- Original Poster
- #1
One of my favourite topics that I come across in my client base. Want to post this and see if the DPO's/my views are supported in this instance.
Scenario 1:
A technology team within a client that I work has purchased a system designed for gauging customer and employee sentiment/mood. The system can tell in real time when a customer is then getting angry (like Bruce Banner) or if an employee is potentially being rude, having a bad day or has missed part of regulatory scripting, say when dealing with FCA credit agreements. The client is very keen to have this as we've offered it across 100% of customer/employee interactions, therefore, in their minds, they should never be non compliant with FCA regulations and customers concerns can be addressed immediately. Unfortunately, the tech team never approached their DPO before launching and selling the tool to the client, so there hasn't been any meaningful due diligence performed. When the DPO found out, they immediately highlighted the biometric data issue and article 9 special category data obligations. My opinion on this differed from their DPO's, and only being a consultant to this firm, the DPO's view was final.
My View:
Agreed that the tool was analysing biometric data by listening to tone and inflection in voices to determine attributes as mood / sentiment, however, I did not believe the use in this case qualified under article 9 as special category data. My interpretation of that rule is that biometrics become special category data when used for the purpose of uniquely identifying that individual. As the tool was not being utilised to identify the customer/employee ( these are done via a series of security questions / employee logs on with their password/username), and it was only being used as a sentiment categorisation system, it couldn't be classed as special category. Feed back from the system would be used to manage employees, however, not to uniquely identify them ( eg. my voice is my password / login) as the system would identify the employee through basic login IDs processes.
DPO View:
Saw the above as a narrow interpretation of biometrics against the special category obligations. Their argument rested on the fact that the tool would identify a trait about the data subject and therefore would fall under article 9. In fact, they argued that if the system had already gone live, they would have fallen on my argument if ever challenged by the ICO, however, as it hadn't they would stick to their guns. The DPO's reinforced their view by pointing to a (in my view) rather lazily worded paragraph in the ICO's guidance. The ICO's guidance page on biometrics starts by stating it will only be special category when used for uniquely identifying the individual and then towards the end of the guidance states that nearly all applications of biometrics will be special category data - even some beyond simply identifying the individual ( learn something about them, make a decision on them etc). Therefore, the DPO decided to take the view that biometrics used for determining sentiment/mood, and therefore to support the management of staff was unlawful as they could not see an appropriate condition for the data to be processed........much to the irk of the client and of the tech team. The system has now been shelved while the tech director spends many exasperated hours trying to convince the DPO how many of the big financial firms and their competitors utilise the same system/techniques. I've seen the use cases and companies that utilise the tech, and while in danger of being seen to take the approach of 'but others do it', some of the firms that utilise this are big on their privacy responsibilities, having privacy notices which are second to none in terms of transparency and detail.
Keen to know what you think. I had to accept their DPO's guidance, however, I'm still of the opinion that it is too wide an interpretation, and quite frankly, the wrong one.
Scenario 1:
A technology team within a client that I work has purchased a system designed for gauging customer and employee sentiment/mood. The system can tell in real time when a customer is then getting angry (like Bruce Banner) or if an employee is potentially being rude, having a bad day or has missed part of regulatory scripting, say when dealing with FCA credit agreements. The client is very keen to have this as we've offered it across 100% of customer/employee interactions, therefore, in their minds, they should never be non compliant with FCA regulations and customers concerns can be addressed immediately. Unfortunately, the tech team never approached their DPO before launching and selling the tool to the client, so there hasn't been any meaningful due diligence performed. When the DPO found out, they immediately highlighted the biometric data issue and article 9 special category data obligations. My opinion on this differed from their DPO's, and only being a consultant to this firm, the DPO's view was final.
My View:
Agreed that the tool was analysing biometric data by listening to tone and inflection in voices to determine attributes as mood / sentiment, however, I did not believe the use in this case qualified under article 9 as special category data. My interpretation of that rule is that biometrics become special category data when used for the purpose of uniquely identifying that individual. As the tool was not being utilised to identify the customer/employee ( these are done via a series of security questions / employee logs on with their password/username), and it was only being used as a sentiment categorisation system, it couldn't be classed as special category. Feed back from the system would be used to manage employees, however, not to uniquely identify them ( eg. my voice is my password / login) as the system would identify the employee through basic login IDs processes.
DPO View:
Saw the above as a narrow interpretation of biometrics against the special category obligations. Their argument rested on the fact that the tool would identify a trait about the data subject and therefore would fall under article 9. In fact, they argued that if the system had already gone live, they would have fallen on my argument if ever challenged by the ICO, however, as it hadn't they would stick to their guns. The DPO's reinforced their view by pointing to a (in my view) rather lazily worded paragraph in the ICO's guidance. The ICO's guidance page on biometrics starts by stating it will only be special category when used for uniquely identifying the individual and then towards the end of the guidance states that nearly all applications of biometrics will be special category data - even some beyond simply identifying the individual ( learn something about them, make a decision on them etc). Therefore, the DPO decided to take the view that biometrics used for determining sentiment/mood, and therefore to support the management of staff was unlawful as they could not see an appropriate condition for the data to be processed........much to the irk of the client and of the tech team. The system has now been shelved while the tech director spends many exasperated hours trying to convince the DPO how many of the big financial firms and their competitors utilise the same system/techniques. I've seen the use cases and companies that utilise the tech, and while in danger of being seen to take the approach of 'but others do it', some of the firms that utilise this are big on their privacy responsibilities, having privacy notices which are second to none in terms of transparency and detail.
Keen to know what you think. I had to accept their DPO's guidance, however, I'm still of the opinion that it is too wide an interpretation, and quite frankly, the wrong one.