Scanning codes to order meals leaks personal information; privacy protection cannot be ignored.
Compiled from: Red Star News, Southern Metropolis Daily
It is now common to use electronic ordering instead of paper menus when dining at restaurants. Each table has a QR code for scanning to order, but after entering the page, you often cannot order directly; instead, you must first follow the restaurant's official account, and some restaurants even require customers to fill in personal information such as phone numbers and birthdays to register as members before ordering. Although this has become normal in some restaurants and customers are used to it, is this series of operations truly legal and reasonable?
Additionally, the incident exposed at this year's 315 Gala about store cameras "stealing faces" has sparked heated public debate. Some well-known brands (such as Heytea and Bestore) have installed seemingly ordinary cameras in their stores that actually record customers' facial photos and consumption habits as advanced cameras. These cameras not only fail to clearly alert customers but also analyze the collected data, such as the customer's consumption preferences, number of visits, and current mood. However, customers are not only unaware of the facial recognition system but also have more private information stolen without authorization. Although Heytea immediately stated that the store cameras are only for security purposes and not for stealing customer data, this seems to have exceeded what customers can accept.
Cybersecurity Law Article 41
Network operators collecting and using personal information shall follow the principles of legality, legitimacy, and necessity, disclose the rules for collection and use, clearly state the purpose, method, and scope of information collection and use, and obtain the consent of the person being collected.
Network operators shall not collect personal information unrelated to the services they provide, shall not collect or use personal information in violation of laws, administrative regulations, or agreements between both parties, and shall process the personal information they retain in accordance with laws, administrative regulations, and agreements with users.
[1] The author's perspective
The promotion of QR code ordering is, overall, a good thing in the age of smart technology. For consumers, it allows timely ordering during peak dining hours and makes group ordering more convenient; for restaurants, it saves a lot of labor costs and makes service and operations more efficient. Additionally, customers who follow the restaurant's official account while ordering provide a targeted marketing group, which helps the restaurant operate better.
However, it now appears that in the process of promoting QR code ordering services, some restaurants have clearly gone astray for their own benefit, potentially infringing on consumers' right to choose and privacy. QR code ordering should be an option, not a necessity. Even if customers choose to order via QR code, restaurants should collect customer information strictly and standardly, ensuring customers are informed and consenting.
The same goes for "face-scanning" cameras. Although Heytea stated that they are not used to collect or analyze customer privacy information and are only for security purposes, ordinary cameras can also perform this function without needing such "high-tech products." Moreover, a warning sign should be placed near the cameras to inform customers that they are within the camera's range, so it wouldn't be called "face-scanning."
The catering industry has a wide reach and involves a huge consumer base. It cannot allow the infringement of the right to choose and privacy to become the norm. Restaurants should have basic self-awareness and a sense of privacy protection, and the industry should establish strict regulations to prevent these from becoming sources of privacy leaks.