Feeds

Private ID scans leave fetish club-goers feeling exposed

If you don't go on the list, you're not coming in

The essential guide to IT transformation

A security clampdown at a London club provides a troubling glimpse of the extent of privatised monitoring brought about by government policy.

A Reg reader drew our attention to complaints that visitors to fetish club Torture Garden must now hand over personal details before they are allowed to enter. Our follow-up investigation gave disturbing new insights into the farming-out of ID checks and its implications; as Phil Booth of No2ID puts it, "Two of the biggest sources of data insecurity over the next few years will be government policy and bureaucratic abdication of responsibility."

Torture Garden regulars must provide details not because sado-masochists are believed to be more prone to violence than anyone else – in fact, research suggests that on the whole, they are often better behaved than the general public – but because Torture Garden events take place on the premises managed by SEOne Club.

Following a shooting incident (not during a TG event), police requested a licensing condition that in future, "all persons entering the premises must supply verifiable identification details that are passed through a digital scanning and recording system such as Club Scan, Idvista or similar computerised system". They duly installed Clubscan – software and equipment developed by IDScan - and now all club-goers must submit one of a number of approved pieces of ID at the door before they are allowed to enter.

IDScan promotes its system on various grounds: it helps organisations comply with legislation, particularly that relating to licensing and age restrictions; it is a useful marketing tool; it assists in maintaining exclusion lists; data can be shared amongst groups of clubs to create area exclusions; and so on.

Its core function is its ability to read 223 different IDs and 162 different passports: it is capable of storing data including, as far as we can tell, name, address, photo and passport number. It is password-protected, and we have had no complaints about its inherent security.

In the case of the SEOne set-up, a spokesman told us that only senior management can access it: that information on the system is password-protected, and the equipment is removed from the front door when the club is shut and locked in a secure place.

A spokesman added that data is retained on the system for three years, in order to comply with the Data Protection Act. IDVista make similar claims for their equipment. According to its site, it "verifies the age and validity of your customers whilst building a unique data base enabling you to monitor, manage and market to your clientele".

So where’s the problem? According to Phil Booth, this is all about coercion through the licensing system and exploitation of a culture created by the Home Office. In its drive toward ever greater security for young people. the government have passed ever more punitive legislation aimed at separating young people from dangerous items. Age limits for cigarettes and knives have both been raised. Meanwhile, the penalties for retailers under legislation such as the Licensing Act 2003 have become ever more draconian.

Speaking in respect of another of IDScan’s products, Agescan, MD Tamlyn Thompson said: "Any shops or licensed premises failing an underage test twice within three months will lose the right to sell the item in question. AgeSafe is designed to both stop teenagers buying these products and also protect retailers’ livelihoods."

The essential guide to IT transformation

More from The Register

next story
Super Cali signs a kill-switch, campaigners say it's atrocious
Remote-death button bad news for crooks, protesters – and great news for hackers?
UK government accused of hiding TRUTH about Universal Credit fiasco
'Reset rating keeps secrets on one-dole-to-rule-them-all plan', say MPs
Caught red-handed: UK cops, PCSOs, specials behaving badly… on social media
No Mr Fuzz, don't ask a crime victim to be your pal on Facebook
Ex US cybersecurity czar guilty in child sex abuse website case
Health and Human Services IT security chief headed online to share vile images
Don't even THINK about copyright violation, says Indian state
Pre-emptive arrest for pirates in Karnataka
The police are WRONG: Watching YouTube videos is NOT illegal
And our man Corfield is pretty bloody cross about it
Felony charges? Harsh! Alleged Anon hackers plead guilty to misdemeanours
US judge questions harsh sentence sought by prosecutors
prev story

Whitepapers

A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.