Face matching or face recognition: biometric identification
The camera compares faces with a stored list to identify people. Every regime held here treats that as the most sensitive thing a camera does: GDPR and UK GDPR as special category data needing an Art. 9 condition as well as an Art. 6 basis and, in most cases, an assessment first; BIPA as a biometric identifier needing written notice, the purpose and term in writing and a written release before collection; the APPs as sensitive information; the CCPA as sensitive personal information.
- When it is raised
- Raised on every camera whose analytics read as face matching or face recognition, where a regime or a named law is placed at the site. Face detection or blurring never raises it.
- The question
- Which condition or written release covers each person this camera matches, and where is it recorded?
- For
- your lawyer
- The column that settles it
- written release
- On the row
- a numbered delta and the words "face matching" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
GDPR (the EU General Data Protection Regulation)
GDPR Art. 9Processing of special categories of personal dataProcessing of special categories of personal data. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.
GDPR Art. 35Data protection impact assessmentData protection impact assessment. Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.
UK GDPR
UK GDPR Art. 9Processing of special categories of personal dataArticle 9 Processing of special categories of personal data. Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.
UK GDPR Art. 35Data protection impact assessmentArticle 35 Data protection impact assessment. Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.
Illinois Biometric Information Privacy Act (BIPA)
BIPA s. 15(a)Written, public retention schedule and destruction guidelines, appliedWritten, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.
BIPA s. 15(b)(1)Written notice that a biometric identifier or information is being collected or storedWritten notice that a biometric identifier or information is being collected or stored. Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.
BIPA s. 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and useWritten notice of the specific purpose and length of term of collection, storage and use. Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).
BIPA s. 15(b)(3)Written release executed by the subject or representative before collectionWritten release executed by the subject or representative before collection. Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.
Australian Privacy Principles (APPs)
APP APP 3Collection of solicited personal informationAPP 3 - Collection of solicited personal information. Only collect personal information that is reasonably necessary for the entity's functions or activities, by lawful and fair means.
California Consumer Privacy Act (CCPA, as amended by the CPRA)
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal InformationRight to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.
Named, not quoted
- Data Protection Act, Schedule 1: the conditions for special category and criminal offence data (United Kingdom; named, not quoted)
- ICO guidance on video surveillance: the regulator's guidance for CCTV, including facial recognition (United Kingdom; named, not quoted)
- Texas Business and Commerce Code, chapter 503: capturing a biometric identifier for a commercial purpose: informing the person and consent before capture, destruction within a year of the purpose ending (Texas; named, not quoted)
- Revised Code of Washington, chapter 19.375: enrolling a biometric identifier for a commercial purpose: notice, consent or a mechanism to prevent later use (Washington; named, not quoted)
- New York City Administrative Code, sections 22-1201 to 22-1205: a clear sign near every customer entrance of a commercial establishment that collects biometric identifier information (New York City; named, not quoted)
- Australian Privacy Principle 3.3: consent to collect sensitive information, which includes biometric templates (Australia; named, not quoted)
- CCPA definition of sensitive personal information, 1798.140: whether biometric information processed to identify a consumer is sensitive personal information (California; named, not quoted)