Mercado Libre Fined for Illegal Facial Recognition Requirement in Colombia

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Colombia’s data protection regulator fined Mercado Libre 214 million pesos for requiring users to submit biometric facial recognition data to access accounts, violating laws on sensitive personal data and habeas data rights. The SIC ordered Mercado Libre to cease the practice, delete collected facial data, and provide alternative authentication options.[AI generated]

Why's our monitor labelling this an incident or hazard?

Facial recognition is an AI system processing sensitive biometric data. Mercado Libre's conditioning of access on providing biometric data constitutes a violation of data protection laws and users' rights (habeas data). This is a breach of legal obligations protecting fundamental rights. The sanction confirms that harm has materialized. Therefore, this event qualifies as an AI Incident due to violation of human rights through the use of an AI system (facial recognition).[AI generated]
AI principles
Privacy & data governanceRespect of human rightsAccountabilityRobustness & digital securityTransparency & explainabilityDemocracy & human autonomy

Industries
Consumer servicesDigital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Business function:
ICT management and information security

AI system task:
Recognition/object detection


Articles about this incident or hazard