Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label biometric privacy. Show all posts

The Future of Age Verification Shifts to On-Device Privacy

 


It has become increasingly common for governments around the world to tighten online age verification requirements, as well as to incorporate a new approach to digital identity verification, which keeps facial data on the user's device rather than sending it to an external server. 

In addition to the United Kingdom, Australia, Brazil, and several US states introducing stricter rules to protect minors online, more than 30 age assurance laws are now in effect worldwide. There has been a growing concern about the gathering and storage of biometric information as platforms race to comply with regulations. 

Major technology companies have also explored alternative means of verifying the age of users in order to protect privacy. As opposed to requiring users to upload government-issued identification or selfies, newer systems are increasingly designed to collect only the essential information such as confirming that a user is part of a particular age group helping platforms comply with legal requirements while limiting the amount of personal information they collect. 

A facial age estimation system traditionally captures a user's face, uploads the image to a cloud server, and is then processed remotely. This model has been effective, however it raises significant privacy and cybersecurity concerns, particularly as biometrics become increasingly valuable targets for cybercriminals. 

As reported by the Identity Theft Resource Center's 2025 Annual Data Breach Report, 3,322 data breaches were reported in the United States in 2025, an increase of 79% compared to the previous five years. There was also a significant concern among consumers regarding how their biometric data is collected and utilized by 63% of respondents.

Identity verification company Incode has launched an on-device age estimation system to address these concerns. Under this approach, facial images are not sent to remote servers or stored after verification, but are only processed on smartphone, tablet, or laptop devices. Only the verification result-that is, whether the user complies with the required age threshold-is shared with the requesting platform. These approaches follow the principle of data minimization, where systems only collect the information necessary to carry out a specific task. 

A developer can offer age-appropriate services while limiting the exposure of sensitive personal data by confirming the eligibility of users instead of storing facial images or identity documents. Additionally, the system incorporates passive liveness detection in order to verify the presence of a real person, which prevents fraud associated with photographs, replayed videos, or artificial intelligence-generated deepfakes. 

If the age check cannot be completed successfully, users are automatically offered an alternative verification method. While facial data remains on the user's device, limited session metadata, such as device and connection characteristics, is analyzed on the server to detect tampering, injected camera feeds, and other sophisticated fraud attempts.

The company states that this information does not include biometric data and is used solely to maintain session integrity. It is nonetheless important to note that, despite these improvements, there is no foolproof age verification system. Determined users may attempt to overcome restrictions, but developers must adhere to applicable privacy regulations and implement verification technologies correctly. Generally speaking, it remains difficult to strike a balance between safeguarding children online, maintaining user privacy, and preventing unauthorized access. 

AI-powered identity fraud has become a growing concern, resulting in the shift. Incode reports that in 2024, AI-aided fraud represented only 3% of fraud attempts, but by 2026, it had increased to 40%. The company believes that figure will exceed 90% in the next 18 months. 

Besides launching its on-device authentication technology, Incode recently announced an investment of $100 million in privacy-protecting identity infrastructure and the acquisition of Identiq, a company focused on privacy.  As a result of this initiative, fraud prevention is enhanced while sensitive user information is reduced through the elimination of the need for central collection or storage. 

There is continued debate among policymakers worldwide about the operation of age assurance systems, with privacy advocates arguing that online platforms should collect as little personal information as possible. It is a reflection of an industry-wide initiative to comply with evolving regulations while reducing the risks associated with storing biometric information by switching to on-device processing and limited data sharing. 

The adoption of digital age verification has become a legal requirement across a growing number of jurisdictions. Privacy-first technologies that minimize the exposure of biometric data may increasingly influence compliance standards in the future.

Governments are increasing age verification requirements, and privacy-preserving technologies are transforming the verification of digital identity. A pivotal role in the future of online safety will be played by solutions that minimize the collection of biometric information while maintaining security and regulatory compliance.

