吉隆格足球俱乐部在GMHBA Stadium推出了人脸认证快速入场选项,会员注册该系统可获得40忠诚度积分[1]。这一举措反映了澳大利亚体育场馆的新趋势,其他AFL俱乐部也正与美国人脸认证技术供应商Wicket洽谈[1]。
然而,这项便利措施引发了关于数据隐私和安全的重大隐忧。澳大利亚隐私法要求同意必须是知情的、自愿给予的、可撤销的[1],但2024年澳大利亚信息专员办公室曾发现Bunnings因未获得知情同意收集人脸数据而违反隐私法[1]。专家指出,生物识别信息与密码或信用卡号不同,一旦泄露无法更改[1]。这一风险在近期数据泄露事件的背景下更显突出,包括影响Optus、Qantas、Medibank和Origin Energy客户的多起事件[1]。有意义的知情同意应当成为保护用户的关键保障,同时需要防范网络安全威胁、未来数据使用范围扩大、功能蔓延和技术规范化等潜在风险[1]。
Australian sports venues are adopting facial recognition systems to expedite entry processes, with Geelong Football Club recently introducing facial authentication as a fast-track entry option for members at GMHBA Stadium [1]. Club members who register for facial recognition receive 40 loyalty points as an incentive [1]. Other Australian Football League clubs are currently in discussions with U.S.-based facial recognition technology provider Wicket about implementing similar systems [1].
The rollout of this technology raises significant privacy risks that warrant careful consideration. Biometric data such as facial information differs fundamentally from passwords or credit card numbers in that it cannot be changed if compromised [1]. Australia's privacy framework requires that consent for data collection be informed, voluntarily given, and revocable [1]. A 2024 investigation by the Australian Information Commissioner found that Bunnings violated privacy law by collecting facial data without obtaining informed consent [1]. Recent major data breaches affecting customers of Optus, Qantas, Medibank, and Origin Energy underscore the cybersecurity risks associated with storing sensitive personal information [1]. Beyond immediate security threats, experts caution that function creep—the gradual expansion of technology use beyond its original purpose—and the normalization of biometric surveillance in everyday settings could lead to future changes in how collected data is shared and used [1].