TECHNIQUES FOR COMPLIANCE WITH PERSONAL RIGHTS WHEN TAKING PHOTOGRAPHS OR VIDEO RECORDINGS OF PEOPLE
Patent Information
- Application Number
- DE502022003734
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-04
- Publication Date
- 2025-05-15
- Estimated Expiration
- 2042-07-04
AI Technical Summary
There is no practical procedure to determine if a person has been recorded unjustifiably, and existing methods are inadequate to prevent recordings that violate personal rights from being distributed on the internet.
A procedure involving the generation and analysis of metadata by end devices and a recording release server to determine if a third person is within the recording area, allowing for automatic blocking or deletion of recordings that violate personal rights.
This solution enables the automatic determination of potential violations of personal rights in photo and video recordings, allowing for efficient blocking or deletion of such recordings, thereby protecting individuals' privacy.
Description
[0001] The present invention relates to the technical field of techniques for complying with personal rights when taking photographs or videos of persons and, in particular, to a method, a terminal and a communication system for complying with personal rights when taking photographs or videos of persons, wherein the recordings were made by a third party and, in particular, without the knowledge of the person.
[0002] Nowadays, photos are taken using numerous devices, and in almost every situation. Smartphones in particular are capable of taking high-resolution photos or video recordings and uploading them virtually in real time to a cloud environment on the internet, thereby potentially making them accessible to the entire world population. This is particularly problematic, both for the user taking the photo and for the person being photographed, if personal rights are violated. The recordings are usually stored and processed in the system of the respective provider of the cloud environment or the provider of a social network, or at least saved in a corresponding user storage area. Automated deletion, especially after a certain period of time, is not provided for and would not always be sufficient to protect personal rights.The management of these recordings is usually the responsibility of the user who created them. However, on many social networks, usage rights are very loose and sometimes even transferred entirely to the operator.
[0003] As already indicated above, it is generally the responsibility of the user who created the recordings to ensure that they are authorized to do so or to upload them to a cloud environment. Violations of personal rights, particularly those of third parties, through video recordings or photographs are sometimes difficult to prevent or control. While such a violation of personal rights may be due to the ignorance of the user taking the recording, it can also be an oversight if a stranger walks through the frame at the moment the recording is taken.
[0004] Currently, there is no practical procedure for determining whether you have been recorded without authorization. Even if you realize that you have been recorded without authorization, it is very difficult to have the recording blocked. While stealing a device, such as a smartphone, allows you to directly destroy the recording, this carries corresponding criminal or civil consequences and, in individual cases, cannot even prevent the recording from possibly already ending up in a cloud environment of a social network like Instagram.
[0005] The problem remains how to prevent recordings, especially those that violate privacy rights, from being disseminated online and becoming accessible to everyone. This problem will be exacerbated in the future by new devices that can capture video and photographs even more "incidentally." Examples include augmented reality systems, such as smart glasses.
[0006] US 2013 / 156331 A1 describes a system for managing and sharing image and video data that tracks the location of devices to protect individuals' privacy. Metadata, such as GPS data and timestamps, are used to determine whether another person was near the recording location. If this is the case, images can be blocked or modified, for example, by blurring them. The metadata is collected from various devices and forwarded to a sharing server for analysis. An algorithm determines whether the image is shared or restricted based on the match in the location data.
[0007] US 2014 / 140575 A1 describes a system for protecting privacy in image and video recordings by blurring people or objects in images based on user preferences. The system can collect information about a device's location using triangulation via cellular base stations or GPS data. This information is stored in a database to determine whether a person who does not wish to be filmed has been captured. Based on this information, the system can modify or block the recordings to protect the privacy of those affected.
[0008] The present invention solves this problem by the features of the independent claims.
[0009] The features of the various aspects of the invention or the various embodiments described below can be combined with one another, unless this is explicitly excluded or technically mandatory.
