← the record
AIAAIC-1010

Mobile World Congress venue access facial recognition

The organiser of the 2021 Mobile World Congress in Barcelona, Spain, was fined EUR 200,000 by Spain's data protection regulator for illegally collecting facial data about attendees. According (pdf - in Spanish) to Spain's data protection agency AEPD, GSMA had failed to carry out a data protection impact assessment (DPIA). The GSMA had offered attendees the option of using BREEZ, an automated identify verification system, to enter the venue in person rather than manually showing their ID documentation to staff. 7,585 chose the former, despite the event taking place during the COVID-19 pandemic. Under the EU's GDPR privacy law, a DPIA must consider the necessity and proportionality of data processing, and examine the risks and how identified risks are to be minimised. However, the complai nant had contended that the GSMA had acted disproportionately by insisting in-person delegates upload their passport details online, contradicting its privacy policy. System 🤖 BREEZ Operator: GSMA Developer: ScanViS Country: Spain Sector: Business/professional services; Telecoms Purpose: Approve attendee access Technology: Facial recognition Issue: Privacy; Transparency Legal, regulatory 👩🏼‍⚖️ AEPD - GSMA/GSMC decision (pdf) Complainant explanation

Date it happened
2021-06-01
Organisation involved
GSMA
Product, system or model
BREEZ
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.