Use of facial recognition in schools. DPIA's are essential.

Facial Recognition – DPIA’s are essential

North Ayrshire council was criticised for attempting to introduce facial recognition technology so that pupils can pay for school meals in an attempt to speed up service and to reduce the risk of spreading Covid-19 via pin pads or fingerprint recognition.

However, the authority came under fire from privacy campaigners and the Information Commissioner’s Office (ICO) stepped in.
The council stated that the “facial registrations” are encrypted and cannot be used by another agency, and when the student leaves school or opts out of the system, they will be deleted.” And that it added : “Facial recognition has been assessed as the optimal solution that will meet all our requirements.”
Many parents questioned its use and said that the phrasing of the consent that they were asked to give for its use wasn’t “freely given, specific, informed and unambiguous indication of the data subject’s wishes..”
Concerns have also been raised previously about facial recognition technology because it frequently misidentifies women and people of colour.
Significantly, the biometrics company refused to disclose who else children’s personal information could be shared, which should certainly ring alarm bells.
In response to the queries, the ICO commented that “Data protection law provides additional protections for children, and organisations need to carefully consider the necessity and proportionality of collecting biometric data before they do so,” an ICO spokesperson told the Guardian.
“Organisations should consider using a different approach if the same goal can be achieved in a less intrusive manner. We are aware of the introduction, and will be making inquiries with North Ayrshire council.”
This prompted the Council to suspend the initiative.
The matter highlights a few things:
  • Firstly, whilst the Council claims it was an appropriate system to use, each school should conduct their own Data Protection Impact Assessment to prove that they are satisfied with the features of the product. 
  • Also it is important to understand that the UK GDPR is in place to protect the individual not an organisation, and the individual’s protection should be paramount. Not knowing things such as exactly where personal data is stored or with whom it is being shared are unacceptable. 
Sharing Personal Data with the Police

Sharing Personal Data with the Police

One of the most common questions we get asked concerns sharing data with law enforcement offices. The UK GDPR does not prevent you sharing personal data with such bodies such as the police (known under data protection law as “competent authorities”) who are...

Core Principles of Data Protection

Core Principles of Data Protection

And the rights of individuals  Core Principles of Data Protection  Data must be processed lawfully, fairly and in a transparent manner Data must be collected for specified, explicit and legitimate purposesThe data collected must be adequate, relevant and limited to...

New Data Retention Guidance

New Data Retention Guidance

This is a subtitle for your new post The UK government recently issued updated guidance on record keeping for academies and trusts to assist them with their record keeping obligations.  Click here to be taken to the Government site....