Amazon Faces Lawsuit Over Ring Facial Recognition Practices


 

Face recognition capabilities are increasingly integrated into consumer surveillance platforms, prompting increased legal scrutiny over Amazon's Ring division's handling of biometric information. Newly filed lawsuits allege that Ring's optional "Familiar Faces" feature captures, processes, and stores facial images without obtaining consent from each individual who may have their likeness recorded. 

Privacy compliance, biometric data governance, and the legal boundaries of AI-driven identification technologies are raised as a result of this lawsuit. In the complaint, which has been filed by a Virginia resident seeking class-action status and substantial damages, one of the most widely used smart doorbell ecosystems is placed at the center of a escalating debate concerning how companies balance convenience with security and data protection. 

Charles Sigwalt, who initiated the proposed class-action lawsuit in Seattle, is at the center of the legal challenge. As part of Ring's "Familiar Faces" technology, individuals within the range of compatible doorbell cameras are scanned and classified through artificial intelligence using artificial intelligence. Sigwalt claims that the feature generates and retains an unique template of the individual's face that may be used in future encounters to identify the same individual. 

Whereas Sigwalt received no notice that his biometric information was being captured or processed during his visits to friends and relatives who used Ring devices, he claims this process occurred while he was visiting those homes. Furthermore, the lawsuit alleges that the company continues to retain such data, as well as asserting that the individuals recorded by the system did not provide consent to such collection. 

Although Amazon did not respond to the allegations, this case highlights the technical operation of Ring's "Familiar Faces" feature that was introduced in September 2025 as an optional tool to enhance visitor notifications. 

By replacing generic alerts with personalized ones, this system enables cameras to recognize recurring visitors over time and send notifications based on their names instead of the usual motion or presence alerts. However Ring claims that the feature can be enabled or disabled by the user at any time, the lawsuit raises broader questions regarding how consent mechanisms adequately address biometric data of individuals who do not own the device, but may still be subjected to facial recognition analysis despite not being device owners. 

Additionally, the complaint asserts that the collection of facial recognition data extends beyond Ring device owners and may negatively affect individuals who walk through cameras monitored entryways without their knowledge or consent. 

In the filing, it is stated that millions of people may have been able to capture their facial images by simply appearing within the viewing area of Ring-equipped properties, raising questions regarding the extent of biometric data collection in residential surveillance settings. Amazon declined to comment on the litigation, however the case adds to a growing list of privacy challenges for Ring since Amazon acquired the smart security company for $1 billion in 2018. 

Ring also faced criticism months ago over its neighborhood camera network feature, which was promoted during the Super Bowl to help users locate missing pets. There has been some controversy surrounding this initiative, since privacy advocates and some users have warned that the expansion of interconnected camera coverage could result in a broader surveillance of public spaces and residential communities than the initiative's stated objective. 

Both controversies emphasize the increased scrutiny that has been focused on the deployment of networked surveillance and the handling of biometric information on a large scale by regulators and the public. Increasingly, consumer security products are providing features such as biometric recognition and artificial intelligence-driven surveillance. 

The legal challenge filed against Ring demonstrates the growing tension between the advancement of technology and the protection of individual privacy. In this case, the outcome could affect the development of facial recognition systems, biometric data management, and the process by which organizations obtain meaningful consent from individuals who are likely to be captured by connected devices. 

As intelligent surveillance technologies continue to evolve, transparency, data governance, and privacy-by-design principles remain essential safeguards for consumers and corporations alike.

AI-Powered License Plate Surveillance Sparks Urgent Push for Stronger Privacy Laws

 


The growing use of license plate tracking systems by companies like Flock Safety and Motorola’s VehicleManager has transformed routine drives into continuously recorded digital trails. Originally designed to capture license plate data, these systems have rapidly advanced into highly sophisticated surveillance tools. With the integration of artificial intelligence, cameras can now identify not only vehicles but also faces and other distinguishing features, silently building detailed records of individuals’ movements.

This technological shift raises an important question about the effectiveness of existing privacy protections. Laws governing surveillance vary widely across states, making it difficult to determine which frameworks are truly effective and where gaps remain.

