ICO Warning Issued To School That Unlawfully Processed Student’s Biometric Data

31st July 2024

High School Violates Data Protection Laws with Facial Recognition Technology

The ICO issued a reprimand to an Essex secondary school regarding their use of facial recognition technology to take payments in the school canteen. Facial recognition technology (FRT) involves processing biometric data, for which the school did not obtain adequate consent or perform a DPIA (data protection impact assessment). This blog explores the importance of DPIAs and the need for obtaining lawful consent for biometric data processing.

The Details

The Controller, Chelmer Valley High School, started using FRT in March 2023 to take payments in the school canteen. Previous to this, the school’s cashless canteen took payment information using fingerprints, which also count as biometric data according to the ICO’s guidance and Article 4(14) of the UK GDPR.

The school failed to obtain consent from students to process their biometric data in this way, as they only sent out a letter giving parents the option to opt out if they did not want their child participating in the FRT. This is unlawful as the school relied on ‘assumed consent’ instead of obtaining explicit permission. Additionally, many of the students were 13 or over, which is old enough to consent for themselves. The school also failed to seek the opinion of its data protection officer or perform a DPIA before using the technology. 

What is a DPIA? 

A DPIA is a way of analysing and identifying any potential data protection risks that may arise as a result of a specific project or plan. A DPIA can assess the level of risk involved when processing data, identify any ways the risks can be minimised or eradicated, and determine if the level of potential risk is acceptable depending on the benefits of said processing. Failing to carry out a DPIA when required can lead to a fine of up to £8.7 million, or 2% global annual turnover, whichever is higher. You will notice that this fine is within the lower level of GDPR penalties, as fines affecting the fundamental rights of individuals are usually up to £17.5 million or 4% of global turnover where appropriate.

DPIAs are a legal requirement according to Article 35 of the UK GDPR, which states that:

“Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.” – Source: UK GDPR

If a DPIA was performed before the introduction of FRT in the school canteen’s payment system, it could have potentially revealed that facial scanning and collecting of biometric data would perhaps be ‘overkill’ for the simple purpose of collecting payments. It may have also found that the school’s ‘opt-out’ consent method was inadequate and that such processing requires affirmative consent, not assumed consent.

The ICO offers a DPIA template which is not mandatory but is a useful tool when planning a DPIA.

 “Conducting a DPIA does not have to be complex or time-consuming in every case, but there must be a level of rigour in proportion to the privacy risks arising.” – Source: ICO website

DPIAs don’t need to be overly time-consuming or complicated and can identify any potential problems that organisations may run into further down the line. They also increase general awareness of data protection, demonstrate a level of trust and responsibility, and enhance the organisation’s reputation.

The ICO’s Guidance on Biometric Data

Biometric data is data that relates to a person’s physical, physiological or biological characteristics, e.g. their voice, face, or fingerprints, and can be used to uniquely identify them. Biometric data that is used to uniquely identify someone is considered to be special category data, so in this case, the school’s FRT was using biometric recognition systems to uniquely identify their students. Special category information can only be processed if there is a valid condition for processing it, such as explicit consent. 

Prior to Chelmer Valley High School using FRT, the ICO did a case study in 2021 into the use of facial recognition technology in North Ayrshire Council schools. The NAC introduced FRT into 9 schools but then stopped the data processing after data protection concerns were raised with the ICO. In January 2023, the ICO issued a letter advising the NAC to ensure they have a valid lawful basis for processing the special category biometric data of children, ensure the processing is transparent and explained to the children in age-appropriate language, and ensure that a DPIA that complies with Article 35 requirements has been completed. While Chelmer Valley High School is not in North Ayrshire, the same advice applies.

It should also be noted, that a long-standing data protection principle applies to all forms of data processing, but especially where special category data is involved or the processing is intrusive, and that is that ‘you should always consider if you could achieve the stated purpose by less privacy intrusive methods’. The processing may be desirable for convenience, but is it truly necessary to use FRT just to take payment in the school canteen?

In conclusion, the school was in clear violation of the UK GDPR for:

  • Not obtaining explicit consent for processing children’s special category biometric data
  • Only issuing the opt-out slip to parents, when many children were old enough to decide upon consent for themselves
  • Not performing a DPIA prior to the use of FRT in the school
  • Failing to consult with students, parents or their Data Protection Officer before implementing the technology

The school was not fined, but given a reprimand and a list of recommendations for the future.

This case serves to remind us of the importance of using the least privacy-intrusive method to achieve a purpose or outcome wherever possible, obtaining explicit consent for processing special category data, not assuming that parents must give consent for the processing of their children’s data and that performing a DPIA before commencing with data processing is essential.

 

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details