A Vending Machine Error Message Exposed Covert Facial Recognition on a Canadian Campus
What happened
In February 2024, a student at the University of Waterloo noticed something unusual on the screen of an M&M-branded vending machine on campus: an error message that should never have been visible to someone buying a snack. The message pointed to facial recognition software running inside the machine. The student posted about it online, others started looking more closely at the machines, and within days students were covering a small concealed camera hole with chewing gum and sticky notes.
The machines were supplied by Invenda Group and operated on campus by Adaria Vending Services. A product brochure that students found online described a built-in "demographic sensor" designed to estimate the age and gender of anyone who approached. The stated purpose was to enable AI-powered product recommendations tailored to the person standing in front of the machine. The machines had been running this analysis silently, with no visible notice to the students walking up to them.
Invenda maintained that the machines did not store or transmit personally identifiable imagery, framing the demographic estimation as an anonymous inference rather than a record of individual faces. The University of Waterloo took a different view. It demanded the facial recognition software be disabled and ordered the machines removed from campus.
The incident fits a recognizable pattern in Canadian retail and public spaces. Cadillac Fairview, one of the country's largest mall operators, had previously operated hidden cameras with facial recognition to monitor shoppers, and Canadian Tire had used similar technology to collect customer demographic data. In each case the systems were already running by the time the public found out. The Waterloo case followed the same sequence: deployment first, disclosure never, exposure only by accident, triggered not by a compliance review but by a software glitch on a candy machine.
What the incident makes clear is the accountability gap running beneath all three cases. No student consented to having their face analyzed when they approached a vending machine, and nothing in the machine's appearance indicated that was happening. The university itself appears to have had limited visibility into what the machines were actually doing until students raised the alarm. That is precisely the gap a provable record of what a system did, on whose authorization it was deployed, and when collection began is meant to close: not a vendor's assurance offered after public exposure, but a documented trail that exists before the error message appears.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.