Feeds

Private ID scans leave fetish club-goers feeling exposed

If you don't go on the list, you're not coming in

The essential guide to IT transformation

A security clampdown at a London club provides a troubling glimpse of the extent of privatised monitoring brought about by government policy.

A Reg reader drew our attention to complaints that visitors to fetish club Torture Garden must now hand over personal details before they are allowed to enter. Our follow-up investigation gave disturbing new insights into the farming-out of ID checks and its implications; as Phil Booth of No2ID puts it, "Two of the biggest sources of data insecurity over the next few years will be government policy and bureaucratic abdication of responsibility."

Torture Garden regulars must provide details not because sado-masochists are believed to be more prone to violence than anyone else – in fact, research suggests that on the whole, they are often better behaved than the general public – but because Torture Garden events take place on the premises managed by SEOne Club.

Following a shooting incident (not during a TG event), police requested a licensing condition that in future, "all persons entering the premises must supply verifiable identification details that are passed through a digital scanning and recording system such as Club Scan, Idvista or similar computerised system". They duly installed Clubscan – software and equipment developed by IDScan - and now all club-goers must submit one of a number of approved pieces of ID at the door before they are allowed to enter.

IDScan promotes its system on various grounds: it helps organisations comply with legislation, particularly that relating to licensing and age restrictions; it is a useful marketing tool; it assists in maintaining exclusion lists; data can be shared amongst groups of clubs to create area exclusions; and so on.

Its core function is its ability to read 223 different IDs and 162 different passports: it is capable of storing data including, as far as we can tell, name, address, photo and passport number. It is password-protected, and we have had no complaints about its inherent security.

In the case of the SEOne set-up, a spokesman told us that only senior management can access it: that information on the system is password-protected, and the equipment is removed from the front door when the club is shut and locked in a secure place.

A spokesman added that data is retained on the system for three years, in order to comply with the Data Protection Act. IDVista make similar claims for their equipment. According to its site, it "verifies the age and validity of your customers whilst building a unique data base enabling you to monitor, manage and market to your clientele".

So where’s the problem? According to Phil Booth, this is all about coercion through the licensing system and exploitation of a culture created by the Home Office. In its drive toward ever greater security for young people. the government have passed ever more punitive legislation aimed at separating young people from dangerous items. Age limits for cigarettes and knives have both been raised. Meanwhile, the penalties for retailers under legislation such as the Licensing Act 2003 have become ever more draconian.

Speaking in respect of another of IDScan’s products, Agescan, MD Tamlyn Thompson said: "Any shops or licensed premises failing an underage test twice within three months will lose the right to sell the item in question. AgeSafe is designed to both stop teenagers buying these products and also protect retailers’ livelihoods."

Secure remote control for conventional and virtual desktops

More from The Register

next story
'Stop dissing Google or quit': OK, I quit, says Code Club co-founder
And now a message from our sponsors: 'STFU or else'
Top beak: UK privacy law may be reconsidered because of social media
Rise of Twitter etc creates 'enormous challenges'
Uber, Lyft and cutting corners: The true face of the Sharing Economy
Casual labour and tired ideas = not really web-tastic
Ex US cybersecurity czar guilty in child sex abuse website case
Health and Human Services IT security chief headed online to share vile images
Don't even THINK about copyright violation, says Indian state
Pre-emptive arrest for pirates in Karnataka
The police are WRONG: Watching YouTube videos is NOT illegal
And our man Corfield is pretty bloody cross about it
Oz biz regulator discovers shared servers in EPIC FACEPALM
'Not aware' that one IP can hold more than one Website
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.