To better understand the landscape, insights were gathered from Chad Marlow, senior policy counsel and lead for surveillance at the American Civil Liberties Union. He emphasized that meaningful privacy protection requires collective effort rather than individual action. "Collective action, rather than individual action, is required," Marlow told. He also warned, "I would caution that while Flock is the most problematic ALPR company in America, there are many other ALPR companies, like Axon and Motorola, that present serious privacy risks, so switching from Flock to Axon/Motorola ALPRs at best may constitute minimal harm reduction, but it is far from a solution."

Current legislation largely focuses on two major tools used by law enforcement: automatic license plate readers (ALPRs), which track vehicles, and drones equipped with AI-enabled cameras. Meanwhile, companies are expanding into traditional surveillance cameras capable of live monitoring and tracking individuals on the ground.

Advanced AI capabilities, such as Flock’s “Freeform” search feature, allow authorities to input open-ended queries and retrieve results from vast camera networks. These developments highlight the need for updated and comprehensive regulations. Several categories of laws are emerging as particularly impactful:

Restrictions on AI Surveillance Capabilities

Some of the most comprehensive laws limit what AI-powered cameras are allowed to detect and analyze. While not always targeting ALPRs directly, they regulate how data can be searched and used. Illinois stands out with its Biometric Information Privacy Act (BIPA), which protects sensitive identifiers like facial data and fingerprints and requires user consent. This law is so strict that certain features, such as facial recognition in consumer devices, are disabled within the state. However, many of these laws still exclude vehicle and license plate data, which often remains unprotected.

Limiting ALPR Use to Specific Investigations

Several states allow ALPR usage only under defined circumstances, such as serious criminal investigations. These restrictions prevent widespread deployment by private entities like homeowners associations or businesses and may also limit camera placement in certain public areas.

Mandatory Data Deletion Policies

One of the most effective privacy safeguards requires that collected data be deleted within a set timeframe unless tied to an active investigation. This prevents long-term tracking and profiling of individuals. As Marlow explained, "The idea of keeping a location dossier on every single person just in case one of us turns out to be a criminal is just about the most un-American approach to privacy I can imagine."

States like New Hampshire enforce extremely short data retention limits, requiring deletion within minutes if the data is not used. Others allow slightly longer windows. "For states that want a little more time to see if captured ALPR data is relevant to an ongoing investigation, keeping the data for a few days is sufficient," Marlow told me. "Some states, like Washington and Virginia, recently adopted 21-day limits, which is the very outermost acceptable limit." He further cautioned that prolonged storage makes it easier to build behavioral profiles "that can eviscerate individual privacy."

Restrictions on Data Sharing Across Jurisdictions

Certain states prohibit sharing surveillance data beyond state borders, including with federal agencies. These measures aim to limit access by organizations such as the Department of Homeland Security or ICE, though enforcing such restrictions remains a challenge. As Marlow noted, "Ideally, no data should be shared outside the collecting agency without a warrant," Marlow said, "But some states have chosen to prohibit data sharing outside of the state, which is better than nothing, and does limit some risks."

Approval and Oversight Requirements

Another approach involves requiring state-level approval before installing ALPR systems. The rigor of these processes varies significantly. For example, Vermont implemented strict approval mechanisms that ultimately discouraged adoption altogether, with no agencies using ALPR systems by 2025.

Despite these efforts, new privacy laws often face resistance from companies and law enforcement agencies, sometimes leading to legal disputes and slow enforcement. Additionally, legislative proposals frequently evolve during the approval process, making it important for citizens to stay informed and engaged.

Advocacy groups and public participation also play a critical role. Initiatives like The Plate Project encourage individuals to take part in privacy discussions and reforms. Local involvement, such as attending city council meetings, can influence decisions on surveillance technology before implementation.

Ultimately, as surveillance capabilities continue to expand, the effectiveness of privacy protections will depend on both robust legislation and active public oversight.