FB pixel

UK school reprimanded by ICO for using facial recognition without DPIA

Proper consent also not obtained
Categories Biometrics News  |  Facial Recognition  |  Schools
UK school reprimanded by ICO for using facial recognition without DPIA
 

A school in Chelmsford, Essex, has been reprimanded by the Information Commissioner’s Office (ICO) for the unlawful implementation of facial recognition technology (FRT) in its canteen.

Chelmer Valley High School, which serves 1,200 students aged 11-18, began using FRT in March 2023 to facilitate cashless payments. However, the use of FRT, which processes biometric data for individual identification, carries data protection risks, and is regulated by the ICO. Organizations deploying such technology are required by law to conduct a data protection impact assessment (DPIA) to manage these risks.

Chelmer Valley High School failed to perform a DPIA before implementing FRT, neglecting to assess the potential risks to students’ information, the ICO says. Additionally, the ICO reports that the school did not secure clear permission to process students’ biometric data, nor did it offer students the choice to opt-in to the system.

Lynne Currie, ICO head of privacy innovation, emphasizes the importance of proper data handling in school environments. “Handling people’s information correctly in a school canteen environment is as important as handling the food itself,” she says.

“We expect all organizations to carry out the necessary assessments when deploying a new technology to mitigate any data protection risks and ensure their compliance with data protection laws.”

Currie stresses that the ICO’s action against Chelmer Valley High School underscores the gravity of introducing measures like FRT, particularly involving children.

In March 2023, a letter was sent to parents allowing them to opt-out their children from FRT, but the affirmative opt-in consent the law requires was not sought. This oversight continued until November 2023, during which the school relied on assumed consent. The law requires explicit permission, and most students were capable of providing their own consent, which the school did not seek, thus infringing on their rights.

Currie adds: “A DPIA is required by law – it’s not a tick-box exercise. It’s a vital tool that protects the rights of users, provides accountability, and encourages organizations to think about data protection at the start of a project.”

The ICO made five recommendations to the school for how it can ensure compliance with UK GDPR.

Similarly, In October 2021, over 2,000 students across nine schools in Scotland began using facial recognition to pay for their lunches. The system required students to present themselves in front of a camera at the till, where staff operated the technology. The camera matched each student to their registered photo, automatically deducting the day’s meal cost from their account. The ICO informed North Ayrshire Council (NAC) that its use of facial recognition for lunch payments is likely to have infringed data protection law under the following articles of the UK GDPR.

The ICO has been getting steadily busier, despite not taking over the regulation of biometrics as planned, due to the failure of the DPDI Bill. The agency’s total spending for the 2023/24 fiscal year was £11.6 million higher than the previous fiscal year, according to PublicTechnology. The ICO spent 15.3 percent more than the year before, some of it targeted to digital, data and technology work, but largely attributed to increased staffing costs.

Related Posts

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Armenia gets patriotic with biometric passports, ID cards coming in fall 2026

Armenia has a new biometric passport. A release from the government says the prime minister, Nikol Pashinyan, can confirm that…

 

AI fraud threat and expanding IDV market presence drives Socure ARR past $340M

Socure’s new annual recurring revenue from its digital identity verification and biometrics and fraud prevention technologies grew by 62 percent…

 

Governance, not tech, needs interrogating in UK digital ID consultation: Tony Allen

Few people in the world, if any, know as much about age assurance as Tony Allen, the chief executive of…

 

FIDO Alliance to start work on interoperable standards for agentic commerce

The FIDO Alliance has announced initiatives to develop interoperable standards for agentic interactions and commerce, and it has a new…

 

Police policy on facial recognition use earns OK in Lawton, needed in Sante Fe

The Lawton, Oklahoma City Council approved a policy governing police use of facial recognition technology (FRT), moving the city closer…

 

EU recommends white label age verification app, but member states are wary

The European Commission really wants member states to adopt its white label age verification app – and quickly. This week,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events