There is an increasing trend in the use of biometric recognition technologies, which rely on biometric data to identify individuals. Examples of such technologies include facial recognition and fingerprint-scanning tools. By implementing those technologies, organisations can secure their systems, company assets, and information, from the risks of cyber-attacks and fraud. On the one side, these technologies can significantly improve security and efficiency, however, on the other side, the usage of biometric data raises data privacy concerns. Therefore, organizations must balance its benefits with taking the necessary data privacy safeguards.
What is Biometric Data?
Following the General Data Protection Regulation (GDPR), biometric data refers to the personal data, allowing a unique identification of an individual, derived from specific technical processing relating to their physical, physiological or behavioural characteristics. This data includes; facial images, fingerprints, or voice patterns. Under the GDPR, biometric data is considered to be a ‘special category’ of sensitive personal data, which is subject to stricter regulations and protections. In the workplace, the most common examples of biometric data processing include facial recognition, fingerprint or hand scanning, and voice recognition tools.
There are fines for unlawful processing!
Recently, the Italian data protection authority (Garante) imposed a fine of €120,000 on an Italian car dealing organisation, for unlawfully processing personal and biometric data of employees for recording attendance. (Here you can find the details of the fine, available in Italian)
How can you process biometric data lawfully?
Here are the key requirements to process your employees’ biometric data in comply with the data protection laws:
- Data Protection Impact Assessment (DPIA): Before implementing biometric systems, organizations must conduct a DPIA to assess potential risks to individuals’ privacy and data protection rights. Irish Data Protection Commission also highlights biometric data in its list of types of data processing activities requiring mandatory DPIA. ( Check out our previous article for the details of DPIA meaning)
- Identification of Lawful Basis: Organizations must identify a lawful basis for data processing and separate conditions for processing biometric data under Article 9 of the GDPR.
- Due Diligence: Conduct comprehansive due diligence on system providers to ensure they comply with data protection laws and provide secure, accurate systems.
- System Accuracy and Bias Mitigation: Ensure biometric systems are accurate for the determined purpose, and do not introduce biases, particularly those that could lead to discrimination based on race, gender, or other factors.
- Transparency: Clearly communicate with employees about the use of biometric data, the reasons for its use, and how their data will be handled. If your legal basis is consent, it must be informed and freely given, particularly when it is the legal basis for processing.
- Security Measures: Implement robust security measures to protect biometric data from unauthorized access, breaches, and other security threats.
- Data Retention and Deletion: Establish clear policies for data retention and ensure the deletion of when it is when no longer needed.
- Documentation and Compliance: Maintain detailed records of all processes related to biometric data handling, including DPIAs, lawful basis determinations, and compliance measures.
In early 2024, UK Information Commissioner’s Office (ICO), has released their updated guidance on biometric data on the workplace. The guidance clarifies the applicable data protection laws for the biometric recognition systems. Moreover, it provides a guideline for organisations to ensure compliance when engaging with biometric data processing activities.
Compliance with the EU AI Act
It is important to note that, many of the biometric-recognition technologies are AI-driven. Therefore organisations must ensure their compliance with the EU AI Act. (Please check our previous post on the EU AI Act publication and timelines.)
You can contact us for more information and guidance.