Facing the Realities of Facial Recognition Technology: Recommendations for Canada’s Privacy Act
February 2021
Executive Summary
Canada’s federal institutions are collecting, using, and disclosing people’s facial information. They are also increasingly relying on technology that uses this information, in combination with automated decision-making processes, to uniquely identify individuals. This is happening in Canada today, without adequate direction and protection from the Privacy Act. The use of this technology raises significant privacy and security concerns for people in Canada, including the potential to enable mass surveillance and discrimination enabled by systems trained on datasets already imbued with prejudice and bias.
By implementing the following recommendations to amend the Privacy Act, the Government of Canada can mitigate serious privacy and security risks currently faced by people in Canada with respect to facial recognition technology:
- Acknowledge and explicitly account for the existence, in the Privacy Act, of personal information relating to a person’s physical or biological characteristics or biometric information, including facial information;
- Adequately safeguard the privacy and security of Canadians by implementing requirements concerning facial information. These requirements should provide: a. Limitations on the collection, use, and disclosure of such information, requiring notice and either consent or explicit legislative permission; b. Requirements to minimize information collection; and c. More expansive security safeguard requirements.
- Align the Privacy Act with the requirements of the Directive on Automated Decision-Making. This alignment would dictate more specific terms for use by law enforcement — ensuring public notice, bias testing, employee training, security risk assessments, and the need for a human to make a final decision in the case of high-impact decisions. These requirements should be expanded to provide for adequate and meaningful consultation before the deployment of this technology.
- Implement a federal moratorium on new and expanded uses of automated facial recognition and the disclosure of facial information, until: a. The framework described in this submission has been developed in consultation with Canadians, as well as with government institutions and public servants in relevant government departments; and b. More research is done on the disproportionate impacts, or potential for disproportionate impact, on members of particular demographic groups, particular to the realities and populations in Canada