Site navigation

ICO Publishes Draft Guidance on Biometric Data Use in the UK

Thom Carter

,

ICO Publishes Draft Guidance on Biometric Data Use in the UK
The Information Commissioner’s Office (ICO), the UK’s independent body for upholding information and data rights, has published the first draft of its guidance on the use of biometric data and technologies.

Biometric data is personally identifiable information, and relates to somebody’s biological and behavioural characteristics, and has been extracted or analysed by technology. Biometric technologies are used in a variety of ways, from iris scanning to fingerprint recognition.

The regulator’s draft biometric data guidance is for organisations using — or considering the use of — biometric recognition systems, as well as vendors of these systems. It lays out how data protection law applies when using biometric data in biometric recognition systems, and offers relevant advice.

For instance, it stipulates that a data-protection-by-design approach must be undertaken, advocates that a Data Protection Impact Assessment (DPIA) should be carried out before using a biometric recognition system, and suggests what to do concerning the risks of discrimination, among other things.

However, and highlighting how the draft guidance isn’t completely extensive, the ICO noted that “This guidance is not intended to be a comprehensive guide to compliance when using biometric data. Where this guidance refers to principles already addressed in our guidance, we provide links to the relevant further reading.”

A consultation on the regulator’s draft guidance will now run until 20 October. The second phase of the guidance, which is set to cover biometric classification and data protection, will launch early next year and include a call for evidence, the ICO has said.

In October last year, the ICO warned that “immature” biometrics technologies could pose data privacy risks or discriminate against vulnerable groups. The warning came after an investigation into the potential challenges that may emerge from the development of biometric technologies.

While biometrics and its associated technologies can — and already does — offer numerous opportunities, particularly concerning security, accessibility, and convenience, there are various pitfalls. Not least, as the ICO stated in the investigation report regarding biometric data being misplaced or taken: “Unlike passwords, if your biometrics data is lost or stolen, you cannot easily change your fingerprint, face or retina.”

In terms of some key risks with myriad biometrics, the ICO’s investigation report highlighted the potential for systemic bias via underlying algorithms in facial recognition. Pupillometry, meanwhile — the measuring of the size and response of a person’s pupil to stimuli — may reveal subconscious responses and highly personal data without the individual’s choice. Further, brain analysis may also reveal subconscious responses and highly sensitive personal data.


Recommended reading


Relatedly, and just two months ago, the ICO released a warning on neurotechnology and discrimination.

The regulatory body predicted that neurotech — technology which has been developed to interface with the nervous system, such as to monitor or modulate the brain — will become widespread over the next ten years and that, if not appropriately trialled and tested, there’s a risk that that inherent bias and inaccurate data could become embedded in neurotech.

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data