[0010] According to the invention, a method is provided for respecting personal rights when photographing or video recordings of persons. In particular, the person is a third party of whom a user A takes unauthorized photos using their device A. Since this third party, as explained below, also carries a device, this third party is also referred to as user B. The method comprises the following steps: Taking a photo or video recording by a user A on their device A, wherein during the recording a first set of metadata is generated which is assigned to the recording, wherein the first set of metadata is suitable for characterizing a local recording area of the recording; ∘ In general, an assignment of metadata to a recording can be realized by means of a table entry, in particular an assignment to a device can be realized, for example, by means of a unique ID of the device, for example a SIM or an eSIM number. This first set of metadata can be generated directly by the device, for example if it is GPS data, i.e. the location of the recording, or the time of the recording. However, it is also possible that the first set of metadata, or at least some parameters of the set of metadata,are generated by the mobile phone provider and assigned to the recording and / or to terminal A. This can, for example, be an identity of the radio cell and / or Wi-Fi network via which terminal A communicates and exchanges data with the communication network, in particular the Internet. However, it is also possible for terminal A to receive or request the identity of the radio cell and / or Wi-Fi network and then independently generate the first set of metadata; for example, both GPS data and the identity of the radio cell (whose geographical location is stored with the mobile phone provider) are suitable for characterizing a local recording area. If, for example, the identity of the radio cell is known, with the current resolution of online-capable terminals, it is realistically only possible to violate the personal rights of a third party ifif the user was in the same radio cell or in an adjacent radio cell at the time of recording, because all other distances are simply "too great"; in a preferred embodiment, the recording area is represented by a cone of vision; generating a second set of metadata, wherein the second set of metadata is assigned to a terminal B of a user B, wherein the second set of metadata is suitable for characterizing a local position area of the terminal B; ∘ As already mentioned above with the first set of metadata, the second set of metadata can in principle also be generated directly by the second terminal and / or by the mobile phone provider or the roaming provider of the terminal B; the second set of metadata can, for example, also be GPS data of the terminal B - in contrast to the first set of metadata, the second set of metadata can contain less information,since this only needs to be suitable to characterize a local position area of the terminal B; thus, in a preferred embodiment, the recording area is represented by a cone of vision, the local position area of the terminal B merely represents a point that can lie within the cone of vision; forwarding the first set of metadata and the second set of metadata to a recording release server, wherein a localization algorithm is implemented on the recording release server to which the first set of metadata and the second set of metadata are transferred, wherein the localization algorithm is configured to determine,whether terminal B is located within the recording range of the recording based on an analysis of the metadata. ∘ The metadata can be forwarded directly from the terminals to the recording release server and / or via the mobile network provider of the respective terminal and / or by the operator of a cloud environment or the social network. According to the invention, the mobile network provider of terminal B knows which radio cells terminal B was connected to and at what times and transmits this information to the recording release server. The advantage of this is that terminal B is not "forced" to engage in data communication by terminal A taking a recording. ∘ In a very simple embodiment, the localization algorithm can determine that terminal B is within the recording range of terminal A's recording.if the distance between the GPS coordinates of the first set of metadata and the second set of metadata, in particular within a specific time window, is less than a predetermined threshold, for example, 25 m. In another embodiment, the localization algorithm can determine that terminal B is located within the recording range of the recording of terminal A if terminal B is in the same radio cell or in a neighboring radio cell when the recording was taken. However, these simple cases do not yet take into account the orientation of terminal A at the time of the recording, so that in these cases, if too many recordings are taken, it would be determined that terminal B is within the recording range of the recording; in any case, this would still provide a way to find all recordings in which the user of terminal B is located;
[0011] The method therefore offers the advantage of using a central instance, namely the recording release server, which can automatically determine whether a third person is located in a recording area. The method is based on the insight that, as a rule, almost everyone nowadays carries a device suitable for providing the second set of metadata for automated analysis. Accordingly, the third person is referred to as user B with device B. Users can, for example, register with the recording release server to participate in the process or to customize it. This also applies to operators of cloud environments and / or online social networks, although participation may also be mandatory for the latter.If it is determined according to the invention that a third person is in a recording area, this potentially constitutes a violation of personal rights, meaning that further measures can be taken.
[0012] The invention is also based on the realization that it is not absolutely necessary to transmit the actual image data of the recording, but that it is sufficient to transmit and analyze the corresponding sets of metadata. By eliminating the transmission of image data, data transfer within the communications network is significantly reduced, thus efficiently conserving resources.
[0013] If device A generates the first set of metadata and / or device B generates the second set of metadata itself, the correspondingly generated first set of metadata and / or the second set of metadata can be forwarded by device A and / or device B to the mobile provider, the cloud environment operator, the social network operator, and / or the recording sharing server. This flexibility enables the most efficient use of the data subsequently.
