DPE-2026-0024

Recognition of every passer-by

A recognition system records everyone it sees, while its purpose concerns only the ones it is looking for.

In het NederlandsIedereen die passeert wordt herkendWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data IoTfirmwarenetwork devicevehicle status active
Not a vulnerabilityNothing is exploited. The system records what it was built to record and the comparison works as intended; the objection is that the recording covers everyone rather than the matches.

What it is

A camera or sensor reads a characteristic that identifies a person or a vehicle, compares it against a list, and stores a record of the reading whether or not it matched. The stored record includes the identifying value, the time and the location. The purpose stated for the system concerns only the matches, but the storage covers every passage.

Why it is a separate entry

Someone who is on no list, suspected of nothing and asked for nothing acquires a location history held by a party they have no relationship with. Combined over several sites, the non-matches alone reconstruct movements. The person cannot know a record exists, and in most deployments there is nothing at the location that says so.

How it arises

Not to be confused with

Comparing against a list and discarding non-matches immediately is not this entry, however extensive the comparison. Nor is a camera that records images without recognising anything. The distinguishing feature is that identifying values of non-matches are retained.

How to establish it

Records of readings that produced no match exist after the comparison, established from the system's configuration, its export, its retention schedule, or from an access request that returns your own passage while you are on no list.

method document-comparisonQoD 78

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itI am on no list and I drove past. What do you have about me, and for how long?
In a DPIA, verify this

Verify what happens to a reading that does not match, separately from what happens to one that does.

As a procurement clause

Readings that produce no match are discarded within the comparison, demonstrated from the delivered configuration and the export.

With a complaint, hand over

The retention configuration or schedule with its date, and where possible the answer to an access request showing your own non-matching passage.

Reproduction

Legal framing

Objections, and the answer

“The readings are deleted automatically.”

After how long, and established how. A period longer than the comparison itself means the non-matches were stored, which is the finding.

“Nobody looks at the non-matches.”

Retention is processing whether or not anyone looks. The question of who may look afterwards is separate and, over years, unknowable in advance.

“There is a sign at the entrance.”

Check what it says. A notice that a camera is present is not information that an identifying characteristic is read, compared and stored, and it rarely names the controller or the retention.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0024 (Recognition of every passer-by)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0024
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0024/index.json
Full
DPE Catalogue. DPE-2026-0024: Recognition of every passer-by. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0024
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0024, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.