Facial recognition technology in the context of personal data protection

30 September 2021

Nowadays, due to the ongoing technological advancement, we increasingly encounter the use of facial recognition technology, both by public and private entities. The application of this technology has a significant impact on individuals' right to privacy and the right to personal data protection. Therefore, it becomes crucial to obtain answers to the question: what principles should be applied when using facial recognition technology to ensure compliance with personal data protection law.

Principles of Processing Biometric Data

Personal data, such as facial images, processed by special technical methods, not only allow for the unambiguous identification and determination of a given individual but are also immutable data. Any potential breach of the protection of personal data of this particular category (e.g., a data leak of this kind) may pose a high risk to the rights and freedoms of individuals. Therefore, the processing of such personal data is permissible only exceptionally based on Article 9(2) of the GDPR, inter alia, with the explicit consent of the data subjects, for the protection of their vital interests, or when the processing is necessary for reasons of substantial public interest.

Facial recognition is the automatic processing of digital images containing the faces of individuals for the purpose of identifying or verifying those individuals using facial templates. However, not every processing of images will involve the processing of sensitive data. The context of processing these images will play a significant role in determining whether sensitive data is being processed in a given case. Images will fall under the definition of biometric data only if they are processed using a special technical means that allows for the unambiguous identification or authentication of a natural person.

Guidelines regarding the principles that should be followed when using facial recognition technology, including live facial recognition, to ensure the human rights and fundamental freedoms of every individual, including the right to personal data protection, can be found in the Guidelines on Facial Recognition adopted on January 28, 2021, by the Committee of Convention No. 108 of the Council of Europe for the protection of individuals in relation to automatic processing.

Guidelines for entities using facial recognition technology

According to the Guidelines on Facial Recognition, data processors utilizing biometric data through facial recognition technology are required to comply with all applicable principles and regulations regarding personal data protection. Above all, they must demonstrate that its use is necessary and proportionate in the specific context of its application and does not infringe upon the rights of the individuals to whom the data pertains. Furthermore, entities using facial recognition technology must ensure that the use of this technology does not affect individuals who may encounter it inadvertently.

The use of facial recognition technology by private entities requires the explicit, specific, voluntary, and informed consent of the individual to whom the data pertains. In this context, particular attention should be paid to the quality of the consent given. To ensure the voluntariness of consent, individuals whose data is being processed should be offered alternative solutions to the use of facial recognition technology (e.g., through a password or identifier) that are easy to use. If these alternatives are too lengthy or complicated compared to facial recognition technology, such a choice cannot be considered genuine.

Transparency and reliability

When utilizing facial recognition technology, a crucial element is providing all necessary information regarding this method of data processing.

Factors determining the provision of transparency include, among others: whether information is communicated to individuals, the context of data collection, reasonable expectations regarding the use of the data, whether facial recognition is merely a feature of a product or service, or whether it constitutes an integral part of the service itself. The information provided must also specify what rights and legal remedies are available to individuals whose data is being processed.

The privacy policy or informational materials regarding facial recognition technology, in addition to the typical information provided under the GDPR, should also include information regarding the retention, deletion, or removal of identifying elements of data processed in the form of facial recognition.

Purpose Limitation, Data Minimization, and Storage Limitation

Personal data being processed should be collected for specified, explicit, and legitimate purposes and must not be processed in a manner incompatible with those purposes. Furthermore, prior to any further processing, it must be considered whether the purposes of the new processing are consistent with the originally defined purposes. Otherwise, the new processing will require a separate legal basis.

DPO Function - it transfers well

Entities utilizing facial recognition technologies must adhere to the principle of data minimization, which requires that only necessary information is processed, rather than all available data. Additionally, it is essential to establish a retention period that must not exceed the time necessary for the specific purpose of processing and to ensure the deletion of biometric templates once that purpose has been fulfilled. In determining the retention period, the biometric nature of the personal data must be primarily considered.

Accuracy

Entities utilizing facial recognition technologies must ensure the accuracy and updating of biometric templates and digital images. The quality of images and biometric templates must be verified to prevent potential false matches, as low-quality images may lead to an increase in errors. In the case of incorrect matches, all necessary actions must be taken to correct future errors and ensure the accuracy of digital images and biometric templates.

Security

Given that a data breach involving facial recognition technology can have particularly severe consequences for the individuals concerned, the most effective security measures must be implemented, both at the technical and organizational levels, to protect data related to facial recognition and image sets from loss and unauthorized access or use at all stages of processing (regardless of whether it involves acquisition, transmission, or storage).

Security measures should evolve over time and in response to changing threats and identified vulnerabilities. They should also be proportional to the sensitivity of the data, the context of the use of the specific facial recognition technology, its purposes, and the likelihood of causing harm to individuals.

Accountability

Entities using facial recognition technologies are required to implement the following organizational measures:

  • implementing transparent policies, procedures, and practices to ensure that the protection of the rights of data subjects is at the core of their use of facial recognition technologies;
  • publishing reports on transparency regarding the specific use of facial recognition technologies;
  • establishing and providing training programs and audit procedures for individuals responsible for processing data related to facial recognition;
  • establishing internal verification committees to assess and approve any processing of data related to facial recognition;
  • contractually extending relevant requirements for third-party service providers, business partners, or other entities utilizing facial recognition technology and denying access to entities that do not meet these requirements.

Data Protection Impact Assessment

E-learning GDPR
E-learning GDPR is now standard!
Employees gain knowledge about data protection in an accessible and practical manner. Final tests confirm the training's effectiveness, and a certificate documents it.
SEE MORE
Entities utilizing facial recognition technologies are required to conduct a Data Protection Impact Assessment prior to processing, as the use of such technologies involves the processing of biometric data and poses a high risk of infringing the fundamental rights of data subjects. When conducting the Data Protection Impact Assessment, entities should not only identify the risks arising from potential processing but must also consider the necessary mitigating measures to address these threats by taking appropriate technical and organizational actions. In this assessment, they will clarify, among other things:

  • the legality of the use of these technologies,
  • which fundamental rights are at risk in the biometric processing,
  • the vulnerability of the data subjects,
  • how these threats can be effectively mitigated.

During the preparation of a Data Protection Impact Assessment, entities must collaborate with stakeholders, including the individuals concerned, to evaluate potential impacts from their perspective. Such assessments must be conducted at regular intervals. Upon completion of the assessment, entities should publish it to obtain public feedback regarding the potential use of facial recognition technology.

Data Protection by Design

Entities utilizing facial recognition technologies for identification or verification purposes must ensure that the products or services they use are designed to process biometric data in accordance with the principles of purpose limitation, data minimization, and storage limitation, as well as implement all other necessary safeguards. This should occur at the stage of determining the technical characteristics of these technologies (i.e., in the design phase of this technology) to ensure that their use complies with data protection law.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.