Jump to content

Recommended Posts

Posted

Hello.

 

Our DPO is Veritau and our onsite rep (Assistant Head) had an audit with them this week to see what we're doing right and wrong.

 

My colleague confidently stated that we don't use biometrics anywhere in school - until the Veritau person asked "...any iPads...?"

 

Staff iPads all have Touch ID fully enabled, student iPads have it enabled for iTunes but not for screen unlock.

 

Has anyone crossed the bridge of GDPR vs Touch ID before, or equivalents on Android etc?

 

Did you obtain opt-in permission to use and store their biometric data for the purposes of unlocking iPads?

 

(I'm kinda playing devils advocate here, because I believe the bio data is stored in the locked security chip on the device? And the use of touch ID is entirely down to the staff/student concerned to voluntarily register their fingerprint on the device itself - but I need some sort of an answer to give to the assistant head so looking for other folks views?)

 

Peter

Posted
I may be oversimplifying this but as long as you are not actually using it for pupil logons then you should be fine regarding not requiring consent. As if staff are using it (or you are using it for IT admin logon) then that is just a daily procedural thing and not subject to explicit permission. (though it may need to be noted in documentation).
  • Thanks 1
Posted
If the staff choose to store their biometric data on the iPad (and the school doesn't make it compulsory), then surely that is that. The school doesn't use the biometric data for anything systematic, it is stored in an encrypted form purely on the device if the staff choose to do so. I doubt the ICO would have any issue with such a system.
  • Thanks 1
Posted

Not sure it matters but the biometric data is stored encrypted on the Touch ID sensor itself and not actually on the device. Each sensor is unique to that device and the OS doesnt have direct access to the biometric data.

 

In my eyes this should make it okay.

Posted

1 - it is biometric Data and so covered by the Protection of Freedoms Act

2 - you require a clear purpose (ensuring devices remain secure and able to be used for delivery of curriculum and running of the school?)

3 - you require lawful basis under both Art. 6 and Art. 9 of GDPR.

 

A DPIA could be done to cover the specific use of Biometric data in this instance or Biometric data in general.

 

Your DPO should assist you in this.

Check https://www.educationdatamatters.org.uk for example templates for DPIAs that could be used to kick start this.

 

I’m interested to catch up with the Veritau team about the EDM site. Are you able to PM me with your contacts’ details? TIA.

Posted (edited)

Hi GrumbleDook

 

The thing is, we don’t require anyone to use TouchID, and it is actively skipped in the Apple setup wizard.

 

Staff and students are choosing to go into settings and enable it, we don’t require it to secure devices and deliver curriculum etc etc etc.

 

Similarly a SAR or Right to Erasure would be impossible as we don’t have any access to that biometric data - it’s not a bio fingerprint/datapoint stored on our servers for the purpose of cross-platform authentication etc.

 

Is this not different?

 

Peter

Edited by howartp
Posted
The school doesn't use the biometric data for anything systematic, it is stored in an encrypted form purely on the device if the staff choose to do so

 

That was my first thought too, but then I asked myself how is this different to biometric in the canteen, which does require consent? The school doesn't require that either, it is stored encrypted, the school can't access it, and it was voluntarily given. Therefore I think we probably should make a record of this in the documentation somewhere. Same goes for mobiles with biometrics on them.

Posted
That was my first thought too, but then I asked myself how is this different to biometric in the canteen, which does require consent? The school doesn't require that either, it is stored encrypted, the school can't access it, and it was voluntarily given. Therefore I think we probably should make a record of this in the documentation somewhere. Same goes for mobiles with biometrics on them.

 

Biometric in the canteen is stored in an SQL type database on a server or kitchen PC (which could be stolen or remotely hacked into) so that multiple biometric endpoints (tills and revals) can use it; touchID is in a secure proprietary chip within the individual iPad and even if the iPad is stolen or hacked, it's not just an SQL database with a network password protecting it.

Posted
Hi GrumbleDook

 

The thing is, we don’t require anyone to use TouchID, and it is actively skipped in the Apple setup wizard.

 

Staff and students are choosing to go into settings and enable it, we don’t require it to secure devices and deliver curriculum etc etc etc.

 

Similarly a SAR or Right to Erasure would be impossible as we don’t have any access to that biometric data - it’s not a bio fingerprint/datapoint stored on our servers for the purpose of cross-platform authentication etc.

 

Is this not different?

 

Peter

 

Subject rights are not absolute. a SAR for biometric data is often rejected as it is something already held by the person. Right to erasure is simple enough ... you remove the records from the device. If that means you have to physically do it on teh device or send an instruction to the end user how to do it ... it covers it.

