GDPR

The UK’s tax office must destroy 7 million voiceprints. Would that happen in the U.S.?

Imagine the IRS sitting on a vast database of unique voiceprints collected from millions of citizens. That’s basically what happened in the U.K., but at least the country has an agency to fix the problem. The U.S. has no such safeguard — and one of its agencies has already started collecting face scans. Her Majesty’s…


Imagine the IRS sitting on a vast database of unique voiceprints collected from millions of citizens.

That’s basically what happened in the U.K., but at least the country has an agency to fix the problem. The U.S. has no such safeguard — and one of its agencies has already started collecting face scans.

Her Majesty’s Revenue and Customs office (HMRC) has been instructing customers to submit “voiceprints” since 2017, and it may not have received proper consent to do so. 

Now, the nation’s data protection enforcement agency, the Information Commissioner’s Office (ICO) has filed an official order that the HMRC must delete the Voice ID data of 7 million citizens. It has 28 days to comply with the May 9 order. 

In the U.S., government agencies are also collecting biometric data. Customs and Border Patrol (CPB) is scanning the faces of individuals leaving the country. It says the images are encrypted, and only stored for a short time. But experts worry that introducing facial recognition technology at airports could turn them into tools of mass surveillance. That could lead to unlawful arrests, which would disproportionately affect women and people of color, who facial recognition softw

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

GDPR

GDPR wasn’t designed for AI and that’s a security problem

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…
Read More

Continue Reading
GDPR

When the intern has admin rights: GDPR in the agentic age

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…

The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm…
Read More

Continue Reading
GDPR

Nigel Farage wants to scrap ‘suffocating’ UK GDPR

Reform UK’s leader proposes ‘light-touch’ alternative, although rival politicians say plans are sparsely detailed and inconsistent with reality…

Reform UK’s leader proposes ‘light-touch’ alternative, although rival politicians say plans are sparsely detailed and inconsistent with reality…
Read More

Continue Reading
GDPR

Tech Tuesday: Data privacy and synthetic data generation tools

Data has become simultaneously the most valuable asset most organisations own and the most heavily regulated one. GDPR fines exceeded €4.5 billion cumulatively by early 2026. The EU AI Act’s classification of training data quality as a high-risk system requirement has made data provenance a legal obligation rather than a best practice…

Data has become simultaneously the most valuable asset most organisations own and the most heavily regulated one. GDPR fines exceeded €4.5 billion cumulatively by early 2026. The EU AI Act’s classification of training data quality as a high-risk system requirement has made data provenance a legal obligation rather than a best practice…
Read More

Continue Reading