TwinEthos homeRequest access

Control

Emotion recognition runs without the person's consent

An AI system must not determine a person's emotions unless that person has consented (or a law expressly allows it).

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Family: Biometric data from AI features is collected, kept, or disclosed without consent or limits · control id cond.emotion-recognition-without-consent

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in KZ.

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — in force 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Ask for and record the person's consent before any emotion recognition runs, and refuse to run the model without it.

A consent gate in the module that calls the emotion model (DeepFace.analyze with the emotion action, FER().detect_emotions, Hume expression measurement, Rekognition face attributes that return Emotions). The capture flow asks the person, stores the consent with a timestamp and the version of the request shown, and lets them withdraw it; the analysis function reads that record and raises or skips when it is absent or withdrawn. Where a law allows emotion inference without consent, record the legal basis per deployment instead, and keep the gate for every other use. A notice alone is not consent.

Where it goes: 1 application source code, 2 data models, 9 AI output handling.

What reviewers look for: in the file that calls the emotion model, a consent lookup (consent.get(person_id, 'emotion'), if not session.emotion_consent) read before the call and stopping it when missing; a consent capture and withdrawal route in the UI or API; no emotion inference on a path for people who never consented.

Example (Python DeepFace), before:

def mood(frame):
    return DeepFace.analyze(img_path=frame, actions=['emotion'])[0]['dominant_emotion']

After:

def mood(frame, person_id):
    if not consents.has(person_id, purpose='emotion_recognition'):
        raise ConsentRequired('ask the person before determining emotions')
    return DeepFace.analyze(img_path=frame, actions=['emotion'])[0]['dominant_emotion']

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Thele v. Google: suit alleges Gemini analysis of Gmail, Chat, and Meet content was switched on by default (2025; alleged (not proven)). A putative class action filed November 11, 2025 in the U.S. District Court for the Northern District of California (No. 5:25-cv-09704) alleges that Google secretly turned on Gemini for users' Gmail, Chat, and Meet accounts, enabling AI to track private communications without users' knowledge or consent, and that the 'Smart features' setting was on by default while still worded as an opt-in; the first amended complaint put the change on or about October 10, 2025, and the second amended complaint 'in or around the fall of 2025'. On July 7, 2026 the court granted Google's motion to dismiss the first amended complaint with leave to amend for lack of standing, observing among other things that the plaintiffs had not alleged that their own data was affected or that the Gemini features were not already on by default before October 10, 2025; it did not rule on the merits. The plaintiffs filed a second amended complaint on August 18, 2026 (ECF 39), adding a third plaintiff, and a motion to dismiss it was docketed on September 29, 2026 (ECF 43), which Law360 reported as Google's. Google's Gmail help page states that smart feature settings are off by default for people in the European Economic Area, Japan, Switzerland, and the United Kingdom. The allegations have not been adjudicated. Source: First Amended Class Action Complaint, Thele v. Google LLC, No. 5:25-cv-09704 (N.D. Cal., filed 2025-11-12, ECF 6) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in
  • Microsoft makes Recall, which analyzes screen snapshots with on-device AI, off unless the user turns it on (2024-06; disclosed by the operator). Recall periodically takes snapshots of what appears on the screen and analyzes them locally with on-device AI so people can search what they have seen. On June 7, 2024, ahead of the feature's release, Microsoft said it was updating the Copilot+ PC set-up experience to give people a clearer choice to opt in to saving snapshots, that Recall would be off by default unless the user proactively turns it on, and that Windows Hello enrollment would be required to enable it, citing feedback that it should be easier for people to choose whether to enable Recall and that privacy and security safeguards should improve. Source: Microsoft, Windows Experience Blog (Pavan Davuluri, 2024-06-07) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in
  • FTC alleges Facebook's face recognition stayed on by default while its data policy implied users had to opt in (2018-04; alleged (not proven)). The FTC's July 2019 complaint alleges that Facebook's data policy, updated in April 2018, suggested that users would need to opt in to having facial recognition enabled for their accounts, while tens of millions of users who had the older 'Tag Suggestions' setting had facial recognition turned on by default. The case was resolved by a settlement order that imposes a $5 billion penalty and requires clear and conspicuous notice of Facebook's use of facial recognition and affirmative express consent before any use that materially exceeds its prior disclosures. The allegations were not adjudicated. Source: U.S. Federal Trade Commission (press release, 2019-07-24) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in
  • FTC order requires Everalbum to delete face-recognition models trained on users' photos (2017-09; alleged (not proven)). The FTC alleged that Everalbum's Ever photo app enabled face recognition by default for most users and that, from September 2017 to August 2019, the company combined facial images extracted from users' photos with public datasets to develop its face-recognition technology, in part without affirmative express consent. Everalbum settled without admitting or denying the allegations; the final order (May 2021) requires deletion of face embeddings from users who had not consented and of any models or algorithms developed in whole or in part with Ever users' biometric information. Source: U.S. Federal Trade Commission (press release, 2021-05-07) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.