您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [美国国家电信和信息管理局]:隐私多利益相关者过程人脸识别技术 - 发现报告

隐私多利益相关者过程人脸识别技术

报告封面

hese“Privacy Best Practice Recommendations for CommercialFacialRecognitionUse”serve as general guidelines forcoveredentities. The fundamental principles underlying therecommendations are based on the Fair Information Practice Principles (FIPPs)1.T It is left to implementers and operators to determine the most appropriate way to implementeach of these privacy guidelines. Given the numerous existing uses in widely different applications (such as authentication, socialmedia and physical access control), as well as potential uses, specific /detailed practices are notfeasible or practical across this wide spectrum. These best practices are intended to provide a flexible and evolving approach to the use of facialrecognition technology, designed to keep pace with the dynamic marketplace surrounding thesetechnologies. This document is intended to provide a general roadmap to enable entities using facialrecognition technologies by recognizing differing objectives, risks and individual expectationsassociated with various applications of these technologies. These principles do not apply to the use of afacial recognitionfor the purpose of aggregate ornon-identifying analysis.For example, whenfacial recognitiontechnology is used only to countthe number of unique visitors to a retail establishment or to measure the genders orapproximate ages of people who view a store display (for marketing research purposes), thosepractices are outside the scope of these principles. These best practices do not apply to securityapplications, law enforcement, national security,intelligence or military uses, all of which are beyond the scope of this document. Definitions CoveredEntity–Any person, including corporateaffiliates, that collects, stores, orprocessesfacial templatedata.Coveredentities do not includegovernments, law enforcementagencies, national securityagencies,or intelligence agencies. Unaffiliated Third Party–Any person other than (1) a userof acovered entity’sproducts orservices; (2) acovered entity’semployees; (3)an entity under commoncontrolorownership with acoveredentity; or (4)a vendor or supplier to acovered entitywhen suchvendor or supplier is used to provide a productor service related to facial template data. Facial TemplateData–A uniquefacialattribute or measurement generated by automaticmeasurements of an individual’sfacial characteristics, which are used byacoveredentityto uniquelyidentifyan individual’s identityor authenticate an individual when the individualaccesses a system or account.Data that has been reasonably de-identified2and theunderlying document from which the data came3is not facial template data and therefore isnot covered by thesebest practices.4 Facial Recognition Technology–Acomputer program used to compare the visible physicalstructure of an individual’s face with a stored facial templateto confirm an individual’sclaimed identity or to uniquely identify an individual. Security Applications-Loss prevention and other applications intended to detect or preventshoplifting, fraud, misappropriations or other malicious and criminal activities. Transparency •Coveredentitiesare encouraged tomake available to consumers, in a reasonablemanner and location, policiesordisclosuresdescribingsuchentities’practicesregardingcollection, storage,and use of facialtemplatedata.Covered entities are encouraged toupdate their policiesordisclosureswhen they make material changes to their facialtemplate data management practices.Generally,policiesordisclosuresshoulddescribe,if applicable, and/or in the appropriate context: othereasonably foreseeablepurposes,or examples,for which the covered entitycollectsand sharesfacial template data or uses facial recognition technologies; othe covered entity’s data retention and de-identification practices; oand, if the covered entity offers the ability to review, correct, or delete facialtemplate data, the process to accomplish such actions. •Wherefacial recognitiontechnologyis used on a physical premisesthat acoveredentitycontrols,such entityis encouraged toprovideconcisenoticeto consumersthat facialrecognitiontechnology is present, and, if contextuallyappropriate, where consumerscan find more information aboutthe covered entity’s use offacial recognitiontechnology. Developing Good Data Management Practices •Whencoveredentitiesformulate their facial template data management practices, andbefore covered entities deploy facial recognition technology, they are encouragedtoconsider the following factors: oVoluntary or involuntary enrollment; 2De-identification of data—removing information from data that could reasonably be used to identify an individual person—is a subject ofintense debate. These best practices do not endorse any particular method of de-identification or set a standard for whendata has beenadequately de-identified. Instead,coveredentities should use their expertise, taking into account the type and use of personal wellness dataand using the technica