The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

92 incidents closest to “Credit Passport” · matched on meaning · public reporting

WF-IEVM2516 Mar 2021

Facebook Allowed Age-Targeted Credit Card Ads Violating Its Policy

The Markup found that four companies—Aspiration, Hometap, Chime, and Varo Bank—ran Facebook ads for credit cards and home equity loans that were targeted by age, excluding users under 25 or 35. This practice violates Facebook's own anti-discrimination policy and may violate the Equal Credit Opportunity Act and California's Unruh Civil Rights Act. Facebook did not respond to requests for comment, and some advertisers said they would review their ad targeting.

Company involved
Facebook
AI system involved
Facebook Ad Platform

9 source articles · read the reporting →

WF-ASJEKJ1 Jan 2021

GSMA fined €200,000 for facial recognition privacy violation at MWC

In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.

Company involved
GSMA

10 source articles · read the reporting →

WF-G3SQSO1 Jan 2018

Canadian Tire chided by BC privacy commissioner for facial recognition without consent

Canadian Tire deployed facial recognition in at least four British Columbia stores between 2018 and 2021 to curb theft and increase staff safety. The BC Privacy Commissioner investigated and found the retailer failed to show a reasonable purpose and did not obtain customer consent, violating the province's Personal Information Protection Act. After the investigation was announced, Canadian Tire discontinued use of the system at all 12 locations and deleted customer data. The commissioner recommended stronger privacy policies and government regulation of biometric technologies.

Company involved
Canadian Tire

10 source articles · read the reporting →

WF-WM35TW1 May 2021

Mercadona fined €2.5 million for facial recognition pilot

Mercadona, a Spanish supermarket chain, tested an early-detection system using facial recognition in 48 stores to identify people with judicial restraining orders. The system, which operated with court authorisation, notified police when such a person was detected. The Spanish data protection authority (AEPD) imposed a €2.5 million fine, which Mercadona paid, and the company has since removed the system citing legal uncertainty.

Company involved
Mercadona
AI system involved
Sistema de Detección Anticipada (Early Detection System)

10 source articles · read the reporting →

WF-IK4RSL1 Jul 2016

CBSA tested facial recognition on millions at Toronto Pearson Airport in 2016

In 2016, the Canada Border Services Agency (CBSA) secretly tested facial recognition technology on millions of travellers at Toronto Pearson Airport without their knowledge. The system, supplied by Face4 Systems, matched faces against a database of previously deported individuals. The CBSA stated that no one was deported as a result of the pilot, and the technology was removed after six months. Privacy advocates raised concerns about lack of consent, transparency, and potential racial bias.

Company involved
Canada Border Services Agency
AI system involved
Faces on the Move

8 source articles · read the reporting →

Amazon expands palm-scanning payments to all Whole Foods stores amid privacy concerns

Amazon is expanding its Amazon One palm-scanning payment system to all Whole Foods stores by the end of 2023. The biometric technology, which creates a unique palm signature from vein patterns, is used for payments and identification. Privacy advocates and lawmakers have raised concerns about surveillance, data sharing, and security risks. Amazon faces a class action lawsuit under New York City's biometric privacy law for allegedly failing to provide adequate notice.

Company involved
Amazon
AI system involved
Amazon One

9 source articles · read the reporting →

Study finds credit score algorithms less accurate for minorities

A study of 50 million US consumers found that credit scoring algorithms used by mortgage lenders are less accurate for minority and low-income applicants due to sparse credit data, leading to higher rejection rates. The inaccuracy is due to noise in the data, not bias, so fairer algorithms cannot fix it. The study suggests that adjusting for bias had no effect, and that addressing the inaccuracy could reduce disparities by 50%.

Company involved
Mortgage lenders (unnamed)
AI system involved
Credit scoring algorithms

6 source articles · read the reporting →

WF-OS1OYR8 Sep 2021

LAPD told officers to collect social media data on every civilian stopped

The Los Angeles Police Department directed officers to record the social media accounts of every civilian they interviewed, including those not arrested or accused of a crime, according to records obtained by the Brennan Center for Justice. The field interview cards, which also ask for social security numbers, have raised civil liberties concerns. Prosecutors have accused three officers of using the cards to falsely label civilians as gang members. The LAPD said the policy was being updated but did not respond to questions about its use of social media monitoring tools including Media Sonar and Geofeedia.

