[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fr-g-cfA8Iw4T3x_N-y3Ab6i7TTbvjGpUleaSNUW4qjI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"9898e870-7d7f-4987-93b8-a14076d742eb","meta-removes-unauthorized-face-recognition-system-after-public-exposure","b3e470e0-eaf7-49c2-b9a2-8a63e6ac31ce","Meta Removes Unauthorized Face Recognition System After Public Exposure","Meta developed and deployed an unreleased face-recognition system called NameTag that created biometric faceprints and stored unrecognized faces without proper authorization or transparency. The system was only removed after external reporting exposed its existence, suggesting inadequate internal privacy controls and review processes. This incident highlights the critical importance of implementing privacy-by-design principles and proper governance over biometric data collection, especially given the sensitive nature of facial recognition technology and strict regulatory requirements.","**Immediate actions:**\n- Conduct comprehensive audit of all data collection systems to identify unauthorized biometric processing\n- Implement mandatory privacy impact assessments before deploying any biometric or facial recognition features\n- Establish clear data retention policies that prohibit storing unrecognized biometric identifiers\n\n**Long-term improvements:**\n- Develop privacy-by-design frameworks requiring legal and privacy team approval before biometric feature development\n- Implement automated compliance monitoring systems that flag potential GDPR or biometric privacy violations\n- Create transparent public documentation of all biometric data collection practices and purposes\n\n**Governance measures:**\n- Establish cross-functional review boards including legal, privacy, and ethics teams for sensitive technology deployments\n- Implement regular third-party privacy audits of data collection and processing systems",[12,13,14,15,16],"GDPR Article 9","GDPR Article 35","NIST Privacy Framework","CIS Control 3","ISO 27001 A.18.1.4","published","2026-06-08T18:20:17.358671+00:00","2026-06-08T18:20:17.239+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fmeta-removes-face-recognition-code-meta-ai-app-smart-glasses\u002F","meta-deletes-face-recognition-system-from-its-smart-glasses-app-after-wired-repo-08f318","Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]