 

If the end user sets it up in the first place then that needs to be considered in the risk assessment. You might decide to prevent that facility completely. You might have a statement in the handover docs to say that the function is turned off by default but if they chose to enable it, then it is their choice and you accept no control, but reserve the right to remove the function at a later date (appropriate details in your data retentions schedule and any other docs to that affect too).

 

Another approach could be to consider that if you as a data controller don't require it, then you could have in your risk assessment that it is personal use of data, and not under your remit ...

 

Whichever way it goes, document the decision, be clear about it to end users and make sure you still have control over other aspects of the devices (which will be processing data on the school's behalf).

Posted
Biometric in the canteen is stored in an SQL type database on a server or kitchen PC (which could be stolen or remotely hacked into) so that multiple biometric endpoints (tills and revals) can use it; touchID is in a secure proprietary chip within the individual iPad and even if the iPad is stolen or hacked, it's not just an SQL database with a network password protecting it.

 

Biometric is biometric. Your risk assessment will take into account the technology and judge any risks appropriately.

Posted
Biometric in the canteen is stored in an SQL type database on a server or kitchen PC (which could be stolen or remotely hacked into) so that multiple biometric endpoints (tills and revals) can use it; touchID is in a secure proprietary chip within the individual iPad and even if the iPad is stolen or hacked, it's not just an SQL database with a network password protecting it.

 

I'm not sure that's true - part of the sales pitch for the biometrics was how the data is stored in such a way that it can't be reverse-engineered into a fingerprint, so we're not actually storing biometric data in an accessible way. If that's the case, I don't see how the tills differ from the iPads/phones.

  • Thanks 1
Posted

The bio-metric data stored is not a fingerprint or an encrypted fingerprint. Its a value that was derived from a fingerprint, this cannot be used to identify a person outside of its ecosystem.

 

To oversimplify the data held is number + fingerprint = this number. You can confidently state that reversing that into identifiable data (outside of the ecosystem) or a fingerprint is impossible.

Posted
The bio-metric data stored is not a fingerprint or an encrypted fingerprint. Its a value that was derived from a fingerprint, this cannot be used to identify a person outside of its ecosystem.

 

To oversimplify the data held is number + fingerprint = this number. You can confidently state that reversing that into identifiable data (outside of the ecosystem) or a fingerprint is impossible.

 

And this is where I start to jump up and down and tell people not to focus on one bit ... the encryption/the string/the hardware used for scanning/whatever else is used to justify that it is not biometric data.

 

Article 4(13) of GDPR has the following definition

‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data

 

If the processing of data is taken from a physical or physiological characteristic (in this case, a fingerprint), then you are processing biometric data. Whether you can reverse the subsequent data string to form a functioning example of that biometric data or not is irrelevant. You are processing biometric data. You provide the kit, you control it, you are giving people the option to use it, then you either accept that you (as data controller) are making a decision on what is processed, or you have some way to show that the decision is down to the individual as part of their processing of their own data for personal use.

 

I am very serious when I say that there are groups that are very concerned about the use of biometric data and the lack of concern schools show in using it.

Posted

"What are the conditions for processing special category data?

Article 9 lists the conditions for processing special category data:

 

(a) Explicit consent"

Posted
You provide the kit, you control it, you are giving people the option to use it, then you either accept that you (as data controller) are making a decision on what is processed, or you have some way to show that the decision is down to the individual as part of their processing of their own data for personal use.

 

So, if I'm reading you correctly, what you're saying is if we can demonstrate the iPad/phone was given to the user in straight-out-of-the-box configuration and they chose to enable fingerprint identification, we need neither worry about nor declare the processing - correct?

Posted
IMHO a "Biometric Authenticator" such as a value derived from your interaction with the ipad fingerprint reader isn't covered by GDPR. The GDPR is concerned about "Biometric Identifiers" These would be photos of your face OR a picture of your fingerprint. Whilst a "Biometric Authenticator" can be used in the process of identification the value stored or processed from the authenticator do not meet the definition of a "Biometric Identifier".
Posted
IMHO a "Biometric Authenticator" such as a value derived from your interaction with the ipad fingerprint reader isn't covered by GDPR. The GDPR is concerned about "Biometric Identifiers" These would be photos of your face OR a picture of your fingerprint. Whilst a "Biometric Authenticator" can be used in the process of identification the value stored or processed from the authenticator do not meet the definition of a "Biometric Identifier".

 

Can you give a definition, as set out in any legislation, agreed standard (not a patent) or any legal case for ‘Biometric Authenticator’ that shows it is not processing biometric information in a manner that can identify a person?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...