
The UK Information Commissioner's Office (ICO) has expressed deep concern about the privacy issues presented by using live facial recognition (LFR) technology in public places.
Information Commissioner Elizabeth Denham said she was extremely concerned about the potential for LFR technology to be used recklessly, excessively or inappropriately. She warned that collecting sensitive data on a mass scale without people's control, consent or knowledge could have a significant impact on privacy; and that the public should be able to visit a shopping centre or move around a city without having their biometric data collected and analysed.
To ensure that due regard is given to data protection as LFR becomes more widespread, Denham has published a Commissioner's Opinion on the use of the technology in public places by public organisations and private companies. This stresses the need to put data protection and privacy at the heart of every decision to use LFR technology; and explains that there is a high level of justification under law for the use of LFR technology and related algorithms in public.
The ICO has conducted six investigations into the use, testing or planned deployment of LFR technology - with use cases included creating biometric profiles to target people with personalised ads and public safety concerns. However, none of the organisations from the completed investigations could fully justify the processing of biometric data. Of those systems that went live, none were 100% compliant with data protection law. All the organisations decided to stop, or nor proceed with, the use of LFR technology.
The Commissioner's Opinion notice outlines strict rules of engagement, with organisations needing to show high levels of governance and accountability from the start. They will have to justify that the use of LFR technology is proportionate, necessary and fair for each specific deployment context, and demonstrate that less intrusive technology cannot be used instead.