iTnews

Australian Federal Police restricts free software trials after Clearview AI

By Ry Crozier on Dec 16, 2021 1:24PM
Australian Federal Police restricts free software trials after Clearview AI

Privacy watchdog left unconvinced.

The Australian Federal Police’s trial of controversial facial recognition database Clearview AI was effectively ‘shadow IT’, officially unapproved and undertaken without a formal privacy assessment.

An investigation by the Office of the Australian Information Commissioner [pdf] found 10 “members” of the Australian Centre to Counter Child Exploitation (ACCCE) registered for trial accounts after learning of the tool’s existence from other authorities. 

They then uploaded a range of images - some publicly available, some “derived from images distributed using underground marketplaces”, and some of ACCCE members - to Clearview AI.

No records of access to Clearview AI, or of “many” of the files uploaded to the service, were kept.

The OAIC said that “outside of the ACCCE operational command, there was no visibility of this limited trial” of the tool.

That led to media spokespeople for the AFP initially denying the tool was being used, only for that to then be flagged internally as incorrect.

Even inside of the ACCCE, it appears not everyone was aware of the trial; following the media reports, the OAIC notes that “the ACCCE coordinator of operations sent an email requesting information on the ACCCE’s use of the facial recognition tool”.

The email sought “details of who had approved the use of the software, and what validation process was followed to ensure information security,” the OAIC said.

“The email states: ‘For clarity there should be no software used without the appropriate clearance for use’.”

The AFP said it had since tightened governance around “the use of free trials in the online environment” and “appointed a dedicated position within the ACCCE, who is responsible for undertaking software evaluations of similar kinds of applications in future.”

The force said the ACCCE members had also weighed privacy impacts of using Clearview AI “through other risk assessment mechanisms” instead of a privacy impact assessment (PIA).

“The trial participants considered that the risks were manageable in the context of the ‘limited trial’, and were outweighed by the need to share intelligence and information to best identify offenders and remove children from harm, and to respond to such matters in a timely manner,” the OAIC said in its report.

The OAIC did not accept this argument, however, and said that a PIA should have been undertaken.

In addition, Australian Information Commissioner and Privacy Commissioner Angelene Falk also said she “cannot be satisfied” that the steps the AFP has taken since the trial would prevent a recurrence.

As a result, she said the AFP would be subjected to an independent review of the changes it has made.

Clearview AI was found last month to have breached Australian privacy rules in the way the service operated.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
afpclearview aifacial recognitionfree trialgovernmentitpolicesecurityshadow itsoftware

Partner Content

Vast majority of surveyed firms still rely on password authentication
Promoted Content Vast majority of surveyed firms still rely on password authentication
DoT Victoria turns to Oracle to implement unified cloud-based platform
Promoted Content DoT Victoria turns to Oracle to implement unified cloud-based platform
Teaching tech teams every step of implementing a machine learning project
Promoted Content Teaching tech teams every step of implementing a machine learning project
How a 'micro data centre' enables your business, your way
Promoted Content How a 'micro data centre' enables your business, your way

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Ry Crozier
Dec 16 2021
1:24PM
0 Comments

Related Articles

  • Service NSW shortlists face matching tech for identity verification
  • OCR Labs upgrades gov digital ID accreditation
  • Police analyse 19 million messages captured in AN0M encrypted comms sting
  • Service NSW to bring facial verification to digital channels
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia stands up consent-as-a-service platform

Kmart Australia stands up consent-as-a-service platform

Telstra to open its 5G network to wholesale customers

Telstra to open its 5G network to wholesale customers

Active Directory defaults lead to no-fix PrivEsc vulnerability

Active Directory defaults lead to no-fix PrivEsc vulnerability

Westpac promotes its head of technology to mortgage role

Westpac promotes its head of technology to mortgage role

Digital Nation

COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
Metaverse hype will transition into new business models by mid decade: Gartner
Metaverse hype will transition into new business models by mid decade: Gartner
As NFTs gain traction, businesses start taking early bets
As NFTs gain traction, businesses start taking early bets
Case Study: PlayHQ leverages graph technologies for sports administration
Case Study: PlayHQ leverages graph technologies for sports administration
The other ‘CTO’: The emerging role of the chief transformation officer
The other ‘CTO’: The emerging role of the chief transformation officer
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.