Is face matching on CCTV biometric data under GDPR and BIPA?
Compares faces in the picture with a stored list of faces (a watchlist, staff, known people) to identify who they are. That is biometric data processed to identify a person: special category data under GDPR and UK GDPR, a biometric identifier under BIPA, and the use the EU AI Act looks at hardest.
- Biometric identification
- yes: it compares faces to identify people
- May infer emotion
- no
- May infer a sensitive characteristic
- no
- May be an AI system
- yes
- Read from words such as
- face recognition
Yes, where it compares faces with stored ones to identify people. GDPR and UK GDPR Art. 9 list biometric data processed to identify a person as special category data, which needs an Art. 9 condition as well as an Art. 6 basis. BIPA treats the face template as a biometric identifier and asks for written notice, the purpose and term in writing and a written release before collection. Face detection or blurring, which does not compare faces, is not identification.
Findings it can raise, with the list
- 1 Face matching or face recognition: biometric identification
- 4 Public area monitored with no assessment recorded
- 5 No retention period set, or retention above the maximum you set
- 6 No signage or notice recorded
- 7 Footage stored outside the site's region: who can access it there?
- 8 A third party can view or manage the footage, and no agreement is recorded
- 12 High-risk AI use in an EU workplace
- 13 No owner, or no list of who can view
- 14 Disclosures to police or insurers not logged
- 15 Covert camera
- 16 Children in view of face matching or demographic estimation
Clauses this analytics type adds
12 clausesGDPR Art. 9Processing of special categories of personal dataProcessing of special categories of personal data. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.
UK GDPR Art. 9Processing of special categories of personal dataArticle 9 Processing of special categories of personal data. Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.
BIPA s. 15(a)Written, public retention schedule and destruction guidelines, appliedWritten, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.
BIPA s. 15(b)(1)Written notice that a biometric identifier or information is being collected or storedWritten notice that a biometric identifier or information is being collected or stored. Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.
BIPA s. 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and useWritten notice of the specific purpose and length of term of collection, storage and use. Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).
BIPA s. 15(b)(3)Written release executed by the subject or representative before collectionWritten release executed by the subject or representative before collection. Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.
BIPA s. 15(c)No sale, lease, trade or other profit from biometric identifiers or informationNo sale, lease, trade or other profit from biometric identifiers or information. No private entity in possession of a biometric identifier or biometric information may sell, lease, trade or otherwise profit from a person's or a customer's biometric identifier or biometric information. The prohibition is absolute; consent does not authorise it. Courts have distinguished profiting from the data itself, which is banned, from charging for a product or service that uses biometrics, which is not.
BIPA s. 15(e)(1)Reasonable standard of care within the entity's industryReasonable standard of care within the entity's industry. A private entity in possession of biometric identifiers or biometric information shall store, transmit and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity's industry. The measure is what a reasonable entity in the same industry does for such data, which makes industry security standards and practice the yardstick.
APP APP 3Collection of solicited personal informationAPP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal InformationRight to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.
EU AI Act Art. 4AI literacyAI literacy. Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.
EU AI Act Art. 6Classification rules for high-risk AI systemsClassification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.