[0014] It can be advantageous if the metadata is forwarded to the recording sharing server by the mobile provider and / or the operator of the cloud environment or the online social network. Otherwise, every data communication from the end devices would first have to go through the recording sharing server, which would generate additional data traffic and increase the latency of the end devices' communication. The mobile provider, the operator of the cloud environment, and / or the operator of the social network can forward the metadata to the recording sharing server in a more targeted manner. For example, the operator of the cloud environment or the operator of the online social network could send the mobile provider radio cells in which recordings were made that are assigned to the first set of metadata.The mobile provider can then look in its databases to see which end devices B were in this radio cell or an adjacent radio cell during the period in question and specifically send only this metadata to the recording release server.
[0015] The image is conveniently blocked and / or deleted if device B is located within the local recording range of the image. Both blocking and deleting are effective methods for preventing the image from reaching social networks or a cloud environment. Blocking generally allows for the possibility of prompting user B to manually release the image. Deletion advantageously frees up storage space and also ensures that the image cannot be otherwise transferred to the cloud environment or a social network.
[0016] In a preferred embodiment, the localization algorithm calculates a score corresponding to the probability that terminal device B is located within the recording area of the image, with the image being deleted and / or blocked if the score exceeds a threshold. Such a score, which is based on a probability value, offers the advantage that the threshold can also be changed, particularly dynamically. Furthermore, it allows user B to individually set the threshold for themselves if they participate in this process. If user B wants to ensure that they are truly unrecognizable in the photo, they can set a lower threshold; however, user B can set the threshold higher if their privacy is not so important to them.
[0017] The localization algorithm can generate a control command to delete the recording and transmit this control command to the terminal A, whereby the terminal A deletes the recording locally upon receiving the control command.
[0018] This has the advantage of ensuring that all copies of the recording that violate personal rights are reliably deleted and are not made accessible to others in any other way.
[0019] It is possible that the recording will be released by the recording release server if device A is stored on a whitelist on the recording release server, in particular on a whitelist of user B. If the query of the corresponding whitelist is performed before analysis by the localization algorithm, analysis by the localization algorithm can be omitted. Devices can be made known to the whitelist, for example, using their telephone, SIM and / or eSIM number. For example, user B can make user A known to the whitelist, especially if this is a family member or acquaintance, so that their recordings are not blocked or deleted. On the other hand, journalists, for example, could be made known to global whitelists so that their recordings (since they could possibly be of social relevance) are definitely not blocked.
[0020] The recording sharing server can have a communication interface that allows users to configure settings on the recording sharing server. The communication interface can be implemented, for example, via a website.
[0021] In a preferred embodiment, the metadata may include: a timestamp of the photos or a time window of the video recording, ∘ by using time information the number of potentially relevant cases can be efficiently reduced. In addition the time information offers a very effective exclusion criterion as to whether a person can be seen in a recording. If the person is in a completely different location at the time the recording is made, it can be almost ruled out that the person can be seen in the recording; GPS positions of end device A and / or end device B, ∘ GPS positions can be transmitted by end devices such as smartphones, tablets and / or other wearables or assigned to the recording and are able to determine the local position of the respective end devices orto determine the location of the recording to within a few meters; radio cells used by terminal A and / or terminal B ∘ this information can be obtained from the mobile phone providers, particularly in the normal "operating mode" of the terminals, without the need for a specially set up data exchange. Using the information about the radio cell used, it can be determined whether terminal B and terminal A were in the same or adjacent radio cells, particularly at the time of the recording. This information can also be exchanged between different mobile phone providers. In particular, a central table can be stored that displays radio cells and their adjacent radio cells. digital compass data of terminal A, and / or gyroscope data of terminal A.∘ The digital compass data and / or the gyroscope data can be used to determine the direction in which device A is facing at the time of the recording. Of course, this depends on whether the recording is being made with the front or rear camera of the device.
[0022] In particular, if all the metadata listed above are used, a time-resolved recording cone can be generated.
[0023] In a preferred embodiment, in addition to the first set of metadata, the image data of the recording is forwarded.
[0024] This offers the advantage of making the image data usable for further analysis. For example, it may be that user B is within the temporally resolved field of view of the recording, but is obscured or at least obscured by other people or objects, so that their privacy rights are not violated.
[0025] In a further development of the method, the image data of the recording can be compared by the localization algorithm with image data of user B stored on the recording release server to determine whether user B is present in the recordings. Suitable image recognition programs can be used for this purpose. This offers the advantage that real recordings of user B, namely their stored image data, are used to determine whether the user is present in the recording. However, by first determining a time-resolved cone of vision, a large number of recordings can be filtered out in a first step before a computationally intensive image comparison is performed.
[0026] Conveniently, user B receives the image data of the recording if the localization algorithm detects that user B appears in the recording, whereby user B can manually release the recording.
