Biometrics and Special Category Data

Xpress Data

Free Member
Nov 6, 2018
42
1
One of my favourite topics that I come across in my client base. Want to post this and see if the DPO's/my views are supported in this instance.

Scenario 1:
A technology team within a client that I work has purchased a system designed for gauging customer and employee sentiment/mood. The system can tell in real time when a customer is then getting angry (like Bruce Banner) or if an employee is potentially being rude, having a bad day or has missed part of regulatory scripting, say when dealing with FCA credit agreements. The client is very keen to have this as we've offered it across 100% of customer/employee interactions, therefore, in their minds, they should never be non compliant with FCA regulations and customers concerns can be addressed immediately. Unfortunately, the tech team never approached their DPO before launching and selling the tool to the client, so there hasn't been any meaningful due diligence performed. When the DPO found out, they immediately highlighted the biometric data issue and article 9 special category data obligations. My opinion on this differed from their DPO's, and only being a consultant to this firm, the DPO's view was final.

My View:
Agreed that the tool was analysing biometric data by listening to tone and inflection in voices to determine attributes as mood / sentiment, however, I did not believe the use in this case qualified under article 9 as special category data. My interpretation of that rule is that biometrics become special category data when used for the purpose of uniquely identifying that individual. As the tool was not being utilised to identify the customer/employee ( these are done via a series of security questions / employee logs on with their password/username), and it was only being used as a sentiment categorisation system, it couldn't be classed as special category. Feed back from the system would be used to manage employees, however, not to uniquely identify them ( eg. my voice is my password / login) as the system would identify the employee through basic login IDs processes.

DPO View:
Saw the above as a narrow interpretation of biometrics against the special category obligations. Their argument rested on the fact that the tool would identify a trait about the data subject and therefore would fall under article 9. In fact, they argued that if the system had already gone live, they would have fallen on my argument if ever challenged by the ICO, however, as it hadn't they would stick to their guns. The DPO's reinforced their view by pointing to a (in my view) rather lazily worded paragraph in the ICO's guidance. The ICO's guidance page on biometrics starts by stating it will only be special category when used for uniquely identifying the individual and then towards the end of the guidance states that nearly all applications of biometrics will be special category data - even some beyond simply identifying the individual ( learn something about them, make a decision on them etc). Therefore, the DPO decided to take the view that biometrics used for determining sentiment/mood, and therefore to support the management of staff was unlawful as they could not see an appropriate condition for the data to be processed........much to the irk of the client and of the tech team. The system has now been shelved while the tech director spends many exasperated hours trying to convince the DPO how many of the big financial firms and their competitors utilise the same system/techniques. I've seen the use cases and companies that utilise the tech, and while in danger of being seen to take the approach of 'but others do it', some of the firms that utilise this are big on their privacy responsibilities, having privacy notices which are second to none in terms of transparency and detail.

Keen to know what you think. I had to accept their DPO's guidance, however, I'm still of the opinion that it is too wide an interpretation, and quite frankly, the wrong one.
 
There's three parts to this in my opinion;
  1. Is this an Article 9 and/or GDPR issue?
  2. Is there an ability for someone to "object" to this processing?
  3. Is this "ethical" in the context of what is being done (i.e. would the organisation involved be happy to tell everyone it's being done and how it's being used and nobody would reasonably object to it).

1.
I think you are right and the DPO is wrong when you say
My interpretation of that rule is that biometrics become special category data when used for the purpose of uniquely identifying that individual

For any special category data processing, Art9(1) specifically says "the purpose of uniquely identifying that individual", so if it cannot be used to identify people, it's not special category data.

the tool would identify a trait about the data subject and therefore would fall under article 9
This doesn't come into it. Identifying traits isn't identifying the person.

That said, if this system does have the ability whether automatically or through some manual matching of timestamps for example, to identify an individual and associate them with a user account, phone call or other activity, then it is being used to identify them and it absolutely would be special category data, as it has the ability to identify from that biometric processing.


2.
As with any processing SCD or not, the Article 21 (object) and possibly Article 22 (automated profiling & decision making) rights apply. People being processed must be informed this is being done and really should have the ability to object to it or consent to it.

3.
If the stated goal of a Data Protection Impact Assessement and/or Legitimate Interest Assessment is to improve quality of customer service, improve customer experience, and not be used to negetively affect individuals, then it could be ethical. That golden question of if you tell people what you're doing and what the benefits and drawbacks are, would a significant majority agree it's fair, proportionate and agree to it freely.
 
Upvote 0
Hi Mike

From an ethical and ability to object, the tool would have been briefed to the employees on why and what it would do and they would have the opportunity to challenge and object ( that being, go back to the standard retrospective coaching and feedback methods. The system itself doesn't have the capability to use the biometric element to match or identify the customer or employee, its pretty rudimentary to be fair.

From the article 9 perspective, as I've mentioned in the above, the DPO's interpretation rests upon the below in bold.

All biometric data is personal data, as it allows or confirms the identification of an individual. Biometric data is also special category data whenever you process it “for the purpose of uniquely identifying a natural person”. This means that biometric data will be special category data in the vast majority of cases. If you use biometrics to learn something about an individual, authenticate their identity, control their access, make a decision about them, or treat them differently in any way, you need to comply with Article 9.

No amount of debate, challenge or myself trying to highlight the WP29/EDPB guidance would change their mind. For myself, Article 9 comes into play when you are uniquely identifying the individual (voice to identify the person, act as a password etc). To be honest, I found it quite an odd argument to have as for me, this was never in article 9 territory and the ICO paragraph sentence before that in bold again reiterates that it becomes special category when used to uniquely identify. For the DPO, its as though that part didn't exist, or they simply couldn't wrap their head around the interpretation. To be honest, I've worked with them for a length of time and they're completely risk adverse (not to be judgmental but I think DPO lawyers to be the worst for this, and in this case the DPO is a former lawyer).

They've simply seen the addition or 'learn something' and 'make a decision about them' without applying the qualifying context of 'to uniquely identify that individual'.
 
Upvote 0

Latest Articles