Facing the Realities of Facial Recognition Technology: Recommendations for Canada’s Privacy Act
Yuan Stevens, Sonja Solomun
doi.org/10.66536/facing-realities-facial-recognition_2021Executive Summary
Canada's federal institutions are collecting, using, and disclosing people's facial information, and are increasingly relying on technology that combines this information with automated decision-making processes to uniquely identify individuals. This is happening in Canada today without adequate direction and protection from the Privacy Act. The use of this technology raises significant privacy and security concerns, including the potential to enable mass surveillance and discrimination stemming from systems trained on datasets already imbued with prejudice and bias.
By implementing the following recommendations to amend the Privacy Act, the Government of Canada can mitigate serious privacy and security risks currently faced by people in Canada with respect to facial recognition technology. First, the Act should explicitly account for personal information relating to a person's physical or biological characteristics or biometric information, including facial information. Second, it should adequately safeguard the privacy and security of Canadians by requiring notice and either consent or explicit legislative permission for the collection, use, and disclosure of facial information, minimizing information collection, and expanding security safeguard requirements. Third, the Act should be aligned with the Directive on Automated Decision-Making, dictating more specific terms for use by law enforcement — including public notice, bias testing, employee training, security risk assessments, and a requirement for a human to make the final decision in high-impact cases — expanded to require adequate and meaningful consultation before deployment. Fourth, a federal moratorium on automated facial recognition and the disclosure of facial information should be implemented until this framework has been developed in consultation with Canadians and government institutions, and until more research is done on the technology's disproportionate impacts on particular demographic groups in Canada.
Addressing these gaps and weaknesses in the Privacy Act would better respect the privacy rights of people in Canada, provide stronger accountability mechanisms that improve public trust in federal institutions, and enhance federal institutions' adaptability in the face of technological change.
Related Publications

Online Harms AI Audit: Technical Brief
Read more
Online Harms AI Audit: Policy Memo
Read more
Survey on Canadians' Preference for Social Media Age Verification Policies
Read more