[0027] This offers the advantage that the image can be used even if User B is visible in the image. In this sense, User B essentially grants permission to use his photo rights.
[0028] The recording sharing server can be logically connected to a cloud environment for storing the recordings or the recording sharing server can be assigned to the cloud environment.
[0029] If the recording sharing server is connected upstream of a cloud environment, it can even be prevented from reaching the cloud environment. Once the images are in a cloud environment, it may be questionable whether technical access to the recordings is even possible, which could lead to them being blocked or deleted. If the recording sharing server is assigned to a cloud environment, the cloud environment can efficiently provide the recordings to the recording sharing server for review. This is particularly possible if the provider of a cloud environment works cooperatively with the recording sharing server. In particular, it is possible that the recording sharing server is operated by a government institution.
[0030] For convenience, the recording sharing server is hosted in a secure IT environment. This offers the advantage of precluding any violation of personal rights as long as the recordings remain on the recording sharing server. In the event of a violation of personal rights, the recordings never leave the recording sharing server but are deleted directly from the recording sharing server.
[0031] A terminal is disclosed, wherein the terminal is configured to i) generate a first and / or a second set of metadata and ii) forward the first and / or a second set of metadata to a recording sharing server.
[0032] Such a device enables the above-described method to be carried out and the advantages of the method to be utilized. Appropriately configured devices can be smartphones, tablets, wearables, AR glasses, cameras, or similar devices.
[0033] Preferably, the terminal is configured to receive a control command to delete a recording associated with the first set of metadata and configured to locally delete the recording.
[0034] This makes it possible for a recording to violate personal rights, whereby the violation has been detected by the recording release server and can be automatically deleted from the device.
[0035] According to a second aspect of the invention, a communication system for respecting personal rights when taking photographs or videos of persons is provided, the communication system comprising: a terminal A of a user A, in particular a terminal A according to the second aspect of the invention, and a terminal B of a user B, in particular a terminal B according to the second aspect of the invention; a recording release server; a communications network, wherein the terminals exchange at least metadata with the recording release server at least indirectly via the communications network; wherein the communications system is configured to carry out the steps of the method described above. In particular, the localization algorithm is implemented on the recording release server.
[0036] This communication system offers the advantages already described in connection with the procedure.
[0037] Conveniently, the communication system comprises a cloud environment for storing recordings, wherein the cloud environment is in a data connection with the recording release server by means of the communication network, wherein the recording release server is logically arranged upstream of the cloud environment in the data direction.
[0038] This advantageously ensures that no recordings that violate personal rights are transferred to the cloud environment.
[0039] Further advantageous features of the present invention are defined in the patent claims.
[0040] In the following, preferred embodiments of the present invention are explained with reference to the accompanying figures: Fig. 1: shows an inventive communication system for observing personal rights during photographic or video recordings. Fig. 2: shows the inventive method for observing personal rights.
[0041] Numerous features of the present invention are explained in detail below using preferred embodiments. The present disclosure is not limited to the specifically mentioned feature combinations. Rather, the features mentioned here can be combined in any desired way to form embodiments of the invention, unless expressly excluded below.
[0042] Fig. 1 shows an embodiment of a communication system 100 according to the invention for observing personal rights during photo or video recordings.
[0043] The communication system 100 comprises terminal devices 110A, B, C, which are each assigned to users 115A, B, C. The terminal devices 110A, B, C, which are preferably embodied as smartphones 110A, B, C, are connected to a base station 125 in a communication connection 120, in particular a radio connection 120. The base station 125 can be assigned to a mobile communications provider and provides the connection of the terminal devices 110A, B, C to a communication network 130, in particular the Internet 130. The spatial radio coverage area of the base station 125 forms a radio cell A 145. The terminal devices 110A, B, C can exchange data with a recording release server 135, in particular a DRM watcher service 135, via the communication network 130. In particular, the terminals 110A, B, C can transmit metadata and / or image data from recordings to the recording release server 135.
[0044] The recording release server 135 can check, as described in more detail below, whether the personal rights of third parties have been violated on the recordings and then determine whether the recordings may be forwarded to a cloud environment 140, in particular a social network 140, or whether the recordings are blocked from being forwarded.
[0045] Specifically, this can happen as follows: A user A named Hanna is in a radio cell A with her smartphone 110A and takes a photo or a video with her smartphone 110A.
