🟡 Medium | Source: Schneier on Security
Madison Square Garden has been using facial recognition technology to identify and flag individuals entering its venues, including activists who oppose the use of facial recognition itself. The system was notably disabled for Taylor Swift’s wedding, highlighting a two-tier privacy model where wealth and influence can buy exemptions from mass surveillance. This case illustrates the broader societal tension around biometric data collection in public and semi-public spaces.
Security Architect’s Take: Cloud security architects procuring or advising on biometric or identity verification systems should ensure data governance frameworks explicitly address consent, purpose limitation, and the legal basis for processing biometric data under UK GDPR and the Data Protection Act 2018 — particularly given the ICO’s strict stance on biometric data as a special category. Review any vendor SLAs and access controls to ensure privileged exemptions or overrides are auditable and cannot be applied arbitrarily.
Original advisory: Facial Recognition at Madison Square Garden