Company involved
Los Angeles Police Department (LAPD)
AI system involved
Field interview cards, Media Sonar, Geofeedia

10 source articles · read the reporting →

Face recognition bypass used to register shell companies for tax fraud in Shanghai

In a major tax fraud case in Shanghai, criminals used face recognition cracking techniques to register shell companies on government platforms. They purchased high-resolution photos and used apps to create fake videos, then used modified phones to bypass face recognition authentication. The scheme resulted in fraudulent invoices totaling over 500 million yuan. The case was prosecuted by the Shanghai procuratorate.

7 source articles · read the reporting →

WF-XHWUDY14 Jun 2022

Zhengzhou officials punished for red health codes on depositors

Five officials in Zhengzhou were punished for ordering red health codes to be assigned to 1,317 depositors of four village banks, restricting their movement and preventing them from withdrawing savings. The officials acted without authorization, and the codes were later turned green after media coverage. Legal experts say the liability for privacy invasion remains unresolved, and the banks may face breach of contract claims.

Company involved
Zhengzhou municipal government
AI system involved
Health code system

10 source articles · read the reporting →

WF-BQBMHB4 Aug 2023

WorldCoin suspended in Kenya over data security concerns

WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.

Company involved
Tools for Humanity GmbH
AI system involved
WorldCoin

10 source articles · read the reporting →

California DMV suspends Cruise LLC driverless and deployment permits

The California Department of Motor Vehicles suspended Cruise LLC's autonomous vehicle deployment and driverless testing permits, saying the vehicles were not safe for public operation and that Cruise had misrepresented safety information. The suspension took effect immediately under California regulations. Cruise may apply to reinstate the permits once it satisfies the department's requirements. Its permit for testing with a safety driver was not affected.

Company involved
Cruise LLC

10 source articles · read the reporting →

IRCC uses AI triage for Temporary Resident Visa applications

Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.

Company involved
Immigration, Refugees and Citizenship Canada (IRCC)
AI system involved
Advanced Analytics Triage of Overseas Temporary Resident Visa Applications

10 source articles · read the reporting →

WF-LEN91Y1 May 2021

US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns

The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.

Company involved
U.S. Customs and Border Protection
AI system involved
CBP One

8 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

WF-ROMQCH5 Feb 2024

OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification

An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.

Company involved
OKX
AI system involved
OnlyFake

10 source articles · read the reporting →

WF-59AG1J1 Dec 2021

Worldcoin collected biometric data from poor villagers in Indonesia without informed consent

Worldcoin, a cryptocurrency startup, recruited users in developing countries by offering free cash in exchange for iris scans. The company used deceptive marketing, collected more personal data than acknowledged, and failed to obtain meaningful informed consent. Many users received worthless tokens instead of promised money. The company acknowledged some friction but continued its operations.

Company involved
Worldcoin
AI system involved
chrome orb

5 source articles · read the reporting →

Northeast Ohio man scammed out of $20,000 by deepfake Elton John video

A 71-year-old man in Northeast Ohio was scammed out of $20,000 after watching a deepfake video of Elton John on Instagram that falsely promised easy money through an online store. He was guided by two individuals posing as company representatives to open bank accounts and credit cards, which they then used to charge his cards. The victim, who was working part-time and seeking extra income, is now in debt and has returned to full-time work. One credit card company has credited $9,400, and he is working to recover the remaining funds.

1 source article · read the reporting →

CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR

A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.

Company involved
Dun & Bradstreet Austria GmbH

7 source articles · read the reporting →

WF-9VIXU423 Mar 2026

Woman denied state welfare card groceries after face scan fails

A grandmother rode her motorcycle several kilometres to a shop in Sapphaya district, Chai Nat province, to use her state welfare card to buy groceries for her family. After selecting items, she failed repeated facial recognition scans because her ID card photo was years old and no longer matched her appearance. She left the shop empty-handed and in tears.

Company involved
Government of Thailand (state welfare card system)

2 source articles · read the reporting →

WF-KBAMLJ1 Oct 2024

Parking Enforcement Services wrongly fines parents due to faulty licence plate cameras

Dozens of parents at a Christchurch childcare centre were wrongly issued $85 parking fines by Parking Enforcement Services after its licence plate recognition cameras failed to accurately capture multiple short visits. The company acknowledged some misreads and waived fines on appeal, but parents described the process as stressful and time-consuming. An additional camera was installed to improve accuracy.

Company involved
Parking Enforcement Services

1 source article · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

← Newerpage 3 of 4Older →