Senators quiz Amazon on palm scanning tech
Lawmakers fret about the privacy implications of Amazon One
 
 
Three senators have written to Amazon with questions about the company's Amazon One palm scanning technology.
The bipartisan group expressed concerns about the biometric system's effect on privacy and its potential to bolster Amazon's market position. The letter, from senators Amy Klobuchar (D-Minn.), Bill Cassidy (R-La.) and Jon Ossoff (D-Ga.) to Amazon CEO Andy Jassy, queries the company's handling of biometric data gathered using the service.
"Amazon’s expansion of biometric data collection through Amazon One raises serious questions about Amazon’s plans for this data and its respect for user privacy, including about how Amazon may use the data for advertising and tracking purposes," the letter said.
Unveiled in September 2020, Amazon One is a contactless payment system that uses palm scanning for applications, including making payments, granting access to locations, presenting loyalty cards, or clocking into work.
The company began rolling it out at its automated Amazon Go stores, which already used technologies like computer vision to replace traditional checkout operators. It has since arrived at some Whole Foods locations, which Amazon acquired in 2017.
Amazon said the service would be an optional entry method at its stores, which would still allow customers to enter using the Amazon app. At launch, the e-commerce giant also vowed to offer customers the devices, including retailers, stadiums, and office buildings.
"Our concerns about user privacy are heightened by evidence that Amazon shared voice data with third-party contractors and allegations that Amazon has violated biometric privacy laws," said the letter, referring to reports the company violated facial recognition privacy law in Illinois by using residents' faces to train its algorithms.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
It also cited a class-action lawsuit filed this month against Amazon for allegedly violating the Illinois Biometric Information Privacy Act (BIPA) with its Alexa system.
"We are also concerned that Amazon may use data from Amazon One, including data from third-party customers that may purchase and use Amazon One devices, to further cement its competitive power and suppress competition across various markets," the senators said.
Amazon recently offered consumers a $10 credit to enroll themselves on Amazon One. To do so, customers must present their credit cards and scan their palms with the Amazon One device.
RELATED RESOURCE
  
Rather than storing scans locally, the devices send them back to Amazon's cloud. This was an area of concern for the senators, who compared it with biometric scanning technology from Apple and Samsung, which store information locally on the device.
The letter asked Amazon several questions, including when the company plans to expand its use of Amazon One; how many third-party customers has it sold its technology to; how many users have signed up for the service; and whether the company pairs the scans with data from biometric systems.
The senators also asked the company to describe how it uses data from the service, with a special focus on whether it uses the data to personalize advertisements or product recommendations.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
- 
 HPE's new Cray system is a pocket powerhouse HPE's new Cray system is a pocket powerhouseNews Hewlett Packard Enterprise (HPE) had unveiled new HPC storage, liquid cooling, and supercomputing offerings ahead of SC25 
- 
 High performance and long battery life: How Dell AI PCs offer the best of both worlds High performance and long battery life: How Dell AI PCs offer the best of both worldsUnlocking the true potential of on-device AI requires a perfect balance between software and hardware 
- 
 Data (Use and Access) Act comes into force Data (Use and Access) Act comes into forcenews Organizations will be required to have an effective data protection complaints procedure and fulfil new requirements for online services that children are likely to use 
- 
 UK businesses patchy at complying with data privacy rules UK businesses patchy at complying with data privacy rulesNews Companies need clear and well-defined data privacy strategies 
- 
 Data privacy professionals are severely underfunded – and it’s only going to get worse Data privacy professionals are severely underfunded – and it’s only going to get worseNews European data privacy professionals say they're short of cash, short of skilled staff, and stressed 
- 
 Hackers are turning Amazon S3 bucket encryption against customers in new ransomware campaign – and they’ve already claimed two victims Hackers are turning Amazon S3 bucket encryption against customers in new ransomware campaign – and they’ve already claimed two victimsNews Attackers are using AWS’ server-side encryption to conduct ransomware attacks 
- 
 Four years on, how's UK GDPR holding up? Four years on, how's UK GDPR holding up?News While some SMBs are struggling, most have stepped up to the mark in terms of data governance policies 
- 
 Amazon confirms employee data compromised amid 2023 MOVEit breach claims – but the hacker behind the leak says a host of other big tech names are also implicated Amazon confirms employee data compromised amid 2023 MOVEit breach claims – but the hacker behind the leak says a host of other big tech names are also implicatedNews Millions of records stolen during the 2023 MOVEit data breach have been leaked 
- 
 Multicloud data protection and recovery Multicloud data protection and recoverywhitepaper Data is the lifeblood of every modern business, but what happens when your data is gone? 
- 
 Intelligent data security and management Intelligent data security and managementwhitepaper What will you do when ransomware hits you? 
