Home Opinion/CommentaryIs someone watching you? Facial recognition tech is here and Canada offers little privacy protection

Is someone watching you? Facial recognition tech is here and Canada offers little privacy protection

by The Conversation
A+A-
Reset
By Neil McArthur

Amid the recent, dizzying advances in generative AI, it’s been easy to miss the slow but steady progress in facial recognition over the last decade. In the past few months, it has broken containment.

In the United States, Immigration and Customs Enforcement (ICE) has deployed a technology known as Mobile Fortify, which uses facial recognition on officers’ cellphones to “quickly verify subjects of interest during operations.”

In the United Kingdom, the Metropolitan Police scanned 4.2 million people’s faces during 2025 using live facial recognition cameras in public areas across London. And the British government recently promised to further “ramp up facial recognition and biometrics.”

Face scans may soon be everywhere and Canada’s patchwork of privacy rules is not ready to protect us. The most striking gaps concern personal and household surveillance.

Let’s look at three examples.

Ring doorbell cameras

First, there are Ring doorbell cameras. Ring, which is owned by Amazon, has sold its cameras to millions of people around the world, including many in Canada.

Last September, Ring announced it was adding facial recognition to its cameras in the form of its “Familiar Faces” feature, which scans the face of everyone who comes to your door and identifies anyone you have added to a database. That same month, it also announced “Search Party,” an AI feature that activates cameras throughout a neighbourhood to scan outdoor footage to help find a lost dog.

This provoked concerns that these two features — Search Party and facial recognition — will ultimately be combined, allowing Ring to use its network of cameras to track people as well.

These fears were seemingly confirmed by a leaked email from the company founder in which he said, though the feature was “first for finding dogs,” the company’s ultimate goal was to use it to “zero out crime in neighbourhoods.”

Equally concerning, the feature was initially supposed to operate through a partnership with Flock Safety, a surveillance technology company that works with law enforcement. After an outcry, Ring cancelled the partnership.

Meta smart glasses

The second example involves Meta, the parent company of Facebook. The New York Times revealed that Meta wants to add facial recognition to its smart glasses, according to a leaked internal memo. The company sold more than seven million pairs of smart glasses last year.

If the “Name Tag” feature works the way the company apparently hopes, it will allow the glasses to identify anyone the wearer looks at and give them information about that person using Meta’s vast database of user profiles.

Appallingly, the memo stated that the company plans to take advantage of current events in the United States, launching the feature while civil society groups “that we would expect to attack us” have “their resources focused on other concerns.”

Meta’s smart glasses have already been at the centre of a controversy after an investigation by Swedish newspapers Svenska Dagbladet and Goteborgs-Posten reported that subcontractors in Kenya reviewed intimate film and images from Meta glasses of people on the toilet, watching porn and having sex, seemingly unaware they were being recorded.

Police use of facial recognition

A third example is Canadian law enforcement. In 2024, York and Peel regional police in Ontario started using facial recognition software to, in the words of York Police Const. Kevin Nebrija, “help speed up investigations and to identify suspects sooner.”

Nebrija told the CBC that, in terms of privacy, “nothing has changed because security cameras are all around.”

In December 2025, Axon, the main supplier of body cameras in Canada, partnered with the Edmonton police department on a pilot project that allowed officers’ body cameras to identify people on a “high-risk” watch list of around 7,000 people.

Canada’s patchwork of privacy rules

Canadian privacy laws currently offer no explicit protections for our biometric data, with the exception of Québec, where Law 25 contains provisions governing its collection and use.

Everywhere else, citizens face an uneven patchwork of general privacy rules. Their application to biometrics depends on who is using the technology and in what context.

When it comes to law enforcement, Section 8 of the Canadian Charter of Rights and Freedoms does protect citizens from unreasonable searches and seizures by the police. However, whether facial recognition qualifies as a search depends in part on whether the target had a reasonable expectation of privacy.

It’s an unresolved question whether biometric scans should be subjected to a higher standard than, say, cellphone cameras, when people are scanned while walking down the street or attending a protest.

Federal law enforcement is also governed by Canada’s Privacy Act, while provinces have their own privacy acts to govern provincial and municipal police. Federal and provincial privacy commissioners, who are tasked with interpreting these acts, have emphasized the sensitivity of biometric data and the importance of due process constraints in the use of facial recognition.

They have not decreed that police must get a warrant to use facial recognition. And neither they nor the courts have ruled on programs like the one in Edmonton, where police say the database only contains known offenders.

Biometric surveillance by corporations

A federal statute — the Personal Information Protection and Electronic Documents Act (PIPEDA) — governs the collection of data by private companies and its use in commercial activity.

Under PIPEDA, companies must obtain meaningful consent before collecting personal information. The law also requires that this data collection has a legitimate purpose, and be reasonable and proportionate to that purpose.

However, the act was written before the emergence of widespread biometric surveillance. It remains unclear how it would apply when companies capture and analyze the faces of people who have no direct relationship with the organization collecting the data.

Is someone watching you?

The most striking gap in our current privacy laws appears when it comes to the actions of private individuals. The laws exempt personal and household surveillance. This means that if someone uses smart glasses or a doorbell camera to identify you or trace your movements, this would normally be legal.

Civil remedies — such as provincial privacy torts or intrusion-upon-seclusion claims — might apply in specific cases where the victim could show there was targeted or harmful misuse. But not all provinces allow such claims. And even in those that do, the legal process is reactive and fact-specific, and it depends on the victim being willing to go to court.

Canada’s privacy framework is not designed for our current moment — one in which mass surveillance is becoming a reality.

Lawmakers need to act. We should demand new, stronger privacy laws, ones that deal explicitly with facial recognition. Otherwise we may find ourselves living in a world that we no longer recognize — but one that recognizes us.

Neil McArthur, Director, Centre for Professional and Applied Ethics, University of Manitoba

This article is republished from The Conversation under a Creative Commons license. Read the original article.

You may also like

Leave a Comment