[0046] The smartphone 110A determines its geolocation at the time of the image capture. There are various ways to determine one's own geolocation. In one embodiment, the geolocation is determined via the radio cell A used, which is known in particular to the mobile operator. It is also possible to determine one's own geolocation for the image capture as longitude and latitude. Additionally, the smartphone 110A can determine the direction of the image capture using a built-in digital compass. Fig. 1 For example, a picture is taken in a direction of 60° northeast. The Smartphone 110A can also use a built-in gyroscope sensor to determine its position in space, for example, whether the camera is pointing upwards, forwards, backwards, or sideways.
[0047] All of this information, or even just a subset of it, is linked to the captured image and transmitted via the communications network 130 to the image release server 135. The transmission of this data may be accompanied by a request to review the image for violations of the personal rights of persons who happen to be in the direction of the image being captured.
[0048] The recording release server 135 has a localization algorithm configured to check whether the privacy rights of persons who happen to be in the direction of the photo have been violated. To this end, the recording release server 135 can query the HLR (Home Location Register) and / or the VLR (Visitor Location Register) of the mobile operator(s) to determine whether other users were present in the radio cell in which the recordings were taken, i.e., the present radio cell A, or whether their terminal devices 110B, C were present at the time the recording was made.
[0049] In particular, it can be determined whether the terminals 110B, C have a longitude and latitude at the time of the recording that is no more than 25 m away from the longitude and latitude of the recording made and whether the terminals 110B, C are located in approximately 240° southwest direction (60° northeast direction from the perspective of the recording, see Figur 1 ) so that they can potentially be found in the recording. Using gyroscope data, it can also be determined whether the end devices 110B, C are in the field of view of the camera of the smartphone 110A. From the data described above, a point in space can be formed with a corresponding vector, whereby the vector can represent a cone of vision and thus specifies the corridor within which a potential third person would have to have been in order to be visible in the recording.
[0050] Fig. 1 shows that user 115B and his smartphone 110B are also located within the same radio cell A 145 as user 115A. The information that user 115B and his smartphone 110B were also located within radio cell A 145, in particular at the time of the recording, can be queried or signaled by the mobile network provider, for example. If this information is transmitted to the recording release server 135, the localization algorithm can determine that user 115B was located within the local recording area 150 of the recording at the time of the recording.
[0051] However, with the available data, this determination is based solely on the match between the radio cells. To enable a more precise analysis, since it is entirely possible that user 115B is located in the same radio cell A but still does not appear in the recording, it may be advantageous to transmit additional information via smartphone 110B.
[0052] For more detailed analysis, smartphone 110B can receive a request for additional information, particularly in the form of metadata, from the recording sharing server 135. The smartphone 110B then determines its own longitude and latitude and can transmit this information to the recording sharing server 135, where the localization algorithm determines whether the recording is located, for example, less than 25 meters from the position of smartphone 110A. In the present case, smartphone 110B is 2 meters away from the position of smartphone 110A.
[0053] In addition, the localization algorithm can use the metadata associated with the recording to determine whether the smartphone 110B was within the field of view 150 of the recording at the time of the recording. If this is the case, the recording can be blocked by the recording release server 135 and / or the recording can be deleted by generating a corresponding signal. The smartphone 110B can have the option of sending certain privacy preferences of the user 115B to the recording release server 135. For example, user 115B can generally approve recordings taken by his family members using an IMSI whitelisting process. Recordings of other people whose IMSI is not on the whitelist must be generally rejected and not approved.
[0054] Fig. 1 also shows another user 115C, who is also located with their smartphone 110C within the same radio cell A as user 115A. The smartphone 110C can then also receive a request from the recording release server 135 because user 115A is taking a recording. The smartphone 110C determines its longitude and latitude, which in this case are more than 25 m from the position of the smartphone 110A, specifically 30 m. Furthermore, the smartphone 110C determines that it is located outside the possible recording angle of 60° north-east (namely 240° southwest and thus in exactly the opposite direction). The smartphone 110C reports this information to the recording release server 135. Furthermore, the smartphone 110C can transmit the privacy preferences of user 115C.Even if the privacy preferences state that no filming or photographing of user 115C is permitted, these will still be released because, in this case, smartphone 110C is more than 25 m away from the position of smartphone 110A at the time of the recording.
[0055] The recording release server 135 compares the information transmitted to it and calculates a so-called Personal Rights Violation Score (PRVS). As already mentioned above, the PRVS can be based on geolocation information and / or the direction of the film or photo recordings. Furthermore, the PRVS can take personal privacy preferences into account and report the result back to the smartphones 110 B, C. The score corresponds to the probability that a person who wishes to prevent the recording from being saved or displayed in the cloud is present in the recorded recording.
