Monthly Archives: July 2026

Person facing a security gate undergoing facial recognition scan on a digital device

When “Consent” Isn’t a Choice: Why Being Forced to Hand Over Your Face Should Worry All of Us

Imagine buying tickets online, from one of the biggest ticketing platforms, for years without a problem. Then one day your account is quietly frozen. You can still see your past orders, but you can no longer buy anything. There was no warning, no explanation of what you did wrong, and no human you can talk to. To get your account working again, the company tells you there is exactly one path forward: submit a scan of your face to a third-party verification company.

That’s it. No document check. No phone call. No manual review. A facial scan, or nothing.

This is happening now, to ordinary customers, at major platforms. And while it might look like a minor inconvenience, it touches some of the most important protections we have under data protection law. Here’s why it matters — not just for one person, but for everyone.

The problem with calling it “consent”

Your face is not like an email address or a postcode. Under the GDPR, a facial scan used to identify you is special-category biometric data — the most sensitive tier of personal information, alongside health records and religious beliefs. The law sets a deliberately high bar for processing it. In most consumer situations, the only realistic legal basis is your explicit consent.

But consent has a precise legal meaning. It must be:

  • Freely given — a genuine choice, with no penalty for saying no.
  • Specific and informed — you know exactly what you’re agreeing to and who gets your data.
  • Explicit — a clear, affirmative act, not something inferred from your behaviour.

Now hold that definition against how these schemes actually work. You’re told your account will stay restricted unless you provide the scan. When you ask whether there’s any other way to prove who you are, you’re told — in writing — that there is no alternative, and that the facial scan is a condition of using the service again.

Pause on that. If something is a condition with no alternative, it is not a choice. And if it is not a choice, it cannot be “freely given consent.” You can’t dress up a requirement as a favour by calling it consent on the sign-up screen. Regulators and the courts have been clear about this for years: consent that is bundled into service access, and backed by a penalty for refusing, is not valid consent at all.

There’s an even simpler tell. Some of these systems treat you as having “consented” merely by proceeding with the verification. But consent to biometric processing must be explicit — a deliberate, unambiguous act. “You clicked next, so you agreed” is the opposite of explicit.

The illusion of alternatives

Companies defending these schemes often point to “options.” Look closely and the options tend to evaporate:

  • “Just delete your account and make a new one.” Except account deletion is frequently blocked if you’re holding tickets or orders for a future event — so you can’t leave even if you want to. And a new account runs through the same risk-scoring system, so it can be flagged and sent down the exact same biometric funnel.
  • “Completing the check restores access.” Sometimes the fine print admits it doesn’t guarantee anything.

When every exit is a dead end, the “choice” is theatre. What’s really happening is compulsory biometric collection wearing a consent costume.

Decisions made by a machine, with no one accountable

Many of these account restrictions are triggered by an automated risk-scoring model — an algorithm that decides you look suspicious. You’re rarely told what data points it used, how it weighed them, or why you specifically were flagged.

The GDPR anticipated exactly this. It gives people rights around decisions made solely by automated means that significantly affect them, including the right to meaningful human intervention and an explanation. But “human review” only counts if a human can actually reach a different outcome. If the review’s only possible result is “comply with what the algorithm already demanded,” and the company won’t explain how it reached its conclusion, that isn’t meaningful oversight. It’s a rubber stamp with a person’s name on it.

Transparency you were never given

Data protection law requires companies to tell you, up front, what they do with your data and who they share it with. Yet in several of these cases:

  • The privacy notice names some fraud-screening partners but not the biometric verification provider actually collecting your face.
  • The notice may even state the company doesn’t typically make automated decisions — while an automated model is quietly freezing accounts.

You cannot meaningfully consent to something you were never told was happening. Transparency isn’t a nicety; it’s the foundation the rest of the framework stands on.

Collecting more than necessary — and keeping it too long

Two more principles are at stake:

  • Data minimisation — you should only collect what’s genuinely necessary. If a document check or manual review can confirm someone’s identity, insisting on a facial scan and refusing every less-intrusive method suggests the goal is to harvest biometrics, not to verify identity.
  • Storage limitation — sensitive data shouldn’t be kept longer than needed. When biometric data from failed or refused checks is retained for years — often because the company chose a long retention period, not because any law requires it — that’s a serious overreach.

Why this is bigger than tickets

It’s tempting to shrug this off. It’s just an entertainment account, right? But the principle scales terrifyingly well. Once we accept “hand over your biometrics or lose access” as a normal way to use everyday services, the same logic can be applied to banking, travel, utilities, healthcare portals — anything. Your face is not a password you can change if it leaks. Once it’s captured, scored, shared with third parties, and stored, you have permanently lost control of it.

Biometric coercion normalised in low-stakes contexts becomes biometric coercion everywhere.

What people can actually do

If you find yourself in this position:

  1. Ask, in writing, for the specific legal basis for processing your biometric data, and request a non-biometric alternative (document check or manual review).
  2. Request the logic behind any automated decision affecting you, and ask for genuine human review.
  3. Make a Subject Access Request to see what data they hold and how it’s being used.
  4. Keep every reply. A company’s own written words — “there is no alternative,” “this is a condition” — are often the strongest evidence that its “consent” basis doesn’t hold up.
  5. Complain to your data protection authority. In Ireland that’s the Data Protection Commission; across the EU, every country has one. Regulators can investigate lawful basis, transparency, automated decision-making, and retention — and can order companies to change course.

The bottom line

Fraud prevention is a legitimate goal. Nobody disputes that companies need to protect their platforms. But the law is clear that fighting fraud does not give a company a blank cheque to demand the most sensitive data you have, strip away real alternatives, hide who’s involved, and then call the result “consent.”

Consent means the freedom to say no. The moment saying no costs you the service, it stops being consent — and starts being coercion. Recognising that difference, and pushing back when the line is crossed, is how we keep it from becoming the default for everything.