritarian regimes” and move on. But police in London run live facial recognition vans outside Tube stations, American forces have pulled protest footage through matching software, and none of that needed a new law.

5. “Mind if we build a business on it?”

Clearview AI scraped photographs from Facebook, Instagram, LinkedIn, Venmo and millions of ordinary websites, by its own later account more than thirty billion of them, and sold searches of the result to police. It asked nobody: not the people in the pictures, and not the platforms, several of which sent cease-and-desist letters that changed nothing.

Clearview is the famous one, and it sells mainly to governments. The part that touches ordinary life sits a tier below, in the consumer engines anyone can use with a credit card. Same method, smaller index, no badge required. We laid out who is actually paying in the face-search subscription business, and what those engines hold in face search engines compared. If you take one thing from this section: the scraping was the easy part. The business is the search box.

6. “Which of these laws do you happen to live under?”

In the United States the answer is decided by your postcode. Illinois passed its Biometric Information Privacy Act in 2008, long before anyone was scraping Instagram, and it remains the one American law with real teeth because it lets individuals sue. It is the reason Clearview, in a 2022 settlement with the ACLU, agreed to stop selling its database to most private companies nationwide. California’s CCPA gives residents deletion and opt-out rights. Texas and Washington have biometric statutes only the state can enforce. Most states have nothing specific at all.

Australia, which the ISACA piece also cites, has its own version of the same patchwork: surveillance-device acts that differ state by state, such as South Australia’s of 2016, sitting under a federal Privacy Act that does the heavy lifting when the regulator chooses to use it. Drive across a state line anywhere in either country and the rules covering your face change while your face does not. We keep a plainer map in is facial recognition legal?

7. “And which country’s rules apply to a website hosted somewhere else?”

Europe went furthest. The AI Act’s prohibitions, in force since February 2025, ban building facial recognition databases through untargeted scraping of the internet or CCTV, which is a description of Clearview’s business model written into law. It also restricts live biometric identification in public spaces, with exceptions wide enough that Hungary believes it can drive a law through them.

And that is the ceiling. There is no treaty, no shared standard, no agreement on what a face even is in law: personal data, biometric data, property, nothing. A face-search company can incorporate in one country, host in a second, scrape the whole world and sell to a third. Regulators in Italy, France, Greece, the UK and Australia have all fined or ordered Clearview to delete their citizens’ data. Collecting on those orders from a company with no office in your country has proved a different matter.

8. “If this goes wrong, who do you call?”

Franz Kafka’s Josef K. spends The Trial looking for the office that is handling his case. The modern version is shorter. You are stopped at a shop door, or refused a flat, or arrested, and the person in front of you says the system flagged you. Which system, run by whom, checked by whom, against what list, with what error rate? They do not know. Often nobody is obliged to.

When the US Federal Trade Commission banned the pharmacy chain Rite Aid from using facial recognition for five years, in 2023, the findings read like a checklist of absent oversight: no testing for accuracy, no check on image quality, staff acting on false matches, and the system disproportionately deployed in non-white neighbourhoods. It had run for eight years. The striking thing is not that it failed. It is that nothing in the process was designed to notice.

The one question that is yours to ask

Eight questions nobody asked you. Most of them you cannot answer alone, and we are not going to pretend a blog post changes what a parliament does. Williams, for the record, eventually won a settlement from Detroit that included new limits on how its police may use face matching. It took four years and a lawsuit.

But one corner of this is different, and it is the corner closest to you. The consumer face-search engines from question five operate under ordinary privacy law, which means they have to accept opt-out and deletion requests, and they do. They were never going to ask you. You are allowed to tell them anyway. That is a form, not a campaign, and it works today. The catch is that they re-crawl, so telling them once does not stay told.

That repetition is what FacePrivacy does. We file opt-out and removal requests with the face-search engines we support, on your behalf, and re-file them every month. We cannot promise any engine’s response, and we do not remove photos from the sites that host them. If you would rather do it by hand, our opt-out guide lists every place you actually can.

They never asked. You can still answer.

FacePrivacy files opt-out and removal requests with the major face-search engines on your behalf and re-files them monthly.

See how the removal tool works →