[0056] Fig. 2shows the inventive method 200 for observing personal rights. The method can be implemented in the communication system 100 and include the following steps: Step 210: Taking the photo or video recording by a user A on their terminal 110A, wherein during the recording, a first set of metadata is generated that is associated with the recording, wherein the first set of metadata is suitable for characterizing a local recording area of the recording; Step 220: Generating a second set of metadata, wherein the second set of metadata is associated with a terminal 110B of a user B, wherein the second set of metadata is suitable for characterizing a local position area of the terminal 110B;Step 230: Forwarding the first set of metadata and the second set of metadata to a recording release server, wherein a localization algorithm is implemented on the recording release server to which the first set of metadata and the second set of metadata are passed, wherein the localization algorithm is configured to determine whether the terminal 110B is located in the local recording area of the recording based on an analysis of the metadata;
Claims
1. Method for maintaining portrait rights related to photographs or video recordings of persons, comprising the following steps: - Preparing the photograph or video recording by a user A (115A) on their terminal device A (110A), wherein a first set of metadata is generated during the recording, and is assigned to the recording, wherein the first set of metadata is suitable for characterizing a local recording area of the recording; - Generating a second set of metadata, wherein the second set of metadata is assigned to a terminal device B (110B) of a user B (115B), wherein the second set of metadata is suitable for characterizing a local position area of the terminal device B (115B); - Forwarding the first set of metadata and the second set of metadata to a recording shared server (135), wherein a localisation algorithm is implemented on the recording shared server (135), to which the first set of metadata and the second set of metadata are transferred, wherein the localisation algorithm is configured to determine whether, based on an analysis of the metadata, the terminal device B (110B) is located in the local recording area of the recording, characterized in that the second set of metadata comprises information about which radio cells the terminal device B was connected to, at what times, wherein a mobile phone provider associated with the terminal device transfers to the recording shared server (135) the radio cells to which the terminal device B was connected, at what times.
2. Method according to Claim 1, wherein the recording is blocked and / or deleted if the terminal device B (110B) is located inside the local recording area of the recording.
3. Method according to one of the preceding claims, wherein the localisation algorithm calculates a score corresponding to a probability that the terminal device B (110B) is located in the recording area of the recording, wherein the recording is deleted and / or blocked if the score is higher than a threshold value.
4. Method according to one of Claims 2 to 3, wherein the localisation algorithm generates a control command to delete the recording, and this control command is transmitted to the terminal device A (110A), wherein the terminal device A (110A) deletes the recording locally upon receipt of the control command.
5. Method according to any one of the preceding claims, wherein the recording is shared if the terminal device A (110A) is stored in a whitelist on the recording shared server.
6. Method according to any one of the preceding claims, wherein metadata comprise: - a timestamp of the photographs or a time span of the video recording, - GPS positions of the terminal device A (110A) and / or terminal device B (110B), - radio cells used by the terminal device A (110A) and / or terminal device B (110B), digital compass data of the terminal device A (110A), and / or - gyroscope data of the terminal device A (110A).
7. Method according to any one of the preceding claims, wherein the image data of the recording is forwarded in addition to the first set of metadata.
8. Method according to Claim 7, wherein the image data of the recording is compared by the localisation algorithm with image data of the user B (115B) stored on the recording shared server (135) to determine whether the user B (115B) is on the recordings.
9. Method according to one of Claims 7 to 8, wherein the image data of the recording is sent to the user B (115B) if the localisation algorithm determines that the user B (115B) appears on the recording, wherein the user B (115B) can release the recording manually.
10. Method according to any one of the preceding claims, wherein the recording shared server (135) is connected logically upstream of a cloud environment (140) and / or is assigned to the cloud environment (140) for the purpose of storing the recordings.
11. Method according to any one of the preceding claims, wherein the recording shared server provides a secure IT environment.
12. Communication system for maintaining portrait rights related to photographs or video recordings of persons, comprising - a terminal device A of a user A and a terminal device B of a user B; - a recording shared server (135); - a mobile phone provider; - a communication network (130), wherein the terminal devices exchange at least metadata with the recording shared server; - wherein the communication system (100) is configured to carry out the steps of the method according to any one of Claims 1 to 11.
13. Communication system according to Claim 12, comprising a cloud environment for storing recordings, wherein the cloud environment has a data connection with the recording shared server via the communication network, wherein the recording shared server is arranged logically before the cloud environment in the data direction.