Sberbank is fraudulently getting its clients to agree to biometric ID usage

Note: this is a translation of this article https://habr.com/ru/post/457686/

TL;DR: Sberbank is getting consent for collecting and using your biometric data without properly informing their clients about it.

Introduction

There is a Unified Biometric System in Russia, which is controlled by Rostelekom. Sberbank is against the UBS since it has its own system in which there are already “Millions” of clients.

But wait…

Did millions of Sberbank clients in Russia really gave their informed consent to provide their biometric data?

Do they know about it?

I recently “gave consent” (not consciously, of course), and I want to tell you about it.

Procedure

Everything began when “Sberbank Online” app offered me to give them my biometric data. I’ve repeatedly pressed “Not now” button, but didn’t refuse entriely, because I wanted to know more about how it will be collected.

Later I’ve visited Sberbank to withdraw my money from my bank account. And something miraculous happened.

Cashier asked me to insert my bank card into the terminal to confirm my withdrawal procedure. I’ve looked at the terminal and there was a really small message which contained something about biometrics.

This was my justified and informed consent: the cashier said “Insert your card”.

One more time: the glorious Sberbank system (“Blockchain”, “Big Data”, “Machine learning”) just showed a message “He should sign the agreement”. This message was shown to the cashier and she, without explaining anything, just said “Enter your PIN and agree”.

Message for the money withdrawal looks differently, of course.

Could I entirely read what exactly I was agreeing to? Of course not. This is a small screen, and the agreement, I think, is fairly long. Is it OK to collect consents that way? Of course not. It should have been a justified and informed consent.

Sberbank support

“Blockchain”, “Big Data” and “Machine learning” couldn’t help a support agent to get the information about whether or not I’ve given my consent. They told me to call the hotline.

The hotline said that in fact I’ve given my consent, but they can’t tell me where and when. Small wonder.

Conclusions

  1. Sberbank collects your consent on biometric data usage with a terminal and a PIN code.
  2. Don’t think that you will be able to actually read it, there will be 2-3 lines of text at the most.
  3. Of course the cashier won’t explain you anything about what you’re signing (and it’s not clear if she actually knows about it either)
  4. That’s why Sberbank has millions of clients who “agreed” to send their biometric data.

Join the Conversation

18 Comments

  1. Just wish to say your article is as astonishing.
    The clearness on your submit is just nice and that i can suppose you’re a professional in this subject.

    Well along with your permission allow me to snatch your RSS feed to
    stay updated with impending post. Thank you one million and please continue the rewarding work.

  2. Hey! Someone in my Myspace group shared this website with us so I came to check it out. I’m definitely enjoying the information. I’m bookmarking and will be tweeting this to my followers! Terrific blog and amazing style and design.|

  3. I’m not sure where you’re getting your information, but good topic. I needs to spend some time learning more or understanding more. Thanks for wonderful information I was looking for this info for my mission.|

  4. I like the helpful info you supply in your articles. I will bookmark your weblog and test again right here regularly. I’m slightly sure I will be told many new stuff right here! Good luck for the next!|

  5. Your style is unique compared to other people I have read stuff from. I appreciate you for posting when you’ve got the opportunity, Guess I will just book mark this web site.|

  6. First off I want to say excellent blog! I had a quick question that I’d like to ask if you don’t mind. I was interested to know how you center yourself and clear your mind before writing. I have had a hard time clearing my thoughts in getting my thoughts out. I do enjoy writing but it just seems like the first 10 to 15 minutes are generally wasted simply just trying to figure out how to begin. Any suggestions or hints? Kudos!|

Leave a comment

Leave a Reply to AffiliateLabz Cancel reply

Your email address will not be published.