24/05/24

ICO Order Serco to cease the use of facial recognition technology to monitor attendance

The law that governs the data protection is the retained EU law version of the General Data Protection Regulation (UK GDPR). Following a public consultation, the Information Commissioners Office (ICO) published guidance on the use of biometric data on the 23rd February 2024.

The guidance covers:

  • What is defined as biometric data
  • When that data is considered to be special category data
  • The use of biometric recognition systems
  • The data protection requirements that organisations need to comply with

On the same day, the ICO also published an enforcement notice it had issued against Serco Leisure Operating Limited.

What did Serco do?

Serco used biometric data processing to monitor their employees attendance. They introduced fingerprint scanning and a facial recognition system due to their previous method being allegedly abused by staff.

The ICO found that Serco failed in establishing a lawful basis and special category data processing condition which were required in this circumstance, and found that Serco had breached Article 5(1)a, 6 and 9 UK GDPR.

Contractual necessity

Serco relied on contractual necessity as a lawful basis for processing the biometric data under Article (6)(1)(b) UK GDPR. Serco believed that processing attendance data from employees was necessary to ensure they were paid correctly for the time that they had worked.

The ICO guidance states that where an organisation wishes to rely on a legal basis other that consent, it must show that processing biometric data is necessary to achieve the overall purpose, known as the necessity test.

The ICO applied the necessity test to Serco’s case and found that they could not rely on this ground. There were less intrusive methods of recording attendance available, therefore the processing of the biometric data was not necessary for Serco to fulfil the employment contracts. Serco failed to provide evidence of the alleged extensive abuse or why alternative methods were not considered appropriate.

Legitimate interest

Serco stated that the legitimate interests under Article (6)(1)(f) UK GDPR, was ensuring its staff were paid the correct salary and the administrative and business functions were supported. The ICO applied the necessity test and found that despite necessity not having the processing be absolutely essential, the processing must be more than just useful. The processing must be seen as a targeted and proportionate way of achieving the relevant purpose.

In Serco’s case, using biometric technology to monitor attendance was not considered a targeted way to pay employees correctly. It was also not a proportionate way of overcoming issues of employees abusing the previous system. It was found that:

  • The process of biometric data in this case did substantially impact on privacy. This type of data is considered extremely sensitive. This is because it is unique to each individual and the risk of harm is large if the data is compromised.
  • Serco’s employees were not provided with clear information regarding how they could object to the processing of their biometric data. They were not given any alternative options of methods for monitoring their attendance.
  • There was a power imbalance between the employer, Serco, and its employees.

Special category data

Serco failed to identify the law that was relevant for them to rely on under Article 9(2)(b), the special category processing condition.

The ICO found that:

  • Article 9(2)(b) does not include processing that is undertaken to meet solely employment rights or obligations under an employment contract.
  • Serco had not produced a policy document that was appropriate required under paragraph 1(1)(b) of Schedule 1 of the Data Protection Act 2018.
  • Serco did not, as required under Article 5(1)(a), process the data fairly. It was found that the processing of this biometric data would be likely to or is causing distress to the data subjects.
  • Serco failed to demonstrate to its data subjects how they could object to the processing of the biometric data.

Other relevant facts were that Serco stated that there were alternative options for employees to show their attendance and these would be available, but it was found that these were not brought clearly to employees attention.. Also Serco stated it would subject its employees to disciplinary action if they refused to use the biometric technology.

What can employers learn from this?

It is clear that the ICO took a strict approach in this case and has now prevented Serco from using biometric systems for employee attendance purposes.

Employers often avoid using consent due to the imbalance of power between employee and employer. However, in situations were the use of biometric recognition systems are being considered for attendance purposes, it could be seen that explicit consent is the most appropriate lawful basis and explicit consent is the condition to process special category biometric data.

When seeking to relying on consent, employers would be wise to follow the following steps:

  1. Ensure employees are given an express statement of consent that they can clearly indicate their agreement to (explicit consent)
  2. Ensure that employees have a genuine choice in how the employer uses their biometric data. Employees must be offered a suitable alternative to the biometric systems if they do not provide consent.
  3. Ensure that employees have the opportunity to refuse and/or to withdraw their consent at any time without suffering detriment from the employer.

This is a very complex area and we strongly recommend you take specialist legal advice before implementing any schemes which involve the use of biometric data.

Need advice on an issue relating to employment?
Please contact me directly with this form

    We use your name, email address, company name and telephone number for the sole purpose of providing you with information regarding this specific enquiry. Your information is transferred and stored securely at all times. We never share your information with any third parties. For more details, please read our privacy policy.

    24/05/24

    About the author