Facial Recognition Technology

Facial recognition is an example of personal data processing and is covered by the GDPR. The General Data Protection Regulations (GDPR) stands as a robust framework protecting personal data both in the UK and across Europe.

One of the ideas behind the GDPR was to make it forward looking. Who knows where technology will go in the coming decades? For example, AI was not in anyone’s mind when the GDPR came into force in 2018. Since then facial recognition technology has also emerged, increasingly being deployed across various sectors from security to retail. Understanding how the GDPR applies in the context of of facial recognition technology is crucial to navigating the complexities of privacy and compliance.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is Facial Recognition Technology?

Technology for recognising faces is a type of artificial intelligence (AI) that can identify or verify a person by analysing their face. Here’s a breakdown of the concept with some examples:

How it Works

Facial recognition systems work by capturing a digital image or video of a person’s face. The system then analyses the image, focusing on key features like the distance between the eyes, the shape of the jawline, and the proportions of the nose and mouth. This information is compared to a database of facial images to identify or verify the person.

Examples of Applications

  • Unlocking smartphones: Many smartphones now recognise faces to unlock the device instead of a passcode.

  • Security applications: Facial recognition can be used in border or security control at airports, railways, or secure buildings.

  • Law enforcement: Law enforcement agencies can use facial recognition to identify suspects or match faces captured on surveillance cameras with known criminals.

  • Social media: Some social media platforms use facial recognition to help users tag friends in photos or suggest connections based on facial similarities.

  • Photo organisation: Facial recognition technology can be used to automatically categorise photos by the people who appear in them.

It’s important to note that this technology is still under development and can be unreliable in certain situations. For example, it may struggle to recognise faces with poor lighting, obscured by sunglasses, or with significant changes in appearance like aging or weight gain (as your author can attest). Additionally, there are privacy concerns surrounding the use of facial recognition technology. It raises questions about data collection and potential misuse..

The GDPR: an Overview

The GDPR was introduced by the European Union as a common and comprehensive data protection framework. Although the UK has left the EU, it has retained the GDPR in UK law primarily through the Data Protection Act 2018.

The GDPR is designed to safeguard personal data, establishing stringent guidelines for its processing. It emphasises principles such as lawfulness, fairness, transparency, data minimisation, accuracy, and integrity. In the context of facial recognition, GDPR’s focus on protecting sensitive data becomes particularly pertinent.

Key takeaways from the GDPR include:

  • understanding all your personal data processing needs

  • knowing the lawful basis for this data processing and

  • comply with people rights to know and control how their data are used.

Facial Recognition and Special Category Data under UK GDPR

The GDPR classifies facial recognition data as special category data. This means it receives a higher level of protection compared to other personal data due to its sensitive nature.

Here’s a breakdown of why facial recognition data falls under special category data:

  • UK GDPR Definition: Article 9(1) of the UK GDPR defines special category data as including “genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, data concerning sex life or sexual orientation, and data concerning religious belief or philosophical belief.”

  • Biometric Data for Identification: Facial recognition technology uses facial features to uniquely identify individuals. This falls squarely within the definition of biometric data for identification purposes under the UK GDPR

Additional Considerations:

  • Transparency and Fairness: Organisations must be transparent about how they use facial recognition technology and the data collected through it. Individuals should be informed of their rights concerning their facial recognition data at the point at which their data is collected.

  • Data Minimisation: As with all personal data processing the collection and storage of facial recognition data should be limited to what’s strictly necessary for the identified purpose.

  • Data Security Measures: Robust security measures must be implemented to protect facial recognition data from unauthorised access, disclosure, or loss.

Facial recognition technology offers potential benefits, but its use under UK GDPR requires careful consideration and compliance. Organisations must ensure they have a lawful basis for processing it, prioritise transparency and fairness, and implement strong data protection measures.

The Legal Basis for Using Facial Recognition Technology

To lawfully process facial recognition data, organisations must identify a valid lawful basis. Explicit consent, is one of these lawful bases. This means individuals must provide clear and affirmative agreement to their data being used.

If you re relying on consent for processing biometric data then:

  • you must get explicit consent separately from other consent; and

  • give people a way of withdrawing their consent.

Regardless of the lawful basis you use the use of biometric data must be necessary and the processing of it must be proportional.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Data Subject Rights

The GDPR gives people various rights concerning their personal data. These include the right to access, rectify, and erase their data, as well as the right to restrict processing and object to it. Data subjects also have the right to data portability, allowing them to transfer their data across different services seamlessly. Ensuring these rights are respected is a key part of processing biometric data via facial recognition technology lawfully.

Data Security

Securing biometric data necessitates robust technical and organisational measures. Encryption and pseudonymisation may play important roles in protecting data against unauthorised access and breaches. Organisations must implement stringent security protocols to safeguard facial recognition data, ensuring compliance with GDPR’s requirements.

Impact Assessments and Compliance Checks

Conducting Data Protection Impact Assessments (DPIAs) is required when you are thinking about processing biometric data.

DPIAs help identify and mitigate potential privacy risks associated with facial recognition technology. You should be able to take steps to mitigate the risk associated with facial recognition technology before you start using it.

Regular compliance audits will also help to ensure that data processing activities remain aligned with GDPR standards, addressing any vulnerabilities promptly.

 

Facial recognition technology

Case Studies and Examples

Face recognising technology has been deployed with varying degrees of success in a number of settings. Alongside the examples above it has been used in ways like:

  • shops are increasingly deploying facial recognition technology to prevent shoplifting.

  • the police have started to use it for public safety reasons.

  • in some countries schools have used it to monitor student attendance.

Each of these examples offer useful lessons in the importance of meaningful consent and ensuring the people whose data are being processed are fully informed.

Conclusion

Balancing the benefits of facial recognition technology with the stringent requirements of GDPR is a complex but essential task. Ensuring compliance not only protects individuals’ privacy but also fosters trust and accountability. As technology continues to evolve, maintaining a commitment to responsible data practices will be paramount in navigating the future of facial recognition within the framework of GDPR.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial